
Somasekhar Keerthi
Verified Expert in Engineering
Identity and Access Management (IAM) Developer
London, United Kingdom
Toptal member since October 2, 2024
Somasekhar, a dynamic leader with a visionary focus, is a seasoned professional with over 28 years of experience in the IT field, including 17 years specializing in implementing identity and access management (IAM) and privileged account management (PAM) solutions. He resolves complex challenges in information security, PAM, and IAM. Somasekhar is a creative problem solver with a proven ability to drive organizational growth.
Portfolio
Experience
- Identity & Access Management (IAM) - 17 years
- Active Directory (AD) - 10 years
- SailPoint IdentityIQ (IIQ) - 9 years
- IdentityIQ - 9 years
- CyberArk - 8 years
- Privileged Access Management (PAM) - 8 years
- AWS IAM - 2 years
- Microsoft Entra ID - 1 year
Availability
Preferred Environment
SailPoint IdentityIQ (IIQ), CyberArk, Privileged Access Management (PAM), Identity & Access Management (IAM), Active Directory (AD), Microsoft Entra ID, Windows PowerShell, BeanShell, SQL Server 2019, C#.NET
The most amazing...
...solution I've implemented uses SailPoint and CyberArk to solve certification and audit issues, meet compliance requirements, and protect privileged accounts.
Work Experience
IAM Architect | Solutions Engineer | Consultant | Developer
Wipro
- Presented architectural solutions to the review board, showcasing progress and seeking approvals. Selected tools for implementing IAM solutions as a key aspect of the responsibilities.
- Prepared high-level designs for SailPoint IdentityIQ (IIQ) and CyberArk to address IAM and PAM issues. Conducted remote workshops to understand existing legacy tools and developed a phased migration plan to SailPoint and CyberArk.
- Created a high-level design document, including architecture diagrams for three different environments with detailed hardware sizing. Collaborated with infrastructure teams to procure hardware on Linux and Windows platforms.
- Onboarded SAP HR, SAP Temp, BPO, and 25 3rd-party providers into SailPoint to build an identity warehouse. Integrated over 100 apps and scheduled certifications for managers and owners. Integrated ServiceNow for ticketing and access requests.
- Designed and implemented single sign-on (SSO) with Azure AD for SailPoint and integrated it with CyberArk for credential cycling. Established schemas for identity, account, entitlement, and certification based on best practices.
- Created segregation of duty policies to address audit issues by implementing detective and preventive controls in SailPoint. Introduced auditing in SailPoint to track access changes for Sarbanes-Oxley Act (SOX) compliant applications.
- Prepared high- and low-level design documents to ensure smooth implementation of the CyberArk on-premise solution, including the Vault, Password Vault Web Access (PVWA), CPM, and Privileged Session Manager (PSM) and a disaster recovery (DR) solution.
- Evaluated the DR failover and fallback processes, scheduling incremental and full backups for vault data. Designed safe and platform naming standards to streamline operations and onboarded Windows, Linux, and AIX platform accounts.
- Integrated ServiceNow ticketing system, forcing users to input ticket numbers before accessing privileged accounts, integrated the ELK tool as a security information and event management (SIEM) solution to monitor user activity logs.
- Upgraded CyberArk from 11 to 12 version. Presented CyberArk Privilege Cloud solution to the architectural review board and migrated on-premise solution to Privilege Cloud.
Senior Software Developer | Delivery Manager
Allstate Northern Ireland
- Translated business requirements into technical specifications and developed solutions using mainframe technologies. Guided the development team in delivering solutions following the software development lifecycle (SDLC).
- Provided leadership and technical expertise while ensuring system reliability and business satisfaction. Fostered strong relationships with the business by swiftly responding to user queries and offering effective solutions to their issues.
- Deployed a C# web application for team managers to generate in-house invoices and provided ongoing support post-deployment, addressing any issues. Enhanced a web application for access requests and onboarded Oracle and SQL databases.
- Developed specialized tools using .NET technologies for access control administration teams, enabling them to handle user administration tasks on Unix and mainframe systems.
- Built comprehensive security applications for Unix, mainframe, and SAP systems, leveraging a SQL Server back end to manage the access request approval process. Integrated them with Active Directory (AD) to streamline the manager approval workflow.
- Developed re-verification applications to facilitate the recertification process for various AD security groups, privileged access security groups, and mainframe security profiles, ensuring compliance and proper oversight by their respective owners.
- Guided various application teams in integrating their systems with AD to implement role-based access control (RBAC), emphasizing the principle of least privilege to enhance the organization's security posture.
- Integrated SAP HR suite to streamline on- and offboarding processes for employees and contingent workers using SailPoint IIQ. Onboarded AD, Resource Access Control Facility (RACF), and CSV-delimited apps for access requests and certification.
- Collaborated with crown jewel application owners to integrate provisioning and de-provisioning of application entitlements with SailPoint. Established a quarterly recertification process to enhance security governance.
- Developed policies and programs to enhance security management. Executed the PAM strategy, implementing solutions to manage privileged accounts efficiently.
Experience
Y2K Compliance and Finance Systems' Enhancement
In this role, I delivered all applications on schedule while maintaining high quality and successfully implemented the Y2K compliance code into the production environment. Alongside compliance work, I proposed and implemented improvements to existing functionalities, enhancing overall system performance. I independently supported four finance applications and monitored night-time batch production jobs from an offshore center. I also troubleshot and resolved issues within the agreed service level agreements (SLAs).
IAM Application Development and System Enhancements
I also built a recertification application to certify AD security groups, ensuring compliance and security integrity across the organization. Throughout the project, I managed all provisioning systems, continuously enhancing them with new functionalities. This involved migrating the existing codebase into a newer version of Visual Studio and rewriting the code to improve performance and system efficiency.
As part of the superuser management process, I maintained the super-user process documentation and scheduled SSIS jobs in SQL Server to load feeds from mainframe, AS/400, Unix, and Windows platforms. I also facilitated the weekly recertification process and led and facilitated the quarterly recertification process for superuser accounts.
SailPoint IAM Solution Implementation and Legacy System Transformation
As part of this project, I created high-level designs to implement IIQ in three different environments and conducted remote workshops to understand the existing Aveksa and the current functionality and identify gaps in the current system. I deployed the SailPoint application across different environments, built an Identity warehouse using multiple HR sources, and deployed JML workflows to handle on- and offboarding activities to meet compliance requirements correctly.
Additionally, I onboarded 100 applications, ensuring that each application adhered to the established identity governance policies. I also established various application connectors to integrate SailPoint with important systems, including AD, ServiceNow, REST API, Azure AD, SQL Server, CyberArk (utilizing SCIM 2.0), RACF, and ACF2.
Implementation of CyberArk PAM Solution
To facilitate the implementation, I prepared comprehensive high- and low-level design documents and deployed CyberArk PAM solution with Vault, PVWA, Central Policy Manager (CPM), PSM, and a DR solution. As part of the project, I evaluated the DR failover and fallback processes and scheduled incremental and full backups for vault data to ensure data integrity and availability. Safe naming and platform naming standards were designed for consistency and clarity in the environment.
I onboarded accounts across Windows, Linux, and AIX platforms to ensure comprehensive coverage of all use cases. Additionally, I integrated the ServiceNow ticketing system to enforce ticket number entries for accessing privileged accounts and the SIEM solution to monitor user activity logs for compliance and security oversight.
CyberArk SaaS Implementation
High- and low-level design documents were created and submitted, ensuring a comprehensive understanding of the implementation requirements. A ticket was created in the CyberArk portal to engage with CyberArk professional services, where the high-level architecture and requirements were reviewed in detail.
To facilitate the installation, we engaged with teams to provision domain-joined Windows connector servers. As part of the jump start program, we collaborated with the CyberArk professional services team to complete the implementation of the CyberArk solution.
Additionally, we integrated the ServiceNow ticketing tool to streamline access management processes. On-premise AD was installed as an identity connector for authentication. New servers that were migrated from the on-premise data center were onboarded into the CyberArk system.
Skills
Tools
AWS IAM, JCL, TELON, Visual SourceSafe, TFS, GitHub
Frameworks
Windows PowerShell
Languages
BeanShell, C#.NET, Java 8, CICS, Easytrieve Plus, SQL
Paradigms
Management
Platforms
Eclipse, Windows Server 2019, Linux, Windows Server 2016, Windows Server 2022
Storage
Microsoft Entra ID, SQL Server 2019, IBM Mainframe, Virtual Storage Access Method (VSAM), IMS DB, IBM Db2, IIS SQL Server, SQL Server Data Tools (SSDT)
Other
SailPoint IdentityIQ (IIQ), Identity & Access Management (IAM), Active Directory (AD), IdentityIQ, CyberArk, Privileged Access Management (PAM), COBOL Batch, COBOL Online, ServiceNow, IT Consulting, IT Project Management, Architecture, Consulting, SQL Server 2015
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring