About


I'm Alex Trandafir, and I'm building toward a career in Identity and Access Management — specifically the corner of it most programmes are only starting to notice: non-human identity. The service accounts, API tokens, workload credentials, and now AI agents that quietly outnumber the humans in every estate by something like eighty to one, and that almost nobody governs. That's the niche I've chosen, and this blog is the evidence I'm earning the right to work in it.

Why non-human identity

Human single sign-on is a mature, crowded field. The identities that actually get organisations breached lately have not been stolen passwords — they've been leaked tokens, forgotten service accounts, and sync credentials nobody was watching. There is no certification for this yet, which means the way in is not a badge; it's demonstrable work. So I do the work in public.

My edge is an unusual combination. I build — including a self-hosted AI agent that runs with real credentials, where I had to solve the exact problem the field is now waking up to: what identity does an autonomous agent act under, and how do you stop it reaching further than it should. I can attack — I reproduce real vulnerabilities and find live attack paths. And I can detect — I run a SOC over my own lab. Attack it, control it, detect it. Most people in identity can do one of those three.

The evidence, not the buzzwords

I'd rather show the work — including the parts that broke — than list skills. A few of the pieces on this blog I'd point a hiring manager at first:

  • Reproducing a critical CVE that had no public exploit. I took a days-old, actively-exploited GitLab vulnerability with no proof-of-concept anywhere, worked the mechanism out from the patch diff, reproduced it reliably — and then stopped exactly where the evidence stopped, instead of overclaiming the impact. Knowing the limit of what you've proven is the job.
  • The shortest path to domain admin in my own lab. Ran attack-path analysis against my Active Directory domain and found the fastest route to owning everything ran through the cloud-sync service account — a non-human identity that every group-membership audit calls harmless, holding domain-replication rights through a direct ACL. Then I built the read-only tool that finds that whole class of exposure.
  • Counting my own machine identities. Forty non-human identities to my one human one, every one of them long-lived — a real before/after audit of my own estate, with the remediation and the honest note about what I fixed and what I deliberately left for later.
  • Hybrid identity, hands-on. A working homelab running Active Directory synced to both Okta and Entra ID, Okta managed as code with Terraform, and the joiner-mover-leaver plumbing that connects them — the fundamentals an IAM role is actually built on.

The rest of the blog fills in the breadth: SAML and OIDC failure modes, OAuth2 done wrong, SCIM's coverage gap, the joiner-mover-leaver problems that wreck least privilege, privileged access, phishing-resistant MFA, and the non-human identity work that's my focus. Each post leads with a real problem and is honest about what doesn't work — because in security, knowing the limits of what you've proven is the skill that separates a professional from someone running downloaded scripts.

Where I'm at

I'm finishing an HND and starting a BSc top-up, doing self-employed IT consulting, and building the identity capability in the open in the meantime. I'm in Leamington Spa and open to IAM and security-engineering roles, remote or Midlands-based.

If you're a recruiter or hiring manager: the posts are the portfolio. Each one is a real project with the decisions, the mistakes, and what I'd do differently. You can reach me on LinkedIn, and the GitHub and LinkedIn links in the footer are the fastest way to get in touch.