IT professional with over 15 + years of experience hands on knowledge on IAM,Ping Federate,Cyberark, WSO2,Saviyant& Okta.
Have a successful track record in managing projects for Banking, Insurance,Health Care and E commerce.
Expertise in Installation, configuration, deployment, and maintenance architecture of the PingFederate & WSO2 .
Specialized in implementing strong authentication mechanisms, such as (MFA), through Single Sign-On (SSO) solutions, particularly with Okta ,Ping Federate and WSO2 Proficient in Okta SSO implementation and lifecycle management.
Maintaining end-to-end accountability for customer satisfaction and overall delivery excellence .
Project leader with proven experience directing all phases of complex projects while managing, motivating and mentoring global team members.
Handled end to end project delivery, start from requirement gathering to providing solution to the customer withing the agreed timeline.
Leading a team of geographically dispersed resources to deliver technology projects on time.
Overview
15
15
years of professional experience
1
1
Certification
Work History
IAM Technical Solution Architect
Capgemini
05.2022 - Current
Stay up to date with the latest releases and security patches of the WSO2 IS.
Maintain comprehensive documentation of configurations, policies, and procedures related to the Identity Server for reference and auditing purposes.
Integrate the Identity Server with other enterprise systems, such as LDAP directories, Active Directory, databases, and third-party applications, to ensure seamless user authentication and authorization.
Customize and extend the Identity Server's functionality to meet specific business requirements.
Performed upgradation from v 5.3 to 5.10.
Design and Deployed Custom SSO pages for specific Service providers.
Migrated all 36 applications to upgraded version without disruptions.
Custom MFA implementation for Specific Service Provider.
Provided expert guidance on technology trends, ensuring that the company remained at the forefront of industry advancements.
IAM Security Operations Manager
Accenture
01.2021 - 05.2022
Managing a team of 7 IAM Experts in different Technologies
Preparing Weekly and Monthly deck for the team's progress on the operational work.
Attending the SOW meetings to forecast the IAM efforts for the agreed tasks.
Representing the Team on the CAB calls for any implementation/Enhancements done.
Remediating the Vulnerabilities reported on IAM infra servers to maintain a secure environment.
Have been part of Successful upgradations in CAPAM and Ping federate.
We ensure to have new SSL certificates Provisioned by Internal CA / external GoDaddy certificates and get them renewed on or before Expiry.
Review and update the Runbook for all services Quarterly.
Lead the daily SCRUM call as a SCRUM master for running the IAM deliverables.
Provide Artifacts/ Evidence supporting the Internal Audit controls.
Conducted Workshop to have the Applications integrated with SSO to comply with Security standards.
Proficient in creating the Daily, Weekly, Monthly and Quarterly reports, SLA Matrix and share with client.
synthesize and communicate project and business issues on an on-going basis, manage the group's awareness of major business and IT issues, and help to prevent escalations, where possible.
conduct regular 1:1 briefing with the direct reports on an on-going and regular basis
Daily review the operational tickets (Incident/Service Request /Change Request) and communicate with Team to complete all the ticket on time without SLA breach.
Senior IAM Consultant
NTT Data Global Delivery Services
09.2018 - 01.2021
Understand the Active Directory existing architecture of fidelity.
Analyzing the current applications for discovery and analysis by survey approach.
Performing top-down approach to understand the application integration with AD.
Conducting workshops with Application owners to gather application information.
Policies configuration for applications authentication & authorization.
Configured different authentication selectors and authentication adapters like IWA composite adapter, HTML form-based adapter.
Renewed new SSL certificates on both web hosted and Amazon cloud hosted applications.
Enabled Kerberos seamless login experience for 82(SAML/open token) application.
Configured Kerberos Adapter.
External Integration done with Google and LinkedIn Adapter for SSO.
SSO integration done for all (100+) SAML based Applications across the organization.
Integrated Splunk with Ping federate V 9.0.3.
Enabled SSO for O365 applications.
Amazon cloud (AMS/AWS) integrated with SSO.
Enabled Ping id (MFA) for 40+ applications to have a enhanced security.
Enabling Custom internet blocking page for external users at SSO page.
Maintaining external users registration via custom user registration portal.
Upgraded from 9.0.3 to 10.0.3 and 10.1
IAM Consultant
Mphasis
08.2016 - 09.2018
Depending on the job designation this process will provide the set of roles to every identity, the basic access like LAN, Email, WIFI, VPN etc, Need to be assigned to the identity.
Document requirements and get signoff from stakeholders and impacted groups.
Provide the requirements to the Development team for creating the workflows.
POC for Coordinating with the provisioning Managers of the applications getting involved in the implementation exercise.
Client walkthrough to application on weekly basis for Business Signoff.
Monitoring the Functional accounts which are not vaulted on TAPM, Using Guardian and Splunk tools.
Provide Guidelines to L2 operations team and maintaining the inventory with the justification provided for interactive logins using Functional accounts.
Identifying the Non-Vaulted Functional accounts and remediate by having these accounts vaulted in TPAM with the approval of the account owners.
Preparing status reports of the Functional Accounts to Senior Manager and major stakeholders on a weekly basis.
Remediating the Non-Vaulted Systems in TPAM by comparing with the Server CI Extract from CMDB Database.
Performed the study of 'Gap Analysis' for Functional Requirement Document.
IT Security Analyst
HSBC
01.2013 - 08.2016
Account management of UNIX accounts on Solaris, Linux, AIX, servers using ESS (Control-SA) application and by also logging on to servers (Putty) remotely.
Create new accounts and groups: non-generic (person) and generic ids (application).
Administration of High Privilege accounts and root passwords using PAR/TPAM (Password Auto Repository).
Administration of PAR/TPAM Database by Uploading servers/Accounts, creation of collections.
Create, modify and delete user ids as per the request form like CICS, TSO, ACF2 Profile in both production and development LPARS.
Rule writing: Define ACF2 rules.
Skills
PAM Tools CyberArk
SSO Tools: Pingfedrate SSO PingID MFA Okta SSO
WS02
IAM Tools:
SailPoint IdentityNow
Saviyant Databases: Oracle, MySQL, Microsoft SQL Server Operating System Servers: Linux Windows Server 2012
Cloud Technology
AWS
Azure
Certification
CISM – Certified Information Security Manager.
CyberArk Certified Trustee.
RHCSA (Red Hat Certified System Administrator - RHEL 7).
Solution Architect / IAM - Active Directory at Daimler Truck Innovation Center IndiaSolution Architect / IAM - Active Directory at Daimler Truck Innovation Center India