Perth, Western Australia

Cloud Identity & Security Engineer
Azure IAM Specialist

Results-driven Cloud Identity & Security Engineer with 5+ years of experience designing and managing IAM solutions across hybrid cloud and on-premises environments. Specialist in Microsoft Entra ID, Zero Trust architecture, and identity lifecycle automation (Joiner-Mover-Leaver). AZ-104 certified; SC-300 in progress. Proficient in Conditional Access, PIM, SAML 2.0, OAuth 2.0, OIDC, and SCIM. Aligned identity governance with ISO 27001:2022 and COBIT 2019 frameworks.

Professional Experience

2025 – Present

Independent IT & Cloud Identity Consultant

Self-Employed · Perth, WA

Design and implement Microsoft Entra ID identity governance solutions for SMB clients — Conditional Access policies, MFA enforcement, and RBAC assignments in hybrid environments. Automate Identity Lifecycle Management (JML) workflows using PowerShell and Microsoft Graph API, achieving a 40% reduction in manual provisioning effort. Architect Zero Trust security postures applying Least Privilege and continuous access evaluation across Microsoft 365 tenants. Develop n8n-based IAM automation workflows integrating GitHub, PostgreSQL, and REST APIs on a self-hosted Ubuntu server.

Microsoft Entra ID JML Automation Zero Trust Conditional Access PowerShell Graph API
Jan 2024 – Jan 2025

Identity Management Analyst

TEUNO · Financial Services · Remote, Ecuador

Administered enterprise IAM platform supporting 500+ user identities across financial services infrastructure. Redesigned VPN provisioning workflow integrating IAM controls, reducing ticket resolution time by 60% while enforcing Least Privilege access. Implemented and maintained RBAC policies covering the full JML identity lifecycle, ensuring timely provisioning and deprovisioning. Maintained ISO 27001:2022 compliance through user access reviews, entitlement certifications, and audit log analysis. Managed identity federation using SAML 2.0 and OAuth 2.0 for SSO integrations between on-premises Active Directory and cloud applications.

Azure AD / Entra ID SAML 2.0 / OAuth 2.0 JML ISO 27001 RBAC MFA
Apr 2023 – Jan 2024

Management System Analyst

Security Data · On-site, Ecuador

Conducted ISO 27001:2022 and COBIT 2019 gap analyses for enterprise clients across financial, logistics, and public sector verticals. Developed access control policies, PAM procedures, and identity governance documentation for ISMS implementations. Supported privileged access reviews and entitlement certification campaigns, producing audit-ready reports for compliance teams. Streamlined ITSM workflows in ServiceNow, reducing mean time to resolution by 25%. Advised clients on Zero Trust security architecture improvements covering network segmentation and identity perimeters.

ISO 27001:2022 COBIT 2019 PAM Zero Trust ServiceNow ISMS
Sep 2020 – Nov 2022

IT Support Engineer

Frenos y Frenos · Automotive Sector · Multi-site, Ecuador

Administered on-premises Active Directory (AD DS) for 200+ endpoints — managing user accounts, group policies, and access control lists. Provided L2/L3 technical support for Microsoft 365 and network infrastructure, maintaining 99%+ uptime SLA and resolving identity and access-related incidents. Administered VPN access controls and endpoint security policies for remote workforce. Led end-to-end migration of the accounting system to a cloud-based platform, reducing manual data entry by 20%.

Active Directory Microsoft 365 L2/L3 Support VPN Cloud Migration

Skills & Technologies

Identity & Access Management

Azure AD / Entra ID Active Directory RBAC SSO / SAML MFA VPN Access Control User Lifecycle CyberArk Okta / SailPoint Conditional Access PIM Zero Trust OAuth 2.0 / OIDC SCIM

IT Support & ITSM

L1 & L2 Help Desk ServiceNow ManageEngine Microsoft 365 Windows 10/11 macOS Device Provisioning

Security & Compliance

ISO 27001:2022 COBIT 2019 NIST CSF Microsoft Sentinel Splunk (SIEM) CrowdStrike Microsoft Defender Internal Auditing

Cloud & Infrastructure

Microsoft Azure Windows Server Ubuntu / Linux Docker Cloud Migration ICT Asset Management Azure Key Vault

Scripting & Automation

PowerShell Bash n8n REST APIs Prompt Engineering AI Workflow Automation Microsoft Graph API Azure Logic Apps

Networking

TCP/IP VPN DNS / DHCP LAN/WAN Network Security

Certifications & Education

Bachelor's in Networks & Telecommunications

Universidad de las Américas (UDLA) — Quito, Ecuador

Completed

Diploma in Cybersecurity

Universidad de las Américas (UDLA) — Quito, Ecuador

Completed

Diploma of Project Management

NIT Australia — Perth, WA

In Progress (Sep 2025)

ISO 27001:2022 Internal Auditor

Information Security Auditing

Certified

Information Security Management Professional

ISO 27001:2022

Certified

COBIT 2019 Fundamentals

IT Governance Framework

Certified

Microsoft AZ-104

Azure Administrator Associate

Achieved — 2026

Master of Science — Information Security Management

Universidad de las Américas (UDLA) — Ecuador

Completed — Nov 2023

Microsoft SC-300

Identity and Access Administrator Associate

In Progress — 2026

Microsoft AZ-500

Azure Security Engineer Associate

Planned — Late 2026

Microsoft SC-200

Security Operations Analyst Associate

Planned — Late 2026

ITIL v4 Foundation

IT Service Management · Target Q3 2026

In Progress

Featured Projects

IAM Sentinel

AI-powered Identity Lifecycle Platform built on Microsoft Entra ID. Automates Joiner/Mover/Leaver operations with AI risk scoring, ISO 27001 audit evidence, drift detection, and Slack approval workflows.

Microsoft Entra ID Graph API Next.js Anthropic Claude ISO 27001 TypeScript

Zero Trust Identity Lab

Entra ID Conditional Access policies, MFA enforcement, Named Locations, and Continuous Access Evaluation configured on a test tenant — documented as a hands-on Zero Trust implementation reference.

Microsoft Entra ID Conditional Access Zero Trust MFA PIM

SCIM Provisioning Integration

Protocol-level implementation of SCIM 2.0 user provisioning via Microsoft Entra ID — automating cross-system identity sync between the identity provider and downstream SaaS applications.

SCIM 2.0 Microsoft Entra ID Identity Provisioning Graph API

PureSpot Cleaning — Web App

Single-page web app for a cleaning business with integrated AI chat agent (Anthropic API), service booking logic, and location-aware service area filtering. Live at purespot.com.au.

Anthropic AI JavaScript REST API Netlify

Get in Touch

Interested in working together or have a question? Feel free to reach out through any of the channels below.