About
Senior Platform Engineering and Identity leader with extensive experience designing, securing and operating complex enterprise Microsoft environments.
I combine hands-on technical expertise with engineering leadership across Microsoft Entra ID, Identity & Access Management (IAM), Active Directory, Azure, Intune, Microsoft 365, Privileged Identity Management (PIM), Conditional Access, endpoint management and infrastructure security.
I have a strong track record of leading geographically distributed engineering teams, modernising enterprise platforms, strengthening identity and security controls, improving operational resilience and reducing technical debt through automation, standardisation and effective governance.
My approach combines technical depth with pragmatic leadership. I am comfortable moving between architecture and engineering discussions, major transformation programmes, operational challenges, cyber risk and senior stakeholder engagement.
I am particularly interested in senior Platform Engineering, Identity/IAM, Cloud Infrastructure and Microsoft technology roles where I can lead teams, shape technical strategy and remain close to the technology.
I am seeking a **100% remote role**, either as a technical leader or in a senior Principal/Architect-level position.
What I'm looking for
I'm looking for a fully remote senior role in Platform Engineering, IAM/Identity, Cloud Infrastructure or Modern Workplace.
I bring strong leadership and hands-on expertise across Microsoft Entra ID, Active Directory, Azure, Intune, Microsoft 365, PIM, Conditional Access, automation and security. Open to Platform Engineering Manager, IAM/Identity Lead, Entra Architect, Cloud Platform Lead or senior hands-on roles. Fully remote only.
Experience
Senior Platform Engineer / Platform Engineering Manager
Intertek Group plc
Aug 2021 – Present
End-to-end ownership of global identity and endpoint management platforms serving a multinational workforce across 170+ countries. Strategic and operational lead for Active Directory, Entra ID, ADFS, WSUS, SCCM/MEM, Intune, and Azure Arc, with accountability for platform resilience, security compliance, and service continuity.
Lead and develop a team of nine engineers across Identity and Endpoint towers, covering AD/Entra ID and SCCM/Intune disciplines, supported by a Platform Supervisor.
Define architecture, strategy, and operating models for all identity and endpoint platforms; drive modernisation aligned to business and security priorities.
Close partner to the cybersecurity function on risk reduction, identity security controls, Conditional Access, MFA (Duo), and regulatory compliance (ISO 27001, SOC 2).
Delivered measurable improvements to patch compliance, incident recovery times, and audit outcomes through disciplined operating models and automation.
Built internal tooling including automated health dashboards, PowerShell-based collection and reporting scripts, and a browser-based M365/Entra backup and recovery tool (TenantVault).
Active DirectoryPowerShellAzure Arc
Active Directory Subject Matter Expert (Contract)
Atos (Willis Towers Watson IAM Transformation)
Jun 2021 – Aug 2021
SME engagement supporting a large-scale IAM transformation programme for Willis Towers Watson, providing specialist Active Directory consultancy and technical assurance.
Active DirectoryIAMTechnical Assurance
Migration Engineer (Contract)
PWC
Jan 2021 – Jun 2021
Contracted to support PwC's global Active Directory upgrade, planning and executing migrations of resources from multiple EMEA-region forests into a purpose-built Windows Server 2016 Active Directory environment.
Active DirectoryWindows Server 2016Migration
Technical Consultant: Enterprise Platform & Workplace (Contract)
Comms-care
Oct 2020 – Jan 2021
Lead consultant for a secure Active Directory design and greenfield implementation using Windows Server 2019.
Delivered BitLocker endpoint encryption, Veeam, WSUS, WatchGuard MFA, Certificate Services, and DFS Namespace/Replication alongside technical and managerial workshops.
Active DirectoryWindows Server 2019BitLocker
IDAM Analyst (Contract)
Brewin Dolphin
Apr 2020 – Oct 2020
Upgraded Quest Active Roles Server and developed import scripts for Quest One Identity Manager within a financial services environment.
Quest Active Roles ServerIDAM
Active Directory Security Engineer (Contract)
Sky Betting & Gaming
Dec 2018 – Apr 2020
Embedded within the InfoSec / Security Engineering function to deliver Active Directory security hardening and SOX compliance initiatives, working across a high-availability betting and gaming environment.
Active DirectorySecurity HardeningSOX Compliance
Lead System Engineer (Contract)
United Utilities
Jun 2016 – Dec 2018
Third-line consultancy and technical leadership across Wintel, Active Directory, and messaging platforms for a critical national infrastructure organisation. Key deliveries included:
Windows Server 2008 R2 Active Directory upgrade (technical lead on critical domain).
Active Directory transformation: new OU hierarchy design and roles-based access control using Quest ActiveRoles Server.
Server hardening Group Policy remediation; Exchange 2016 upgrade; DSRM password automation.
Bespoke PowerShell tooling: sensitive group alerting, account/password auditing, and automated AD health reporting.
Active DirectoryPowerShellExchange 2016
Active Directory & Messaging Specialist (Contract)
Hiscox
Jan 2014 – May 2016
Senior specialist providing third-line support and project consultancy across multiple Windows Server 2008 R2 global AD forests, ADAM/LDAP, Exchange 2010, and McAfee ePO.
Delivered AD CS migration to 2012 R2, DFS migration, AGPM implementation, Quest OneIM enhancements, and automated PowerShell AD health check tooling.
Active DirectoryExchange 2010PowerShell
Active Directory Consultant / Technical Project Manager (Contract)
King's College London
May 2011 – Sep 2011
Project manager and architect on the consolidation of seven disparate Windows Active Directory forests into a single 52,000+ user environment at one of the UK's leading research universities.
Active DirectoryProject ManagementArchitecture
Active Directory Technical Design Authority (Contract)
Capgemini
Dec 2010 – May 2011
Designed and built three separate multi-domain Active Directory forests for a leading UK internet business, ensuring compliance with rigorous PCI-DSS requirements.
Active DirectoryPCI-DSSMulti-domain Design
Directory Services Technical Authority
Norwich Union Insurance / Aviva / Hewlett-Packard
May 2004 – Aug 2010
Over six years as technical lead for all directory services (Active Directory, Novell NDS, LDAP) within one of the UK's largest insurance groups, including transition to the Hewlett-Packard managed service.
Active DirectoryNovell NDSLDAP
Education
The Open University
BSc · Cyber Security
2022 – 2027
Certifications
ISC2 System Security Engineering Foundations Certificate (2 of 3)
ISC2
CompTIA Security+
CompTIA
Skills
IAMTechnical LeadershipMicrosoft AzureInfrastructure AutomationConditional AccessEndpoint ManagementPowerShellPIM/PAMMicrosoft 365Cloud SecuritySCCMMicrosoft IntuneActive DirectoryMIcrosoft Entra ID
Languages
English (Native or bilingual proficiency)