IT Security Specialist
Ilisagvik Tribal College
6/2025 – Present
- Administered Microsoft Entra ID (Azure AD), integrating Conditional Access, MFA enforcement, SSPR, Seamless SSO, identity delegation, least privilege.
- Implemented identity federation by integrating Zendesk with Active Directory for SSO.
- Managed JML full identity lifecycles, AD GPO, privileged access, and security policies to maintain least‑privilege and compliance requirements.
- Architected SharePoint sites, governed internal and external user access, and led the migration of on‑prem network drives to SharePoint; integrated Cyturus GRC platform with SharePoint for centralized audit evidence storage.
- Led GRC initiatives aligned with NIST SP 800‑171 CMMC Level 2, GLBA, and PCI DSS by performing gap and risk assessments, implementing and validating controls, and producing POA&Ms, policies, SOPs, and audit evidence in the Cyturus GRC platform and SharePoint.
- Investigated and remediated security incidents across M365 Defender, Cisco Meraki firewall, Cisco Secure Endpoint, and Sophos EDR.
- Conducted vulnerability scanning using Qualys, Greenbone, OpenVAS, and Belarc, and performed remediation using ManageEngine.
- Applied automation using PowerShell, Power Automate, and Python to streamline administrative and security tasks.