/Conditional Access, and ongoing hardening for production. Validating MFA, Conditional Access, encryption, logging in discovery phase. Designing + embedding IAM, RBAC, federation + authentication patterns into architectures. Defining AWS security guardrails, SCPs, monitoring + compliance baselines. Configuring IAM roles, key management, encryption, logging, CloudTrail, Config, GuardDuty … pilot migration and bulk migration (200+ workloads) across IAM, MFA, encryption, BCP. Tuning monitoring dashboards, alerting + incident triage in hypercare. Technical Skills: IAM, RBAC, SCP, AWS Organizations, MFA, Conditional Access, Entra AD federation, CIS, compliance, encryption, KMS, RPO/RTO, enabling GuardDuty, Security Hub, CloudTrail, Config + ...