Selected Work

Projects & case studies

Representative engagements showing the kind of identity problems I solve and the outcomes delivered.

Forest Migration

Multi-domain AD consolidation

Led the consolidation of seven legacy forests (post-merger) into a single hardened forest with tiered admin model and modern ADCS. Migrated 18,000 users and 45,000 endpoints with zero unplanned outages.

Outcome ~£1.2m/yr operational saving · 60% reduction in privileged accounts
ADMTQuestPowerShellPingCastle
Cloud Identity

Entra ID + Conditional Access rollout

Designed and deployed a Conditional Access policy framework across 12,000 seats, including risk-based MFA, device-compliance enforcement and phased NTLM deprecation. Integrated with Defender for Identity.

Outcome 97% MFA adoption · phishing-resistant auth for all admins · audit clean
Entra IDConditional AccessIntunePIM
Governance

JML automation with SailPoint

Built a SailPoint IdentityIQ deployment integrated with Workday HR, AD, Entra ID and 30+ downstream apps. Replaced manual onboarding tickets with role-based birthright provisioning and quarterly access reviews.

Outcome Day-1 access for new joiners · 4,200 stale entitlements removed
SailPoint IIQWorkdaySCIMRBAC
PAM

Tier 0 hardening & CyberArk integration

Re-architected the Tier 0 estate following a red-team finding. Introduced PAWs, gMSAs, time-bound CyberArk vaulted credentials and full session recording for domain admins.

Outcome Mean time to detect lateral movement reduced from 14 days to 22 minutes
CyberArkPAWgMSABloodHound
Federation

SaaS portfolio SSO consolidation

Migrated 60+ SaaS apps from local credentials to Okta-fronted SAML/OIDC SSO with SCIM provisioning, retiring AD FS in the process. Built a self-service catalogue for app owners.

Outcome Helpdesk password tickets down 73% · ADFS retired
OktaSAMLOIDCSCIM
Zero Trust

Zero Trust identity blueprint

Authored a multi-year Zero Trust roadmap aligned to NIST SP 800-207, sequencing identity-first wins (CA, PIM, passwordless) before network and data tiers. Adopted as the firm-wide reference architecture.

Outcome Board-approved 3-year programme · year-1 milestones delivered on plan
NIST 800-207Entra IDStrategyArchitecture
Get in touch

Let’s talk identity.

Open to advisory, contract and permanent opportunities involving Active Directory, Entra ID, identity governance, or zero-trust programmes. The best way to reach me is by email.

Location
United States — Remote