Designing who gets in, and who doesn't.
I'm Madhu Satti, an IAM Security Architect and full-stack engineer. I design identity federation, access governance, and least-privilege systems — then build the applications and platforms that enforce them.
Security-minded engineering, end to end.
My work sits at the intersection of Identity & Access Management (IAM), Cloud Security, and Enterprise Technology.
On the IAM side, I specialize in designing, implementing, and optimizing secure, scalable, and compliant identity solutions across enterprise environments. With expertise in Microsoft Entra ID (Azure AD), Okta, Active Directory, CyberArk, SailPoint, AWS IAM, and Zero Trust, I architect authentication, authorization, identity governance, privileged access, and access lifecycle management solutions that balance security, compliance, and user experience.
On the cloud and infrastructure side, I help organizations modernize identity ecosystems by integrating cloud platforms, hybrid environments, and enterprise applications. My experience includes Single Sign-On (SSO), Multi-Factor Authentication (MFA), Conditional Access, Privileged Access Management (PAM), Identity Governance & Administration (IGA), and federation standards including SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC). I also automate and streamline IAM operations using PowerShell, Terraform, Azure DevOps, and cloud-native technologies.
Beyond architecture, I enjoy translating complex security requirements into practical, business-focused solutions. My passion is building resilient identity frameworks that enable digital transformation while reducing cyber risk. I focus on delivering secure, scalable, and future-ready IAM strategies that empower organizations to embrace Zero Trust and confidently protect their most valuable asset—Identity.
Least privilege by default
Every access decision starts from zero and earns its way up, not the reverse.
Protocol-first design
SAML, OIDC, and OAuth flows are mapped before UI or business logic is written.
Encryption as a default
Data at rest is encrypted unless there's a documented reason it isn't.
Auditable by design
If a system can grant access, it can also show exactly who has it and why.
Experience
Senior IAM Consultant
HCLTechSenior Solution Architect
WiproAssociate Architect
Innominds SoftwareConsultant
ADP Private LimitedSkills & Domains
Identity architecture, backed by hands-on engineering across web and mobile.
IAM Platforms & Protocols
- Okta
- Microsoft Entra ID & B2C
- SailPoint
- SAML 2.0
- OIDC / OAuth 2.0
Security Engineering
- Least-privilege access design
- Zero Trust Security Architecture
- Identity-Centric Security Design
- Passwordless Authentication
- Federation & Identity Integration
Application Development
- Java / J2EE
- Python
- Node.js
- HTML / CSS / JavaScript
Tooling & Automation
- Terraform for Okta Identity Infrastructure
- CI/CD Pipeline for SailPoint IIQ
- PowerShell Automation
- Python Scripting
- REST API Automation
Selected Projects
Each entry logged the way an access ledger would: subject, resource, protocol, outcome.
Okta Implementation, App Migration & Automation
IMPLEMENTED
- Architected and deployed a GitOps-based Okta configuration management framework using Terraform and GitLab CI/CD, automating configuration propagation across multiple tenants and embedding governance via code reviews, approvals, and audit traceability.
- Delivered a factory-style application onboarding model with reusable patterns for SAML, OIDC, and policy integrations, enabling predictable, high-quality migrations and reducing delivery friction between IAM and application teams.
- Executed large-scale application migration of applications from Entra ID and Keycloak to Okta and establishing a scalable pipeline capable of supporting thousands of applications.
- Enhanced Terraform automation for scale and reliability by consolidating modules, splitting pipelines into logical stacks, introducing targeted apply workflows, and tuning parallelism—resulting in reduced rate-limit failures, improved error handling, and minimized state drift.
Okta Implementation & App Migration
IMPLEMENTED
- Modernized Bombardier’s IAM platform by replacing legacy CASiteMinder with Okta SSO and Okta Access Gateway, enabling secureintegration for legacy and cloud applications.
- Executed enterprise-scale user migration of 100,000+ identities fromOracle LDAP and Active Directory into Okta Universal Directory.
- Improved authentication performance by 60–70% through LDAP indexing and filter optimization, ensuring reliable large-scale imports beyond the standard 24-hour threshold.
- Standardized MFA enforcement by integrating SafeNet MobilePASS with Okta, achieving 100% coverage across all access scenarios without disrupting existing enrollment models, thereby avoiding costly MFA replacement.
- Delivered dynamic, application-aware login customization using JSON-driven configurations hosted on AWS S3.
- Deployed secure Okta Access Gateway nodes aligned with Bombardier’s network segmentation strategy, enabling seamless SSO for SAP and other legacy applications.
Entra ID Implementation
IMPLEMENTED
- Implemented enterprise-wide MFA rollout in phased waves, onboarding pilot groups first and extending coverage to all users and privileged accounts; reduced unauthorized access risk by ~40% while maintaining business continuity through MFA-exempt service accounts.
- Optimized Azure AD role management by configuring Privileged Identity Management (PIM) with approval workflows.
- Streamlined identity protection and conditional access policies, enforcing adaptive security controls across applications and user groups, improving compliance posture and reducing policy exceptions by 25%.
- Onboarded multiple SSO applications into Entra ID, enabling seamless authentication and reducing login friction for end users while ensuring adherence to corporate security standards.
- Authored detailed runbooks and design documentation for IAM transition services, ensuring smooth handover to the HCL BAU team and enabling reproducible operations with minimal knowledge gaps.
Okta Access Gateway Deployment
ARCHITECTURED & IMPLEMENTED
- Deployed multi-instance Okta Access Gateway (OAG) across Production and UAT environments, configuring high-availability clusters (admin + worker nodes) to ensure seamless failover and patch validation before production rollout.
- Integrated Okta Access Gateway with Okta SaaS and successfully onboarded five enterprise applications (OBIEE, Oracle E-Business Suite, Access Gateway Admin Console, Sample Header App, and others), enabling secure SSO and reducing login friction for thousands of users.
- Strengthened application security posture by aligning OAG deployment with Scientific Games’ network segmentation strategy, ensuring strict DMZ compliance while enabling secure cloud identity integration.
- Led requirement gathering, design, and UAT support, collaborating with cross-functional teams to validate application access, streamline onboarding, and accelerate time-to-production by 30%.
Identity and Access Management V2
ARCHITECTURED & IMPLEMENTED
- Evaluated multiple cloud authentication platforms (Auth0, Okta, Keycloak) and recommended Okta as the strategic IAM solution, aligning with scalability, security, and enterprise governance requirements.
- Developed REST APIs leveraging Okta Management APIs to automate creation of SAML/OIDC identity providers, password policies, MFA policies, users, and groups, reducing manual configuration effort by 40%.
- Led cross-functional team of backend, frontend, and QA engineers, driving feature design, authentication flow development, and regression bug resolution; improved delivery velocity by 25%.
- Migrated users and authentication configurations from legacy clusters to Okta, ensuring seamless transition with minimal downtime and strengthening IAM reliability.
- Authored detailed design documents, user stories, and runbooks, enabling reproducible deployments and effective knowledge transfer to client teams.
Robot Certificate Management Agent & IAM Configurations
ARCHITECTURED & IMPLEMENTED
- Developed and deployed the Robot Certificate Management Agent (RCMA) using Java, Spring Boot, and REST services, automating daily certificate validation and renewal via Certificate Web Service (CWS), reducing manual intervention by 90%.
- Implemented third-party IAM integration with CAS, enabling seamless redirection to customer IdPs via SAML-based authentication flows, strengthening security and ensuring compliance with enterprise identity standards.
- Optimized authentication and authorization configurations with Spring Security and PLSQL, improving login success rates and reducing authentication errors by 25%.
- Led end-to-end module development including design documentation, code reviews, debugging, and UAT support; resolved client-reported issues within SLA, improving customer satisfaction scores.
- Delivered performance tuning and regression fixes, enhancing system reliability and reducing certificate renewal failures by 30% across robotic fleets.
SailPoint CI/CD Integration
IMPLEMENTED
- Implemented CI/CD pipelines for SailPoint IdentityIQ artifacts using GitHub, Jenkins, Ant scripts, JFrog, and Tomcat, enabling automated builds and deployments that reduced manual deployment effort by 40% and improved release consistency.