
Deepan Udaiyar
Verified Expert in Engineering
System Administrator and Developer
Vancouver, BC, Canada
Toptal member since September 22, 2023
Deepan's view is that you cannot define a problem you cannot see. Most identity estates he inherits have been accumulating for a decade, so he clears the ground first, not for tidiness but for visibility. What's left is smaller and simpler than expected. He has 10 years in identity, from a helpdesk to owning the architecture—Okta and Microsoft Entra ID, phishing-resistant authentication, device trust, SAML and SCIM lifecycle provisioning, and automation in Okta Workflows, Python, and PowerShell.
Portfolio
Experience
- IT Security - 10 years
- Security Assertion Markup Language (SAML) - 7 years
- Identity and Access Management - 7 years
- SCIM - 7 years
- Okta - 7 years
- Multi-factor Authentication (MFA) - 5 years
- Mobile Device Management (MDM) - 5 years
- Microsoft Entra ID - 4 years
Preferred Environment
Okta, Bash Script, Python 3, Microsoft Entra ID
The most amazing...
...thing I've done was design an authentication model where sign-in friction falls as attested device trust rises, so the secure path is also the fastest.
Work Experience
Principal Consultant, Identity & Access Management
MU Tech Inc.
- Ran Okta health assessments and delivered phishing-resistant baselines for clients: passwordless authentication, session policy design, and removal of password-only sign-in paths. Most rollouts leave recovery phishable; these did not.
- Implemented SCIM lifecycle provisioning with an HRIS as the identity source of record, using import safeguards, dry-run validation, and staged cutovers so a bad upstream record could not cascade into production access.
- Designed contractor and third-party access models with dedicated authentication and session policies, and built joiner and leaver automation in Okta Workflows and n8n for applications that could not support SCIM.
- Hardened Microsoft Entra ID tenants with Conditional Access, Privileged Identity Management for administrative roles, administrative account separation, and Intune device baselines.
IT Systems & Integration Engineer
EarthDaily Analytics
- Owned the identity architecture for a satellite-imaging company, covering authentication policy, lifecycle provisioning, and device trust across a dual-IdP estate of Okta and Microsoft Entra ID.
- Led a phishing-resistant authentication program across the organization, designing the policy model in which sign-in friction scales inversely with attested device trust.
- Led an end-to-end Active Directory decoupling and decommission for several hundred users in two months with no cutover downtime, using an Okta Workflows self-service conversion.
- Merged two Okta tenants following an acquisition, migrating several dozen application integrations and their supporting group model within a month.
- Consolidated multiple Atlassian instances in-house rather than through a six-figure vendor engagement, and built cross-tenant mailbox and SharePoint migration tooling from open-source components.
- Standardized SSO and SCIM lifecycle provisioning across the SaaS estate, with the HRIS as the identity system of record, so joiner, mover, and leaver events flowed from a single source.
Enterprise Identity Analyst (Contract)
ATB Financial (via Raise Recruiting)
- Contributed to an enterprise role-based access control program, defining role-to-entitlement mappings with business owners and the identity and application security function.
- Replaced a per-application ServiceNow request-form model with a single metadata-driven request form, so onboarding a new application became a configuration entry rather than a development task.
- Automated directory group provisioning directly from approved requests, removing over 100 hours of manual group assignment.
- Built a single intake path for applications that could not be provisioned automatically, so request handling stayed uniform regardless of downstream capability.
- Delivered the redesign in under two months, holding technical oversight, stakeholder engagement, and implementation direction.
Senior Consultant, Delivery
T-Mobile (via TechDemocracy)
- Supported and advised on a 10,000+ user enterprise Okta tenant spanning hundreds of application integrations.
- Resolved cross-tenant provisioning failures, multi-factor authentication faults, and SAML sign-in issues across that tenant.
- Advised on Okta application assignment strategy, profile optimization, and Microsoft Entra ID integration for large-scale application management.
- Governed service principals and privileged accounts across Microsoft Azure and Okta, keeping non-human identity inside the same review cycle as people.
IT Support Specialist
Dialpad
- Integrated business-critical SaaS applications with Okta for single sign-on, and automated application assignment through attribute-based group rules.
- Proposed and implemented HRIS attribute sourcing into Okta and downstream to connected SaaS platforms, making the HR record the origin of identity data rather than a copy of it.
- Automated joiner and leaver processing in Google Workspace through Okta Workflows and the Okta API, including account archiving and deletion.
- Owned identity integration during an acquisition, engineering a scripted onboarding pipeline that provisioned the acquired team with no manual intervention.
- Administered Jamf Pro: configuration profiles, smart groups, scoped app deployment, DEP and VPP, certificate and network payloads, OS update policies, and automation scripts.
System Support Specialist
Peak Products
- Selected and deployed a low-cost MDM platform for full lifecycle management of mobile assets, using Apple Business Manager and Apple Configurator for zero-touch enrollment.
- Removed 90% of the manual workload from routine helpdesk operations by designing and implementing custom PowerShell automation.
- Imaged and hardened company laptops through SCCM, applying a standard security policy baseline at build time rather than after deployment.
IT Support Analyst
Sleep Country Canada
- Administered 600+ Wyse thin clients via PowerShell and batch scripts across 250 retail stores and 16 warehouses nationally.
- Automated vendor file transfers using the MoveIT software solution, improving processing time by 35%.
- Reduced Level 2 helpdesk volume by 20% through root-cause analysis of systemic problems across the retail estate.
Technical Support Analyst
IBM
- Administered Active Directory user accounts for IBM enterprise clients, including Scotiabank and Irving Oil, working to the access and change-control standards of a regulated Canadian bank.
- Handled escalations across those accounts, prioritizing work by impact and severity for high-profile enterprise clients.
- Developed batch and VBScript automation that streamlined workflow applications and improved helpdesk turnaround by 5%.
Experience
Phishing-resistant Authentication Program - Okta FastPass
This program was built from the opposite end. Recovery and enrollment were designed first, and the authentication policy followed a single principle: friction should scale inversely with attested device trust. A device the organization can vouch for signs in with one hardware-protected factor and gets on with its day. A device that it cannot vouch for has to prove more. Trust is asserted by the device management platform rather than by the endpoint itself, which is the difference between a signal and a claim.
The work covered authentication policy across every sign-in surface, an enrollment route for populations that cannot hold a standard authenticator, and administrative access treated as its own tier rather than an extension of ordinary access.
Active Directory Decoupling & Decommission - Zero-downtime Migration to Cloud Identity
https://github.com/deepanudaiyar/OktaJoiner and Leaver Automation - Bash and Python Provisioning Pipeline
https://github.com/deepanudaiyar/IT-AutomationThis is a Bash and Python pipeline that runs the whole sequence across Google Workspace, Okta, Jamf, and BambooHR in a single pass. It turns half an hour of manual work into about five minutes, and makes a batch of fifty users no harder to process than one. The time saved matters less than the two properties that come with it: the run is identical every time, and it leaves an auditable trail of what was created, changed, and removed. Published as an open repository.
Education
Course in Programming with Python
Langara College - Vancouver, BC, Canada
Post-secondary Diploma in Computer Systems Networking and Telecommunications
Centennial College - Toronto, ON, Canada
Certifications
HashiCorp Certified: Terraform Associate
HashiCorp
AWS Certified Cloud Practitioner
Amazon Web Services Training and Certification
Okta Certified Professional
Okta
Okta Certified Administrator
Okta
Okta Certified Consultant
Okta
Apple Certified Support Professional 11
Apple
Skills
Libraries/APIs
Pandas
Tools
Microsoft Intune, Google Workspace, Slack, GitHub, Jamf Pro, Terraform, Atlassian Suite, n8n
Frameworks
OAuth 2
Industry Expertise
Cybersecurity
Languages
Python 3, Bash, Bash Script
Paradigms
Role-based Access Control (RBAC), ABAC
Platforms
Linux, Azure, AWS IoT, Android, MacOS, Windows, Hexnode
Storage
Microsoft Entra ID
Other
Okta, IT Support, Single Sign-on (SSO), IT Administration, Apple Business Manager, Apple DEP, Mobile Device Management (MDM), Device Trust, OpenID Connect (OIDC), Microsoft Conditional Access, Zero Trust, Endpoint Security, IT Security, Security, Technical Leadership, Microsoft Graph API, APIs, IT Networking, IT Automation, Jamf, Kandji, Microsoft Entra, Integration, HR Integration, Migration, Active Directory (AD), MDM, PowerShell, Security Assertion Markup Language (SAML), SCIM, Multi-factor Authentication (MFA), Identity and Access Management, ServiceNow, Privileged Access Management (PAM), HRIS, Passwordless Authentication, Compliance, Microsoft Purview
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring