I design, automate, and secure identity platforms for enterprise, telco, and critical infrastructure environments.
My work sits at the intersection of IAM, PKI, PAM, Azure, and network reliability — with a validator mindset that prioritises operational truth, audit‑grade documentation, and clean, modular engineering.
- Azure AD / Entra ID architecture
- Hybrid identity (AD + AAD Connect + Cloud Sync)
- Conditional Access, PIM, RBAC, Zero Trust
- PKI (ADCS, Keyfactor, Venafi), certificate lifecycle automation
- PAM (CyberArk, BeyondTrust)
- MS Graph automation (Python + PowerShell)
- Terraform, Bicep, ARM for identity & security infrastructure
- Python automation for IAM, PKI, and cloud operations
- Terraform modules for identity, networking, and security baselines
- Bicep templates for Azure landing zones
- MS Graph + REST API integrations
- CI/CD pipelines for identity configuration and compliance
- Modular, testable, production‑grade engineering
Before specialising in IAM, I engineered and supported mission‑critical networks across:
- SDH/PDH, DWDM, OTN
- MPLS, microwave, fibre
- Multi‑vendor environments (Ericsson, Huawei, Nokia, Cisco)
- High‑pressure fault diagnosis and service restoration
- Preventative & corrective maintenance
- Operational reliability for telco and transport networks
This gives me a unique blend of identity + infrastructure thinking — ideal for organisations where uptime, safety, and security are non‑negotiable.
A modular, enterprise‑grade IAM automation repository featuring:
- Azure AD / Entra ID automation
- PKI lifecycle workflows
- PAM onboarding automation
- Terraform/Bicep identity modules
- MS Graph Python SDK examples
- Architecture diagrams & operational runbooks
Reusable Terraform modules for identity, security, and compliance.
A hands‑on PKI lab with ADCS, certificate automation, and security hardening.
- Build a complete IAM + PKI + PAM automation portfolio
- Complete SC‑300, AZ‑204, AZ‑800/801, SC‑100, Terraform Associate
- Target roles in:
- Sydney Trains (Technical Specialist – Transmission / Identity)
- Optus (Service Design & Delivery)
- BAI Communications (Critical Communications / IAM)
- LinkedIn: https://www.linkedin.com/in/isuruvh
- GitHub: https://github.com/Isuruvh


