Identity & Access Management

Designing who gets in, and who doesn't.

I'm Madhu Satti, an IAM Security Architect and full-stack engineer. I design identity federation, access governance, and least-privilege systems — then build the applications and platforms that enforce them.

OktaEntra IDSailPointCA SiteMinderLayer 7 (API Management)SAML 2.0OIDCJavaNode.js
access-review.log
whoami --role madhu satti · iam-security-architect identity verify --user madhu --mfa true
IDENTITY VERIFIED
policy evaluate --resource this-portfolio --action view scope: public · session: read-only · decision:
ALLOW

Security-minded engineering, end to end.

My work sits at the intersection of Identity & Access Management (IAM), Cloud Security, and Enterprise Technology.

On the IAM side, I specialize in designing, implementing, and optimizing secure, scalable, and compliant identity solutions across enterprise environments. With expertise in Microsoft Entra ID (Azure AD), Okta, Active Directory, CyberArk, SailPoint, AWS IAM, and Zero Trust, I architect authentication, authorization, identity governance, privileged access, and access lifecycle management solutions that balance security, compliance, and user experience.

On the cloud and infrastructure side, I help organizations modernize identity ecosystems by integrating cloud platforms, hybrid environments, and enterprise applications. My experience includes Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Privileged Access Management (PAM), Identity Governance & Administration (IGA), and federation standards including SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC). I also automate and streamline IAM operations using PowerShell, Terraform, Azure DevOps, and cloud-native technologies.

Beyond architecture, I enjoy translating complex security requirements into practical, business-focused solutions. My passion is building resilient identity frameworks that enable digital transformation while reducing cyber risk. I focus on delivering secure, scalable, and future-ready IAM strategies that empower organizations to embrace Zero Trust and confidently protect their most valuable asset—Identity.

01

Least privilege by default

Every access decision starts from zero and earns its way up, not the reverse.

02

Protocol-first design

SAML, OIDC, and OAuth flows are mapped before UI or business logic is written.

03

Encryption as a default

Data at rest is encrypted unless there's a documented reason it isn't.

04

Auditable by design

If a system can grant access, it can also show exactly who has it and why.

Experience

Jul 2022 — Present

Senior IAM Consultant

HCLTech

Nov 2020 - Jul 2022

Senior Solution Architect

Wipro

Dec 2014 - Nov 2020

Associate Architect

Innominds Software

Jan 2008 - Dec 2014

Consultant

ADP Private Limited

Skills & Domains

Identity architecture, backed by hands-on engineering across web and mobile.

DOMAIN / 01

IAM Platforms & Protocols

  • Okta
  • Microsoft Entra ID & B2C
  • SailPoint
  • SAML 2.0
  • OIDC / OAuth 2.0
DOMAIN / 02

Security Engineering

  • Least-privilege access design
  • Zero Trust Security Architecture
  • Identity-Centric Security Design
  • Passwordless Authentication
  • Federation & Identity Integration
DOMAIN / 03

Application Development

  • Java / J2EE
  • Python
  • Node.js
  • HTML / CSS / JavaScript
DOMAIN / 04

Tooling & Automation

  • Terraform for Okta Identity Infrastructure
  • CI/CD Pipeline for SailPoint IIQ
  • PowerShell Automation
  • Python Scripting
  • REST API Automation

Selected Projects

Each entry logged the way an access ledger would: subject, resource, protocol, outcome.

Okta Implementation, App Migration & Automation

IMPLEMENTED
CLIENTRichemont
ROLEOKTA SME
DomainEnterprise Security - IAM

  • Architected and deployed a GitOps-based Okta configuration management framework using Terraform and GitLab CI/CD, automating configuration propagation across multiple tenants and embedding governance via code reviews, approvals, and audit traceability.
  • Delivered a factory-style application onboarding model with reusable patterns for SAML, OIDC, and policy integrations, enabling predictable, high-quality migrations and reducing delivery friction between IAM and application teams.
  • Executed large-scale application migration of applications from Entra ID and Keycloak to Okta and establishing a scalable pipeline capable of supporting thousands of applications.
  • Enhanced Terraform automation for scale and reliability by consolidating modules, splitting pipelines into logical stacks, introducing targeted apply workflows, and tuning parallelism—resulting in reduced rate-limit failures, improved error handling, and minimized state drift.

Okta Implementation & App Migration

IMPLEMENTED
CLIENTBombardier
ROLEOKTA SME
DomainEnterprise Security - IAM

  • Modernized Bombardier’s IAM platform by replacing legacy CASiteMinder with Okta SSO and Okta Access Gateway, enabling secureintegration for legacy and cloud applications.
  • Executed enterprise-scale user migration of 100,000+ identities fromOracle LDAP and Active Directory into Okta Universal Directory.
  • Improved authentication performance by 60–70% through LDAP indexing and filter optimization, ensuring reliable large-scale imports beyond the standard 24-hour threshold.
  • Standardized MFA enforcement by integrating SafeNet MobilePASS with Okta, achieving 100% coverage across all access scenarios without disrupting existing enrollment models, thereby avoiding costly MFA replacement.
  • Delivered dynamic, application-aware login customization using JSON-driven configurations hosted on AWS S3.
  • Deployed secure Okta Access Gateway nodes aligned with Bombardier’s network segmentation strategy, enabling seamless SSO for SAP and other legacy applications.

Entra ID Implementation

IMPLEMENTED
CLIENTHeubach
ROLEEntra ID SME
DomainEnterprise Security - IAM

  • Implemented enterprise-wide MFA rollout in phased waves, onboarding pilot groups first and extending coverage to all users and privileged accounts; reduced unauthorized access risk by ~40% while maintaining business continuity through MFA-exempt service accounts.
  • Optimized Azure AD role management by configuring Privileged Identity Management (PIM) with approval workflows.
  • Streamlined identity protection and conditional access policies, enforcing adaptive security controls across applications and user groups, improving compliance posture and reducing policy exceptions by 25%.
  • Onboarded multiple SSO applications into Entra ID, enabling seamless authentication and reducing login friction for end users while ensuring adherence to corporate security standards.
  • Authored detailed runbooks and design documentation for IAM transition services, ensuring smooth handover to the HCL BAU team and enabling reproducible operations with minimal knowledge gaps.

Okta Access Gateway Deployment

ARCHITECTURED & IMPLEMENTED
CLIENTScientific Games Lottery
ROLEOkta SME
DomainEnterprise Security - IAM

  • Deployed multi-instance Okta Access Gateway (OAG) across Production and UAT environments, configuring high-availability clusters (admin + worker nodes) to ensure seamless failover and patch validation before production rollout.
  • Integrated Okta Access Gateway with Okta SaaS and successfully onboarded five enterprise applications (OBIEE, Oracle E-Business Suite, Access Gateway Admin Console, Sample Header App, and others), enabling secure SSO and reducing login friction for thousands of users.
  • Strengthened application security posture by aligning OAG deployment with Scientific Games’ network segmentation strategy, ensuring strict DMZ compliance while enabling secure cloud identity integration.
  • Led requirement gathering, design, and UAT support, collaborating with cross-functional teams to validate application access, streamline onboarding, and accelerate time-to-production by 30%.

Identity and Access Management V2

ARCHITECTURED & IMPLEMENTED
CLIENTThoughtSpot
ROLEOkta Consultant
DomainEnterprise Security - IAM

  • Evaluated multiple cloud authentication platforms (Auth0, Okta, Keycloak) and recommended Okta as the strategic IAM solution, aligning with scalability, security, and enterprise governance requirements.
  • Developed REST APIs leveraging Okta Management APIs to automate creation of SAML/OIDC identity providers, password policies, MFA policies, users, and groups, reducing manual configuration effort by 40%.
  • Led cross-functional team of backend, frontend, and QA engineers, driving feature design, authentication flow development, and regression bug resolution; improved delivery velocity by 25%.
  • Migrated users and authentication configurations from legacy clusters to Okta, ensuring seamless transition with minimal downtime and strengthening IAM reliability.
  • Authored detailed design documents, user stories, and runbooks, enabling reproducible deployments and effective knowledge transfer to client teams.

Robot Certificate Management Agent & IAM Configurations

ARCHITECTURED & IMPLEMENTED
CLIENTVecna Robotics
ROLESecurity Consultant
DomainEnterprise Security - IAM

  • Developed and deployed the Robot Certificate Management Agent (RCMA) using Java, Spring Boot, and REST services, automating daily certificate validation and renewal via Certificate Web Service (CWS), reducing manual intervention by 90%.
  • Implemented third-party IAM integration with CAS, enabling seamless redirection to customer IdPs via SAML-based authentication flows, strengthening security and ensuring compliance with enterprise identity standards.
  • Optimized authentication and authorization configurations with Spring Security and PLSQL, improving login success rates and reducing authentication errors by 25%.
  • Led end-to-end module development including design documentation, code reviews, debugging, and UAT support; resolved client-reported issues within SLA, improving customer satisfaction scores.
  • Delivered performance tuning and regression fixes, enhancing system reliability and reducing certificate renewal failures by 30% across robotic fleets.

SailPoint CI/CD Integration

IMPLEMENTED
CLIENTConvera
ROLEIAM Consultant
DomainEnterprise Security - IAM

  • Implemented CI/CD pipelines for SailPoint IdentityIQ artifacts using GitHub, Jenkins, Ant scripts, JFrog, and Tomcat, enabling automated builds and deployments that reduced manual deployment effort by 40% and improved release consistency.