Chandler W. Williams

Security engineer. Identity, vulnerability management, and the tooling behind both.

Identity architecture·Vulnerability programs·Detection engineering·Automation that outlives me

CISSP· DMV· ch@ndler.net· GitHub· LinkedIn· Résumé
8
Years in security
100+
SSO & SCIM integrations
3
Platform migrations led
CISSP
ISC2, active

Selected work

01
Identity
Aprio LLP

SSO and SCIM consolidated across Okta and Entra ID, with Workday as the lifecycle source of truth.

  • Joiner and leaver run from Workday events, with no ticket in the path
  • Application assignment is attribute-driven; standing access is granted just in time
  • Passwordless on both providers — Okta Desktop MFA and Windows Hello for Business
  • 100+ integrations across the SaaS estate
02
Vulnerability management
Aprio LLP

A vulnerability program built from nothing — collection, triage, routing, and reporting leadership will actually read.

  • Findings pulled from scanners across the estate into a single view
  • Critical and high lists curated and routed to the teams that own the patching
  • Remediation ordered by severity and exploitability, not by whoever asked last
  • Weekly KPI summaries to leadership on a fixed cadence
03
Detection & response
Aprio LLP

Endpoint XDR and SIEM platform transitions, and a phishing pipeline that stopped scaling with headcount.

  • Led endpoint XDR and SIEM migrations end to end, including the cleanup afterwards
  • Owned detection tuning and integration work across both platforms
  • Automated phishing triage, isolation, and hand-off across the email security stack
  • Lower time to detect and respond, without adding analysts

Experience

Dec 2022 — Present
Senior Cybersecurity Engineer
Aprio LLP · promoted to Senior in 2024
  • CATO SASE and Palo Alto, managed through Panorama, for zero-trust network access.
  • Deployed Keeper Password Manager firm-wide and ran the adoption office hours.
  • Partnered with GRC on SOC 2 and NIST CSF mappings, and on POA&Ms.
  • Interviewed candidates, reviewed resumes, and mentored offshore engineers.
Sep 2018 — Dec 2022
Cybersecurity Analyst
Aronson LLC
  • Implemented Okta MFA and SSO — SAML and SWA — across the application estate.
  • Designed 802.1x secure wireless networks.
  • Ran vulnerability remediation by severity, and user access reviews.
  • Took CMMC Level 3 compliance forward through POA&Ms.
  • Automated provisioning and reporting in PowerShell on Windows Server.
Nov 2016 — Sep 2018
IT Helpdesk Specialist
Morgan Keller, Inc.
  • Engineered high-availability Hyper-V environments and server migrations.
  • Tier 1 and 2 support, and the documentation behind it.

Tools

Identity & access
Okta — Workforce Identity, Workflows, Lifecycle Management, Universal Directory, Desktop MFA·Microsoft Entra ID·Conditional Access·Privileged Identity Management·Identity Protection·Workday·SAML 2.0·OIDC·OAuth 2.0·SCIM·SWA·Just-in-time provisioning·RBAC and ABAC
Strong auth & zero trust
Passwordless·FIDO2 and WebAuthn·Passkeys·YubiKey·Windows Hello for Business·Okta Desktop MFA·CATO SASE·Palo Alto with Panorama·ZTNA
Detection & response
Microsoft Defender XDR — Endpoint, Identity, Cloud Apps, Office 365·SentinelOne XDR and MDR·Microsoft Sentinel·Defender for Outlook·Abnormal AI·CrowdStrike Falcon·Sysmon·Threat hunting with KQL·Incident response playbooks
Vulnerability & endpoint
OpenVAS·Tenable Nessus·CVE and CVSS triage·CISA KEV catalog·Patch cadence·Microsoft Intune·BitLocker·Keeper Password Manager
Automation
Python·PowerShell·KQL·Bash·REST APIs·Postman·Git·Azure DevOps·JSON and YAML
Compliance
SOC 2 Type I and II·NIST CSF·NIST 800-53 and 800-171·CMMC Level 3·POA&Ms·Vendor security reviews·User access reviews·KnowBe4
Networks & platforms
802.1x with PEAP and EAP-TLS·RADIUS and NPS·IPsec and SSL VPN·Site-to-site VPN·VLAN segmentation·Cloudflare·Wireshark·Microsoft 365 and Azure·Active Directory·Windows Server·Hyper-V·VMware

Background

Education

B.S. Computer Networks & Cybersecurity
University of Maryland Global Campus · 2025
A.S. Cybersecurity
Hagerstown Community College · 2016

Certification

CISSP
ISC2 · active

Based

Washington, DC metro
Maryland · remote or hybrid

Blog

All posts
Teardown A blog with no build step 2026-07-27

Contact

Open to interesting problems
Email
ch@ndler.net
GitHub
chandler-williams
LinkedIn
chandler-w-williams
Résumé
RESUME-CWW-PUB.pdf