Projects

Flagship programmes

The headline identity and architecture programmes from a career spanning global IAM strategy, Zero-Trust transformation, sovereign cloud, greenfield directory builds and enterprise governance. Each entry summarises the mandate, the approach taken and what was delivered. Recent engagements are described at the level client agreements permit - the archive further down records the wider body of work behind them.

Global Industrial Group · 100+ countries · 2023 - present

Global IAM strategy, governance and AI identity standards

Global architecture steering for identity across a multinational enterprise operating in more than one hundred countries - setting the strategy, owning the roadmap and governing every significant identity design decision across a hybrid, multi-cloud estate spanning Active Directory, Entra ID, Google Identity and multiple IGA platforms. Translated business drivers, regulatory obligations and security imperatives into a coherent multi-year architectural vision now steering investment and delivery worldwide. Co-authored the ratified enterprise security architecture standard for AI applications, leading the IAM domain: twelve mandatory principles - spanning agent identities, non-human identity lifecycle, constrained delegation chains, attribute and policy based access control, and cloud-native authentication mandates - that now govern how every AI workload authenticates and is authorised across the group.

Entra ID Governance programme · global

Identity governance and access control framework at enterprise scale

Established a single, enterprise-wide access governance model where fragmented, manual practices had accumulated over years. Designed the Entra ID Governance estate end to end - Access Packages, Catalogues, Access Reviews and Entitlement Management - and owns the enterprise RBAC, ABAC and PBAC framework that underpins it. Architected joiner-mover-leaver automation integrating ServiceNow and ClearSkye IGA with Workday as the authoritative HR source, replacing ticket-driven provisioning with policy-driven lifecycle orchestration and giving audit and certification a defensible, evidence-backed foundation.

Direct Line Group · 2021 - 2022

Identity-centric Zero-Trust transformation

Led the strategic redesign of the full identity and end-user computing estate for a FTSE-listed insurer, moving the organisation from perimeter-based security to a cloud-first, identity-centric Zero-Trust model. Consolidated more than forty accumulated Conditional Access policies into a compact, governed framework - cutting administrative overhead while strengthening compliance posture. Retired legacy federation infrastructure in favour of modern cloud authentication, redesigned joiner-mover-leaver processes across every user type, and deployed Zero-Trust network access end to end - eliminating the legacy VPN across the entire device estate.

MHRA / CPRD / NIBSC · 2019 - 2020

Greenfield Active Directory and IDAM transformation

An initial three-month identity discovery for a national regulator surfaced systemic architectural debt across a complex multi-forest directory estate - findings that reshaped the organisation’s multi-year IAM roadmap, secured a strategic mandate for a greenfield rebuild, and extended through continuous renewals into an eighteen-month engagement. Authored the complete design documentation suite: migration strategy, cloud identity integration and PKI replacement, engineered to preserve certificate-based authentication continuity for critical national services throughout the transition.

Major UK bank · via Microsoft · 2018

Greenfield Active Directory for 60,000 users on Azure

Engaged by Microsoft as joint design authority for a greenfield, secure-by-design Active Directory environment serving 60,000 users across a bank’s global operations. Personally accountable for the full design documentation suite, PowerShell deployment automation, security hardening and implementation oversight - delivered to Microsoft best-practice standards and distributed globally without disruption to banking operations.

Network Homes · 2018 - 2019

Zero-touch endpoint identity for 1,200 devices

Technical lead for a modern endpoint identity programme covering roughly 1,200 devices: Microsoft Intune with Autopilot delivering true zero-touch provisioning, device compliance woven into Conditional Access, and legacy Group Policy restrictions replaced with cloud policy management. Handed over a complete design, build and operations documentation suite - leaving the in-house team fully equipped to run the estate without ongoing consultancy dependency.

London & Quadrant · 2013 - 2018

Enterprise architecture function and merger identity integration

Built the enterprise architecture function from the ground up as Head of Architecture and acting CTO - recruiting and leading a team of four architects, establishing Technical Design Authority governance, and partnering with the C-suite on IT strategy and a multi-million-pound capital budget. Delivery highlights: a 3,200-employee merger integrated with zero service disruption, enterprise PKI design, security architecture credited with averting three malware intrusions, and directory and DNS re-architecture that cut helpdesk calls by forty per cent.

Archive

Over two decades of delivery

Twenty years of dedicated identity work sits on top of a longer engineering career across infrastructure, networks, platforms and online services. A condensed record of further projects designed, documented and delivered along the way.

Consulting & freelance engagements · 2017 - present

  • IAM and IGA assessments and roadmaps - current-state discovery, gap analysis and prioritised improvement roadmaps for organisations across multiple sectors
  • Identity Fabric architecture design - vendor-neutral capability models, trust topologies and integration patterns spanning multi-vendor identity estates
  • Enterprise architecture modelling for the identity domain - motivation, conceptual, logical and physical views in ArchiMate, aligned to business drivers
  • Zero-Trust assessments - maturity evaluation, enforcement topology review and prioritised recommendations against NIST SP 800-207 principles
  • Joiner-mover-leaver process design and delivery - automated identity lifecycle across permanent, contract, external and guest populations
  • Azure / Entra Privileged Identity Management design and deployment - privileged access lifecycle, activation workflows and standing-privilege elimination
  • Granular administrative RBAC design and implementation - delegated administration models scoped to least privilege
  • Tiered Administration Model design and deployment - Tier 0/1/2 privilege isolation, PAW patterns and credential hygiene
  • Active Directory consolidation and hardening programmes - forest rationalisation, security baselining and attack-path reduction
  • Active Directory migration planning and M&A identity integration - directory strategy for mergers, acquisitions and divestments
  • Malware recovery and protection services for Active Directory - post-incident forest recovery, containment and resilience hardening
  • Entra ID / Azure AD hardening and best-practice optimisation - configuration reviews and remediation against Microsoft security baselines
  • Greenfield Azure AD / Entra ID integrations - hybrid identity topologies, synchronisation design and cloud authentication rollout
  • Entra External ID design and deployment - customer and partner identity journeys with policy-driven user flows
  • External identity services architecture - partner and consumer identity models, B2B federation and guest lifecycle governance
  • ADFS design and implementation - resilient federation farms with third-party relying-party integrations and operational handover
  • Conditional Access policy review and consolidation - governed policy frameworks replacing accumulated policy sprawl
  • PKI design and delivery using ADCS for UK critical national health infrastructure - offline root, issuing CA and certificate services architecture
  • PKI migration and modernisation - certificate services moved to current Windows Server platforms with full design, scripting and operational documentation
  • Intune and Autopilot design and deployment - zero-touch provisioning, device compliance and Conditional Access integration
  • Intune policy design and deployment - configuration profiles, restriction policies and compliance baselines replacing legacy Group Policy
  • Group Policy optimisation and hardening programmes - consolidation, performance improvement and security baseline enforcement
  • Microsoft 365 implementations - SharePoint, Teams, information protection and collaboration services with governed rollout
  • Okta, Ping Identity and WSO2 evaluations and assessments - objective platform fit analysis, integration patterns and selection support
  • DSEvolve design and delivery engagements for a range of clients
  • Zscaler design and rollout - ZIA, ZPA and ZDX architectures replacing legacy VPN with per-application Zero-Trust access

London & Quadrant · identity & platform

  • Active Directory in-situ migration - consolidation of multiple AD forests to a single corporate forest on AD 2016, introducing RBAC with Microsoft Identity Manager and just-in-time / just-enough administration
  • Azure Active Directory, Azure Application Proxy and Azure MFA implementation
  • ADFS and Web Application Proxy multi-site architecture - highly available across geographically dispersed data centres with global and local server load balancing
  • Windows 10 Group Policy architecture, legacy policy consolidation and Advanced Group Policy Management with change auditing
  • Office 365 tenancy rollout, Skype for Business Online pilot, LAPS proof-of-concept
  • Active Directory upgrades, merger-driven forest consolidation and user migration, and a 70-page AD architecture review with security recommendations

London & Quadrant · infrastructure & always-on

  • Enterprise network redesign - from collapsed core to zoned architecture on Cisco Nexus data centre cores, 10Gbps fibre backbones, active/active data centres
  • Enterprise SAN replacement with HP 3PAR and geographically dispersed DFS file services
  • Always-on application architecture - active/active redesign of line-of-business and housing management platforms, plus Dynamics CRM with SQL Always-On availability groups
  • Database virtualisation on a dedicated VMware ESXi farm - reduced server sprawl, licensing cost and complexity
  • Cross-site resilient VMware farm with Site Recovery Manager and physically separated production and QA/development environments
  • Network separation programme - production, QA/development, management and iSCSI traffic isolated across hardware, storage and network layers

Anglo Beef Processors

  • Active Directory upgrade across a data centre and sixteen branch offices, including two new sites brought into the forest
  • VMware ESXi farm with NetApp SAN and Cisco networking - physical server consolidation cutting hosting costs and environmental footprint
  • SharePoint solution designed and implemented for the entire business
  • Email domain splitting across multiple mail systems, and endpoint protection platform upgrade

Codemasters Online Games

  • EgoNET - design, implementation and technical lead for the online platform integrating Xbox Live Server Platform and PlayStation server platform, including DiRT3 infrastructure
  • JumpGate Evolution MMO - highly available, scalable infrastructure across development, QA, alpha and beta environments: networking, monitoring, MySQL HA, SAN storage, login and game services
  • Operations and infrastructure for Lord of the Rings Online, Dungeons & Dragons Online and Archlord MMOs - implementation, patch deployment and operational documentation
  • Enterprise monitoring with automated alerting, SQL-backed logging and performance reporting; hardware monitoring for the Netherlands data centre
  • SharePoint platform with bespoke change management, incident management and reporting systems - saved eight hours of administration per week

Early career foundations · pre-2006

  • Greenfield Active Directory design and implementation for a range of client organisations
  • Brownfield Active Directory redesign, optimisation and hardening engagements
  • IBM AS/400 RPG analyst programming - business application development, maintenance and reporting
  • Millennium bug (Y2K) code evaluation and remediation across business-critical systems
  • Infrastructure engineering - servers, storage and core platform services across multi-site estates
  • Citrix engineering and support - published applications and thin-client environments
  • Network and Wi-Fi installation, configuration and troubleshooting
  • SQL database support and administration
  • Desktop support services across multi-site environments
  • PC build and repair services

Have an identity challenge worth solving?

I take a small number of freelance and contract engagements each year.

Start a conversation