Skip to content
View ChromeData's full-sized avatar

Block or report ChromeData

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ChromeData/README.md

Michael, Privileged Access and Cloud Security Engineer

Hi, I'm Michael πŸ‘‹

LinkedIn Labs

I'm a privileged access and cloud security engineer working where PAM meets cloud infrastructure. The accounts, secrets, and escalation paths that most tooling treats as two separate problems, I treat as one.

I learn by building the thing and writing down where it broke. Everything below is a real lab: a real environment stood up, real tooling run against it, and honest notes on what failed. Right now I'm building secrets management patterns that put a CyberArk/Idira lens on cloud native tooling. That is my main focus.

πŸ”§ What I'm building

  • PAM x Cloud Labs: 11 hands on labs across CyberArk/Idira, Linux, AWS, and Azure. Each documents what I built, what broke, and what I would do differently.
  • Conjur to Terraform secrets injection: provisioning AWS with zero credentials in Terraform state, proven by an automated check.
  • Shadow admin audit: scoring CyberArk's SkyArk against known escalation paths in AWS and Azure.
  • Secrets Manager as a PAM control plane: a CyberArk engineer's honest evaluation of the cloud native alternative to a vault.
  • Full index in the labs repo: Kubernetes RBAC, RHEL 9 hardening, Sentinel detections, IAM least privilege, and more.

πŸ›‘οΈ Focus areas

Privileged Access Management Β· Secrets Management Β· IAM least privilege Β· Policy as code Β· Cloud security posture Β· Infrastructure as code

πŸ“œ Certifications

Privileged Access, CyberArk/Idira

CyberArk Guardian CyberArk Sentry CyberArk Defender

Linux, Red Hat

RHCSA RHCE

Identity and Security

SC-300 Security+ Network+

Education

WGU WGU

🧰 Tech I work with

Terraform Ansible Kubernetes PowerShell Linux Python

Connect

LinkedIn GitHub


Pinned Loading

  1. Conjur-Kubernetes-KubiScan Conjur-Kubernetes-KubiScan Public

    Conjur secrets on Kubernetes + KubiScan RBAC audit

    Python

  2. Conjur-Terraform-AWS Conjur-Terraform-AWS Public

    Conjur secrets injection into a Terraform/AWS pipeline β€” zero credentials in state

    HCL

  3. PAM-Cloud-Labs PAM-Cloud-Labs Public

    Hands-on labs at the intersection of privileged access management and cloud infrastructure β€” CyberArk/Idira, Linux, AWS, Azure

    Python

  4. psPAS-PAM-Automation psPAS-PAM-Automation Public

    CyberArk/Idira PAM lifecycle automation with psPAS (PowerShell)

    PowerShell

  5. Secrets-Manager-PAM Secrets-Manager-PAM Public

    AWS Secrets Manager as a PAM control plane β€” rotation + an honest CyberArk comparison

    HCL

  6. SkyArk-Shadow-Admin-Audit SkyArk-Shadow-Admin-Audit Public

    Shadow-admin discovery across AWS + Azure, scoring CyberArk SkyArk against known escalation paths

    Python