San Francisco Bay Area
Engineering leader and Principal-level architect specializing in AI-driven cybersecurity and large-scale Identity platforms. I lead CIAM transformation initiatives supporting 50M+ identities, delivering 10x scalability, 7.5K+ LPS performance, and 99.99%+ availability in cloud-native environments. I lead EIAM supporting 500K+ identities and support forturn 100 with SLA productive Employee in 24-hours after joining with SOX,PCI, GLBA, HIPPA complient Expert in zero-trust architecture, privileged access governance, and resilient authentication systems at enterprise scale. Bridge strategy and execution across platform engineering, security architecture, and product innovation. Focused on building high-performing teams and secure, scalable systems that power trusted digital experiences.
Led post-merger Client Identity consolidation for Charles Schwab and TD Ameritrade, integrating enterprise authentication ecosystems into a unified identity platform serving ~40M clients across Retail, Web, Mobile, and Voice channels; completed full consolidation within two years while maintaining uninterrupted client experience. Defined and executed the multi-year strategy for a high-volume Authentication Platform, scaling capacity by 35% and later engineering the architecture to support 7,500 logins per second (LPS) with p99 < 800ms, <0.01% error budget, and 99.99–99.999% availability across all client-facing channels. Modernized Client IAM architecture, replacing legacy homegrown solutions with standards-based identity protocols (OIDC 2.0, SAML 2.0) and redesigning the platform for cloud-native scalability; enabled 10x scalability improvement and strengthened enterprise security posture. Spearheaded migration of the Client Authentication Platform from PCF to GCP, delivering 30% infrastructure cost reduction, 25% latency improvement, and materially enhanced resiliency and elasticity through containerization and distributed system redesign. Built and scaled a global engineering organization (2 Engineering Managers, 32 Engineers, 4 Scrum Masters), improving engineering productivity by 40% with AI adoption, accelerating time-to-market for security capabilities by 35%, and establishing a high-performance culture aligned to enterprise reliability, compliance, and AI-enabled PDLC transformation.
Served as Senior Engineering Manager & Principal Architect for Enterprise IAM, owning end-to-end identity strategy across governance, identity intelligence, authorization, provisioning, entitlements, privileged access management, and enterprise-wide access reviews spanning retail applications and infrastructure boundaries. Provided technical and architectural leadership across 30+ engineers (16 FTEs, 14 consultants), driving execution across the full IAM product lifecycle using agile delivery while personally shaping architecture, design standards, and security patterns. Designed and built a centralized, product-agnostic Identity Management UI platform adopted by ~500,000 enterprise users, abstracting multiple vendor systems into a unified control plane and significantly improving user experience and operational efficiency. Led large-scale enterprise IAM modernization initiatives, migrating legacy identity platforms (OIM, Microsoft Forefront Identity Manager, AMP) to CA Identity Management and architecting an in-house Identity Governance solution using Java and MEAN stack; eliminated vendor fragmentation while strengthening compliance and scalability. Architected and implemented enterprise Privileged Access Management (CyberArk) and automated privileged access detection systems, remediating ~2 million privileged access records within two years and establishing continuous access certification and risk-based governance controls. Designed and delivered UEBA (User & Entity Behavior Analytics) platform for access risk scoring, anomaly detection, and recommendation engine capabilities; integrated behavioral intelligence into IAM workflows to proactively identify access outliers and reduce insider risk exposure. Personally contributed as a hands-on Principal Engineer, leading solution design reviews, coding critical components, defining security models, and mentoring senior engineers on scalable IAM patterns and enterprise-grade architecture.
Acted as Principal IAM Architect, partnering with senior executives to shape multi-year IAM strategy and roadmap, influencing enterprise-wide direction for next-generation identity platforms across retail systems and infrastructure. Led the architectural evolution of Next-Gen IAM, proactively identifying and resolving deeply complex technical and organizational challenges impacting scalability, resiliency, governance, and long-term platform sustainability. Operated in a hands-on technical leadership role, directly designing and resolving high-impact architectural issues, debugging critical production challenges, and guiding engineering teams through complex identity modernization initiatives. Re-architected legacy IAM systems into a programmable, highly available, cloud-scalable identity infrastructure, establishing best practices for automation, API-driven identity services, and cost-optimized platform engineering. Engineered IAM capabilities to enable enterprise regulatory compliance (SOX, PCI, GLBA) by embedding auditability, access certification, privileged controls, and policy enforcement directly into identity workflows and governance models. Drove IAM DevSecOps innovation by researching, evaluating, and implementing modern identity automation and DevOps tooling, reducing operational overhead and accelerating secure delivery cycles. Collaborated cross-functionally with business units and security architecture teams to ensure IAM products aligned with enterprise security standards, operating models, and long-term digital transformation goals. Served as Subject Matter Expert (SME) across critical IAM platforms including Oracle Identity Manager (OIM), Securonix (security analytics), and CyberArk (PAM), providing architectural guidance, solution oversight, and enterprise integration leadership.
The Manager, Identity & Access Management Analytics is responsible for the overall strategy, planning, evaluation, architecture and implementation of the entire Identity/Access Analytics Management program. Provide overall direction and oversight into the IAM functions across the organization, including areas such as Privileged Access Management integration, Authentication and Authorization integration, Security and Provisioning Identity Data with Securonix . The role reports to the Director of IT and will be responsible for documenting & designing the IAM program. This individual will also manage a team of IAM analysts that are responsible for the day to day configuration, reporting, & alert monitoring of all IAM solutions Providing support to security and develop appropriate audit controls and procedures to ensure the integrity of applications. Working closely with the project managers, Security and Compliance personnel, application developers and other administrators in creating functional, scalable and secure applications from design and development through implementation. This person will also be responsible for putting controls in place to support RBAC/Least Privileged access for all associates Responsible for identifying, evaluating and participating in decision-making around new and emerging technologies.
Principal IAM Engineer leading enterprise-wide design and engineering of Identity & Access Management platforms, covering certifications, access requests, provisioning, and workflow automation at scale. 12+ years of deep hands-on expertise with Oracle Identity Manager (OIM 11G R1/R2 PS1+), building custom connectors, SOA-based approvals, UI customizations, and scalable provisioning workflows across large enterprise deployments. Owned end-to-end IAM system lifecycle — architecture, development, integration, performance tuning, production deployment, and Tier-3 engineering support — ensuring high availability and operational resilience. Re-engineered legacy IAM workflows and connectors to improve automation, enhance governance controls, and optimize system performance while reducing operational overhead. Partnered with engineering, QA, operations, and business stakeholders to strengthen identity data quality, compliance readiness, and enterprise security architecture alignment.
AS Lead Engineer translating enterprise business strategy into scalable technology execution, delivering solutions supporting millions of users across global platforms while improving delivery predictability and system resilience. Architected and implemented enterprise IAM and SOA-based Java/J2EE systems that reduced manual access provisioning efforts by ~40%, improved authentication/authorization performance by 25%+, and strengthened regulatory compliance controls. Led cross-functional teams (10–20 engineers across Dev, QA, and Ops) through full SDLC, consistently delivering complex programs 15–20% faster time-to-market while maintaining production stability above 99.9% availability. Designed distributed integration frameworks enabling cross-platform interoperability across Retail, Pharmaceutical, Logistics, and Telecom ecosystems, improving system throughput by 30% and reducing integration defects by 35%. Modernized legacy architectures into scalable, service-oriented platforms, lowering operational overhead by 20% and improving deployment efficiency through automation and reusable enterprise components.
Design, implement, configure, troubleshoot and tune Oracle I&AM products like OIM, OVD, OAM, OIF,ODSEE etc. Work closely with Application Integration Architect, Fusion Middleware Admin and Client Security teams to architect Oracle Identity Management suite of products for scalability and maintainability. Troubleshoot issues as when they arise. Administer the Oracle Identity Management Suite. Identifies cross-team issues, and communicate them to the appropriate leads. Validates that the Security solutions and Security architecture designs utilize the security components appropriately to meet Enterprise needs.