<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://seeknay.com/feed.xml" rel="self" type="application/atom+xml" /><link href="https://seeknay.com/" rel="alternate" type="text/html" /><updated>2026-06-27T20:21:34-04:00</updated><id>https://seeknay.com/feed.xml</id><title type="html">seeknay.com</title><subtitle>A personal tech blog with maybe some interesting information.</subtitle><author><name>seeknay</name></author><entry><title type="html">Breaking Into IAM: A 2026 Career Guide</title><link href="https://seeknay.com/identity/career-development/state-of-iam-job-market-2026/" rel="alternate" type="text/html" title="Breaking Into IAM: A 2026 Career Guide" /><published>2026-02-02T08:00:00-05:00</published><updated>2026-02-02T00:00:00-05:00</updated><id>https://seeknay.com/identity/career-development/state-of-iam-job-market-2026</id><content type="html" xml:base="https://seeknay.com/identity/career-development/state-of-iam-job-market-2026/"><![CDATA[<blockquote>
  <p><em>Heads up: These are my own views. I used Google Gemini Deep Research for the heavy lifting, but I promise a human reviewed every word.</em></p>
</blockquote>

<style>
  details.toc-container {
    background: #f8f9fa;
    border: 1px solid #e1e4e8;
    border-radius: 8px;
    padding: 0;
    margin: 20px 0 24px 0;
  }
  details.toc-container summary {
    padding: 14px 18px;
    font-weight: 600;
    cursor: pointer;
    list-style: none;
    display: flex;
    align-items: center;
    gap: 8px;
  }
  details.toc-container summary::-webkit-details-marker {
    display: none;
  }
  details.toc-container summary::before {
    content: "▶";
    font-size: 0.75em;
    transition: transform 0.2s ease;
  }
  details.toc-container[open] summary::before {
    transform: rotate(90deg);
  }
  details.toc-container .toc-content {
    padding: 0 18px 14px 18px;
    border-top: 1px solid #e1e4e8;
  }
  details.toc-container .toc-content ul {
    margin: 12px 0 0 0;
    padding-left: 20px;
  }
  details.toc-container .toc-content li {
    margin: 6px 0;
  }
</style>

<details class="toc-container">
<summary>📖 Table of Contents</summary>
<div class="toc-content">

    <ul>
      <li><a href="#the-market-reality">The Market Reality</a>
        <ul>
          <li><a href="#the-ai-factor">The AI Factor</a></li>
        </ul>
      </li>
      <li><a href="#title-changes">Title Changes</a>
        <ul>
          <li><a href="#the-death-of-the-system-admin">The Death of the “System Admin”</a></li>
          <li><a href="#the-analyst-split">The Analyst Split</a></li>
          <li><a href="#ciam-vs-workforce-two-different-worlds">CIAM vs. Workforce: Two Different Worlds</a></li>
        </ul>
      </li>
      <li><a href="#salary-data-us-market">Salary Data (US Market)</a>
        <ul>
          <li><a href="#geography-still-matters">Geography Still Matters</a></li>
          <li><a href="#the-premium-kickers">The Premium Kickers</a></li>
        </ul>
      </li>
      <li><a href="#the-technical-stack">The Technical Stack</a></li>
      <li><a href="#certification-strategy">Certification Strategy</a>
        <ul>
          <li><a href="#entry-level-0-2-years">Entry-Level (0-2 Years)</a></li>
          <li><a href="#practitioner-2-5-years">Practitioner (2-5 Years)</a></li>
          <li><a href="#the-lab-shortcut">The “Lab” Shortcut</a></li>
        </ul>
      </li>
      <li><a href="#what-interviewers-actually-ask">What Interviewers Actually Ask</a></li>
      <li><a href="#paths-in">Paths In</a></li>
    </ul>

  </div>
</details>

<style>
  .stats-card {
    background: #fff;
    border: 1px solid #e1e4e8;
    border-radius: 12px;
    box-shadow: 0 4px 6px rgba(0, 0, 0, 0.04);
    padding: 20px;
    margin: 24px 0;
  }
  .stats-header {
    display: flex;
    align-items: center;
    gap: 12px;
    margin-bottom: 16px;
    border-bottom: 2px solid #f0f0f0;
    padding-bottom: 8px;
  }
  .stats-title {
    margin: 0 !important;
    font-size: 1.4em !important;
    font-weight: 700;
    color: #24292e;
  }
  .stats-icon {
    font-size: 1.6em;
  }
  .stats-table {
    width: 100%;
    border-collapse: collapse;
    font-size: 1.1em;
    color: #24292e;
  }
  .stats-table th {
    text-align: left;
    padding: 10px 8px;
    color: #586069;
    font-weight: 600;
    font-size: 0.9em;
    text-transform: uppercase;
    letter-spacing: 0.5px;
    border-bottom: 1px solid #e1e4e8;
  }
  .stats-table td {
    padding: 12px 8px;
    border-bottom: 1px solid #eaecef;
  }
  .stats-table tr:last-child td {
    border-bottom: none;
  }
  .stats-table tr:hover {
    background-color: #f6f8fa;
  }
  .text-center { text-align: center; }
  .text-right { text-align: right; }
  .stats-meta {
    margin-top: 12px;
    font-size: 0.85em;
    color: #586069;
    font-style: italic;
  }
</style>

<p>Identity and Access Management (IAM) has decoupled from general IT administration. While the broader tech sector has stabilized with flat compensation, IAM has split into a high-value vertical driven by cybersecurity mandates and regulatory pressure.</p>

<p>The “IAM Administrator” role, historically defined by manual provisioning and GUI management, is dead. It has been replaced by the “IAM Engineer,” a role that demands security theory, software engineering principles, and automation.</p>

<p>At the entry level, the “IAM Analyst” title has bifurcated. One track handles support tickets; the other handles Governance, Risk, and Compliance (GRC). The money is in the latter.</p>

<h2 id="the-market-reality">The Market Reality</h2>

<p>General tech salaries are projected to rise just <strong>1.6%</strong> in 2026. Security roles are tracking at <strong>4.0%</strong>. AI/ML leads the pack at 4.4%, but IAM rides alongside it because you can’t deploy AI without identity governance.</p>

<p>Here’s what matters: <strong>52% of tech leaders say they’ll increase starting offers for candidates with security skills.</strong> That’s second only to AI/Data Science (59%). If you’re on the fence about pivoting into security, that number should settle it.</p>

<p>The market has tiered technology roles into “Commodity” and “Strategic” buckets. Roles susceptible to automation, such as entry-level help desk, basic coding, and manual administration, are seeing wage stagnation. Strategic roles that ensure business continuity and audit survival are seeing aggressive growth.</p>

<h3 id="the-ai-factor">The AI Factor</h3>

<p>Cliches about “AI taking jobs” are partially true here. The “Joiner-Mover-Leaver” (JML) process used to employ thousands of junior admins. That work is now automated by IGA platforms.</p>

<p>But AI has created a massive new headache: <strong>Non-Human Identities</strong>.</p>

<p>Bots, service principals, and AI agents now outnumber human employees by a factor of 10 to 45, depending on your architecture. They need accounts, permissions, and governance. A specialist who knows how to secure an AI agent using Workload Identity Federation writes their own ticket in this market.</p>

<p>The same goes for Secrets Management. If you can automate the rotation of API keys and certificates, you’re solving a problem that keeps CISOs up at night.</p>

<h2 id="title-changes">Title Changes</h2>

<h3 id="the-death-of-the-system-admin">The Death of the “System Admin”</h3>

<p>For twenty years, “System Administrator” was a solid career. In IAM, that title now signals “legacy.”</p>

<p>Recruiters and hiring managers associate “Administrator” with:</p>
<ul>
  <li>Manual clicking in Active Directory</li>
  <li>Resetting passwords</li>
  <li>“Keeping the lights on”</li>
</ul>

<p>They associate “Engineer” with:</p>
<ul>
  <li>Writing Python or PowerShell to hit APIs</li>
  <li>Integrating SaaS apps via OIDC</li>
  <li>Managing configuration via Git (Infrastructure-as-Code)</li>
</ul>

<p>If your resume says “Administrator” but you do engineering work, change it. A Reddit thread from last year put it bluntly: “Unless your end game is to be an IT Manager… pivot now.”</p>

<h3 id="the-analyst-split">The Analyst Split</h3>

<p>If you are applying for an “IAM Analyst” role, check the job description. The title is used for two completely different jobs.</p>

<p><strong>Job A: The Ticket Queue (Operations)</strong>
You will unlock accounts and troubleshoot MFA failures. It pays $55k - $75k. It is effectively specialized Help Desk. Metrics are driven by ticket closure rates and SLAs. It’s high-volume, reactive work.</p>

<p><strong>Job B: The Auditor (Governance)</strong>
You will run Access Certification campaigns, chase managers for approvals, and gather evidence for SOX/ISO audits. It pays $75k - $90k. The work is cyclical. It is brutal during audit season, but calmer otherwise. This path leads to IAM Manager, IT Risk Manager, or GRC Architect.</p>

<p>Overlooked angle: The Governance track is a back door into cybersecurity for people without a CS background. Candidates from business analysis, library science, or legal studies often outperform here because the job is about process, detail, and documentation, not tinkering with code.</p>

<h3 id="ciam-vs-workforce-two-different-worlds">CIAM vs. Workforce: Two Different Worlds</h3>

<p>There’s a third split you should know about: <strong>who</strong> you’re managing identities for.</p>

<p><strong>Workforce IAM:</strong> Your users are employees and contractors. Focus is on security, Zero Trust, and internal efficiency.</p>

<p><strong>Customer IAM (CIAM):</strong> Your users are paying customers. This is treated less like IT Security and more like Product Engineering. You’re expected to know API security, UX design, and how the login flow affects conversion rates.</p>

<p>CIAM pays more. It’s also harder to get into because the interview process is more technical. If you have a software development background, CIAM is where you should aim.</p>

<h2 id="salary-data-us-market">Salary Data (US Market)</h2>

<div class="stats-card">
  <div class="stats-header">
    <div class="stats-icon">💰</div>
    <h3 class="stats-title">Salary Data (US Market)</h3>
  </div>

  <table class="stats-table">
    <thead>
      <tr>
        <th width="30%">Role</th>
        <th width="20%" class="text-center">25th %</th>
        <th width="25%" class="text-center">Median</th>
        <th width="25%" class="text-center">75th %</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td><strong>IAM Analyst</strong></td>
        <td class="text-center">$65,000</td>
        <td class="text-center">$71,000</td>
        <td class="text-center">$78,000</td>
      </tr>
      <tr>
        <td><strong>IAM Engineer</strong></td>
        <td class="text-center">$102,000</td>
        <td class="text-center">$115,000</td>
        <td class="text-center">$133,000</td>
      </tr>
      <tr>
        <td><strong>IAM Architect</strong></td>
        <td class="text-center">$103,000</td>
        <td class="text-center">$120,000</td>
        <td class="text-center">$137,000</td>
      </tr>
      <tr>
        <td><strong>IAM Manager</strong></td>
        <td class="text-center">$136,000</td>
        <td class="text-center">$145,000</td>
        <td class="text-center">$154,000</td>
      </tr>
    </tbody>
  </table>
  
  <div class="stats-meta">
    Source: Robert Half, Betts, ZipRecruiter, and Q4 2025 hiring data.
  </div>
</div>

<h3 id="geography-still-matters">Geography Still Matters</h3>

<p>Remote work has compressed the gap, but it hasn’t eliminated it.</p>

<p><strong>Tier 1 (San Francisco, NYC, Seattle):</strong> Expect 20-30% above the median. An IAM Engineer in NYC starts around $130k, not $100k. You pay for it in rent.</p>

<p><strong>Government Hubs (DC, Northern Virginia):</strong> A TS/SCI clearance is an automatic +$40k. An IAM Engineer with a clearance can hit $150k-$180k, which is more than their private sector peers in the same building. The catch: you’re usually onsite, and the clearance process takes a year.</p>

<p><strong>Regional Hubs (Chicago, Austin, Atlanta):</strong> Salaries track close to the national median ($110k-$120k for Engineers), but cost of living is 30-40% lower than the coasts. Best “real” income.</p>

<p><strong>Remote/National:</strong> The market has consolidated around Tier 2 salaries. You can live in a low-cost area and earn Austin money. The tradeoff is more competition for fewer fully-remote roles.</p>

<h3 id="the-premium-kickers">The Premium Kickers</h3>

<ul>
  <li><strong>The Developer Premium:</strong> Engineers who write real code (not just copy-paste scripts) see a ~20-25% bump. ZipRecruiter lists “IAM Developer” roles with medians around $144k.</li>
  <li><strong>The SailPoint Tax:</strong> If you can implement and maintain SailPoint IdentityIQ, you’re looking at $130k+ as a floor. The tool is complex enough that supply never meets demand.</li>
</ul>

<h2 id="the-technical-stack">The Technical Stack</h2>

<p>You can no longer survive on “Active Directory Users and Computers.”</p>

<ol>
  <li><strong>The Duopoly:</strong> You need to know <strong>Microsoft Entra ID</strong> (formerly Azure AD) or <strong>Okta</strong>. Ideally both. Microsoft owns the enterprise; Okta owns the startups and the CIAM market (via Auth0).</li>
  <li><strong>The Plumbing:</strong> Stop memorizing button clicks. Learn the protocols.
    <ul>
      <li><strong>OIDC:</strong> For logging into apps. The modern standard for mobile and SPAs.</li>
      <li><strong>OAuth 2.0:</strong> For authorization, which defines what you can <em>do</em> once you’re logged in.</li>
      <li><strong>SAML 2.0:</strong> The legacy standard. Still everywhere in enterprise SaaS (Salesforce, Workday).</li>
      <li><strong>SCIM:</strong> The unsung hero. This is the API standard for automatic user provisioning. When HR creates an employee, SCIM creates their Slack account.</li>
    </ul>
  </li>
  <li><strong>Governance (IGA):</strong> SailPoint remains the standard for big companies. It’s complex and demanding, and pays extremely well. Saviynt is the up-and-comer.</li>
  <li><strong>Secrets &amp; PAM:</strong> CyberArk and HashiCorp Vault. This is where the machine identity work happens. If you understand secrets rotation, you’re ahead of most candidates.</li>
</ol>

<div class="stats-card">
  <div class="stats-header">
    <div class="stats-icon">🛠️</div>
    <h3 class="stats-title">Top 5 In-Demand Skills</h3>
  </div>

  <table class="stats-table">
    <thead>
      <tr>
        <th width="70%">Skill Category</th>
        <th width="30%" class="text-center">Usage Rate</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td><strong>IDP Platforms</strong> (Okta/Entra ID)</td>
        <td class="text-center">85%</td>
      </tr>
      <tr>
        <td><strong>Identity Standards</strong> (OIDC/SAML/SCIM)</td>
        <td class="text-center">72%</td>
      </tr>
      <tr>
        <td><strong>IGA</strong> (SailPoint/Saviynt)</td>
        <td class="text-center">65%</td>
      </tr>
      <tr>
        <td><strong>Scripting</strong> (Python/PowerShell)</td>
        <td class="text-center">60%</td>
      </tr>
      <tr>
        <td><strong>PAM</strong> (CyberArk/Delinea)</td>
        <td class="text-center">45%</td>
      </tr>
    </tbody>
  </table>
</div>

<h2 id="certification-strategy">Certification Strategy</h2>

<p>Most certs are useless for getting hired. They’re checkboxes for HR, not proof of skill. That said, some checkboxes are mandatory.</p>

<h3 id="entry-level-0-2-years">Entry-Level (0-2 Years)</h3>

<ol>
  <li><strong>CompTIA Security+:</strong> The HR filter. You usually can’t get a government-adjacent job without it. DoD 8570 requires it.</li>
  <li><strong>Microsoft SC-900:</strong> The introduction. Low-barrier exam that gets you familiar with Entra, Purview, and Sentinel vocabulary. Good for resumes, not proof of skill.</li>
  <li><strong>Okta Certified Professional:</strong> Unlike multiple-choice exams, this one involves practical simulations. It proves you can actually navigate a console.</li>
</ol>

<h3 id="practitioner-2-5-years">Practitioner (2-5 Years)</h3>

<ol>
  <li><strong>Microsoft SC-300:</strong> The “I know how to do the job” exam. It covers Conditional Access, Identity Protection, and Governance. This is the current gold standard for operational IAM roles.</li>
  <li><strong>CISSP:</strong> The management card. Get this if you want to be a lead or a manager. If you have under 5 years of experience, you get “Associate of ISC2” status, which still signals the management mindset.</li>
</ol>

<h3 id="the-lab-shortcut">The “Lab” Shortcut</h3>
<p>If you have no experience, don’t just get a cert. Build a lab.</p>

<p>Get a free Microsoft 365 Developer tenant (it comes with Entra ID P2). Get a free Okta Developer account. Now:</p>
<ol>
  <li>Set up Okta as your IdP.</li>
  <li>Federate it to Entra ID using OIDC or SAML.</li>
  <li>Enable MFA on the Okta side.</li>
  <li>Configure Conditional Access on the Entra side.</li>
  <li>Document the whole thing: screenshots, config snippets, problems you hit.</li>
</ol>

<p>Put it on GitHub or write a blog post. In an interview, “I built a federation between Okta and Entra ID last weekend and here’s what I learned” beats “I passed a multiple choice exam” every time.</p>

<div class="stats-card">
  <div class="stats-header">
    <div class="stats-icon">📈</div>
    <h3 class="stats-title">Typical IAM Career Progression</h3>
  </div>

  <table class="stats-table">
    <thead>
      <tr>
        <th width="10%" style="text-align: center;">Stage</th>
        <th width="25%">Role</th>
        <th width="65%">Focus Areas</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td style="text-align: center; font-weight: bold; color: #0366d6;">1</td>
        <td><strong>IAM Analyst</strong></td>
        <td>Governance, Access Reviews, Reporting, Basic Ops</td>
      </tr>
      <tr>
        <td style="text-align: center; font-weight: bold; color: #0366d6;">2</td>
        <td><strong>IAM Engineer</strong></td>
        <td>Implementation, Integrations, SSO/MFA, Python/API</td>
      </tr>
      <tr>
        <td style="text-align: center; font-weight: bold; color: #0366d6;">3</td>
        <td><strong>IAM Architect</strong></td>
        <td>Strategy, Design, Zero Trust Roadmap, Stakeholders</td>
      </tr>
    </tbody>
  </table>
</div>

<h2 id="what-interviewers-actually-ask">What Interviewers Actually Ask</h2>

<p>Interviews have moved away from trivia (“What port is LDAP?”) toward scenario-based questions. Be ready for:</p>

<p><strong>For Analyst/Operations roles:</strong></p>
<ul>
  <li>“A user is locked out of their account at 2 AM and says they have a critical deadline. Walk me through your process.”</li>
  <li>“How do you explain MFA to an executive who thinks it’s too inconvenient?”</li>
</ul>

<p><strong>For Engineer roles:</strong></p>
<ul>
  <li>“Design an authentication flow for a mobile app. When would you use OIDC vs. SAML?”</li>
  <li>“We have 10,000 users who haven’t logged in for 90 days. How would you automate the cleanup?”</li>
  <li>“A service principal in Azure needs to write to a storage account. How do you secure it without a client secret?”</li>
</ul>

<p><strong>For Architect roles:</strong></p>
<ul>
  <li>“We’re migrating from on-prem Oracle Identity to cloud-based Okta. What’s your 12-month roadmap?”</li>
  <li>“How do you handle pushback from a VP who says your new policy is too restrictive?”</li>
</ul>

<p>The Architect questions are partly technical, partly political. You’re being tested on whether you can advocate for security without torpedoing relationships.</p>

<h2 id="paths-in">Paths In</h2>

<p>There are many paths into IAM; these are just examples. None of this is set in stone; the beauty of technology is that people break the mold all the time.</p>

<p><strong>From Help Desk:</strong> Leverage your access. Ask the current IAM team if you can handle their ticket backlog. Use the Operations Analyst role as a stepping stone, but start learning Python or PowerShell and SC-300 material immediately to pivot into Engineering.</p>

<p><strong>From a Non-Tech Background:</strong> Target the Governance Analyst track. Highlight attention to detail, process management, and writing ability. Learn the language of compliance (SOX, GDPR, HIPAA). You’ll become valuable to the CISO during audit season.</p>

<p><strong>From CS/Development:</strong> Skip the Analyst tier entirely. Target “IAM Developer” or “Identity Engineer” roles. You already know how to code; now show that you understand identity as a concept, not just an API to call.</p>

<hr />

<p><em>Data compiled from Robert Half 2026 Technology Salary Guide, Motion Recruitment, ZipRecruiter, Payscale, Salary.com, and Q4 2025 public job boards. Interview questions sourced from r/IdentityManagement and r/cybersecurity.</em></p>]]></content><author><name>seeknay</name></author><category term="identity" /><category term="career-development" /><category term="iam" /><category term="career-paths" /><category term="it-security" /><category term="salary-guide" /><category term="job-market" /><category term="2026" /><summary type="html"><![CDATA[An in-depth analysis of US hiring trends, salary bands, and skill requirements for Identity & Access Management professionals in 2026.]]></summary></entry><entry><title type="html">Home Automation Decision Assistant</title><link href="https://seeknay.com/home-automation/decision-guides/home-automation-decision-helper/" rel="alternate" type="text/html" title="Home Automation Decision Assistant" /><published>2025-08-24T22:00:00-04:00</published><updated>2025-08-24T22:00:00-04:00</updated><id>https://seeknay.com/home-automation/decision-guides/home-automation-decision-helper</id><content type="html" xml:base="https://seeknay.com/home-automation/decision-guides/home-automation-decision-helper/"><![CDATA[<p><strong>Home Automation Decision Assistant</strong> helps nontechnical homeowners go from idea to working automation with minimal guesswork. It inventories what you have, proposes multiple approaches, explains tradeoffs in plain language, and gives step-by-step instructions with validation and rollback. (link to try at the bottom of this post)</p>

<blockquote class="notice--info">
  <p>🎯 <strong>Goal:</strong> Deliver the <em>simplest reliable plan</em> that matches your priorities, with safety and privacy by default.</p>
</blockquote>

<hr />

<h2 id="-why-i-built-it">💡 Why I Built It</h2>

<p>Jen Hamilton posted a great TikTok asking for the most life-changing home automations. One reply jumped out: “When the dishwasher finishes, my kids’ Wi-Fi pauses until they empty it.” Genius.</p>

<p>The comments told two stories: lots of creative ways to build it, and lots of people unsure where to start. There is no single answer that fits every home network, platform, and appliance. I built this Custom GPT to meet people where they are: ask about goals and gear, compare a few safe paths, and provide clear steps with simple validation and rollback. I also wanted to make sure nontechnical folks feel encouraged, not discouraged, to try.</p>

<blockquote class="notice--success">
  <p>✅ Friendly tone without fluff. Plain terms, small decisions at a time, and protective guardrails.</p>
</blockquote>

<hr />

<h2 id="-role-and-audience">👥 Role and Audience</h2>

<ul>
  <li><strong>Who it’s for:</strong> Nontechnical homeowners who want dependable results without deep configuration.</li>
  <li><strong>Tone:</strong> Friendly, patient, concise. Necessary terms are defined in one short line.</li>
  <li><strong>Encouragement:</strong> Reassures, offers alternatives, and avoids dead ends.</li>
</ul>

<hr />

<h2 id="-must-ask-first-then-it-waits-for-your-answers">🧾 Must Ask First (then it waits for your answers)</h2>

<p>1) <strong>Outcome:</strong> What should happen automatically first?<br />
   <em>Examples: text me when laundry is done, lights at sunset, lock at bedtime.</em><br />
2) <strong>Priorities:</strong> Pick any two to prioritize now: <strong>easy setup</strong>, <strong>low cost</strong>, <strong>fast results</strong>.<br />
3) <strong>What you already have:</strong> Devices, hubs, apps, smart speakers. Include brand if known.<br />
4) <strong>Networking:</strong> Router or mesh brand, guest network or VLANs.<br />
5) <strong>Constraints:</strong> Budget, privacy preference <em>(local only, cloud OK, hybrid)</em>, rental or wiring limits, timeline.</p>

<blockquote class="notice--info">
  <p>Optional follow-ups if they change the design: <strong>reliability/uptime needs</strong> and <strong>skill comfort</strong> <em>(app-only, light config, or OK with Docker/YAML)</em>.</p>
</blockquote>

<hr />

<h2 id="️-working-method">🛠️ Working Method</h2>

<p>1) <strong>Intake</strong> - Ask the 3-5 questions above. If gaps remain, at most 2 quick follow-ups.<br />
2) <strong>Inventory</strong> - Build a concise table of current gear and reuse potential.<br />
3) <strong>Verify</strong> - Check trusted docs to confirm compatibility, protocols <em>(Matter, Thread, Zigbee, Z-Wave, Wi-Fi)</em>, and platform integrations <em>(Home Assistant, Apple Home, Google Home, Alexa, SmartThings)</em>.<br />
4) <strong>Options</strong> - Generate 2-4 viable solution paths within your constraints.<br />
5) <strong>Score</strong> - For each option, score and sort by your two chosen priorities:</p>
<ul>
  <li><strong>Difficulty:</strong> 1 very easy, 3 moderate, 5 advanced</li>
  <li><strong>Time:</strong> 1 under 15 min, 3 about 1 hour, 5 multi-evening</li>
  <li><strong>Cost:</strong> 1 no new spend, 3 under $100, 5 $300+<br />
6) <strong>Recommend</strong> - Pick the best fit and explain the tradeoffs clearly.<br />
7) <strong>Implement</strong> - Numbered steps with exact app paths or commands, validations after each milestone, and simple rollback notes.<br />
8) <strong>Diagram</strong> - A compact flowchart of data and control paths.<br />
9) <strong>Next steps</strong> - 2-3 small expansions.<br />
10) <strong>References</strong> - 3-8 credible sources used, with links.</li>
</ul>

<blockquote class="notice--warning">
  <p>Safety: No high-voltage or gas/plumbing instructions. For mains power, it defers to a licensed pro. No secrets requested; if keys are needed, it shows how to create and store them safely.</p>
</blockquote>

<hr />

<h2 id="-what-you-get-in-every-plan">📦 What You Get In Every Plan</h2>

<ul>
  <li><strong>Executive summary</strong> with a one-sentence problem statement and a top recommendation.</li>
  <li><strong>Environment snapshot</strong> table and <strong>Options matrix</strong> sorted by your priorities.</li>
  <li><strong>Step-by-step build</strong> with validations and rollbacks.</li>
  <li><strong>Mermaid flowchart</strong> plus a text-only fallback for accessibility.</li>
  <li><strong>Expansion ideas</strong> and a <strong>References</strong> section with sources used.</li>
</ul>

<hr />

<h2 id="-example-scenario">🧪 Example Scenario</h2>

<ul>
  <li><strong>Outcome:</strong> “Text me when the washer is done, then pause the kids’ Wi-Fi until laundry is unloaded.”</li>
  <li><strong>Approaches offered:</strong>
    <ul>
      <li>Smart plug with energy sensing in <strong>Home Assistant</strong> <em>(local, reliable)</em>.</li>
      <li>Vendor app or <strong>Google Home</strong> routine if supported <em>(fast, cloud)</em>.</li>
      <li><strong>n8n</strong> workflow that calls router profiles or parental controls <em>(flexible)</em>.</li>
    </ul>
  </li>
  <li><strong>Scoring:</strong> Sorted by your choice of <em>easy setup</em>, <em>low cost</em>, or <em>fast results</em>.</li>
  <li><strong>Output:</strong> Step-by-step with validations. If a device isn’t compatible, it shows a safe fallback.</li>
</ul>

<hr />

<h2 id="-privacy-and-reliability">🔐 Privacy and Reliability</h2>

<ul>
  <li>Prefers <strong>local control</strong> when feasible. If cloud is used, it explains what data flows to the cloud and how to limit it.</li>
  <li>Adds <strong>retries, timeouts, and health checks</strong> where appropriate.</li>
  <li>Labels any unverified assumptions and shows how to verify them.</li>
</ul>

<hr />

<h2 id="️-flowchart-template-the-assistant-includes-in-plans">🗺️ Flowchart (template the assistant includes in plans)</h2>

<p><a href="https://raw.githubusercontent.com/pbuffolino/seeknay747.github.io/refs/heads/master/assets/images/ha-flowchart.png?raw=true"><img src="https://raw.githubusercontent.com/pbuffolino/seeknay747.github.io/refs/heads/master/assets/images/ha-flowchart.png?raw=true" alt="ha-flowchart.png" /></a></p>

<hr />

<h2 id="-try-it-in-chatgpt">🚀 Try It in ChatGPT</h2>

<p>👉 <a href="https://chatgpt.com/g/g-68a93b756c9881919fd340a111203f5b-home-automation-decision-assistant">Launch <strong>Home Automation Decision Assistant</strong> in ChatGPT</a></p>

<blockquote class="notice--info">
  <p>💬 Share your outcome and pick any two priorities (easy setup, low cost, fast results). The assistant inventories your gear, verifies compatibility, scores 2–4 options, and returns a step-by-step plan with a flowchart, validation checks, and simple rollback notes.</p>
</blockquote>]]></content><author><name>seeknay</name></author><category term="home-automation" /><category term="decision-guides" /><category term="smart-home" /><category term="home-assistant" /><category term="matter" /><category term="thread" /><category term="n8n" /><summary type="html"><![CDATA[A friendly, patient assistant that helps nontechnical homeowners plan and build reliable automations with clear tradeoffs, validation, and safety.]]></summary></entry><entry><title type="html">PowerShell Arrays for Beginners</title><link href="https://seeknay.com/powershell/scripting/powershell-arrays/" rel="alternate" type="text/html" title="PowerShell Arrays for Beginners" /><published>2025-06-01T23:00:00-04:00</published><updated>2025-06-01T23:00:00-04:00</updated><id>https://seeknay.com/powershell/scripting/powershell-arrays</id><content type="html" xml:base="https://seeknay.com/powershell/scripting/powershell-arrays/"><![CDATA[<p>In this short video, I walk through the fundamentals of working with <strong>PowerShell arrays</strong>. If you’re just getting started, this is a great place to begin.</p>

<p>👉 <strong>Watch here</strong>: <a href="https://www.youtube.com/watch?v=sV77XsKhiP4">PowerShell Arrays for Beginners</a></p>

<h3 id="topics-covered-in-the-video">Topics Covered in the Video</h3>

<ul>
  <li>
    <p><strong>Declare an empty array</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">@()</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Populate the array with strings</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">"zero"</span><span class="p">,</span><span class="w"> </span><span class="s2">"one"</span><span class="p">,</span><span class="w"> </span><span class="s2">"two"</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Access elements by index</strong></p>

    <ul>
      <li>
        <p>First element (<code class="language-plaintext highlighter-rouge">0</code>), last element (<code class="language-plaintext highlighter-rouge">-1</code>), or any position:</p>

        <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="p">[</span><span class="mi">0</span><span class="p">]</span><span class="w">      </span><span class="c"># zero</span><span class="w">
</span><span class="nv">$myArray</span><span class="p">[</span><span class="nt">-1</span><span class="p">]</span><span class="w">     </span><span class="c"># two</span><span class="w">
</span></code></pre></div>        </div>
      </li>
    </ul>
  </li>
  <li>
    <p><strong>Select multiple elements</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="p">[</span><span class="mi">0</span><span class="p">,</span><span class="mi">2</span><span class="p">]</span><span class="w">      </span><span class="c"># zero and two</span><span class="w">
</span><span class="nv">$myArray</span><span class="p">[</span><span class="mi">1</span><span class="o">..</span><span class="mi">3</span><span class="p">]</span><span class="w">     </span><span class="c"># one, two, three</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Add elements with <code class="language-plaintext highlighter-rouge">+=</code></strong><br />
<em>(recreates the array each time — fine for small lists)</em></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="w"> </span><span class="o">+=</span><span class="w"> </span><span class="s2">"three"</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Inspect the variable type</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="o">.</span><span class="nf">GetType</span><span class="p">()</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>List available members</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="w"> </span><span class="o">|</span><span class="w"> </span><span class="n">Get-Member</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Check array length</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="o">.</span><span class="nf">Length</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Clear the array</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$myArray</span><span class="o">.</span><span class="nf">Clear</span><span class="p">()</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Review and reuse console history</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="n">Get-History</span><span class="w">      </span><span class="c"># alias: h</span><span class="w">
</span><span class="n">Invoke-History</span><span class="w"> </span><span class="nx">3</span><span class="w"> </span><span class="c"># alias: r 3</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Join array elements into a string</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$joined</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nv">$myArray</span><span class="w"> </span><span class="o">-join</span><span class="w"> </span><span class="s2">", "</span><span class="w">
</span></code></pre></div>    </div>
  </li>
  <li>
    <p><strong>Split a string back into an array</strong></p>

    <div class="language-powershell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$newArray</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nv">$joined</span><span class="w"> </span><span class="o">-split</span><span class="w"> </span><span class="s2">", "</span><span class="w">
</span></code></pre></div>    </div>
  </li>
</ul>

<p>Arrays are one of the most common and useful data structures you’ll use in PowerShell scripting—get to know them well. Thanks for watching!</p>]]></content><author><name>seeknay</name></author><category term="powershell" /><category term="scripting" /><category term="arrays" /><category term="beginners" /><category term="automation" /><summary type="html"><![CDATA[A quick walkthrough of PowerShell arrays for beginners. Learn how to declare, access, modify, and join array data in scripts or the console.]]></summary></entry><entry><title type="html">Exploring Careers in Identity and Access Management (IAM)</title><link href="https://seeknay.com/identity/career-development/exploring-iam-careers/" rel="alternate" type="text/html" title="Exploring Careers in Identity and Access Management (IAM)" /><published>2025-05-18T08:00:00-04:00</published><updated>2024-06-09T00:00:00-04:00</updated><id>https://seeknay.com/identity/career-development/exploring-iam-careers</id><content type="html" xml:base="https://seeknay.com/identity/career-development/exploring-iam-careers/"><![CDATA[<h2 id="-introduction">🔐 Introduction</h2>

<p>When people say they “work in Identity,” it can mean a lot of different things, and that’s what makes this field both interesting and confusing for those just starting out. Identity and Access Management (IAM) is about making sure the right people and systems have access to the right things, and nothing more. That might sound simple, but in practice it spans everything from handling logins and managing accounts to enforcing security policies across thousands of users and applications.</p>

<p>This post breaks down the types of IAM jobs that exist today; some technical, some operational, some focused on governance or cloud - and outlines what skills are helpful for each. I also included examples pulled from real job listings to show how these roles show up in the wild. If you’re curious about IAM, switching roles, or just figuring out where to start, I hope this gives you a useful jumping-off point.</p>

<blockquote class="notice--info">
  <p>👥 <strong>Workforce vs Customer Identity</strong></p>

  <p>The role breakdowns in this article mostly focus on <strong>Workforce IAM</strong>, which covers access for employees, contractors, service accounts, etc.</p>

  <p><strong>Customer IAM (CIAM)</strong> involves many of the same tools and titles, but the work is centered on user sign-up flows, privacy, consent, and fraud protection for external users.</p>

  <p>I’m not breaking every role out by identity type, but it’s worth knowing the difference as you explore this space.</p>
</blockquote>

<hr />

<h2 id="-a-quick-note-on-role-scope">🔍 A Quick Note on Role Scope</h2>

<p>In larger organizations, you’ll often find specialized IAM roles like the ones described below, each focused on a specific area such as governance, engineering, or architecture. In medium or smaller companies, these responsibilities are often combined into hybrid roles. For example, instead of a dedicated Identity and Access Management Administrator, you might see a System Administrator or Cloud Engineer managing access control as part of their broader responsibilities. Job titles and scopes can vary depending on company size, team structure, and priorities.</p>

<hr />

<h3 id="-identity-and-access-management-iam-analyst">👩‍💼 Identity and Access Management (IAM) Analyst</h3>

<p><strong>Responsibilities:</strong></p>

<ul>
  <li><strong>User Lifecycle Management:</strong> Oversee the creation, modification, and deactivation of user accounts across various systems, ensuring timely and accurate provisioning and deprovisioning.</li>
  <li><strong>Access Reviews and Audits:</strong> Conduct regular audits and reviews of user access rights to ensure compliance with internal policies and external regulations.</li>
  <li><strong>Policy Enforcement:</strong> Implement and enforce IAM policies, procedures, and controls to maintain security and compliance standards.</li>
  <li><strong>Collaboration:</strong> Work closely with IT, HR, and security teams to align IAM processes with organizational needs and to address access-related issues.</li>
  <li><strong>Troubleshooting:</strong> Identify and resolve access-related issues, ensuring minimal disruption to business operations.</li>
  <li><strong>Documentation:</strong> Maintain up-to-date documentation of IAM processes, configurations, and procedures for audit and operational purposes.</li>
</ul>

<p><strong>Ideal Background:</strong></p>

<ul>
  <li><strong>Education:</strong> Bachelor’s degree in Computer Science, Information Technology, or a related field.</li>
  <li><strong>Experience:</strong> Will vary; typically 2+ years of experience in identity and access management or a related IT security role.</li>
  <li><strong>Technical Skills:</strong> Familiarity with IAM tools and platforms (e.g., Active Directory, LDAP, SAML, MFA solutions).</li>
  <li><strong>Analytical Skills:</strong> Strong analytical and problem-solving abilities, with attention to detail.</li>
  <li><strong>Communication:</strong> Effective verbal and written communication skills, with the ability to convey complex information to non-technical stakeholders.</li>
  <li><strong>Certifications (Optional):</strong> Certifications such as CompTIA Security+, vendor-specific IAM certifications from Okta, Microsoft, or similar.</li>
</ul>

<p><strong>Similar Job Titles:</strong></p>

<ul>
  <li>Access Management Analyst</li>
  <li>Identity Governance Analyst</li>
  <li>Identity Management Analyst</li>
  <li>Identity and Access Provisioning Analyst</li>
  <li>Identity and Access Business Analyst</li>
  <li>Identity and Access Risk Analyst</li>
  <li>Security Analyst – Identity and Access Management</li>
</ul>

<hr />

<h3 id="️-identity-and-access-management-iam-administrator">🛠️ Identity and Access Management (IAM) Administrator</h3>

<p><strong>Responsibilities:</strong></p>

<ul>
  <li><strong>User Lifecycle Management:</strong> Manage the provisioning, modification, and deactivation of user accounts across systems, ensuring timely and accurate access control.</li>
  <li><strong>Access Control Implementation:</strong> Define and enforce access policies, including role-based access control (RBAC), to ensure users have appropriate permissions.</li>
  <li><strong>IAM System Maintenance:</strong> Configure, maintain, and optimize IAM tools and platforms to support authentication, authorization, and directory services.</li>
  <li><strong>Monitoring and Auditing:</strong> Regularly monitor system activity, conduct access reviews, and audit logs to ensure compliance with security policies and regulatory requirements.</li>
  <li><strong>Multi-Factor Authentication (MFA):</strong> Implement and manage MFA solutions to enhance security for user authentication processes.</li>
  <li><strong>Issue Resolution:</strong> Troubleshoot and resolve IAM-related issues, providing support to users and collaborating with IT teams to address access concerns.</li>
  <li><strong>Documentation:</strong> Maintain comprehensive documentation of IAM processes, configurations, and procedures for audit and operational purposes.</li>
</ul>

<p><strong>Ideal Background:</strong></p>

<ul>
  <li><strong>Education:</strong> Bachelor’s degree in Information Security, Information Technology, Computer Science, or a related field.</li>
  <li><strong>Experience:</strong> Will vary; typically 3+ years in IAM or related roles, with hands-on experience in user provisioning, access control, and directory services.</li>
  <li><strong>Technical Skills:</strong> Proficiency with IAM tools (e.g., Active Directory, LDAP), understanding of authentication protocols (e.g., SAML, OAuth), and familiarity with security frameworks.</li>
  <li><strong>Communication:</strong> Strong ability to convey technical information to non-technical audiences and collaborate across departments.</li>
  <li><strong>Certifications (Optional):</strong> Certifications such as CompTIA Security+, vendor-specific IAM certifications from Okta, Microsoft, or similar.</li>
</ul>

<p><strong>Similar Job Titles:</strong></p>

<ul>
  <li>Access Management Administrator</li>
  <li>Identity Management Administrator</li>
  <li>IAM Systems Administrator</li>
  <li>IAM Operations Administrator</li>
  <li>IAM Support Administrator</li>
  <li>IAM Analyst/Administrator</li>
  <li>IAM Specialist</li>
  <li>IAM Engineer</li>
</ul>

<hr />

<h3 id="-identity-and-access-management-iam-developer">🔧 Identity and Access Management (IAM) Developer</h3>

<p><strong>Responsibilities:</strong></p>

<ul>
  <li><strong>System Design and Implementation:</strong> Design, develop, and maintain IAM solutions that manage digital identities and access rights across the organization.</li>
  <li><strong>Application Integration:</strong> Integrate applications and services with identity providers using protocols such as OAuth 2.0, OpenID Connect (OIDC), and SAML to enable single sign-on (SSO) and secure authentication.</li>
  <li><strong>Custom Development:</strong> Develop custom scripts and applications to automate identity workflows, including user provisioning, deprovisioning, and access reviews.</li>
  <li><strong>Directory Services Management:</strong> Work with directory services like Active Directory and LDAP to manage user information and access controls.</li>
  <li><strong>Security Compliance:</strong> Ensure IAM solutions comply with security policies and regulatory requirements, conducting regular assessments and implementing necessary controls.</li>
  <li><strong>Collaboration:</strong> Collaborate with cross-functional teams, including security, IT, and application developers, to implement IAM best practices and solutions.</li>
  <li><strong>Troubleshooting and Support:</strong> Identify and resolve issues related to identity management systems, providing support for IAM-related incidents and requests.</li>
</ul>

<p><strong>Ideal Background:</strong></p>

<ul>
  <li><strong>Education:</strong> Bachelor’s degree in Computer Science, Engineering, or a related field.</li>
  <li><strong>Experience:</strong> Will vary; typically3+ years of experience in IAM development or a related role, with hands-on experience in designing and implementing IAM solutions.</li>
  <li><strong>Technical Skills:</strong> Proficiency in programming and scripting languages such as Python, PowerShell, JavaScript, or Java; experience with IAM tools and platforms; familiarity with authentication and authorization protocols (e.g., OAuth 2.0, OIDC, SAML).</li>
  <li><strong>Security Knowledge:</strong> Understanding of security principles and practices, including access control models, encryption, and compliance standards.</li>
  <li><strong>Communication:</strong> Strong communication skills to effectively collaborate with technical and non-technical stakeholders.</li>
</ul>

<p><strong>Similar Job Titles:</strong></p>

<ul>
  <li>Identity and Access Management Developer</li>
  <li>Identity Management Developer</li>
  <li>Identity and Access Management Software Engineer</li>
  <li>Identity and Access Management Solutions Developer</li>
  <li>Identity and Access Management Integration Developer</li>
  <li>Identity and Access Management Engineer</li>
</ul>

<hr />

<h3 id="-identity-and-access-management-iam-security-specialist">🔒 Identity and Access Management (IAM) Security Specialist</h3>

<p><strong>Responsibilities:</strong></p>

<ul>
  <li><strong>Threat Identification and Mitigation:</strong> Analyze and address identity-related security threats, including unauthorized access and privilege escalation attempts.</li>
  <li><strong>Collaboration with Security Teams:</strong> Work closely with red, blue, and purple teams to enhance the organization’s security posture through coordinated efforts.</li>
  <li><strong>Advanced Security Measures Implementation:</strong> Deploy and manage advanced security controls for identity protection, such as multi-factor authentication (MFA) and privileged access management (PAM) solutions.</li>
  <li><strong>Audits and Assessments:</strong> Conduct regular audits and assessments of IAM systems to ensure compliance with security policies and regulatory requirements.</li>
  <li><strong>Policy Development and Enforcement:</strong> Develop, implement, and enforce access control policies and procedures to maintain secure and compliant access to systems and data.</li>
  <li><strong>Incident Response:</strong> Participate in incident response activities related to identity and access management, including investigation and remediation of security incidents.</li>
  <li><strong>Continuous Improvement:</strong> Stay updated on emerging threats and IAM technologies to continuously improve the organization’s identity security framework.</li>
</ul>

<p><strong>Ideal Background:</strong></p>

<ul>
  <li><strong>Education:</strong> Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.</li>
  <li><strong>Experience:</strong> Will vary; typically3+ years in IAM or a similar security role, with hands-on experience in implementing and managing IAM solutions.</li>
  <li><strong>Technical Skills:</strong> Proficiency with IAM tools (e.g., Active Directory, LDAP, SAML, OAuth), and understanding of security protocols and frameworks.</li>
  <li><strong>Regulatory Knowledge:</strong> Familiarity with regulatory requirements such as GDPR, HIPAA, SOX, and ISO 27001.</li>
  <li><strong>Analytical Skills:</strong> Strong analytical and problem-solving abilities, with attention to detail.</li>
  <li><strong>Communication:</strong> Effective communication skills to collaborate with cross-functional teams and convey technical information to non-technical stakeholders.</li>
  <li><strong>Certifications (Optional):</strong> Certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or vendor-specific IAM certifications.</li>
</ul>

<p><strong>Similar Job Titles:</strong></p>

<ul>
  <li>Identity and Access Management Security Specialist</li>
  <li>Identity and Access Management Security Consultant</li>
  <li>Identity and Access Management Security Analyst</li>
  <li>Identity Security Engineer</li>
  <li>Identity and Access Management Governance Specialist</li>
  <li>Identity and Access Management Risk Analyst</li>
  <li>Identity and Access Management Compliance Specialist</li>
  <li>Identity and Access Management Threat Analyst</li>
</ul>

<hr />

<h3 id="-identity-and-access-management-iam-architect">🧱 Identity and Access Management (IAM) Architect</h3>

<p><strong>Responsibilities:</strong></p>

<ul>
  <li><strong>Architectural Design:</strong> Design and implement scalable, secure, and resilient IAM infrastructures that align with organizational goals and regulatory requirements.</li>
  <li><strong>Federated Identity and SSO Strategies:</strong> Develop and oversee strategies for identity federation and single sign-on (SSO) to streamline user access across diverse systems and platforms.</li>
  <li><strong>Stakeholder Collaboration:</strong> Collaborate with business and IT stakeholders (Information Security, Internal Audit, etc.) to ensure IAM solutions meet current and future business needs.</li>
  <li><strong>Integration of IAM Solutions:</strong> Integrate identity management, access management, and governance solutions into existing infrastructures and applications.</li>
  <li><strong>Policy and Compliance Oversight:</strong> Establish and enforce IAM policies, standards, and procedures to ensure compliance with industry regulations and best practices.</li>
  <li><strong>Technology Evaluation:</strong> Evaluate emerging IAM technologies and recommend solutions that enhance security and operational efficiency.</li>
  <li><strong>Mentorship and Leadership:</strong> Provide guidance and mentorship to IAM teams, fostering a culture of continuous improvement and knowledge sharing.</li>
</ul>

<p><strong>Ideal Background:</strong></p>

<ul>
  <li><strong>Education:</strong> Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.</li>
  <li><strong>Experience:</strong> Extensive experience in IAM architecture, including the design and implementation of complex IAM solutions.</li>
  <li><strong>Technical Proficiency:</strong> Deep understanding of IAM protocols (e.g., SAML, OAuth, OpenID Connect), directory services (e.g., Active Directory, LDAP), and IAM tools (Sailpoint, Okta, Entra ID, Saviynt).</li>
  <li><strong>Strategic Thinking:</strong> Ability to align IAM strategies with business objectives and adapt to evolving technological landscapes.</li>
  <li><strong>Communication Skills:</strong> Strong verbal and written communication skills to effectively convey complex IAM concepts to diverse audiences.</li>
  <li><strong>Certifications (Optional):</strong> Certifications such as Certified Information Systems Security Professional (CISSP), Certified Identity and Access Manager (CIAM), or similar credentials.</li>
</ul>

<p><strong>Similar Job Titles:</strong></p>

<ul>
  <li>Identity and Access Management Solutions Architect</li>
  <li>Identity and Access Management Technical Architect</li>
  <li>Identity and Access Management Infrastructure Architect</li>
  <li>Identity and Access Management Security Architect</li>
  <li>Identity and Access Management Enterprise Architect</li>
  <li>Identity and Access Management Domain Architect</li>
  <li>Identity and Access Management Systems Architect</li>
  <li>Lead Identity and Access Management Architect</li>
</ul>

<hr />

<h2 id="career-pathways-into-identity-and-access-management-iam">Career Pathways into Identity and Access Management (IAM)</h2>

<p>There’s no single way to break into Identity and Access Management (IAM). People arrive here from all sorts of tech backgrounds—whether it’s helpdesk support, system administration, software development, cloud engineering, or cybersecurity.</p>

<p>Some IAM roles are hands-on and technical, others are more strategic or compliance driven. Many blend both. The good news? You don’t need to follow a rigid path. Whether you’re starting out or pivoting from another IT role, there are multiple ways to grow into an IAM career.</p>

<p>In the sections below, I’ll cover potential routes into IAM and how your existing skills can help you get there.</p>

<p><strong>Note:</strong> These pathways are illustrative and not exhaustive. Individual journeys into IAM can vary based on personal interests, organizational needs, and emerging technologies.</p>

<hr />

<h3 id="️-it-support--helpdesk">🛠️ IT Support &amp; Helpdesk</h3>

<p><strong>Starting Roles:</strong></p>

<ul>
  <li>Helpdesk Technician</li>
  <li>IT Support Specialist</li>
</ul>

<p><strong>Transition Path:</strong></p>

<ul>
  <li><strong>Helpdesk Technician → Identity and Access Management Analyst:</strong> Building upon experience in resolving user access issues to managing and auditing access controls and policies.</li>
</ul>

<p><strong>Key Skills:</strong></p>

<ul>
  <li>User account management</li>
  <li>Basic understanding of access controls</li>
  <li>Familiarity with directory services like Active Directory</li>
</ul>

<hr />

<h3 id="️-systems--infrastructure">🖥️ Systems &amp; Infrastructure</h3>

<p><strong>Starting Roles:</strong></p>

<ul>
  <li>System Administrator</li>
  <li>Infrastructure Engineer</li>
</ul>

<p><strong>Transition Path:</strong></p>

<ul>
  <li><strong>System Administrator → Identity and Access Management Administrator:</strong> Building upon experience in system management to oversee identity systems and implement access controls.</li>
</ul>

<p><strong>Key Skills:</strong></p>

<ul>
  <li>Directory services management</li>
  <li>Understanding of network protocols and security</li>
  <li>Experience with server and infrastructure management</li>
</ul>

<hr />

<h3 id="️-cloud--devops">☁️ Cloud &amp; DevOps</h3>

<p><strong>Starting Roles:</strong></p>

<ul>
  <li>Cloud Engineer</li>
  <li>DevOps Engineer</li>
</ul>

<p><strong>Transition Path:</strong></p>

<ul>
  <li><strong>Cloud Engineer → Identity and Access Management Engineer:</strong> Integrating IAM solutions within cloud platforms and managing cloud-based access controls.</li>
</ul>

<p><strong>Key Skills:</strong></p>

<ul>
  <li>Cloud platform proficiency (e.g., AWS, Azure, GCP)</li>
  <li>Infrastructure as Code (IaC) tools</li>
  <li>Automation and scripting</li>
</ul>

<hr />

<h3 id="-software-development">👨‍💻 Software Development</h3>

<p><strong>Starting Roles:</strong></p>

<ul>
  <li>Software Developer</li>
  <li>Application Developer</li>
</ul>

<p><strong>Transition Path:</strong></p>

<ul>
  <li><strong>Software Developer → Identity and Access Management Developer:</strong> Developing and integrating identity solutions within applications, focusing on authentication and authorization mechanisms.</li>
</ul>

<p><strong>Key Skills:</strong></p>

<ul>
  <li>Programming languages (e.g., Python, Java, PowerShell)</li>
  <li>Understanding of authentication protocols (e.g., OAuth 2.0, SAML, OpenID Connect)</li>
  <li>API integration</li>
</ul>

<hr />

<h3 id="-cybersecurity">🔐 Cybersecurity</h3>

<p><strong>Starting Roles:</strong></p>

<ul>
  <li>Security Analyst</li>
  <li>Information Security Specialist</li>
</ul>

<p><strong>Transition Path:</strong></p>

<ul>
  <li><strong>Security Analyst → Identity and Access Management Security Specialist:</strong> Focusing on identity-specific threats and implementing security measures within IAM frameworks.</li>
</ul>

<p><strong>Key Skills:</strong></p>

<ul>
  <li>Risk assessment and mitigation</li>
  <li>Compliance and regulatory knowledge (e.g., GDPR, HIPAA)</li>
  <li>Security auditing and monitoring</li>
</ul>

<hr />

<h3 id="-cross-functional-transitions">🧩 Cross-Functional Transitions</h3>

<p>IAM roles often require collaboration across various IT domains. Professionals may find themselves transitioning into IAM from roles that overlap multiple areas:</p>

<ul>
  <li>
    <p><strong>IT Project Manager → Identity and Access Management Program Manager:</strong> Overseeing IAM projects and aligning them with organizational goals.</p>
  </li>
  <li>
    <p><strong>Business Analyst → Identity and Access Management Business Analyst:</strong> Analyzing business requirements to inform IAM solutions and policies.</p>
  </li>
</ul>

<hr />

<p>By understanding these pathways, professionals can identify how their current roles and skills align with opportunities in IAM and plan their career development accordingly.</p>

<h2 id="-conclusion">🧭 Conclusion</h2>

<p>Identity and Access Management (IAM) isn’t confined to a single career trajectory. Whether you’re just starting out or considering a specialization, there are multiple avenues to explore. From roles in IT support and systems administration to positions in cloud computing, software development, and cybersecurity, IAM offers diverse opportunities. Each individual’s journey is unique, so it’s essential to assess your interests and skills to determine the path that aligns best with your career goals.</p>]]></content><author><name>seeknay</name></author><category term="identity" /><category term="career-development" /><category term="iam" /><category term="career-paths" /><category term="it-security" /><category term="entry-level" /><summary type="html"><![CDATA[Explore real-world IAM roles, required skills, and how to build a career in this space.]]></summary></entry><entry><title type="html">Cyber Crisis – A CXO’s Quest</title><link href="https://seeknay.com/tabletop/cybersecurity/cyber-crisis-a-cxos-quest/" rel="alternate" type="text/html" title="Cyber Crisis – A CXO’s Quest" /><published>2025-04-12T22:00:00-04:00</published><updated>2025-06-01T22:00:00-04:00</updated><id>https://seeknay.com/tabletop/cybersecurity/cyber-crisis-a-cxos-quest</id><content type="html" xml:base="https://seeknay.com/tabletop/cybersecurity/cyber-crisis-a-cxos-quest/"><![CDATA[<p><strong>Cyber Crisis: A CXO’s Quest</strong> is a tabletop simulation game I created (inspired by Dungeons &amp; Dragons) to help players understand what happens inside a company during a cybersecurity incident.</p>

<p>Players take on executive roles—like CEO, CISO, or CFO—and respond to a simulated breach over a series of turns. The game is based on real-world incidents and focuses on how decisions are made, what’s at stake, and how different roles within a business react under pressure.</p>

<blockquote class="notice--info">
  <p>🎯 <strong>Goal:</strong> You don’t win. You learn what can go wrong when teams misalign or under-communicate.</p>
</blockquote>

<hr />

<h2 id="-why-i-built-it">💡 Why I Built It</h2>

<p>Most security tabletop exercises are overly technical or compliance-focused. They often miss the <em>human and organizational</em> elements—like miscommunication, competing priorities, or executive pressure.</p>

<p>This game flips the script. It focuses on leadership dynamics during crisis:</p>

<blockquote class="notice--info">
  <p>⚖️ A Legal Officer may prioritize liability. A CISO may prioritize stopping the breach. Both are “right”—but those differences affect outcomes.</p>
</blockquote>

<hr />

<h2 id="️-how-it-works">🕹️ How It Works</h2>

<ul>
  <li>The game is turn-based. Each round introduces a new twist in the cyber incident.</li>
  <li>Players make decisions with limited time and incomplete information.</li>
  <li>Each role has unique objectives that may conflict with others.</li>
  <li>Real-world inspiration comes from events like the <strong>SolarWinds hack</strong> or the <strong>MGM ransomware attack</strong>.</li>
  <li>After play, you get a written debrief summarizing outcomes and alternate paths.</li>
</ul>

<blockquote class="notice--info">
  <p>🧠 It’s designed to spark discussion—not just test knowledge.</p>
</blockquote>

<hr />

<h2 id="-ways-to-use-it">👥 Ways to Use It</h2>

<ul>
  <li><strong>Solo</strong> — Explore breach scenarios or prep for your own tabletop at work.</li>
  <li><strong>Team Play</strong> — Assign CXO roles to coworkers and walk through a breach together.</li>
  <li><strong>Learning Tool</strong> — Great for understanding how legal, technical, and business decisions intersect during an incident.</li>
</ul>

<blockquote class="notice--success">
  <p>📢 Perfect for tabletop first-timers or folks who want to see what executive crisis response actually looks like.</p>
</blockquote>

<hr />

<h2 id="-try-it-in-chatgpt">🚀 Try It in ChatGPT</h2>

<p>I built a custom GPT that runs the game, acts as the <em>Incident Master</em>, and guides gameplay:</p>

<p>👉 <a href="https://chatgpt.com/g/g-67eb431e39e881919e375401ea44d7f2-cyber-crisis-a-cxo-s-quest">Launch Cyber Crisis: A CXO’s Quest in ChatGPT</a></p>

<blockquote class="notice--info">
  <p>💬 Ask it questions. Push its logic. Step out of the checkbox.<br />
The more creative you get, the more dynamic the session becomes.</p>
</blockquote>

<hr />

<h2 id="-agent-instructions-for-chatgpt-gpt-builder">🔧 Agent Instructions (for ChatGPT GPT Builder)</h2>

<blockquote>
  <p>Below are the prompt instructions I used to build it.  Feel free to tinker and build your own!</p>
</blockquote>

<div class="language-text highlighter-rouge"><div class="highlight"><pre class="highlight"><code>You are a specialized GPT designed to assist in designing, refining, and running **Cyber Crisis: A CXO’s Quest**—a cybersecurity-themed tabletop role-playing game modeled after Dungeons &amp; Dragons. The game supports 1 to 8 players, each roleplaying as a Chief Officer (CEO, CIO, CISO, CFO, COO, CMO, CHRO, CLO) of a fictional enterprise facing escalating cyber threats. One player acts as the Incident Master (IM), guiding the narrative and adjudicating outcomes like a Dungeon Master.

🎯 Primary Functions:
- Help design game mechanics, CXO role cards, threat scenarios, industry packs, and decision systems.
- Act in two modes:
  - 🛠 **Design Mode**: Brainstorm and refine rules, character systems, and educational outcomes.
  - 🎭 **Live Play Mode**: Serve as the Incident Master (IM), narrating the session, presenting threats, facilitating decisions, and resolving actions with immersive storytelling.
- Ensure all enterprise scenarios are grounded in realistic, current cybersecurity threats. Use the MITRE ATT&amp;CK framework and high-profile cyber incidents (fictionalized) as inspiration.

---

## 🧱 Core Game Concepts:

### 🎯 Session Objectives:
- Reveal blind spots in decision-making, escalation, and communication.
- Simulate the high-stakes world of cyber crisis management at the executive level.
- Reinforce strategic trade-offs, real-world limitations, and urgency.

---

### 🧨 Scenario Structure:
Every scenario includes:
- **Trigger**: Entry vector (e.g., phishing, supply chain compromise, misconfiguration)
- **Indicators of Compromise** (IOCs)
- **Escalation Path**: Lateral movement, persistence, or extortion
- **Impact Zones**: Data, operations, finances, brand, compliance
- **Resolution Paths**: Contain, disclose, negotiate, remediate

Use **probabilistic threat modeling**:
- Assign escalating probability ranges (e.g., 10%, 30%, 60%) for attacker progression.
- The longer an indicator or threat is ignored, the higher the success chance for the attacker’s next move.

Introduce a **Crisis Curve Timer**, reflecting stages of a breach:
- T1: Initial Detection  
- T2: Attacker Movement  
- T3: Exfiltration or Extortion  
- T4: Reputational or Legal Fallout  

Player actions delay or accelerate curve progression.

---

### 🧑‍💼 CXO Roles:
Each Chief Officer has:
- **Primary Stat**: Functional strength (e.g., CFO = Budget, CHRO = Morale)
- **Passive Trait**: Ongoing bonus  
- **Power Card**: A one-use high-impact strategic move  
- **Dice Modifiers**: For or against various decision types  
- **Asymmetric Objective**: Private CXO win condition that may conflict with others

Examples:
- CISO: Prevent persistent access  
- CFO: Keep response under $1M  
- CLO: Avoid regulatory disclosure  
- CMO: Restore public trust to 8+  

This models executive misalignment during real-world crises.

---

### 💼 Resource Management:
Players manage limited:
- **Time**: Decisions must be made within turns
- **Budget**: Allocate toward defense, legal, comms, or upgrades
- **Staff Capacity**: Reflects burnout, attrition, or misallocation

Players must weigh trade-offs. **Delayed action increases attacker success odds** and introduces **Risk Debt**—unaddressed issues that reappear in later turns.

---

### 🎲 Decision System:
Use dice or fate-based systems:
- Standard rolls: 50%, 75%, or 90% success chance  
- Modifiers: Role alignment, preparation, inter-CXO conflict  
- Outcomes: Critical Success, Success, Partial Success, Failure, Critical Failure

---

### 📊 Trust &amp; Influence Meters:
Track dynamic values affected by player decisions:
- **Public Trust**
- **Board Confidence**
- **Regulatory Attention**
- **Employee Morale**

Actions by CXOs directly affect these. Consequences occur when thresholds are crossed:
- Trust &lt; 3 → PR Crisis  
- Board Confidence &lt; 2 → Forced Resignation Vote  
- Regulatory Attention = MAX → Surprise Audit  
These drive realism and increase pressure as the game progresses.

---

### 📢 Communication Dynamics:
Encourage realistic tension:
- **Intel Asymmetry**: Only some CXOs have full visibility
- **Side Conversations**: Backchannels, secret alliances, or legal shielded discussions
- **Role Friction**: Simulate internal disagreement (e.g., CISO vs CLO over breach disclosure)

---

### ❌ Failure Is Valid:
Failure is encouraged when justified. Reflect consequences such as:
- Revenue loss  
- Lawsuits  
- Long-term brand damage  
- Increased scrutiny from board or regulators

Make space for player reflection: “Why did we fail?”

---

### 📅 End-of-Game Reporting (AAR):
At the end of a session, generate a professional After-Action Report:
- 📍 Timeline of threat evolution  
- 🧠 CXO actions and reasoning  
- 🔥 Impacts (data loss, financial, operational, brand)  
- 📚 Lessons learned (link to MITRE ATT&amp;CK where relevant)  
- 📈 Delta: Risk posture from Turn 1 vs Turn 10  
- 🧭 Team Alignment Score  
- 🚨 Missed Opportunities &amp; Ideal Paths  
- 🧠 *Real World Parallels*: At the end, describe a real incident this scenario mirrors and what was done differently (or worse) in reality.

---

### 🧘 Leadership Reflection (Optional):
Offer prompts between rounds or at the end of play:
- “What policy would you propose after this incident?”
- “Which team decision do you most disagree with, and why?”
- “What would you do differently in your real-world role?”

These encourage professional growth and internalization.

---

### 🏭 Industry Customization Packs:
Adapt scenarios and mechanics per industry vertical. Each has unique assets, risks, and external pressures.

- **Healthcare**: PHI, ransomware prioritization, HIPAA  
- **Finance**: Insider trading, SOX, real-time payment risks  
- **Media**: Talent leaks, brand risk, reputational volatility  
- **Retail**: PCI scope, fraud vectors, supply chain  
- **Education**: Student data, old systems, limited budget  

Scenarios should reflect vertical-specific tension, attacker motives, and regulatory sensitivity.

---

### 🧠 Guiding Principle:
Your job is to teach *strategic decision-making under fire*, modeled through the lens of executive cyber crisis response.  
Always prioritize realism, urgency, collaboration, trade-offs, and consequences.  
This is not about being perfect—it’s about surfacing what goes wrong in the real world, and why.
</code></pre></div></div>]]></content><author><name>seeknay</name></author><category term="tabletop" /><category term="cybersecurity" /><category term="game" /><category term="ciso" /><category term="leadership" /><category term="incident-response" /><category term="training" /><summary type="html"><![CDATA[A tabletop game, styled after D&D, where executives respond to a live cyber breach and learn how incident response works under pressure.]]></summary></entry><entry><title type="html">Blog Highlight: Active Directory Hardening Blog Series</title><link href="https://seeknay.com/activedirectory/security/active-directory-hardening/" rel="alternate" type="text/html" title="Blog Highlight: Active Directory Hardening Blog Series" /><published>2025-02-24T10:30:00-05:00</published><updated>2025-06-01T23:00:00-04:00</updated><id>https://seeknay.com/activedirectory/security/active-directory-hardening</id><content type="html" xml:base="https://seeknay.com/activedirectory/security/active-directory-hardening/"><![CDATA[<p><a href="https://techcommunity.microsoft.com/users/jerrydevore/199458">Jerry Devore</a>, a Senior Premier Field Engineer at Microsoft (at the time of this post), has created an absolute must-read blog series on Active Directory Hardening. Even if AD hardening isn’t your primary focus, this is one of the most comprehensive collections of AD knowledge I’ve come across. If you manage Active Directory, you need to understand the concepts he covers.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-1-%E2%80%93-disabling-ntlmv1/3934787">Active Directory Hardening Series - Part 1 – Disabling NTLMv1</a></p>

<p>NTLMv1, an outdated authentication protocol, is vulnerable to various attacks. Transitioning to NTLMv2 enhances security by providing stronger encryption and better resistance to attacks.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-2-%E2%80%93-removing-smbv1/3988317">Active Directory Hardening Series - Part 2 – Removing SMBv1</a></p>

<p>SMBv1, introduced decades ago, lacks modern security features and is susceptible to multiple vulnerabilities. Eliminating SMBv1 reduces the attack surface. This process includes auditing current SMB usage, identifying dependencies, and systematically disabling SMBv1 on all systems.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-3-%E2%80%93-enforcing-ldap-signing/4066233">Active Directory Hardening Series - Part 3 – Enforcing LDAP Signing</a></p>

<p>LDAP traffic, if unsigned, can be intercepted or tampered with, posing significant security risks. Enforcing LDAP signing ensures the integrity and authenticity of LDAP communications. This measure involves configuring domain controllers to require LDAP signing and ensuring all client applications support and implement LDAP signing.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-4-%E2%80%93-enforcing-aes-for-kerberos/4114965">Active Directory Hardening Series - Part 4 – Enforcing AES for Kerberos</a></p>

<p>Kerberos, a cornerstone of AD authentication, traditionally used the RC4 encryption algorithm, which is now considered weak. Enforcing AES encryption for Kerberos tickets enhances security by utilizing stronger cryptographic methods. This transition requires updating account encryption settings and ensuring all systems and applications support AES.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-5-%E2%80%93-enforcing-ldap-channel-binding/4235497">Active Directory Hardening Series - Part 5 – Enforcing LDAP Channel Binding</a></p>

<p>LDAP channel binding adds an extra layer of security by binding the TLS tunnel to the LDAP session, mitigating man-in-the-middle attacks. Implementing this involves configuring domain controllers to require channel binding tokens and updating clients to support this feature.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-6-%E2%80%93-enforcing-smb-signing/4272168">Active Directory Hardening Series - Part 6 – Enforcing SMB Signing</a></p>

<p>SMB signing ensures that SMB communications are authenticated and that their integrity is verified, protecting against tampering and certain types of relay attacks. Enforcing SMB signing involves configuring both clients and servers to require signed SMB communications.</p>

<p><a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-7-%E2%80%93-implementing-least-privilege/4366626">Active Directory Hardening Series - Part 7 – Implementing Least Privilege</a></p>

<p>Adopting the principle of least privilege involves granting users and services only the permissions necessary to perform their tasks, minimizing potential attack vectors. This practice includes regular audits of user permissions, reducing the number of privileged accounts, and implementing role-based access controls.</p>]]></content><author><name>seeknay</name></author><category term="activedirectory" /><category term="security" /><category term="hardening" /><category term="ldap" /><category term="kerberos" /><category term="smb" /><category term="privilege" /><summary type="html"><![CDATA[A quick spotlight on Jerry Devore’s excellent AD Hardening series, with links to each post and why they matter.]]></summary></entry><entry><title type="html">Defense in Depth: How to Layer Your Personal Digital Security</title><link href="https://seeknay.com/security/digital-safety/defense-in-depth/" rel="alternate" type="text/html" title="Defense in Depth: How to Layer Your Personal Digital Security" /><published>2025-02-12T08:30:00-05:00</published><updated>2025-06-01T23:00:00-04:00</updated><id>https://seeknay.com/security/digital-safety/defense-in-depth</id><content type="html" xml:base="https://seeknay.com/security/digital-safety/defense-in-depth/"><![CDATA[<h2 id="introduction">Introduction</h2>

<p>Protecting yourself online can feel challenging at times, but there’s an approach that works well and is used by businesses everywhere: <strong>Defense in Depth</strong>. Think of it like peeling an onion; security comes in layers, and each one adds extra protection against threats.</p>

<p>This guide provides useful insights and actionable tips to help you enable security features and adopt a security-first mindset at every layer of your digital life.</p>

<h2 id="1-physical-security">1. Physical Security</h2>

<p class="notice--primary"><strong>Purpose:</strong> Protect your physical devices from theft or tampering.</p>

<p>Imagine losing your phone or laptop. Your photos, bank details, and passwords could all be at risk if someone else gets your device. Physical security is about protecting the “front door” to your device so strangers can’t just pick it up and access your life.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself">How to Protect Yourself:</h4>

<ul>
  <li><strong>Use device locks</strong> (PINs, passwords, or biometrics like fingerprints or facial recognition). This prevents unauthorized people from unlocking your device. Avoid easy codes like “1234” or birthdays, and don’t reuse device PINs/passwords across different devices.</li>
  <li><strong>Never leave devices unattended</strong> in public places, and be mindful of shoulder-surfing (someone looking over your shoulder). Opportunistic thieves can quickly snatch or peek at an unprotected device.</li>
  <li><strong>Enable device tracking and remote wipe</strong> so you can locate or erase your device if it’s lost or stolen. For example, smartphones and laptops offer features to find a lost device or wipe its data remotely.</li>
</ul>

<h3 class="notice--info no_toc" id="platform-specific-tips">Platform-Specific Tips</h3>

<ul>
  <li><strong>Windows:</strong> Set up <strong>Windows Hello</strong> for biometric sign-in (fingerprint or face). This adds secure, convenient access to your PC.</li>
  <li><strong>Apple (iPhone/iPad/Mac):</strong> Enable <strong>Apple’s Stolen Device Protection</strong> (on iPhone with iOS 17.3 or later) to add an extra layer of security when your device is away from trusted locations. Also, turn on <strong>Face ID or Touch ID</strong> on your iPhone, iPad, and Mac for quick biometric unlocking. Be sure to enable <strong>Find My</strong> on all your Apple devices to locate, lock, or erase them remotely if needed.</li>
  <li><strong>Android:</strong> Set a strong screen lock on your phone (PIN or biometrics). Keep <strong>Find My Device</strong> enabled to help locate or remotely secure your phone if it goes missing.</li>
</ul>

<h2 id="2-network-security">2. Network Security</h2>

<p class="notice--primary"><strong>Purpose:</strong> Safeguard your devices from unauthorized access and attacks, especially when they’re online.</p>

<p>Think of your home Wi-Fi like the door to your house. You wouldn’t leave it wide open, right? Network security ensures only trusted people and devices can use your internet. This protects not just your connection but everything connected to it — from your smart TV to your work emails.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself-1">How to Protect Yourself:</h4>

<ul>
  <li><strong>Secure your Wi-Fi network:</strong> Change the default administrator password on your home router to a strong, unique password. Also use a strong Wi-Fi network key with modern encryption (WPA2 or WPA3) so only authorized people can connect.</li>
  <li><strong>Keep your router updated:</strong> Regularly install your router’s firmware updates from the manufacturer. Updates fix security weaknesses and improve protection.</li>
  <li><strong>Enable firewalls:</strong> Use the built-in firewall on your computers (e.g. enable Windows Defender Firewall or the macOS firewall) to block unwanted incoming connections. These help shield your devices from network-based attacks.</li>
  <li><strong>Be cautious on public Wi-Fi:</strong> Public hotspots (like those in cafes or airports) are not secure. Avoid accessing sensitive accounts or information on public Wi-Fi, or use a trusted VPN service if you must use those networks.</li>
</ul>

<h2 id="3-identity-and-access-management-iam">3. Identity and Access Management (IAM)</h2>

<p class="notice--primary"><strong>Purpose:</strong> Make sure only <strong>you</strong> can access your accounts and personal information.</p>

<p>Imagine someone pretending to be you online; they could open credit cards in your name or even lock you out of your own accounts. IAM is like showing ID on the internet. It ensures only the real you can log in or make important changes to your accounts.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself-2">How to Protect Yourself:</h4>

<ul>
  <li><strong>Use strong, unique passwords:</strong> Create passwords that are long (at least 12 characters) and hard to guess. Use a mix of unrelated words or a passphrase. Never reuse passwords across different accounts — if one account is breached, you don’t want the same password to unlock others.</li>
  <li><strong>Use a password manager:</strong> A password manager can generate and securely store complex passwords so you don’t have to remember them all. Many phones and browsers have one built-in (like the Passwords app for iPhone), or you can use trusted apps like 1Password, Keeper, or Bitwarden.</li>
  <li><strong>Consider single sign-on (SSO):</strong> Using options like “Sign in with Apple,” “Sign in with Google,” or “Sign in with Microsoft” can be convenient and secure. These big providers invest heavily in security and it reduces the number of passwords you need to manage.</li>
  <li><strong>Freeze your credit:</strong> This prevents anyone from opening new financial accounts in your name. It’s a free service you can activate with the credit bureaus and greatly reduces the risk of identity theft.</li>
  <li><strong>Enable multi-factor authentication (MFA):</strong> MFA adds an extra verification step (like a code on your phone or a fingerprint) when logging in. Even if someone steals your password, they can’t get in without that second factor. According to Microsoft, accounts with MFA enabled are <strong>99.9% less likely</strong> to be compromised.</li>
</ul>

<p><strong>Not all login methods are equal.</strong> The table below shows common authentication methods ranked by security strength. Try to use the stronger methods (toward the top of the table), especially for accounts with sensitive information like finances or personal photos.</p>

<table>
  <thead>
    <tr>
      <th>Strength</th>
      <th>Login Method</th>
      <th>Examples</th>
      <th>Characteristics</th>
      <th>Type</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Very Strong</td>
      <td><strong>Passkeys</strong></td>
      <td>Apple Passkeys, Google Passkeys</td>
      <td>Device-bound, phishing-resistant, user-verifying <br /><em>(combines possession with knowledge or biometric)</em></td>
      <td>Possession + Knowledge/Biometric</td>
    </tr>
    <tr>
      <td>Very Strong</td>
      <td><strong>Hardware security keys</strong></td>
      <td>YubiKey, Titan Security Key</td>
      <td>Device-bound, hardware-protected, phishing-resistant</td>
      <td>Possession</td>
    </tr>
    <tr>
      <td>Strong</td>
      <td><strong>Biometric authentication</strong></td>
      <td>Fingerprint, Face ID</td>
      <td>Requires user’s physical presence (device-bound) and is user-verifying</td>
      <td>Biometric</td>
    </tr>
    <tr>
      <td>Moderate</td>
      <td><strong>Authenticator apps</strong></td>
      <td>Google Authenticator, Authy</td>
      <td>Device-bound one-time codes, require user interaction</td>
      <td>Possession</td>
    </tr>
    <tr>
      <td>Weak</td>
      <td><strong>SMS-based codes</strong></td>
      <td>One-time PIN via text message</td>
      <td>One-time code sent to a device; vulnerable to SIM-swapping attacks</td>
      <td>Possession</td>
    </tr>
    <tr>
      <td>Weak</td>
      <td><strong>Email-based codes</strong></td>
      <td>Verification links or codes via email</td>
      <td>Relies on email security; can be phished</td>
      <td>Possession</td>
    </tr>
    <tr>
      <td>Weakest</td>
      <td><strong>Security questions</strong></td>
      <td>“What is your mother’s maiden name?”</td>
      <td>Based on personal knowledge; often guessable via research or social media</td>
      <td>Knowledge</td>
    </tr>
    <tr>
      <td>Weakest</td>
      <td><strong>Password only</strong></td>
      <td>Just the account password</td>
      <td>Single secret; vulnerable if leaked or guessed</td>
      <td>Knowledge</td>
    </tr>
  </tbody>
</table>

<h2 id="4-application-security">4. Application Security</h2>

<p class="notice--primary"><strong>Purpose:</strong> Ensure the apps and software you use are safe and don’t misuse your information.</p>

<p>Have you ever downloaded an app and thought, “Why does it need access to my camera or contacts?” Application security is about trusting the tools on your phone or computer. We want to be sure the apps we install (like banking apps or social media) aren’t leaving us exposed to malware or privacy invasions.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself-3">How to Protect Yourself:</h4>

<ul>
  <li><strong>Keep your apps updated:</strong> Updates often include security fixes. Set your phone and computer to update apps automatically, if possible, so you always have the latest protections.</li>
  <li><strong>Keep your operating system updated:</strong> When your device prompts you to install an update (especially a security update), do it promptly. These patches fix known vulnerabilities that attackers could exploit.</li>
  <li><strong>Download apps from official sources:</strong> Stick to trusted app stores (the Apple App Store, Google Play Store, or Microsoft Store). Avoid downloading software from random websites, since it could hide viruses or spyware.</li>
  <li><strong>Review app permissions:</strong> Check what data and features your apps can access (location, contacts, camera, microphone, etc.). If something seems unnecessary for an app’s function, revoke that permission. For example, a simple flashlight app shouldn’t need to see your contacts.</li>
  <li><strong>Use antivirus/anti-malware protection:</strong> Make sure you have security software active on your devices. For Windows, the built-in <strong>Microsoft Defender</strong> (Windows Security) provides solid antivirus protection. Mac computers have built-in malware protections as well. These tools can help catch and remove malicious software if it slips onto your device.</li>
</ul>

<h3 class="notice--info no_toc" id="platform-specific-tips-1">Platform-Specific Tips</h3>

<ul>
  <li><strong>Windows:</strong> Use the <strong>Microsoft Store</strong> to install apps whenever possible, since apps there are vetted for security.</li>
  <li><strong>Apple:</strong> Download software from the <strong>App Store</strong> or from trusted developers only. On Mac, check your <strong>System Settings &gt; Privacy &amp; Security</strong> for App Permissions to control which programs can access sensitive information (files, camera, microphone, etc.). On iPhone, you can use <strong>Safety Check</strong> (in Settings) to review what data is being shared with others and quickly reset permissions if needed.</li>
  <li><strong>Android:</strong> Keep <strong>Google Play Protect</strong> on (it’s enabled by default in the Play Store settings) to automatically scan your apps for harmful behavior. Avoid “sideloading” apps (installing from outside the Play Store) unless you absolutely trust the source.</li>
</ul>

<h2 id="5-cloud--data-security">5. Cloud &amp; Data Security</h2>

<p class="notice--primary"><strong>Purpose:</strong> Safeguard your personal files and information from loss, theft, or unauthorized access.</p>

<p>Your data holds precious memories and essential information. Data security means protecting important files (like family photos or critical documents) so they remain safe and accessible even if your device is lost or stolen. Cloud security extends this protection to your online life by securing backups, emails, and files stored in cloud accounts — keeping your information private no matter where it lives.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself-4">How to Protect Yourself:</h4>

<ul>
  <li><strong>Enable device encryption:</strong> Turn on full-disk encryption on your devices. This scrambles your data so that only someone with the right key (your password, PIN, or fingerprint) can read it. For example, Windows offers <strong>BitLocker</strong> and macOS has <strong>FileVault</strong> to encrypt your device’s storage.</li>
  <li><strong>Back up your data:</strong> Regularly back up important files and photos. Cloud backups (like OneDrive, iCloud, or Google Drive) can automatically save copies of your data, or you can use an external hard drive. Backups ensure that if your device crashes or is stolen, you don’t lose everything.</li>
  <li><strong>Secure your cloud accounts:</strong> Protect the accounts that hold your online data (email, cloud storage, etc.) with strong passwords and MFA (as discussed above). Take advantage of extra security settings available from providers. For instance, Google’s <strong>Advanced Protection Program</strong> offers additional safeguards for Google accounts that are at higher risk, requiring a physical security key and limiting third-party access.</li>
</ul>

<h3 class="notice--info no_toc" id="platform-specific-tips-2">Platform-Specific Tips</h3>

<ul>
  <li><strong>Windows:</strong> Enable <strong>BitLocker</strong> on compatible Windows PCs to encrypt your hard drive, so your data remains locked without your login. Also, use <strong>OneDrive</strong> (built into Windows) or another trusted cloud service to automatically back up important folders like Documents and Photos.</li>
  <li><strong>Apple:</strong> Turn on <strong>FileVault</strong> on your Mac to encrypt all data on the disk. (For iPhones and iPads, device data is automatically encrypted when you use a passcode.) Use <strong>iCloud Backup</strong> on your iPhone/iPad to save your device settings, photos, and messages to iCloud, making it easy to restore if you get a new device. On Mac or PC, use <strong>iCloud Drive</strong> to securely store and sync files across your devices. Apple’s optional <strong>Advanced Data Protection</strong> for iCloud can extend end-to-end encryption to more of your iCloud data, meaning only you (with your devices) can access that information.</li>
  <li><strong>Google/Android:</strong> Make sure your Android phone’s built-in <strong>Google Backup</strong> is turned on (this will back up things like contacts, photos, and app data to your Google account). If you need the highest level of security on your Google account, consider enrolling in <strong>Google’s Advanced Protection Program</strong>. It requires using physical security keys and blocks untrusted apps from accessing your Google data, giving you strong protection against account hijacking.</li>
</ul>

<h2 id="6-monitoring-and-logging">6. Monitoring and Logging</h2>

<p class="notice--primary"><strong>Purpose:</strong> Stay aware of what’s happening with your accounts and devices.</p>

<p>Think of monitoring your accounts like having a security camera for your digital life. It helps you catch suspicious activity early. If someone is trying to access your account or something isn’t right, you can spot it and take action before too much damage is done.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself-5">How to Protect Yourself:</h4>

<ul>
  <li><strong>Use breach notification services:</strong> Sign up for a service that alerts you if your email address or personal data appears in a known data breach. For example, the free site <strong>Have I Been Pwned</strong> can notify you if your email or phone number was exposed in a data leak, so you can promptly change passwords and secure those accounts.</li>
  <li><strong>Regularly check account activity:</strong> Take advantage of tools that show you where and when your accounts have been accessed. For instance, you can view the list of devices logged in to your Apple ID, review recent security events on your Google account, or check the login history on your Microsoft account. Make a habit of checking these for your important accounts (email, social media, banking). If you ever see a login or device that you don’t recognize, secure that account immediately by changing your password and removing that unknown device from your account.</li>
  <li><strong>Monitor your credit and financial statements:</strong> Review your bank and credit card statements and credit reports regularly for any unusual activity. Many banks and credit bureaus offer free alerts or monitoring services that will flag new accounts or large transactions. Early detection of identity theft can save you a lot of trouble.</li>
</ul>

<h2 id="7-incident-response-and-recovery">7. Incident Response and Recovery</h2>

<p class="notice--primary"><strong>Purpose:</strong> Be ready to handle security problems quickly and bounce back if something goes wrong.</p>

<p>Think of this like having a digital first-aid kit. Despite all your precautions, accidents happen — a hacker might slip through, or you might lose a device. Incident response and recovery is about having a plan so that one breach or mistake doesn’t derail your digital life. It’s how you <strong>respond</strong> to issues and <strong>recover</strong> afterward.</p>

<h4 class="notice--info no_toc" id="how-to-protect-yourself-6">How to Protect Yourself:</h4>

<ul>
  <li><strong>Keep backups for emergencies:</strong> If ransomware locks your files or your hard drive fails, having recent backups (as mentioned in Cloud &amp; Data Security) means you can restore your important data and carry on with minimal interruption.</li>
  <li><strong>Know how to recover accounts and devices:</strong> Take some time to learn the recovery options for your devices and accounts. For example, know how to reset your Apple ID or Google account password if you get locked out, and how to remotely lock or erase a lost phone. When trouble strikes, you’ll be able to act faster instead of scrambling to figure it out.</li>
  <li><strong>Have a plan for identity theft:</strong> If your identity or accounts are compromised, time is critical. Know which banks, credit card companies, or other institutions you would need to contact to freeze accounts or cards. You can also report identity theft and get a personalized recovery plan from an official resource like <strong>IdentityTheft.gov</strong> (a U.S. government site). Having a list of steps to take will help you stay calm and organized during a stressful event.</li>
</ul>

<h2 id="final-thoughts">Final Thoughts</h2>

<p>This may seem like a lot to take in, but you don’t need to do everything at once. Start by choosing the most important areas for you and implement those security measures first. Over time, layer on more defenses as you become comfortable. By gradually applying these layers of defense, you’re not just reacting to threats but proactively protecting yourself.</p>

<p>No single security step is foolproof, but together they make you a much harder target. Stay alert for <strong>phishing</strong> or scam attempts (like suspicious emails or texts that try to trick you), because even the best locks won’t help if you accidentally let the thief in the door! Keep learning about new tools and best practices, stay vigilant, and you’ll significantly enhance your personal digital security.</p>]]></content><author><name>seeknay</name></author><category term="security" /><category term="digital-safety" /><category term="defense-in-depth" /><category term="identity" /><category term="personal-security" /><category term="privacy" /><summary type="html"><![CDATA[A practical, layered guide to help everyday people improve their digital security using enterprise-grade Defense in Depth principles.]]></summary></entry><entry><title type="html">My TikTok Experience and the Ban</title><link href="https://seeknay.com/blog/the-tiktok-ban/" rel="alternate" type="text/html" title="My TikTok Experience and the Ban" /><published>2025-01-19T08:30:00-05:00</published><updated>2025-01-19T08:30:00-05:00</updated><id>https://seeknay.com/blog/the-tiktok-ban</id><content type="html" xml:base="https://seeknay.com/blog/the-tiktok-ban/"><![CDATA[<p>With the impending TikTok ban set for Sunday, January 19, 2025, I wanted to share some insights from my journey on the platform. If you’re reading this, chances are you found me through TikTok.</p>

<p>But first (IYKYK); a little bit of background…</p>

<p>I began posting on TikTok on October 30, 2023, after discovering the “TechTok” community—a engaging, organically formed group of tech enthusiasts spanning various disciplines, including Information Security, Networking, Cloud Engineering, DevSecOps, Infrastructure, and Sales Engineering. This welcoming community actively interacted with one another through comments, shares, and stitches of tech-related videos.</p>

<p>My objectives as a creator were:</p>

<ol>
  <li>To network with like-minded individuals</li>
  <li>To participate in tech-related memes</li>
  <li>To share valuable insights on Identity and IT</li>
  <li>To enhance my public speaking skills</li>
</ol>

<p>Before I share some fun metrics; please know that I was quite literally “winging it” and honestly that’s what made this fun.  Youtube and IG feel very polished and have often have decent production value.  As I consider increasing my presence on these platforms, I feel the need to produce more refined content. While becoming an influencer isn’t my goal, reaching like-minded individuals is essential for rebuilding a sense of community.</p>

<p>Here are some fun metrics I screenshot before the service went down:</p>

<blockquote>
  <p>Tip: Click the image to expand!</p>
</blockquote>

<p>Profile Stats:
<a href="/assets/images/tt-profile-stats.png"><img src="/assets/images/tt-profile-stats.png" alt="TikTok profile stats screenshot" /></a></p>

<p>Follower Stats:
<a href="/assets/images/tt-followers.png"><img src="/assets/images/tt-followers.png" alt="TikTok follower stats screenshot" /></a></p>

<p>Viewer Stats:
<a href="/assets/images/tt-viewers.png"><img src="/assets/images/tt-viewers.png" alt="TikTok viewer stats screenshot" /></a></p>

<p>My Most Popular Videos:
<a href="/assets/images/tt-popularvideos.png"><img src="/assets/images/tt-popularvideos.png" alt="TikTok most popular videos screenshot" /></a></p>

<p>Stats on my most popular video:
<a href="/assets/images/my-most-popular-video.png"><img src="/assets/images/my-most-popular-video.png" alt="Stats for my most popular TikTok video" /></a></p>

<p>I hope to continue the connections I’ve made along the way on any platform that will have us. It’s critically important to have a group in your industry or field where you can bounce questions off of each other, discuss challenges, and sometimes just vent. Having a support network is invaluable in both personal and professional growth.</p>

<p>If you’ve ever thought about posting content to social media, regardless of your field, I encourage you to do it—start yesterday! When I look back at my first video, it’s hands-down the cringiest thing I’ve ever recorded. But hey, we all have to start somewhere. My friends would probably still say I’m cringey, but you know what? That’s just me. 😄</p>]]></content><author><name>seeknay</name></author><category term="blog" /><category term="blog" /><category term="non-technical" /><category term="personal" /><category term="tiktok" /><summary type="html"><![CDATA[With the impending TikTok ban set for Sunday, January 19, 2025, I wanted to share some insights from my journey on the platform. If you’re reading this, chances are you found me through TikTok.]]></summary></entry><entry><title type="html">PowerShell Basics Video Series</title><link href="https://seeknay.com/blog/powershell-basics/" rel="alternate" type="text/html" title="PowerShell Basics Video Series" /><published>2024-09-10T11:45:00-04:00</published><updated>2024-09-10T11:45:00-04:00</updated><id>https://seeknay.com/blog/powershell-basics</id><content type="html" xml:base="https://seeknay.com/blog/powershell-basics/"><![CDATA[<h1 id="introduction">Introduction</h1>

<p>Why, hello there!</p>

<p>I’ve seem to have stumbled upon an area of interest (at least for now) in the TikTok community. That area happens to be one of my favorite tools: <strong>PowerShell</strong>!</p>

<h1 id="recorded-videos">Recorded Videos</h1>

<p>Here are some videos I’ve recorded so far:</p>

<h2 id="part-1-introduction-to-the-clip-command">Part 1: Introduction to the “CLIP” Command</h2>

<p>The goal for this video was honestly to show off the <code class="language-plaintext highlighter-rouge">CLIP</code> command, and everything preceding it was completely ad-libbed. It turns out a lot of people were interested in seeing more!</p>

<p><a href="https://www.youtube.com/watch?v=EtAfqEAlJkk">Watch Part 1 on YouTube</a></p>

<h2 id="part-2-powershell-aliasing">Part 2: PowerShell Aliasing</h2>

<p>In this video, I specifically cover Aliasing in PowerShell to address some comments about the verbosity of the tool.</p>

<p><a href="https://www.youtube.com/watch?v=wWbOpLoxMrM">Watch Part 2 on YouTube</a></p>

<h2 id="part-3-powershell-what-is-_-">Part 3: PowerShell (What is <code class="language-plaintext highlighter-rouge">$_</code> ?)</h2>

<p>In this video, we dive into the basics of PowerShell, specifically focusing on the $_ symbol. These are essential when working with objects in a pipeline, especially when processing arrays or handling errors in a try-catch block.</p>

<p><a href="https://www.youtube.com/watch?v=tFNpOhMngmk">Watch Part 3 on YouTube</a></p>

<h1 id="get-involved">Get Involved</h1>

<p>If you are reading this and want to see anything specifically covered within PowerShell, please feel free to leave a comment on the YouTube video. I’ll do my best to cover everything that I am familiar with and can.</p>

<p>Thanks!</p>

<p><em>P.S. I’ll eventually spend some time on proper video thumbnails.</em> 🙂</p>]]></content><author><name>seeknay</name></author><category term="blog" /><category term="powershell" /><category term="scripting" /><category term="videos" /><summary type="html"><![CDATA[Introduction]]></summary></entry><entry><title type="html">Podcast Review: Kelsey Hightower: You have to put in the work.. Forever</title><link href="https://seeknay.com/podcasts/you-have-to-put-in-the-work-prodcast-review/" rel="alternate" type="text/html" title="Podcast Review: Kelsey Hightower: You have to put in the work.. Forever" /><published>2024-07-09T02:30:00-04:00</published><updated>2024-07-09T02:30:00-04:00</updated><id>https://seeknay.com/podcasts/you-have-to-put-in-the-work-prodcast-review</id><content type="html" xml:base="https://seeknay.com/podcasts/you-have-to-put-in-the-work-prodcast-review/"><![CDATA[<p>In the sea of podcasts and YouTube videos that exist, every so often you come across one that truly strikes a chord. If you’re trying to grow your career or move onto this next step, give this video a watch. It may be long, but it’s absolutely worth it.</p>

<p>I actually didn’t know who Kelsey Hightower was before this podcast. I learned about him through Gerald Yerden, who I was fortunate enough to find on TikTok and Youtube.</p>

<p>There are 3 parts to this interview that I have listened to at least a dozen times already.</p>

<p>➡ 30:23 - “Separating yourself from the crowd”</p>

<p>Disclaimer: Everyone’s career and situation is different and none of this is meant to be prescriptive.</p>

<p>I really enjoyed listening to this part because I could see similarities in what I did in my own career (and continue to do).</p>

<ul>
  <li>Continuously grow and learn! You may not need to use the skill immediately, but you never know when the opportunity can arise where it can provide value.</li>
  <li>Surround yourself with people who will give you honest feedback!</li>
  <li>“Don’t be safe”: If you’re not putting yourself out there, it’s hard to showcase the skills you’ve learned.  This is actually a big part of why this blog and my public social media presence now exists.</li>
</ul>

<p>➡ 55:10 - “AI: What it is, isn’t, and could be”</p>

<p>I hadn’t heard this correlation before, and I thought it was brilliant. You’ll have to watch the video for this one because I won’t do the segment justice in a blog post.</p>

<p>➡ 01:29:45 - “How do you retire early? Tech Lottery Tickets” which leads into examples: ➡ 01:32:59 - “Kelsey’s Career”</p>

<p>My absolute favorite quote, “It doesn’t often pay off in real time, so we think it’s a waste of time”. I swear when I heard this, I was taken aback the same way Gerald was. 😂</p>

<p>YouTube Video:</p>

<p><a href="https://www.youtube.com/watch?v=O49Ms-qLjok"><img src="https://i.ytimg.com/vi/O49Ms-qLjok/maxresdefault.jpg" alt="&quot;Kelsey Hightower: You have to put in the work.. Forever&quot;" /></a></p>]]></content><author><name>seeknay</name></author><category term="podcasts" /><category term="career" /><category term="podcasts" /><summary type="html"><![CDATA[In the sea of podcasts and YouTube videos that exist, every so often you come across one that truly strikes a chord. If you’re trying to grow your career or move onto this next step, give this video a watch. It may be long, but it’s absolutely worth it.]]></summary></entry></feed>