A selection of recent architecture, identity, cloud, risk and transformation projects delivered for global enterprises, public institutions and critical-infrastructure organizations.
Each project demonstrates structured architecture, practical governance, clear ownership and security improvements that can be implemented and operated
Structured privileged access and IAM governance across Microsoft Entra, Azure, Active Directory, Okta, CyberArk, ServiceNow and SOC monitoring. Authored Azure privileged access model covering cloud-only admin accounts, Entra PIM, Access Packages, break-glass, Conditional Access, lifecycle and monitoring.
Key outcomes:
• Clear Azure management-plane vs AD data-plane boundaries
• Tier 0 / Tier 1 privileged access risk prioritization
• Improved CyberArk onboarding direction and governance
• Stronger ISO 27001/NIS2 alignment, documentation and audit evidence
Delivered cloud and identity transformation support for a fast-growing global organization. Designed Azure privileged access strategy, PIM and break-glass governance, passwordless patterns, AD Tiering, PAM policies, BitLocker/LAPS playbooks, Azure RBAC/tagging standards and Sentinel monitoring guidance.
Key outcomes:
• Clear Azure governance framework
• Standardized privileged access and cloud administration patterns
• Improved alignment with NIST/ISO expectations
• Stronger identity, endpoint and monitoring controls
Delivered advanced workshops and architecture advisory for Microsoft enterprise customers. Covered hybrid identity, Entra ID, Conditional Access, AD Tiering, PAW, break-glass, ADFS-to-Entra migration, RC4 deprecation, phishing-resistant MFA and Defender for Identity.
Key outcomes:
• Delivered Zero Trust and privileged access architecture sessions
• Clarified workshop materials and implementation considerations
• Advised regulated and public-sector clients on identity governance changes
• Supported secure modernization of legacy identity patterns
Improved cybersecurity integration practices for acquisitions by standardizing documentation, security baselines, asset discovery, AD consolidation planning, vulnerability remediation and follow-up. Created Armis IoT discovery and deployment procedures and network documentation standards for acquired companies.
Key outcomes:
• Reduced onboarding and integration risk
• Clear technical and governance requirements
• Improved cross-team accountability
• Better visibility of inherited infrastructure and unmanaged assets
Assessed IAM, infrastructure, application and security governance gaps during acquisition integration. Coordinated vulnerability remediation, reviewed controls and delivered ISO 27001 / Secure SDLC awareness to support integration readiness.
Key outcomes:
• Improved security visibility
• Clear remediation responsibilities
• Better application-owner awareness
• Structured integration support
Performed OT remote access assessment for ICS / SCADA operations. Delivered a 60-page configuration review and designed a secure access model aligned with Purdue and IEC 62443 principles.
Key outcomes:
• Hardened Citrix-based remote access
• Clear RBAC and identity governance recommendations
• MFA, monitoring, segmentation and PAM integration guidance
• Audit-ready documentation for security and operational stakeholders
Drove security architecture improvements across Azure, Active Directory and PAM. Defined AD Tier 0 isolation, Azure RBAC governance and BeyondTrust PAM onboarding/support framework aligned with ISO 27001.
Key outcomes:
• Reduced risk around Domain Admin access
• Clearer delegation and privileged access model
• PAM operating procedures and ownership structure
• Stronger auditability and privileged access governance
Acted as escalation lead for one of the world’s largest hybrid AD and Entra environments, supporting more than 700k users. Resolved cross-domain issues, misconfigured trusts, DNS/Infoblox problems, GPO failures and high-impact outages. Built PowerShell automation for IAM operations and incident recovery.
Key outcomes:
• Improved operational stability
• Faster incident response and service request fulfillment
• Reduced configuration drift
• Stronger reliability across complex directory services
Localized ISO 27001 controls and security policies for the Polish branch. Delivered training, evidence packs, Microsoft Defender and Tenable rollout support, and access-control improvements.
Key outcome:
• Improved audit readiness from approximately 30% to 80% with supporting evidence
• UBS — IT Risk & Control
Infrastructure risk assessments, control mapping and regulatory readiness.
• GAIN Capital — Identity & Threat Response
Identity-related remediation after Citrix NetScaler compromise.
• EY — Incident Response & PKI Governance
NIST/ISO-aligned incident response plans and Venafi-based PKI governance.
• Earlier Enterprise Infrastructure & IAM Roles
AD, Citrix, VMware, PKI, VPN, GPO, access governance and endpoint security.
• Founder of IT Consultancy
Secure LANs, remote access, endpoint protection and IT support services for SMB and public-sector clients.