ProjectsFlagship programmes
The headline identity and architecture programmes from a career spanning global IAM strategy, Zero-Trust transformation, sovereign cloud, greenfield directory builds and enterprise governance. Each entry summarises the mandate, the approach taken and what was delivered. Recent engagements are described at the level client agreements permit - the archive further down records the wider body of work behind them.
Global Industrial Group · 100+ countries · 2023 - present
Global IAM strategy, governance and AI identity standards
Global architecture steering for identity across a multinational enterprise operating in more than one hundred countries - setting the strategy, owning the roadmap and governing every significant identity design decision across a hybrid, multi-cloud estate spanning Active Directory, Entra ID, Google Identity and multiple IGA platforms. Translated business drivers, regulatory obligations and security imperatives into a coherent multi-year architectural vision now steering investment and delivery worldwide. Co-authored the ratified enterprise security architecture standard for AI applications, leading the IAM domain: twelve mandatory principles - spanning agent identities, non-human identity lifecycle, constrained delegation chains, attribute and policy based access control, and cloud-native authentication mandates - that now govern how every AI workload authenticates and is authorised across the group.
Entra ID Governance programme · global
Identity governance and access control framework at enterprise scale
Established a single, enterprise-wide access governance model where fragmented, manual practices had accumulated over years. Designed the Entra ID Governance estate end to end - Access Packages, Catalogues, Access Reviews and Entitlement Management - and owns the enterprise RBAC, ABAC and PBAC framework that underpins it. Architected joiner-mover-leaver automation integrating ServiceNow and ClearSkye IGA with Workday as the authoritative HR source, replacing ticket-driven provisioning with policy-driven lifecycle orchestration and giving audit and certification a defensible, evidence-backed foundation.
Direct Line Group · 2021 - 2022
Identity-centric Zero-Trust transformation
Led the strategic redesign of the full identity and end-user computing estate for a FTSE-listed insurer, moving the organisation from perimeter-based security to a cloud-first, identity-centric Zero-Trust model. Consolidated more than forty accumulated Conditional Access policies into a compact, governed framework - cutting administrative overhead while strengthening compliance posture. Retired legacy federation infrastructure in favour of modern cloud authentication, redesigned joiner-mover-leaver processes across every user type, and deployed Zero-Trust network access end to end - eliminating the legacy VPN across the entire device estate.
MHRA / CPRD / NIBSC · 2019 - 2020
Greenfield Active Directory and IDAM transformation
An initial three-month identity discovery for a national regulator surfaced systemic architectural debt across a complex multi-forest directory estate - findings that reshaped the organisation’s multi-year IAM roadmap, secured a strategic mandate for a greenfield rebuild, and extended through continuous renewals into an eighteen-month engagement. Authored the complete design documentation suite: migration strategy, cloud identity integration and PKI replacement, engineered to preserve certificate-based authentication continuity for critical national services throughout the transition.
Major UK bank · via Microsoft · 2018
Greenfield Active Directory for 60,000 users on Azure
Engaged by Microsoft as joint design authority for a greenfield, secure-by-design Active Directory environment serving 60,000 users across a bank’s global operations. Personally accountable for the full design documentation suite, PowerShell deployment automation, security hardening and implementation oversight - delivered to Microsoft best-practice standards and distributed globally without disruption to banking operations.
Network Homes · 2018 - 2019
Zero-touch endpoint identity for 1,200 devices
Technical lead for a modern endpoint identity programme covering roughly 1,200 devices: Microsoft Intune with Autopilot delivering true zero-touch provisioning, device compliance woven into Conditional Access, and legacy Group Policy restrictions replaced with cloud policy management. Handed over a complete design, build and operations documentation suite - leaving the in-house team fully equipped to run the estate without ongoing consultancy dependency.
London & Quadrant · 2013 - 2018
Enterprise architecture function and merger identity integration
Built the enterprise architecture function from the ground up as Head of Architecture and acting CTO - recruiting and leading a team of four architects, establishing Technical Design Authority governance, and partnering with the C-suite on IT strategy and a multi-million-pound capital budget. Delivery highlights: a 3,200-employee merger integrated with zero service disruption, enterprise PKI design, security architecture credited with averting three malware intrusions, and directory and DNS re-architecture that cut helpdesk calls by forty per cent.