Skip to content
About Rivitan

Senior identity expertise, without the overhead

One accountable architect, 14+ years of Fortune 500 experience, and a focus on outcomes that hold up under audit.

The story

Why Rivitan exists

Rivitan exists for a simple reason: most enterprises are running identity infrastructure that grew organically over a decade or more — and it shows. Duplicate accounts, over-privileged admins, fragile federation, and access nobody can fully account for.

Over 14+ years working inside Fortune 500 environments, I have seen the same patterns repeat across retail, finance, healthcare, and manufacturing. The good news is that they are solvable with the right architecture, a disciplined approach, and a focus on outcomes that hold up under scrutiny.

I started Rivitan to give organizations access to that senior, hands-on expertise directly — without the overhead, hand-offs, and junior staffing of a large firm. When you engage Rivitan, you work with the architect who does the work.

“When you engage Rivitan, you work with the architect who does the work — not a rotating cast of juniors.”

Currently booking new engagements

I'm a hands-on identity architect — not a sales team and not a content mill. If you reach out, you talk to the person who will actually do the work.

Every diagram, article, and recommendation on this site comes from real engagements inside large, messy, real-world environments. It was written and built by hand, deliberately.

Rivitan

Founder & Principal Consultant · Dallas–Fort Worth, TX

Connect on LinkedIn
Certifications

Credentials that back the work

SC-300

Microsoft Identity & Access Administrator

Azure

Microsoft Certified

AWS

Amazon Web Services Certified

SC-100

Microsoft Cybersecurity Architect

Industries

Trusted across regulated industries

Experience spanning the sectors where identity, compliance, and uptime carry the highest stakes.

Financial Services
Healthcare
Retail & E-commerce
Manufacturing
Higher Education
Technology & SaaS
Logistics
Public Sector
Platforms

Microsoft-deep, multi-vendor capable

Microsoft identity is the core specialty — but real environments are rarely single-vendor. Engagements routinely span directories, cloud IAM, governance, and privileged access tools.

Directories & IdPs

  • Microsoft Entra ID
  • Active Directory
  • Okta
  • Ping Identity
  • Google Workspace

Cloud IAM

  • AWS IAM & IAM Identity Center
  • Azure RBAC
  • GCP IAM

Governance (IGA)

  • Entra ID Governance
  • ConductorOne
  • SailPoint
  • Saviynt

Privileged Access (PAM)

  • Entra PIM
  • CyberArk
  • BeyondTrust

Automation & standards

  • Microsoft Graph
  • PowerShell
  • SCIM
  • SAML / OIDC
  • Terraform
How I work

Principles behind every engagement

Outcomes over jargon

Security work only matters if it reduces real risk and survives an audit. Every engagement is measured by outcomes a CISO can defend, not buzzwords.

Leave teams stronger

Good consulting transfers knowledge. Documentation, runbooks, and training mean your team owns the result long after the engagement ends.

Senior, hands-on, accountable

You work directly with the architect doing the work — not a rotating cast of juniors. One accountable point of contact from first call to handoff.

Security without disruption

Phased rollouts, pilot groups, and documented rollback plans mean we improve your posture without breaking what your business depends on.

Experience

14+ years in enterprise identity

2010 – 2014

Active Directory Engineer

Cut teeth running large multi-domain Active Directory environments — replication, Group Policy, and the unglamorous work of keeping the directory healthy at scale.

2014 – 2018

Identity & Security Architect

Led federation and single sign-on programs across Fortune 500 environments, designing ADFS, SAML, and the early hybrid bridges between on-prem and the cloud.

2018 – 2022

Cloud Identity Lead

Owned enterprise Entra ID (Azure AD) adoption: Conditional Access, MFA and passwordless rollouts, and large-scale migrations off legacy federation.

2022 – Present

Founder & Principal Consultant, Rivitan

Independent identity consulting for enterprises that need senior expertise without the overhead of a large firm — hands-on architecture, governance, and automation.

Notes from the field

Short, honest takes from real work

Not polished articles — just things I keep running into on engagements, written as they come up.

The 'temporary' admin account is never temporary

Found a Domain Admin created 'just for the migration' in 2019. It still had a password from then. Standing privilege is debt — it compounds quietly until someone finds it. Usually a pen tester. Sometimes worse.

Start Conditional Access in report-only

Every painful CA rollout I've cleaned up skipped report-only mode. A week of watching the sign-in logs tells you exactly which policy will lock out the CFO at 7am. Patience here is cheaper than an outage.

I still sketch the architecture by hand first

Before any diagram tool, I draw the identity flow on paper. If I can't explain it in a napkin sketch, the design is too complicated — and the client's team won't be able to run it after I'm gone.

ADFS isn't evil — it's just finished

It was the right call a decade ago. The problem isn't the technology, it's that it became a forgotten internet-facing server nobody patches. Most migrations off it are easier than teams fear once you map the relying parties.

Ready to secure your identity foundation?

Book a free 30-minute discovery call. We'll talk through your environment and where the biggest wins are — no obligation.

Book a Call