brian marshall

Sr. Manager, Identity and Access Management

Sherman, Texas, United States

About

Experience

  • Accelya Group (Remote)
    • Sr. Manager, Identity and Access Management
      Jul 2023 - Aug 2025 · 2 yrs 2 mos

      • Built 5-member IAM team managing security across 26+ domains, reducing incident response time by 30%. • Identity Governance Administration collaborating with creating policies, procedures and following through with auditing and reporting compliance. • resurrect aged CyberArk Private Ark environment while implementing the new CyberArk Privileged Access Cloud for over 500 devices and servers. • Implemented CyberArk Enterprise Password Management and led training sessions for teams to move from clear text password storage to the secure enterprise managed solution. • Implemented Zscaler Zero Trust Exchange replacing multiple antiquated VPN solutions. This reduced >$200,000 from redundant VPN linceses while removing backdoor vulnerabilities and preventing rogue devices from network access. • Remediated security breaches, implemented access automation, and strengthened. compliance posture — raising overall Microsoft Secure Score by 25 points. • Designed and implemented role-based access models aligned with Zero Trust principles, Identity Management. • Directed architectural design and administration of the Active Directory and M365 environments. • Oversaw enterprise email infrastructure for 3K+ users, reducing downtime and improving delivery reliability. • Integrated Workday API driven user provisioning with Entra and Active Directory • Managed Entra SSO while onboarding Enterprise Applications driven by RBAC and SoD. Maintained ISO 27001 certification by collaborating with multiple teams to review and revise polices, procedures and controls leading to faster breach detection and response. • Created training content for end users, administrators and collaborators while also presenting training materials using live stream as well as pre-recorded media. • Migrated acquisitioned users and computers • Upgraded domains from 2008 to 2016 while staging to move to 2022. This required replacing old OS domain controllers, upgrading to DFRS, and isolating systems.

    • Information Technology Security Architect
      Sep 2022 - Jul 2023 · 11 mos

      Security review of Active Directory and M365 environment. Implement changes to primary domains to secure environment after security breaches.

  • Orthofix (Full-time · 12 yrs 7 mos)
    • Manager, Network Administration
      Jan 2020 - Sep 2022 · 2 yrs 9 mos

      • Technical Manager with 7 team members. • Managed $700K IT budget, optimizing resource allocation to support enterprise infrastructure and security initiatives. • Controlled US management of Storage, Networking, Servers (Linux and Windows), and Telephony. • Migrated 1,500 users to modern AD forest with Azure AD integration, improving login efficiency and reducing downtime. • Integrated a single Azure AD tenant with two forest domains. • Litigation Discovery and Forensics. • Identity Governance leader • Audio/Visual lead conducting earnings calls and company-wide townhalls. • Created training content for end users, administrators and collaborators while also presenting training materials using live stream as well as pre-recorded media. • SOX audit policy review and updates while also providing evidence for audits. • Planned Disaster Recovery strategies to accommodate company directives. • Supported Healthcare systems to ensure compliance with FDA, PCI, HIPAA, and SOX • Extensive PowerShell programing.

    • Network Systems Administrator
      Mar 2010 - Jan 2020 · 9 yrs 11 mos

      • Upgraded Forest level from 2000 to 2003. Continued work towards mitigating risks to upgrade to 2008/2012. • Audit systems to document AD, Exchange, File Systems, and Remote Access. This includes being an integral part of yearly SOX auditing. Head reporting administrator for a Microsoft Audit. • Lead migration person for upgrading Exchange from 2003 to 2010; 2010 to 2016. • Fully responsible for the Exchange environment. • Managed Cisco Firewalls, Switches and Wireless infrastructure • Utilize VMware ESX and Cisco UCS as the virtual platforms for systems. • Prepare yearly project planning and budgeting. • Documented changes to the environment as best able using our Helpdesk software as tracking and approval processes. • Enthusiastic to do all levels of Helpdesk support as needed. • Litigation Discovery and Forensics. • Identity Governance group • Automation of reporting and processes using PowerShell