Results-driven Senior Information Security Engineer with over 13 years of experience in Identity and Access Management (IAM) and Cloud Directory Services, including Active Directory, Microsoft EntraID (Azure AD), and AWS. Proven track record of leading cross-functional teams and managing complex projects, with a strong focus on security compliance, automation, and process improvement in large-scale enterprise environments. Adept at collaborating with stakeholders to align IT initiatives with business objectives, enhancing operational efficiency and security posture.
· Cloud IAM Leadership: Led strategic cloud IAM initiatives managing Microsoft EntraID (Azure AD), AWS, and on-premises Active Directory services, ensuring secure, scalable identity management across the enterprise.
· Domain Controller Migrations: Spearheaded Domain Controller migrations from Windows Server 2012 to 2016, ensuring minimal downtime and adherence to compliance standards.
· Privileged Access Management (PAM): Implemented and managed the PAM solution ManageEngine. Created policies for managing privileged accounts and set up automated password rotations every 90 days for elevated accounts and daily for stored accounts.
· Managing Large User Base: Managed around 45,000 users company-wide. Identified and cleaned up terminated accounts (~40,000) across AD, AAD, and Okta domains in collaboration with the Workday HRIS team.
· License Cost Savings: Saved significant costs by freeing up licenses in Azure and Okta after cleaning up inactive accounts, resolving long-standing termination issues.
· Automation: Developed automated termination scripts to permanently resolve account deactivation issues, ensuring users are properly removed from all identity systems, including AD, AAD, and Okta.
· Security Automation: Developed automated scripts to monitor AD health daily, reducing downtime and proactively addressing issues.
· Privileged Identity Management (PIM): Created PIM roles in Azure AD for privileged roles, ensuring stringent control over high-privilege access within the organization.
· Server & Tool Management: Completely managed the servers and the ManageEngine PAM tool, ensuring smooth operations and optimal performance.
· Certificate Management: Managed certificates across the environment, ensuring renewal and deployment without disruptions.
· Security and Vulnerability Management: Collaborated with security teams to assess and remediate vulnerabilities in Active Directory and Azure AD, enhancing security posture.
· Active Directory Management: Managed Active Directory, DNS, DHCP, and Group Policy in a large enterprise environment, ensuring directory health and performance.
· Cloud Identity Integration: Integrated on-prem AD domains with Okta for federated SSO and user lifecycle management, supporting MFA and SAML 2.0 authentication.
· VMware Infrastructure Management: Managed a virtual infrastructure of 6000+ VMs across 200+ ESXi hosts, overseeing system upgrades and resource optimization.
· Automation: Created PowerShell scripts to automate routine administrative tasks, enhancing operational efficiency and reducing manual errors.
· Cross-Department Collaboration: Worked with other company departments to solve Information Technology problems, providing innovative solutions to management and above.
· User Training & Support: Provided comprehensive training to internal and off-site users on various tools, virtual machine builds, SSL generation and replacement, optimizing system maintenance, and resolving recurring issues.
Key Projects & Leadership