Intelligent Architecture
Location: Sunnyvale, CA
Email: steventuschman2@gmail.com
Phone: (763) 746-6185
LinkedIn: https://www.linkedin.com/in/steven-tuschman
GitHub: https://github.com/Compcode1

About Intelligent Architecture
Intelligent Architecture is an independent cloud security and systems architecture practice established by Steven Tuschman (SC-300, PMP, CySA+) to govern a disciplined technical roadmap in enterprise cloud defense and solutions engineering.
Structured around formal Project Management Professional (PMP®) governance and integrated with continuous Generative AI workflow orchestration, this initiative serves as an operational force multiplier. It maximizes technical ingestion velocity, maintains complex system states, and drives rapid advancements in zero-trust identity architecture to bridge deep technical engineering with enterprise risk management.
Core Architectural Frameworks & Outputs
Leveraging AI acceleration to reverse-engineer complex cloud environments, I have authored the following active engineering baselines and enterprise protocols:
The 54-Page Operational Field Manual (Version 1.0)
An active engineering baseline unifying five dependent components into a single operational playbook for non-human identity (NHI) security and zero-trust OIDC federation within Microsoft Entra ID. This manual enforces systematic design over manual UI configuration and verifies compliance through raw KQL log correlation. It is structured across five interconnected pillars:
- Pillar 1: The ACPHF Core Engineering Specification. A 4-phase architectural blueprint for passwordless OIDC federation. It enforces data-plane RBAC isolation and a strict 60-minute token volatility ceiling to entirely eliminate static secrets and UI-based configuration traps (e.g., GitHub OIDC database claim mismatches / AADSTS700213).
- Pillar 2: The Identity Architecture Ledger (IAL). An immutable configuration record that mirrors the core specification. It captures hard boolean validation states, directory GUIDs, exact subject claim strings, and explicit RBAC role assignments to generate an audit-ready architectural record.
- Pillar 3: Log Navigation & Telemetry Audit Guide. An operational runbook utilizing Microsoft Entra sign-in logs and Azure Log Analytics (KQL). It establishes diagnostic workflows to verify inbound OIDC token handshakes and trace downstream data-plane requests, specifically exposing “Silent 403” authorization drops.
- Pillar 4: The Audit Results Ledger (ARL). A formal proof-of-governance verification template structured around 4 Audit Gates (Coordinates, Characters, Clock, Plane). It standardizes the logging of KQL telemetry correlations, pass/fail outcomes, and remediation action plans.
- Pillar 5: Microsoft Entra Capability Index. An overarching architectural taxonomy mapping 35 core directory services across 7 functional security domains, categorizing directory capabilities by control-plane scope and deployment depth.
Enterprise Solutions Engineering & Security Architecture Framework
While the Field Manual dictates the raw engineering mechanics, this secondary framework serves as the strategic bridge between complex cloud identity architecture and executive risk management. It operates as a structured, 4-stage pre-sales and technical evaluation playbook. It applies my core engineering artifacts directly to the enterprise sales lifecycle, allowing me to audit complex environments, manage hands-on Proof of Concepts (PoCs), and validate zero-trust identity controls for prospective clients.
This framework is executed across a strict, 4-stage technical lifecycle:
- Stage 1: Technical Discovery & Baseline Risk Audit Utilizing the Microsoft Entra Control Plane Capability Index, this stage transforms initial customer discovery calls into audited, 35-capability baseline risk assessments. It systematically maps a prospective client’s native directory structural gaps, unmonitored non-human identity risks, and exact integration points for specialized third-party security overlays.
- Stage 2: Solution Architecture & Target-State Design Deploying the ACPHF specification and Cross-Platform Topology matrix, I design zero-trust target states for prospective clients. This stage proves to enterprise security architects that we can secure automated DevSecOps pipelines, Kubernetes clusters, and AI vector data flows by enforcing passwordless OIDC federation and granular data-plane RBAC isolation without introducing administrative friction.
- Stage 3: Proof of Concept (PoC) Execution & Technical Validation During hands-on staging evaluations, this stage enforces strict configuration governance. By deploying the Identity Architecture Ledger (IAL v2) to lock in deployment parameters, and utilizing the SecOps Audit Guide to run deterministic Kusto Query Language (KQL) diagnostic traces, I ensure that all live evaluation environments are cleanly deployed, deterministically audited, and free from unmonitored configuration drift.
- Stage 4: Value Realization & Technical ROI The final stage translates raw technical telemetry and zero-trust validation metrics into executive-level business outcomes. It provides the Chief Information Security Officer (CISO) with quantifiable risk reduction data (e.g., the 100% elimination of hardcoded secrets), operational cost efficiencies, and explicit proof of alignment with global compliance standards (NIST SP 800-207, SOC 2 Type II, and ISO 27001).
Professional Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Project Management Institute: Project Management Professional (PMP®)
- CompTIA: Cybersecurity Analyst (CySA+) & Security+
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- Python Institute: PCAP – Certified Associate Python Programmer
- Dataquest: Data Engineering Professional
Get in Touch
If you are reviewing my resume or interested in cloud identity security architecture, feel free to reach out directly:
- Email: steventuschman2@gmail.com
- LinkedIn: https://www.linkedin.com/in/steven-tuschman
- GitHub: https://github.com/Compcode1
