Available for New Roles & Projects
// Raleigh/RTP, NC · Healthcare IT Security

MarkSchwinnRaleigh/RTP

I protect organizations from the inside out. Deep hands-on experience in identity management, access control, and healthcare security, building defenses that actually hold.

Mark Schwinn
MARK_SCHWINN.EXE // LOADED
Network
Raleigh/RTP
Status
Active
Identity ManagementActive DirectorySailPointEntra IDCisco ISEHIPAA SecurityMFA & SSORBACAWS CloudZero TrustIncident ResponsePython Identity ManagementActive DirectorySailPointEntra IDCisco ISEHIPAA SecurityMFA & SSORBACAWS CloudZero TrustIncident ResponsePython
About

Who I Am

I've spent the last year embedded inside a major regional health system, in one of the most tightly regulated environments security touches. I've seen what real enterprise security looks like from the inside: the vulnerabilities nobody talks about, the access controls that slip through the cracks, the systems that look secure but aren't.

That experience translates directly. Identity, access governance, and security operations don't stop being hard problems outside of healthcare, they just lose one extra layer of regulatory pressure. Not textbook knowledge. Real world defense, wherever it's applied.

I'm building something bigger: a consulting practice that makes enterprise-grade security accessible to every organization that needs it, not just the ones with Fortune 500 budgets. If your data matters, your security should too.

4+
SECURITY TOOLS BUILT & SHIPPED
16
AUTOMATED HIPAA CHECKS BUILT
2 WKS
FULL REMEDIATION, ZERO DOWNTIME
✓ CompTIA Security+
✓ Google Cybersecurity
↗ B.S. IT & Cybersecurity · 4.0 GPA
↗ CySA+ & AWS SAA In Progress
Get In Touch LinkedIn Profile
IAM ArchitectureAccess GovernanceHIPAA ComplianceThreat DetectionCloud SecurityIdentity LifecycleIncident ResponseZero TrustPython AutomationHealthcare IT
// 01
Enterprise Scale Experience
Managing identity and access operations inside a large, HIPAA-regulated healthcare environment daily. High-stakes security work where the wrong call affects patient care.
// 02
Healthcare Security Specialist
HIPAA compliance, patient data protection, and healthcare IT security aren't services I just offer. They're the environment I operate in every single day.
// 03
Builder, Not Just Advisor
I don't just identify problems and hand you a report. I build tools, automate processes, implement fixes, and stay involved until your environment is actually secure.
// 04
No Corporate Overhead
Working directly with me means enterprise-level expertise without the consulting firm markup. You get the same knowledge and a lot more of my actual attention.
Services

What I Do

Fixed-scope engagements built on the same skillset I use every day in a live enterprise environment. Clear deliverables, clear pricing, no surprise invoices.

Most Requested
HIPAA Security Risk Assessment
Know exactly where you're exposed before an auditor or attacker finds it first.
  • Full security environment scan
  • Written vulnerability report
  • Prioritized remediation roadmap
  • 30-day follow-up call
Full Stack
Cybersecurity Audit & Remediation
Find every gap. Fix every gap. Most consultants stop at the report. I don't.
  • Comprehensive security audit
  • Hands-on remediation
  • Access control overhaul
  • 90-day priority support
Cloud
Microsoft 365 & Cloud Security
Out-of-the-box M365 is not secure. I configure it the way enterprise health systems do.
  • M365 security hardening
  • Entra ID & Azure AD setup
  • MFA & conditional access
  • RBAC implementation
Identity
Identity & Access Management
Wrong access controls are the #1 cause of breaches. I design IAM frameworks that solve this permanently.
  • IAM environment assessment
  • Active Directory consulting
  • RBAC framework design
  • SSO architecture guidance
Training
Security Awareness Training
Most breaches happen because of people, not technology. I teach your team to recognize threats before they become incidents.
  • Phishing & social engineering
  • Password & access hygiene
  • Incident reporting procedures
  • Custom session for your team
Compliance
IT Security Policy Development
No policies means no protection and no compliance. I write the security documentation your organization actually needs.
  • Password & access control policy
  • Incident response procedures
  • HIPAA-aligned documentation
  • Employee security guidelines
Bundle
Policy + Training Bundle
Written policy your team follows, plus a live session that makes sure they actually do. Documentation and behavior change, together.
  • Full policy package
  • Team training session
  • HIPAA-aligned documentation
  • One combined engagement
Retainer
Managed Security Partnership
Your dedicated security operator every month. Threats don't take breaks. Neither does this. Most small organizations can't afford a full-time security team, but they can't afford not to have one.
  • Monthly monitoring & reporting
  • Quarterly risk assessments
  • Access control reviews
  • Incident support & response
  • Monthly strategy call
  • Priority 24-hour response
Technical Stack

Tools I Operate

// Identity & Access
SailPoint IAMMicrosoft Entra IDActive DirectoryCisco ISEMFA / SSORBAC / PAMZero Trust
// Security & Compliance
HIPAA FrameworksIncident ResponseAccess AuditingThreat DetectionRisk AssessmentSecurity Operations
// Cloud & Infrastructure
AWSAzure ADMicrosoft 365CitrixEpic EHRVPN Administration
// Dev & Tools
PythonServiceNowGitHubKali LinuxWiresharkWindows / macOS
Portfolio

Things I've Built

HIPAA // Assessment // Case Study
Keystone Family Dental
A 7-person Philadelphia dental practice had critical HIPAA violations, including no MFA, shared credentials, no access controls, and no security policies. I assessed, remediated, and fully documented the environment in two weeks with zero downtime.
HIPAAM365 SecurityIAMPolicy DevelopmentHealthcare
Read Full Case Study →
Python // AWS // HIPAA
HIPAA AWS Compliance Checker
An automated Python tool that scans AWS environments for HIPAA security compliance gaps. It generates reports identifying violations along with prioritized remediation steps, built from real healthcare security knowledge.
PythonAWSHIPAAAutomation
github.com/markthedev12 →
AWS // IAM // S3 // KMS
AWS Secure S3 Lab
I architected and deployed a security hardened S3 environment implementing IAM least privilege policies, KMS server side encryption, restrictive bucket policies, and full public access blocking.
AWSIAMS3KMSBucket Policies
github.com/markthedev12 →
Python // IAM Governance // Automation
IAM Access Review Bot
An automated access certification tool that compares real access exports against defined role baselines, flagging excess access, stale entitlements, and privilege violations, then compiles the results into a certification-ready HTML report with risk scoring and recommended actions.
PythonIAM GovernanceAutomationAccess Certification
github.com/markthedev12 →
HTML // CSS // Netlify
This Website
Designed and built from scratch with no templates and no site builders, just pure code. It has a custom cyberpunk aesthetic, is fully responsive, and is deployed on Netlify. This is the site you're looking at right now.
HTML/CSSDesignNetlify
You're already here →
VMware // Windows Server // Kali
Enterprise IAM Home Lab
A personal cybersecurity lab built to mirror enterprise healthcare IT, using Windows Server AD, Kali Linux for attack simulation, and hybrid Azure AD integration. I use it to break things on purpose so I understand how they actually work.
Active DirectoryKali LinuxAzure ADVMware
Follow progress →
Security Consulting // Live Application
AphoriaApp.com Security Implementation
I served as security consultant for Aphoria, a consumer productivity web application. I conducted a security architecture review, implemented data protection principles, advised on secure authentication practices, and delivered security awareness guidance to the founding team throughout the platform's development.
Security ArchitectureWeb SecurityOWASPConsultingLive App
aphoriaapp.com →
Field Notes

From The Trenches

Notes from real IAM and healthcare security work: what breaks, what I'm learning, and what I'd tell someone starting where I started.

SailPoint // Access Governance
What Enterprise-Scale IAM Taught Me About Least Privilege
How entitlement reviews actually surface risk in a live HIPAA environment, and the access patterns nobody flags until it's too late.
SailPointIAMHIPAA
Read the post →
Microsoft Entra // Conditional Access
Conditional Access Policies That Actually Stop Breaches
The difference between a Conditional Access policy that looks secure on paper and one that holds up against real authentication risk signals.
Entra IDZero Trust
Read the post →
Career // CySA+
Why I'm Betting on IAM Over Generic SOC Work
My honest read on where AI is compressing security operations roles, and why identity governance is the part that's harder to automate.
CareerCySA+AI & Security
Read the post →
IAM Governance // Automation
Why Access Reviews Are the Most Boring, Most Important Part of IAM
The pattern behind almost every breach post-mortem, and why I built a tool to automate the check most teams skip.
IAM GovernancePythonAutomation
Read the post →
Feedback

What People Say

“Mark helped me understand security principles I didn't have the background for and made sure the implementation was actually done right, not just talked about.”

M
M.
Early-Stage Product Founder
// PERSONAL PROJECT
// M365 & Cloud Security Engagement

Typical engagement: an exposed Microsoft 365 tenant with default security settings, no Conditional Access, and no documentation. Outcome: hardened configuration, MFA enforced, and a policy handoff the internal team can maintain without ongoing support.

// Security Policy Engagement

Typical engagement: a small business with no written security policy and no plain-language risk explanation. Outcome: risk translated out of jargon, prioritized fixes implemented directly, and documentation the team actually understands.

// Initialize Contact Protocol

Let's Secure
Your World

Whether you need a HIPAA assessment, an IAM overhaul, an ongoing security partner, or you're looking to hire someone who actually knows this space, I'm ready to talk.

Book Free Consultation
// mark@markschwinn.com · // Response within 24hrs

Free consultation · No commitment · Raleigh/RTP, NC