Open to Full-Time Opportunities
// Raleigh/RTP, NC · Healthcare IT Security

MarkSchwinnRaleigh/RTP

I protect organizations from the inside out. Deep hands-on experience in identity management, access control, and healthcare security, building defenses that actually hold.

Mark Schwinn
MARK_SCHWINN.EXE // LOADED
Network
Raleigh/RTP
Status
Active
Identity ManagementActive DirectorySailPointEntra IDCisco ISEHIPAA SecurityMFA & SSORBACAWS CloudZero TrustIncident ResponsePythonTerraformPowerShell Identity ManagementActive DirectorySailPointEntra IDCisco ISEHIPAA SecurityMFA & SSORBACAWS CloudZero TrustIncident ResponsePythonTerraformPowerShell
About

Who I Am

I've spent the last year embedded inside a major regional health system, in one of the most tightly regulated environments security touches. I've seen what real enterprise security looks like from the inside: the vulnerabilities nobody talks about, the access controls that slip through the cracks, the systems that look secure but aren't.

That experience translates directly. Identity, access governance, and security operations don't stop being hard problems outside of healthcare, they just lose one extra layer of regulatory pressure. Not textbook knowledge. Real world defense, wherever it's applied.

I'm building something on the side too: practical security and career help for individuals, not enterprise contracts. Getting your resume noticed, locking down your own accounts, mapping out a path into this field. The same skillset, just scaled down to a person instead of an organization.

4+
SECURITY TOOLS BUILT & SHIPPED
16
AUTOMATED HIPAA CHECKS BUILT
60-100+
ACCESS TICKETS RESOLVED WEEKLY
✓ CompTIA Security+
✓ Google Cybersecurity
↗ B.S. IT & Cybersecurity · 4.0 GPA
↗ AWS Solutions Architect Associate · Expected Oct 2026
Get In Touch LinkedIn Profile
IAM ArchitectureAccess GovernanceHIPAA ComplianceThreat DetectionCloud SecurityIdentity LifecycleIncident ResponseZero TrustPython AutomationHealthcare IT
// 01
Enterprise Scale Experience
Managing identity and access operations inside a large, HIPAA-regulated healthcare environment daily. High-stakes security work where the wrong call affects patient care.
// 02
Healthcare Security Specialist
HIPAA compliance and patient data protection aren't theory to me. They're the environment I operate in every single day, on a live, large-scale identity system.
// 03
Builder, Not Just Analyst
I don't just work tickets. I build tools that automate the checks most teams skip, ship them publicly, and document how they work.
// 04
Actively Growing
AWS Solutions Architect Associate expected October 2026, a 4.0 in a B.S. in IT & Cybersecurity, and a growing portfolio of independent Terraform and AWS projects. Deliberately building toward cloud security engineering.
Technical Stack

Tools I Operate

// Identity & Access
SailPoint IAMMicrosoft Entra IDActive DirectoryCisco ISEMFA / SSORBAC / PAMZero Trust
// Security & Compliance
HIPAA FrameworksIncident ResponseAccess AuditingThreat DetectionRisk AssessmentSecurity Operations
// Cloud & Infrastructure
AWSAzure ADMicrosoft 365CitrixEpic EHRVPN Administration
// Dev & Tools
PythonServiceNowGitHubKali LinuxWiresharkWindows / macOSTerraformPowerShell
Portfolio

Things I've Built

HIPAA // Assessment // Practice Scenario
Keystone Family Dental
A sample engagement walking through a 7-person dental practice with critical HIPAA violations, including no MFA, shared credentials, no access controls, and no security policies. A realistic look at how I'd assess, remediate, and document an environment like this.
HIPAAM365 SecurityIAMPolicy DevelopmentHealthcare
Read Full Case Study →
Python // AWS // HIPAA
HIPAA AWS Compliance Checker
An automated Python tool that scans AWS environments for HIPAA security compliance gaps. It generates reports identifying violations along with prioritized remediation steps, built from real healthcare security knowledge.
PythonAWSHIPAAAutomation
github.com/markthedev12 →
AWS // IAM // S3 // KMS
AWS Secure S3 Lab
I architected and deployed a security hardened S3 environment implementing IAM least privilege policies, KMS server side encryption, restrictive bucket policies, and full public access blocking.
AWSIAMS3KMSBucket Policies
github.com/markthedev12 →
Python // IAM Governance // Automation
IAM Access Review Bot
An automated access certification tool that compares real access exports against defined role baselines, flagging excess access, stale entitlements, and privilege violations, then compiles the results into a certification-ready HTML report with risk scoring and recommended actions.
PythonIAM GovernanceAutomationAccess Certification
github.com/markthedev12 →
Terraform // AWS RDS // Python
AWS RDS Secure PostgreSQL Tier
Provisioned an isolated, encrypted PostgreSQL tier with Terraform: a private Multi-AZ subnet group, ingress limited to the VPC, and KMS encryption at rest with zero public exposure, then validated the deployed posture with a custom Python/boto3 compliance audit script.
TerraformAWS RDSPythonIaC
github.com/markthedev12 →
Terraform // AWS EC2 // DevSecOps
AWS EC2 DevSecOps Lab
Built an Infrastructure as Code pipeline that provisions an EC2 web server which bootstraps itself via Terraform user_data, then audits the deployed Security Groups with a Python/boto3 script to flag any public internet exposure.
TerraformAWS EC2PythonDevSecOps
github.com/markthedev12 →
Terraform // Route 53 // High Availability
AWS Route 53 DNS Failover
Designed a DNS failover architecture in Terraform with an active and passive endpoint pair, using automated health checks to reroute production traffic to the backup endpoint the moment the primary fails.
TerraformRoute 53High Availability
github.com/markthedev12 →
HTML // CSS // Netlify
This Website
Designed and built from scratch with no templates and no site builders, just pure code. It has a custom cyberpunk aesthetic, is fully responsive, and is deployed on Netlify. This is the site you're looking at right now.
HTML/CSSDesignNetlify
You're already here →
VMware // Windows Server // Kali
Enterprise IAM Home Lab
A personal cybersecurity lab built to mirror enterprise healthcare IT, using Windows Server AD, Kali Linux for attack simulation, and hybrid Azure AD integration. I use it to break things on purpose so I understand how they actually work.
Active DirectoryKali LinuxAzure ADVMware
Follow progress →
Security Consulting // Live Application
AphoriaApp.com Security Implementation
I served as security consultant for Aphoria, a consumer productivity web application. I conducted a security architecture review, implemented data protection principles, advised on secure authentication practices, and delivered security awareness guidance to the founding team throughout the platform's development.
Security ArchitectureWeb SecurityOWASPConsultingLive App
aphoriaapp.com →
Field Notes

From The Trenches

Notes from real IAM and healthcare security work: what breaks, what I'm learning, and what I'd tell someone starting where I started.

SailPoint // Access Governance
What Enterprise-Scale IAM Taught Me About Least Privilege
How entitlement reviews actually surface risk in a live HIPAA environment, and the access patterns nobody flags until it's too late.
SailPointIAMHIPAA
Read the post →
Microsoft Entra // Conditional Access
Conditional Access Policies That Actually Stop Breaches
The difference between a Conditional Access policy that looks secure on paper and one that holds up against real authentication risk signals.
Entra IDZero Trust
Read the post →
IAM Governance // Automation
Why Access Reviews Are the Most Boring, Most Important Part of IAM
The pattern behind almost every breach post-mortem, and why I built a tool to automate the check most teams skip.
IAM GovernancePythonAutomation
Read the post →
On The Side

Independent Services

A handful of things I take on outside my full-time role, for individuals rather than businesses. Recruiters and hiring managers: this is separate from my day job. Jump to Work or grab my resume instead.

Most Requested
Resume & LinkedIn Overhaul
Built by someone who just used this exact positioning to land an IAM role. For IT/cybersecurity job seekers who want to actually get noticed.
  • Full resume rewrite & formatting
  • ATS-friendly structure
  • LinkedIn profile overhaul
  • One round of revisions
Career
IT & Cybersecurity Career Roadmap Session
A 60-minute 1:1 call to map your path into IT or security: which certs, what order, what to build, and how to talk about it in interviews.
  • 60-min live video call
  • Personalized cert & skill roadmap
  • Portfolio/project suggestions
  • Follow-up notes doc
Personal Security
Personal Account & Access Hygiene Setup
Lock down your own digital life the way I lock down enterprise identities. Not a business audit, just your accounts, done right.
  • Password manager setup
  • MFA on critical accounts
  • Breach/exposure check
  • Written cleanup checklist
Automation
Custom Python Script
A small automation for the repetitive thing you do by hand every week: a report, a file cleanup, a data pull. Built, tested, and handed off.
  • Scoped 30-min discovery call
  • Working script, delivered on GitHub
  • Basic usage documentation
  • One round of tweaks
// Initialize Contact Protocol

Let's Secure
Your World

Whether you want your resume and LinkedIn to actually get noticed, help mapping your path into IT/security, your own accounts locked down properly, or a script built for something you do by hand every week, I'm ready to talk.

Book Free Consultation
// mark@markschwinn.com · // Response within 24hrs

Free consultation · No commitment · Raleigh/RTP, NC