Turning 5+ years of regulated healthcare operations discipline into hands-on Healthcare IT, Application Support, and IAM skills -- built in real systems, not just studied.
Healthcare Operations Professional -> Healthcare IT & Identity/Access Management
PMP-certified operations professional with 5+ years in regulated healthcare logistics, currently building hands-on Healthcare IT and IAM skills through self-directed projects. I bring proven compliance documentation, cross-functional coordination, and process-improvement experience to a technology career, backed by real certifications and portfolio work.
Transitioning from 5+ years in regulated healthcare operations into Healthcare IT, IAM, and GRC -- Â nine hands-on projects below, each built in a real system (Okta, ServiceNow, SQL) and published on GitHub, not just written about.
SKILLS
Identity & Access Management: Okta, RBAC design, quarterly access reviews, provisioning/deprovisioning
Healthcare IT / Application Support: Epic workflows, ServiceNow ticketing, incident triage, ITIL practices
Data & Reporting: SQL, Excel, Power BI-style reporting on support and operations data
Compliance & Documentation: HIPAA-aligned access audits, process documentation, change management
Project & Operations: PMP-certified, cross-functional coordination, regulated healthcare logistics
Featured Projects
Portfolio: 9 of 9 hands-on projects complete. Certifications: actively studying for CompTIA Security+ now, with ISC2 CC, SC-900, and SC-300 next on the roadmap.
Impact: Tiered MFA and quarterly access reviews cut standing access risk on PHI-adjacent accounts -- the exact control gap auditors flag first in a HIPAA security risk assessment.
Open to: Remote Healthcare IT Analyst, Application Support Analyst, and IAM Analyst roles. Utah & Texas based.
2. ServiceNow Healthcare IT Service Desk
Impact: Structured tiering and SLA-based prioritization cut resolution time on high-impact tickets like password resets and clinical system access -- the difference between a service desk that reacts and one that meets its SLA.
3. SQL Analytics on Support & Operations Data
Impact: Turns raw ticket and clinic data into answers leadership can act on -- SLA compliance by priority, no-show rates by department -- the kind of reporting that shows where a team is actually losing time.
4. Epic Workflow Build, Test & Documentation
Impact: Redesigned a manual, no-confirmation booking flow into a risk-tiered reminder system built to cut no-shows, then proved it with a documented unit/system/integration test cycle -- including the one failure and fix, the way a real go-live record would look.
5. HIPAA-Aligned User Access Review & Compliance Audit
Impact: Found and documented four real-shaped findings -- including an offboarded contractor's account still active 11 days after their last day -- the exact kind of access-lifecycle gap that turns into a breach or a failed audit.
See GRC resume below.
6. Application Support Playbook - ITIL Incident, Change & Escalation Framework
A self-directed reference document covering incident management, problem management, change management, release management, an escalation matrix, and communication templates, built to demonstrate ITIL-aligned process design for Application Support roles. Full document viewable on its own page.
Impact: Gives a support team a documented, ITIL-aligned reference for incident, change, and escalation handling -- the difference between tribal knowledge and a process new hires can actually follow.
7. IT Risk Register - Access, Compliance & Third-Party Risk
A 10-entry IT risk register applying likelihood x impact scoring, documented treatment plans, ownership, and review cadence to the same environment used in the Okta, HIPAA audit, and ServiceNow projects above. 2 entries are deliberately cross-validated against findings the HIPAA audit surfaced independently, showing the register and the audit agree on severity without being copy-pasted from each other. Full register (github.com/shaquillej/it-risk-register) covers 10 risks across access control, third-party/vendor, governance, and data governance categories -- 3 High, 4 Medium, 3 Low.
Impact: Cross-validated against the HIPAA audit's own findings, showing the register reflects real risk rather than a template exercise.
IT Risk Register (Project 7) - Screenshots
8. Vendor & Third-Party Risk Review - Okta & ServiceNow
Applied a 6-criteria vendor risk review methodology to the two real SaaS vendors already used hands-on above (Okta, ServiceNow) -- not a fictional vendor -- scoring each on data sensitivity, compliance certifications, sub-processor transparency, breach notification commitment, contractual data protection terms, and availability, using only their public trust-center documentation (SOC 2 Type II, ISO 27001, FedRAMP status). Both scored Low-Medium overall risk with an Approve-with-conditions recommendation. Full review: github.com/shaquillej/vendor-third-party-risk-review. See GRC resume below.
Impact: Scored two real vendors against 6 risk criteria using only public trust-center documentation -- the actual method a GRC or vendor risk analyst uses before a SaaS vendor gets approved.
Vendor & Third-Party Risk Review (Project 8) - Screenshots
9. AI Risk Assessment - Generative AI Clinical Note Summarization
Analyst-scoped AI risk assessment extending the IT Risk Register and HIPAA audit into the AI risk category: five new risks scored against generative AI used for clinical note summarization, mapped to the NIST AI Risk Management Framework's Generative AI Profile (NIST AI 600-1). Trade-off analysis compares three deployment options and recommends mandatory clinician review before signature - the same underlying control gap the register's cross-validated R-10/R-15 pairing independently points to. Full assessment (github.com/shaquillej/ai-clinical-documentation-risk-assessment) covers the NIST AI RMF mapping, HIPAA/BAA vendor requirements, and lessons learned.
Impact: Applies the NIST AI Risk Management Framework to a live use case and flags the same control gap the HIPAA audit found independently -- showing the methodology holds up in a newer, less-defined risk category.
AI Risk Assessment (Project 9) - Screenshots