Cybersecurity Strategy · Identity & Access Management · Risk & Compliance · Cloud Security Architecture · Security Operations · AI Governance
Accomplished cybersecurity executive and Microsoft Certified Expert with deep expertise in security strategy, identity and access management, risk governance, and cloud security architecture. Proven track record of designing and implementing enterprise security programs for Fortune 500 companies, financial institutions, and government agencies. Adept at aligning security initiatives with business objectives, ensuring regulatory compliance across NIST, FFIEC, FISMA, and data privacy frameworks. Trusted advisor to C-suite leadership on cyber risk posture, digital transformation security, and AI governance. Microsoft 365 AI Platform Engineer with specialized expertise in securing Copilot, Copilot Studio, and Power Platform deployments at the enterprise level.
Microsoft Certified ExpertAzure Solutions Architect
FrameworksNIST · FFIEC · FISMA · FedRAMP
Cloud SecurityAzure · Microsoft 365 · Purview
Industries ServedFortune 500 · Financial · Government
Focus Areas
Cybersecurity Strategy
Identity & Access Management
Risk & Compliance
Cloud Security Architecture
Security Operations
AI Governance
Lead enterprise identity and access management strategy while engineering and governing a secure AI platform built on Microsoft 365 Copilot, Copilot Studio, and Power Platform.
- Architected and manage the full identity lifecycle — onboarding, offboarding, access reviews, and privilege management — ensuring least-privilege access across the enterprise.
- Designed and enforced Conditional Access, MFA, and SSO/SAML integration policies, reducing unauthorized access incidents and strengthening Zero Trust posture.
- Engineered enterprise AI governance framework covering Copilot Studio agents, generative AI responses, plugins, and Dataverse integrations with Entra ID identity controls.
- Established organization-wide AI security standards encompassing architecture, data boundaries, lifecycle management, compliance guardrails, and responsible AI practices.
- Led Microsoft 365 Copilot readiness at the tenant level, aligning configuration with Purview data governance, Power Platform security policies, and regulatory requirements.
- Created reference architectures, reusable security templates, and compliance controls to accelerate secure AI adoption across business units.
Drive new business and revenue growth for Technology Consulting Group — building client relationships across Identity Governance, Dynamics CRM Sales, Microsoft Power Platform, Copilot AI, Identities Monitoring, and Resource Monitoring practice areas.
- Identify new business opportunities by conducting market research to surface potential clients and growth avenues.
- Build and maintain relationships, establishing and nurturing connections with potential and existing clients to ensure long-term business growth.
- Drive strategic planning, developing and implementing growth strategies that align with the company's goals.
- Negotiate and close deals, presenting the company's offerings compellingly and securing new business.
- Collaborate with teams, working closely with sales, marketing, and product development to ensure alignment and achieve business objectives.
- Monitor market trends, staying current on industry developments and competitor activity to inform strategic decisions.
- Train and mentor junior salespeople and team members to improve their skills and meet sales goals.
Served as a Cyber & Strategic Risk Advisor across four Deloitte engagements — spanning greenfield workforce IAM, managed security service architecture, international data localization, and financial-services regulatory compliance.
IAM Solutions Architect
November 2022 – October 2023
Client: Boeing Employees Credit Union (BECU)
Led the design and deployment of a greenfield workforce identity and access management (WIAM) solution supporting the client's digital transformation and security modernization.
- Designed scalable, secure Azure Active Directory architecture for a greenfield tenant, establishing foundational IAM infrastructure for the enterprise.
- Configured Privileged Identity Management (PIM) to govern elevated role assignments, enforcing just-in-time access and approval workflows for sensitive resources.
- Implemented Entitlement Management with access packages for both internal users and external B2B collaboration partners, creating automated lifecycle governance.
- Developed comprehensive IAM design documentation including target-state configuration, onboarding workflows, and design consideration guides for stakeholder alignment.
- Engineered a B2B collaboration framework through Azure External Identities, enabling secure partner and vendor access with appropriate boundary controls.
Security Architecture Lead
January 2022 – August 2022
Internal: Managed Security Service Provider (MSSP)
Architected a managed cybersecurity service for Azure integrating native security capabilities with DevSecOps automation.
- Designed macro and micro security architectures for Azure-native managed security services, delivering end-to-end infrastructure blueprints.
- Developed IAM use cases for ServiceNow integration, runbooks, configuration guides, and standard operating procedures for security operations.
- Built baseline and custom Azure IAM policies ensuring compliance controls verification across the managed security platform.
- Engineered security logging and monitoring infrastructure using Azure Monitor and Log Analytics Workspace for real-time threat visibility.
- Delivered comprehensive security documentation including flow diagrams, component dependencies, and compliance controls mapping.
Data Security & Compliance
December 2021 – January 2022
Client: Mastercard — Data Localization for India
Led data risk control verification and compliance for international data localization requirements, ensuring data sovereignty and regulatory adherence.
- Verified compliance controls across access control policy, privileged access, DAM, logging, monitoring, geo-location, encryption, DLP, and backup/DR.
- Delivered security controls for the Security Audit Report (SAR) covering data localization policy measures restricting cross-border data flows.
- Assessed network security, SDLC, change management, and incident management controls ensuring end-to-end data risk governance.
Regulatory Compliance
March 2021 – October 2021
Client: USAA — Cybersecurity Compliance
Developed remediation strategies following comprehensive gap assessments to ensure regulatory compliance within the financial services industry.
- Prepared executive summaries with remediation recommendations mapped to FFIEC CAT statements and aligned with the NIST 800-53 controls framework.
- Researched and analyzed red-level tasks to determine appropriate control mappings, developing and updating security controls and governing procedures.
- Conducted walkthrough sessions with operational managers to validate control design effectiveness and documented findings in the governance tool.
- Coordinated CyberArk PSM & EPM proof-of-concept activities, evaluating privileged access management solutions for enterprise deployment.
Designed and implemented secure Azure cloud solutions, evaluating and integrating new technologies with security-first architecture principles.
- Managed Active Directory Identity Protection and Conditional Access policies, conducting regular access reviews for group membership governance.
- Architected Azure network security with virtual networks, subnets, NSGs, application security groups, and service tags for defense-in-depth.
- Implemented recovery service vaults for backup and disaster recovery, ensuring business continuity across cloud workloads.
- Leveraged Azure Advisor to optimize security posture alongside cost, reliability, operational, and performance benchmarks.
Developed security and privacy controls aligned with the NIST Cybersecurity Framework in compliance with FISMA, advising organizations on information security and risk management.
- Delivered NIST gap analyses and facilitated executive roadmap workshops, producing prioritized cybersecurity improvement roadmaps.
- Developed security policies, procedures, and processes using NIST 800-53, conducting compliance workshops and validating framework worksheets.
- Led business process reengineering initiatives to embed security controls into organizational workflows and operational practices.
- Consulted on architecting secure Azure solutions for clients, ensuring cloud deployments met security and compliance requirements.
Security Strategy & Governance
- Security Program Development
- Policy & Standards Frameworks
- Board-Level Risk Reporting
- Security Roadmap & Vision
- Vendor Risk Management
Identity & Access Management
- Entra ID / Azure AD
- Conditional Access & MFA
- Privileged Identity Mgmt (PIM)
- SSO / SAML Federation
- Identity Governance & Lifecycle
Risk & Compliance
- NIST 800-53 / CSF
- FFIEC CAT
- FISMA / FedRAMP
- Data Localization & Privacy
- Security Audit & Reporting
Cloud Security
- Microsoft Azure Security
- Microsoft 365 & Purview
- Azure Sentinel / Log Analytics
- Network Security Groups
- Disaster Recovery & BCP
AI Security & Governance
- Microsoft 365 Copilot
- Copilot Studio & Power Platform
- Responsible AI Practices
- AI Agent Governance
- Data Boundary Controls
Leadership
- Executive Advisory & Briefings
- Cross-Functional Team Leadership
- Digital Transformation
- Security Awareness Programs
- Incident Response Planning
Education
B.S. Information Technology
Computer Security
Capella University
Summa Cum Laude · 2016
A.A. Information Systems
Computer Security
Strayer University
Magna Cum Laude · 2012
Certifications
- Microsoft Certified: Azure Solutions Architect, Expert
- Microsoft Certified: Identity & Access Administrator Associate
- Microsoft Certified: M365 Associate
- Microsoft Certified: Security, Compliance & Identity Fundamentals
- Microsoft 365 Certified: Copilot and Agent Administration Fundamentals
Applause Award — Deloitte
Award AmountXXXXXX
DateSeptember 12, 2023
Award Number1561237
Presented ByAnish Srivastava & Deepak Goyal
Chosen to receive an Applause Award in the amount of XXXXXX in recognition of dedication and a willingness to go the extra mile. Specifically recognized for excellent contribution and partnership towards defining, building, and launching the technical foundation and enterprise capabilities for BECU's Member Identity and Access Management platform as part of the digital transformation journey. The successful go-live of MVP 1.1 is a testimony to hard work, dedication, and resiliency.
Recognition Letter — BECU
September 27, 2023
BECU — Cybersecurity, Customer Identity & Access Management
Recognized by BECU leadership for excellent teamwork and partnership in defining and building the technical foundation and enterprise capabilities for the new BECU Member Identity and Access Management platform. With this participation, BECU's first deployment as part of its digital transformation journey was successful and ahead of schedule. Contributions to the maturation of the Azure Active Directory environment enabled new functionality that improved the internal customer access experience and strengthened the security posture.
- Sean Murphy — SVP, Chief Information Security Officer
- Ciera Armstrong — Sr Product Owner, Cybersecurity CIAM
Recommendations
Jeff Benge
Cybersecurity Architect at BECU
Worked with Carl on the same team · November 5, 2023
Having had the privilege to work alongside Carl during a long-running consulting engagement, I can wholeheartedly attest to his remarkable skill and outstanding work ethic. In Azure Identity and Access Management, Carl showcased expertise that not only met but exceeded expectations. His development of a program for login account access reviews revolutionized the way we manage the lifecycle for group membership, making the process not just efficient but also more secure and a model for other parts of the organization.
Moreover, his strides in constructing the functionality for cross-tenant access served as a testament to his profound knowledge. But beyond his technical acumen, Carl is a beacon of positivity. In an environment where the workload and shifting priorities can become burdensome, Carl's buoyant personality and genuine enthusiasm had a way of lightening the mood of the entire team.
What stands out most, perhaps, is Carl's meticulousness when it came to documentation. In the fast-paced world of tech, comprehensive and clear documentation is invaluable. Carl consistently delivered in this aspect, ensuring that even the most intricate processes were documented clearly, allowing for seamless knowledge transfer, and understanding among team members.
Carl was truly a pleasure to work with and delivered results. Any team or organization would be fortunate to have such a skilled, positive, and dedicated individual as Carl. I have no doubt that he will continue to shine and make significant contributions wherever his career takes him.
Rahul Nair
Senior Manager at Deloitte | Cloud Cyber Risk
Managed Carl directly · October 31, 2023
Carl is hardworking, diligent and proactive in his approach. Carl goes above and beyond his assigned duties to ensure success of projects with attention to detail, high quality and timely delivery of outputs and tasks. He is not only able to take on complex tasks of his own, but also drive coordination among team members and leadership, taking ownership of the end-to-end project delivery to ensure the team's success. His work was greatly appreciated by Deloitte leaders and client alike, with applause awards as proof of his quality and commitment. Carl has a great impact on the teams he works with, keeping a positive team spirit alive and building meaningful relationships in spite of the remote-first culture. Through his contributions to DEI initiatives and volunteering, Carl gives back to the community and helps build them stronger and more inclusive.
Yogendra Naik
Cybersecurity AI Strategist @ Deloitte | AI Security Architect | Cyber Defense
Worked with Carl on the same team · October 28, 2023
As a colleague, I have had first hand experience working with Carl and seen his vast experience on understanding of complex cybersecurity challenges, and ability to develop innovative solutions. He has demonstrated a deep knowledge of access control, identity management, and the safeguarding of critical resources. Apart from technical proficiency, he is an outstanding collaborator and a great team player. Wishing him continued success in his career journey.
Alagarsamy Selva Arasu
Identity and Access Management Professional
Managed Carl directly · October 2, 2023
Carl was part of my team to set up greenfield tenants as part of technology modernization. Carl brings extensive knowledge of Azure Active Directory. His design proposals are highly appreciated by the client. He was the single point of contact for all Azure-related work to the client. Carl has been constantly receiving high remarks from customers for his quality deliveries. His documentation details are high quality in nature. Carl brings great energy to the team. He is a great team player.
Partho Sankar Roy
Specialist Leader (Senior Manager) at Deloitte | Ex-TCS | Ex-Capgemini
Worked with Carl on the same team · August 16, 2023
I am delighted to write this LinkedIn recommendation for Carl with whom I had the pleasure of collaborating on an IAM (Identity and Access Management) project. Working alongside Carl was an absolute pleasure, and his contributions to the project were invaluable.
Throughout our time together, Carl demonstrated exceptional expertise in IAM concepts and technologies. His thorough understanding of access control, authentication, and authorization mechanisms was evident in the seamless implementation and execution of our project's IAM framework.
What stood out most was Carl's ability to think critically and solve complex challenges with innovative solutions. His attention to detail and methodical approach ensured that every aspect of IAM was carefully addressed, resulting in a highly secure and efficient system.
Moreover, Carl proved to be an excellent team player and communicator. He actively engaged with all team members, fostering a collaborative atmosphere and encouraging open discussions. Carl's willingness to lend a helping hand and support colleagues in overcoming obstacles made a significant difference in our project's success.
Aside from his technical prowess, Carl also demonstrated strong leadership skills. He took ownership of critical tasks and guided the team through difficult decisions, always keeping the project's objectives at the forefront.
I wholeheartedly recommend Carl for any IAM-related endeavor. His expertise, professionalism, and dedication are commendable qualities that make him an asset to any team. It would be a privilege to work with him again in the future. — PSR
Ciera Armstrong
Cybersecurity CIAM at BECU
Senior to Carl, not a direct manager · August 12, 2023
Carl joined my team to support us standing up new Azure Active Directory functionality as a part of our digital transformation and technology modernization. He was a joy to work with and brings great energy to the team. He is enthusiastic about delivering high quality work and robust documentation to benefit his customers. Carl brings an extensive Azure Active Directory knowledge and is structured in his approach to advising and implementing valuable functionality.
Brian Bybee
Staff Engineer - Cybersecurity IAM @ BECU
Worked with Carl, at different companies · August 2, 2023
I had the pleasure of working directly with Carl for a long running consulting engagement and would not hesitate to recommend him. His contributions at a technical level in Identity Governance, the thorough documentation of that product, and his diligence as a go-to resource in our Group was of high value. Furthermore, Carl's ability to gain rapport and exercise his personal style to nurture team building and collaboration is deserving of recognition. I look forward to the opportunity to work directly as a trusted peer in the future.
Grant Beck
Agile Coach In-Service
Worked with Carl on the same team · July 28, 2023
I had the pleasure of working with Carl on a team where he served as Cyber Security Risk advisor and developer. Carl excels in his chosen field, and was a great technical asset to the team on which he served. However, of greater value to me as an Agile Coach, was the enthusiasm, humor, and good nature he consistently exhibited within the team. His ability to show up every day with humility and grace helped the whole team relax and achieve a sense of psychological safety, enabling better conversations, better productivity and more trust. What he contributes to a team goes well beyond his technical expertise. I greatly enjoyed working with Carl and would welcome the opportunity to do so again.
Vinay Govindam
Manager & Lead IAM Architect | Crafting Secure, Future-Proof Digital Identity Solutions
Worked with Carl on the same team · July 24, 2023
Carl is an amazing teammate, who brings in positive energy to the table no matter the situation is and one of the great colleagues to work with. His Azure deep expertise helped our client design and configure solutions on a complex environment. Carl's involvement helped meticulously to deliver a successful project. I highly recommend him for any Azure projects and would love to have him on the team again.
Managers & Reference Contacts
Rahul Nair
Senior Manager, Deloitte — Cloud Cyber Risk
Served as Carl's coach and direct manager on two Azure Identity & Access Management projects, with visibility into the full scope of his project work.
Glenn Schneck Jr.
Former Sr. Manager, Azure Identity & Access Management
Led the Azure Identity & Access Management practice during Carl's tenure at Deloitte; now leads Microsoft Dynamics 365.