Privileged Access Management
Vault design, rotation policy, least-privilege scoping, and the unglamorous work of keeping a large secret inventory clean, current, and defensible at audit time.
type help in the terminal
// operator profile
Senior security professional with roughly three and a half decades in IT, the last several years focused on privileged access management. I build and run the tooling that keeps credentials rotated, access scoped, and audits boring — mostly around Delinea Secret Server, PowerShell automation, and the SIEM stack that watches all of it.
// focus areas
Vault design, rotation policy, least-privilege scoping, and the unglamorous work of keeping a large secret inventory clean, current, and defensible at audit time.
PowerShell-first tooling that turns manual credential and permissions work into repeatable, reportable processes — built to survive contact with a real production environment.
SIEM integration and tuning, mail-security administration, and the day-to-day operational discipline that keeps detection signal ahead of noise.
Gap analysis and reporting that maps technical control state to the language auditors and leadership actually need to see.
// notes from the field
Notes on staged rotation for service accounts with hard-coded dependencies, and how to find those dependencies before they find you.
A practical approach to alert-fatigue triage: what to mute, what to escalate, and how to tell the difference without guessing.
How gap analysis on a large vault environment turns into a report someone outside security can actually read and act on.
// off the grid
Outside of vault work I run a permanent Reticulum propagation node and hold a General class amateur radio license. I like infrastructure that keeps working when the usual infrastructure doesn't — which probably explains both the day job and the hobby.
Received transmission, shift unknown. The band tells you the number.
// restricted
A minimal secret store demo. Doesn't hold anything real — but the passphrase check is.
// connect
Open to conversations about PAM, security automation, and the occasional mesh-networking tangent. Reach out through your channel of choice.