Identity & Access Management Engineer — United States
About this portfolio
These projects are built to mirror the real work of an Identity & Access Management professional in enterprise environments — hybrid identity, privileged access, lifecycle automation, and access governance.
Each lab is hands-on: directories stood up from scratch, federation and SSO wired end-to-end, and the identity lifecycle automated across Active Directory, Entra ID, and Okta. The goal is to show how identity is designed, automated, and secured at scale — not just that the tools were touched.
| Project | What it proves | Stack | Status |
|---|---|---|---|
| Enterprise Identity Lab | Hybrid identity built from the ground up: on-prem AD synced to Entra ID via Entra Connect, with SAML SSO federated to Salesforce. | Active Directory · Entra ID · Entra Connect · SAML · Conditional Access | |
| Okta Identity Lab | Six-part lab covering Okta Workforce Identity end-to-end — Universal Directory, SAML/OIDC federation, phishing-resistant MFA, SCIM provisioning, Workflows, and Python API automation. | Okta · SAML · OIDC · SCIM · MFA · Python | |
| CyberArk PAM Lab | Privileged access deployment — Vault, PVWA, CPM, and PSM integrated with Active Directory for credential vaulting and session control. | CyberArk · Vault · PVWA · CPM · PSM · AD | |
| Identity Governance (IGA) Lab | Policy-driven provisioning, access certifications, and separation-of-duties enforcement in a dedicated IGA platform. | IGA · SailPoint · RBAC · Access Reviews |
Focus area: Managing identity across hybrid environments — bridging on-prem Active Directory with Entra ID and Okta, and automating the identity lifecycle so access stays consistent, least-privilege, and auditable at scale. Privileged access (CyberArk) and identity governance (IGA) labs are next.
Click any badge to verify the credential.
📍 United States · 🌐 alvinalves.com · 💼 LinkedIn