From zero background to job-ready in identity security.
The complete path across Level 1 foundations and Level 2 advanced tooling, the full governance, risk, and compliance stack, and a capstone that becomes a defensible line on your resume.
Two levels, one path.
Identity security is a specialty, not a generalist track. You go deep on the exact tools and frameworks that show up in real job descriptions, working in live environments instead of watching slides. Level 1 lays the foundations with Chad. Level 2 takes you into advanced work and the full GRC stack with Lance. No one advances to Level 2 before the fundamentals are genuinely solid.
Each topic lists what you'll be able to do, a hands-on lab, what you'll produce, and the industry certification it maps toward. Certifications are taken separately. Privance prepares you for them; it does not issue or guarantee them.
Foundations: the platforms underneath everything.
Assumes no prior tech background. You build a working understanding of how enterprise identity is structured, get your first hands-on privileged-access work, and learn the tooling the rest of the membership connects to.
Privileged access CyberArk
Privileged accounts are the most powerful credentials in any organization, and CyberArk is the platform most enterprises use to lock them down.
- Vault and safe structure: how credentials are stored and segmented
- Account onboarding and the basics of managing privileged accounts
- Introduction to the Central Policy Manager (CPM) and rotation
- Introduction to the Privileged Session Manager (PSM)
- Core access policies and least-privilege thinking
- Explain what a privileged account is and why it's the top target in a breach
- Navigate the vault, locate safes, and describe how credentials are segmented
- Onboard a basic privileged account and retrieve a credential through the vault
- Describe how CPM rotation and PSM session isolation protect a credential
Identity and SSO Okta
Okta is how modern organizations centralize who can sign in and what they can reach. You learn how SSO and MFA work, then practice the lifecycle tasks identity teams handle every day.
- Single sign-on (SSO) and federation fundamentals
- Multi-factor authentication (MFA) and authentication policies
- User lifecycle: create, update, deactivate, and offboard
- Groups, roles, and application assignments
- How Okta connects to directories and downstream apps
- Explain how SSO and federation let one login reach many applications
- Enroll and enforce MFA for a user
- Run the full user lifecycle: create, update, deactivate, offboard
- Assign applications to users through groups and roles
Active Directory Microsoft AD
Active Directory is the backbone that nearly everything else in IAM connects to. You learn how enterprise identity is organized and how the pieces of a domain fit together.
- Domains, forests, and organizational units (OUs)
- Users, groups, and group-based access
- Delegation and basic administrative boundaries
- Group Policy fundamentals
- How AD feeds identity into Okta and CyberArk
- Explain domains, forests, and OUs and how they organize identity
- Grant access through group membership instead of per-user permissions
- Read a Group Policy object and describe what it enforces
- Trace how AD identities flow into Okta and CyberArk
The Gate: readiness check
Chad signs off against a clear checklist before you advance. The fundamentals have to be solid first; advanced work only lands when the foundation is real.
Advanced: deeper into the same platforms.
Level 2 takes the tools you met in foundations and pushes into the work real identity engineers do: designing access, automating it, and managing privileged sessions at scale. Led by Lance, a practicing identity and privileged-access engineer.
Advanced CyberArk operate the vault
You move from understanding the vault to operating it: session management, credential rotation, and onboarding at scale become hands-on skills you can speak to in an interview.
- Privileged Session Manager (PSM): monitoring and isolating sessions
- Central Policy Manager (CPM): automated credential rotation
- Bulk account onboarding and platform configuration
- Safe design, access workflows, and approval flows
- Session recording and audit trails for privileged activity
- Configure PSM to monitor and isolate a privileged session
- Set a CPM policy to rotate credentials automatically
- Onboard accounts in bulk and configure a platform
- Design a safe with an access workflow and dual-control approval
- Pull session recordings and audit trails for an investigation
Advanced Okta and provisioning identity at scale
You go beyond logging in to designing how identity flows through an organization: automated provisioning, policy-driven access, and the integrations that connect Okta to everything else.
- Automated provisioning and deprovisioning across applications
- SAML and OIDC application integration
- Conditional and risk-based authentication policies
- Directory integration and identity sources
- Lifecycle automation and access request workflows
- Build automated provisioning and deprovisioning across connected apps
- Integrate one app via SAML and another via OIDC
- Write conditional and risk-based authentication policies
- Connect a directory as an identity source and automate lifecycle events
Advanced Active Directory design & secure
You learn to design and secure the directory, not just navigate it: how access is structured, where it goes wrong, and how identity teams keep it clean and auditable.
- Group and OU design for least privilege
- Delegated administration and tiered access models
- Group Policy at scale and security baselines
- Synchronization between AD and cloud identity
- Common access risks and how to remediate them
- Design groups and OUs for least privilege at scale
- Implement a tiered administration model
- Apply Group Policy and security baselines across many objects
- Synchronize AD with cloud identity and spot and remediate access risks
The compliance work that keeps regulated companies running.
Technical skill gets you in the door. Knowing the governance and compliance side is what makes you valuable to regulated employers in finance and healthcare. You learn the frameworks from real practice and connect them back to the access work you have already done.
Governance and SOX where identity meets the auditor
The access-control work that keeps public companies compliant, and how to produce the evidence an audit actually asks for.
- Access reviews and periodic recertification
- Segregation of duties (SoD) and conflict detection
- IT general controls (ITGC) over access
- Gathering and presenting audit evidence
- Provisioning and deprovisioning as a controlled process
- Run a user access review and produce recertification evidence
- Detect segregation-of-duties conflicts
- Map IT general controls (ITGC) over access
- Assemble an audit evidence pack an auditor will accept
- Treat provisioning and deprovisioning as a controlled, evidenced process
HIPAA and healthcare data protecting PHI
Healthcare is one of the largest employers of identity and access talent. You learn how protected health information is safeguarded through access control and what compliance looks like day to day.
- Protected health information (PHI) and why it is regulated
- The Privacy and Security Rules at a working level
- Role-based access and the minimum-necessary principle
- Access logging and audit controls for sensitive data
- How identity teams support HIPAA compliance
- Identify PHI and explain why it is regulated
- Apply the Privacy and Security Rules at a working level
- Enforce role-based access and the minimum-necessary principle
- Configure access logging and audit controls for sensitive data
NIST frameworks a language for risk
NIST gives organizations a recognized language for managing risk. You learn how the major frameworks fit together and how identity controls map into them.
- The Cybersecurity Framework (CSF) and its core functions
- The Risk Management Framework (RMF) at a high level
- Access-control families and how they map to your work
- Identifying, assessing, and managing risk against a standard
- How frameworks connect to SOX and HIPAA in practice
- Walk the CSF core functions: Identify, Protect, Detect, Respond, Recover
- Describe the Risk Management Framework (RMF) lifecycle at a working level
- Map access-control families to the hands-on work you've done
- Assess and document risk against a recognized standard
A capstone that ties the tools to the frameworks.
Level 2 closes with applied work that connects what you've learned: privileged access, identity, and directory skills put to work against real governance and compliance requirements, the same way the job will ask you to. On the IAM Engineer Track, your capstone runs under Privance and becomes a defensible line on your resume, not a fabricated one.
What each track includes.
| Bronze | IAM Analyst Track | IAM Engineer Track | |
|---|---|---|---|
| Target role | Explore first | IAM Analyst · ~6 months | IAM Engineer · ~12 months |
| Typical US pay for the role | — | $70k–$110k | $110k–$160k+ |
| Price | $299one-time · yours to keep | $275/mo · cancel anytime | $675/mo · cancel anytime |
| Best for | Self-paced foundations | Getting hired as an IAM Analyst | Going all the way to IAM Engineer |
| Recorded curriculum | Entry IAM & CyberArk + compliance basics | Everything in Bronze | Everything in the Analyst Track |
| Live sessions | No | Foundations with Chad, advanced with Lance | Foundations with Chad, advanced with Lance |
| Hands-on labs & full GRC track | No | Yes | Yes |
| One-on-one with Lance | No | Bounded 1:1 time | Extensive 1:1 |
| Career services | Private community | Resume & LinkedIn coaching, mock interviews, portfolio project | Resume & LinkedIn done for you, mentor support for as long as you stay a member |
| Real capstone under Privance | No | Portfolio project | Capstone you can list as experience + a paid CyberArk course included |
Month to month: every membership is an open-ended monthly subscription you can cancel anytime. No deposit, no upfront lump sum, no fixed term. A rotating weekly promotion may discount one membership further. The live deal is always shown on the pricing page.
Taught by two people, start to finish.
Chad foundations lead
Entry IAM and CyberArk, IT and Active Directory fundamentals, core identity concepts. Runs Level 1 and signs off the readiness gate.
Lance advanced & GRC lead
A practicing identity and privileged-access engineer with enterprise and SOX-audit experience. Leads Level 2, the full GRC stack, the capstone, and career work.
What we promise, and what we don't.
No job is guaranteed. Privance provides the skills, verifiable hands-on experience, and mentorship; the effort and the interviews are yours. Certifications are earned separately through their providers. The membership prepares you for them but does not issue or guarantee them. No tech background is required. Bronze and Level 1 start from the fundamentals. Delivery is remote: Bronze is self-paced, while the IAM Analyst Track (~6 months) and IAM Engineer Track (~12 months) add live sessions you can join anytime.
Ready when you are.
Apply now and we will help you pick the right track. Most people start with the Analyst Track. Month to month, cancel anytime. Engineer Track spots are limited. Questions? Email hello@privance.io.