CIAM Implementation, 05/2022 - Present, Chennai, The objective is to modernize and replace the existing Customer Authentication platform using a SaaS based CIAM product (Auth0), and onboard the 10 major customer facing business channels onto the new platform. These 10 business channels are currently utilizing legacy authentication systems that do not have the required security posture. They wanted to establish basically next generation Enterprise Customer Identity and Access Management platform will address the shortcomings of the current CAMS solution, providing secure and quicker time-to-market., Strategic CIAM Leadership: Spearheaded the development and execution of CIAM strategy to enhance customer experience, data security, and regulatory compliance which resulted in a 20% increase in user adoption and a 15% reduction in security incidents., Defined and communicated the CIAM vision, goals, and objectives to cross-functional teams., Team Leadership and Development: Led and managed a team of CIAM specialists and professionals, providing guidance, training, and mentorship., CIAM Solution Architecture: Assess the current state problems and define future state solutions for CIAM architecture., Oversaw the design and architecture of CIAM solutions, ensuring scalability, performance, and integration with existing systems., Evaluated and selected CIAM technologies and solutions to meet business needs., System Integration: Successfully integrated CIAM solutions with existing customer databases, ensuring seamless user experience across multiple platforms., Orchestrated the implementation of strong authentication methods, including multi-factor authentication (MFA) and single sign-on (SSO)., Streamlined the customer identity life cycle, optimizing user registration, profile management and self-service options., Security Enhancement: Implemented robust security protocols and access controls, reducing data breaches by 30% and enhancing compliance with industry regulations., Vendor and Stakeholder Management: Managed relationships with CIAM solution providers and vendors, including contract negotiations, SLAs and licensing agreements., Collaborated with stakeholders to gather and understand business requirements and ensure CIAM solutions aligned with organizational goals., Continuous Improvement and Innovation: Continuously identified opportunities for process improvements and technological enhancements., Implemented changes and updates based on industry best practices and evolving business needs. Cigna - Online Experience Program, 07/2017 - Present, Chennai, Online Experience Program consists of multiple projects within portfolio, tailored to fully enable the company’s goals in delivering world-class online servicing experience for their external constituents: customers, healthcare professionals, employers and brokers as well as retaining existing customers and reducing administration costs due to improved experience of online channel. OEP Business model was classified into 5 major modules which includes Products and Benefits, Portal Integration, Identity Management, Claims and Balances and Frameworks., Prepared Design Documents and Deployment Manuals. Design and Setting up various environments (DEV/QA/PreProd/Prod)., I am involved in meetings with business users to discuss and finalize requirements and design. I was responsible for identifying technical and product requirements by engaging Business and leading delivery team to implement requirement through safe agile process, guide team in analysis, design, coding and testing with in a sprint., Configured SSO, Federation for various applications using webseal/ISAM., Implementation of the Multi Factor Authentication capability into the customer facing websites meant to balance the desire to improve the security of our sites along with the need to minimize impacts to the customer experience. This involves Advanced Access Control, Policy Server and reverse Proxy configurations with SI services and other third-party integrations., Setting up authorization in ISAM via JWT access tokens. we can use a pass-by-value tokens which contain all necessary claims encapsulated in a cryptographic token which can then be validated locally by a resource server. So, in order to achieve authorization via JWT access tokens, I involved in configuring OIDC setup, OIDC Custom Mapping, JWT STS Chain Setup OIDC Metadata endpoint changes and AAC changes., As all portals are migrated to ISAM from webseal automated the existing processes available for Webseal (6.x) version in UrbanCodeDeploy to ISAM using the custom ISAM ansible roles provided by IBM., I have automated environment build using using single YML file which included several YMLs (for creating portal, non-portal junctions, ACL create, object attach etc.) to build a new environment completely from the scratch. This is automated which saves manual hours 6 to Automation (within an hour), Worked singlehandedly in Production releases. Xerox MMIS IAM, 12/2013 - 06/2017, Chennai, Medicaid Management Information System (MMIS) should be secure enough so that only authorized personnel can access the restricted functionality based on the roles assigned to them. IBM’s Tivoli Identity Manager (TIM) and IBM’s Tivoli Access Manager (TAM) are utilized/customized, along with the MMIS database for user authentication and authorization management. The customizations were around policy definitions on the role-based access and state specific compliance workflows that involve extensive auditing., Understanding Overview of Enterprise/Medicaid Provider Enrollment, MMIS, Types of Users, States using Enterprise and involved in setting up security Architecture using Tivoli components (TIM/TAM/Webseal)., Worked in Daily/On call tasks which includes Email Requests, Tickets, Defect, CRs, Deploys, Restarts, Triage Calls, ACL deploy, Demo monitoring, password expiry emails] Approval Process, On calls. Mentoring team members., Worked in Data Refresh, creating the ACLs for HTML5 Integration, Streamlining the ACL deployment process, HTML5 clone environment builds., Worked in Enhancements/Defect fixes., Working in Release Management like Tivoli tracking sheet, Sharepoint, Code base, Clear Quest, SCM Team, Patch process. Participated actively in PRODUCTION TRIAGE calls and ROOT CAUSE ANALYSIS., Worked in Development environment Debugging, Working in Third Party Integrations like cognos, Docfinity about 4 States [New Hampshire, Alaska, North Decotta, New York] MMIS, Involved in Environment Build. Logitech, 01/2011 - 11/2013, Chennai, This project involves Identity Management (User Provisioning, maintaining User Life Cycle Management via IBM Tivoli Identity Manager). Also provides SSO for its intranet and other protected applications. Also, on boarded several partners of Logitech, to its portal for whom, the Federation solution was provided. Both Single-Sign On (SSO) and Federation were achieved using IBM Tivoli Access Manager and Federated Identity Manager product, Prepared Design Documents and Deployment Manuals. Design and Setting up various environments (DEV/QA/PreProd/Prod)., Configured SSO for various applications using webseal. Enabled Fallback authentication and making it reusable for new applications., Configured Federated Single Sign on for Logitech’s Intranet and various other partner sites like benefits management, skillsoft, webex, sharepoint, google mail, Innovation blogs etc. Configured Cluster setup for Websphere to ensure High Availability of SSO Components., Implemented 2 factor Authentication to enable high security of Logitech Applications. This includes Phone OOB (Out of Band Authentication) using IBM Tivoli RSA Adapter, configuring with webseal. Helps user access Logitech Application via internet with 2 step Authentication, first level being Username/Password and Second (Call from VPN Based Network)., Worked singlehandedly in Migrating Entire TAM/TFIM/Webseal environment from Windows servers 2003 to Windows server 2008 R2 with latest version of components which was very challenging. Involved in Unit testing, bug fixing, production support activities ITIM Cognizant, 11/2008 - 05/2010, Chennai, The scope of the project was to implement Tivoli Identity Manager 4.6 in the Cognizant domain and automating the user lifecycle and enabling SSO through Access manager and WebSEAL. The Tivoli Identity Manager 4.6 is an identity management solution that manages the growing variety of users who require access to the IT resources and enables the organization to comply with regulations and audit requirements. It helps to manage the growing number of users that come in contact with our IT systems and consistently administer access to those users in alignment with your business requirements., Involved in the setup and configuration of the development and production environment of Identity manager and all its components like TDI. Installed Agents for the Active Directory and Domino Directory and clients for the agents and configured the agents to provision the user accounts., Customized the services for all the resources and done reconciliation., Defined Identity Policy for the accounts in ITDI and created that using JavaScript., Worked with JAVA API's and ITIM API’s in the ITIM Implementation. Created Life cycle rules for account suspension, deletion and user profile updating. Customization of user interface. Developed batch files to automate the production process like starting & stopping the Web sphere Application Server, LDAP, DB2 and backup of Log files., Involved in the performance tuning of the production system. Thrivent – RISaF (Reusable Integration Services and Framework), 06/2008 - 10/2008, Chennai, Reusable Integration Services and Framework program addresses the reusable application services requirement to meet the Integration program. It delivers IT components that will enable consistent member experience across all member access points, Gathered business requirements, analyzing the business needs and specifications Preparation of the test plans, test cases and test data., Ensured that test scripts reflected and confirmed each business requirement. Prepared RTM (Requirements Traceability Matrix), Writing Test Cases according to the Functional Specifications using tools like SOAP UI Pro 2.0.2, Performed Functional & System Testing to ensure Application Security. Executing Test Cases to validate the Functionality and Transactions. Involving in Functional Testing by using automation tools. Preparation of Defect report using Defect Tracking Tool, Managed test scripts and grouped into productive test scenarios., Responsible for collecting test authentication tokens/credentials for each user type., Automated Test Execution by adding assertions to Test Cases., Owned the Software Quality Assurance and release related activities., Project documentation related to development and testing. General Motors Acceptance Corporation – International Operations –DA Localization, 01/2008 - 03/2008, Chennai, GMAC Financial Services is a global, diversified financial services company. GMAC maintains a diversified portfolio of business operations, including automotive finance, dealer and insurance, real estate finance and other commercial businesses. GMAC was established as a wholly owned subsidiary by General Motors Corporation (GM) in 1919, and currently operates in approximately 40 countries. GMAC IO (International Operations) offers wholesale and retail automotive financing products to Opel, Vauxhall, Holden, Saab, Daewoo, Cadillac and Chevrolet dealers., Involved in segregation of gif files, Documenting the required JS and XSLs used for localization of all screens., Involved in preparing the test cases for all the modules., Involved in unit testing and Integration testing. General Motors Acceptance Corporation – International Operations -Delegated Admin, 09/2007 - 01/2008, Chennai, GMAC Financial Services is a global, diversified financial services company. GMAC maintains a diversified portfolio of business operations, including automotive finance, dealer and insurance, real estate finance and other commercial businesses. GMAC was established as a wholly owned subsidiary by General Motors Corporation (GM) in 1919, and currently operates in approximately 40 countries. GMAC IO (International Operations) offers wholesale and retail automotive financing products to Opel, Vauxhall, Holden, Saab, Daewoo, Cadillac and Chevrolet dealers., Involved in customization of XSL and Java Scripts in order to meet the client requirements for screen look and feel. Worked on Attribute Access Control, Workflow Configuration and Code Drop Preparation., Involved in testing the applications. CardSpace Authentication, 07/2007 - 09/2007, Chennai, Card Space is a new feature within Microsoft Windows that will help users to manage and control their digital identities such as passwords and usernames, when online. Windows CardSpace (WCS) is a technology that provides a management of digital identities with interoperability, security and ease-of-use in mind. With CardSpace it is possible to use various online services with only one user account/card instead of dealing with multiple usernames/passwords (U/P). Windows CardSpace and Information Card are SSO (Single-Sign-on) solutions from Microsoft. This project aims at developing a platform independent plugin for Java-based web application servers, which finally allows to use Information Card functionality with an existing web application with minimum integration effort., Deployed the source code from repository, Worked on the drafting of the complete business workflow of the project., Worked on rapid prototyping based on the client specifications. General Motors Acceptance Corporation – International Operations -Delegated Admin, 01/2008 - 03/2008, Chennai, GMAC Financial Services is a global, diversified financial services company. GMAC maintains a diversified portfolio of business operations, including automotive finance, dealer and insurance, real estate finance and other commercial businesses. GMAC was established as a wholly owned subsidiary by General Motors Corporation (GM) in 1919, and currently operates in approximately 40 countries. GMAC IO (International Operations) offers wholesale and retail automotive financing products to Opel, Vauxhall, Holden, Saab, Daewoo, Cadillac and Chevrolet dealers., Involved in customization of XSL and Java Scripts in order to meet the client requirements for screen look and feel. Worked on Attribute Access Control, Workflow Configuration and Code Drop Preparation., Involved in testing the applications. CardSpace Authentication, 07/2007 - 09/2007, Chennai, Card Space is a new feature within Microsoft Windows that will help users to manage and control their digital identities such as passwords and usernames, when online. Windows CardSpace (WCS) is a technology that provides a management of digital identities with interoperability, security and ease-of-use in mind. With CardSpace it is possible to use various online services with only one user account/card instead of dealing with multiple usernames/passwords (U/P). Windows CardSpace and Information Card are SSO (Single-Sign-on) solutions from Microsoft. This project aims at developing a platform independent plugin for Java-based web application servers, which finally allows to use Information Card functionality with an existing web application with minimum integration effort., Deployed the source code from repository, Worked on the drafting of the complete business workflow of the project., Worked on rapid prototyping based on the client specifications.