Mehdi Rezaei
Strategic and forward-thinking leader with 14+ years of experience designing and modernizing enterprise-scale Identity & Access Management (IAM), Role-Based Access Control (RBAC), and directory services. Expert in architecting RBAC models, access governance frameworks, and least-privilege security policies across Azure (Entra ID), AWS IAM, and complex on-premises environments.
Identity architecture, end to end
I lead Zero Trust transformations, design enterprise-wide role hierarchies and separation-of-duties controls, and align hybrid identity infrastructures with SOX, ISO 27001, and SOC 2 compliance frameworks — bridging legacy infrastructure with modern, cloud-native IAM architectures.
14+
Years in enterprise identity
150K+
Directory objects managed
5+
Industry certifications
Core areas of expertise
Microsoft-deep identity, multi-cloud capable, with automation and compliance woven through every engagement.
Hybrid Identity & Directory Strategy
- Multi-forest Active Directory architecture & forest trusts
- Legacy AD → Azure Entra ID & AWS IAM modernization
- Large-scale directory mergers & forest decommissioning
- Bastion forests & AD Tiering (Tier 0/1/2)
Security, Compliance & Zero Trust
- Zero Trust architecture — "Never Trust, Always Verify"
- RBAC, least-privilege & separation-of-duties (SoD)
- Access certification & entitlement reviews
- NIST, SOX, SOC 2 & ISO 27001 alignment
- Okta, SailPoint, Entra ID PIM
Cloud & Infrastructure Engineering
- Multi-cloud identity across AWS (IAM/SSO) & Azure
- DNS, DHCP (IPAM) & load balancing (ALB/NLB)
- VMware vSphere / vCenter
- NetApp, Pure Storage & EMC VMAX
Automation & DevOps
- Infrastructure as Code — PowerShell, Python, CloudFormation
- Microsoft Graph, Workday & ServiceNow API integration
- CI/CD pipelines & automated remediation
- Joiner-mover-leaver lifecycle automation
Observability & Troubleshooting
- Splunk, SolarWinds, Nagios & Azure Monitor
- AD replication & schema conflict diagnostics
- LDAP / ADFS authentication troubleshooting
- Rapid7, Delinea Secret Server & Varonis
14+ years in enterprise identity
Senior IT Architect
Signet Jewelers · Irving, TX
- Define the multi-year technology roadmap for enterprise-wide directory services across Active Directory, Azure Entra ID, and federation services.
- Lead the large-scale re-architecture and consolidation of legacy forests to optimize replication topology, security, and performance.
- Architect Zero Trust-aligned authentication and enterprise RBAC frameworks defining role hierarchies, permission scopes, and least-privilege access policies.
- Serve as Principal Architect for CoreSphere, a custom IAM/AD management platform automating RBAC provisioning, access governance, and SOX/ISO 27001 compliance at enterprise scale.
- Design AD tiering models (Tier 0/1/2), hardened delegation, and SoD controls based on CIS and NIST frameworks.
Senior IT Engineer IV
Signet Jewelers · Irving, TX
- Directed the engineering team responsible for core Microsoft services — Entra ID, DNS, DHCP, and Group Policy — for a 150,000-object environment.
- Orchestrated the merger and transition of objects between global Azure tenants during a major cloud consolidation.
- Designed an Employee Services Automation platform integrating Workday, ServiceNow, and Varonis APIs to automate RBAC role assignment across the identity lifecycle.
- Architected AWS IAM RBAC policies and SSO/SAML federation to support AppStream 2.0 while migrating 50% of the server fleet to AWS.
- Led DHCP relocation, DNS modernization, and the replacement of Radiant Logic with AD LDS.
Senior IT Engineer V
Cognizant (Contract for Merck) · Teaneck, NJ
- Led the Intune deployment and configuration for a global pharmaceutical environment, focused on security hardening and policy-based group management.
- Performed critical OS patching and hardening across a multi-platform environment during the COVID-19 remote-work transition.
IT Engineer IV
Signet Jewelers · Akron, OH
- Deployed two new SCCM/Intune tenants to standardize global endpoint management.
- Implemented SSO for all corporate legacy applications, reducing credential-related friction.
- Engineered an RBAC-based AD group management platform using Varonis DataPrivilege to enforce SoD controls and meet PCI and SOX audit requirements.
- Managed enterprise storage migrations (EMC VMAX, Pure Storage) and optimized NetBackup strategies.
Systems Administrator
Amazon (Contract) · Bellevue, WA
- Resolved high-level identity issues related to SSO, app registration, and Service Provider integrations for internal Amazon teams.
- Managed complex Access Control Lists (ACLs) within DSP to protect critical directory resources.
System Engineer
Pioneer Data Systems · Tehran, Iran
- Architected and deployed large-scale VMware and EMC VNX storage environments for national banking and energy clients.
- Designed backup and recovery strategies using Veeam and Symantec, ensuring zero-data-loss for critical government and financial institutions.
Network Administrator
Zaman ISP · Iran
- Supported and maintained LAN/WAN infrastructure, ensuring seamless network operations.
- Diagnosed and resolved network issues promptly to minimize downtime.
Credentials that back the work
AWS Solutions Architect – Associate
Amazon Web Services · 2024
SC-300 — Identity & Access Administrator
Microsoft · 2024
VMware Certified Professional (VCP 6.0)
VMware · 2019
Python
Coursera · 2018
SQL Server
Bellevue College · 2017
Agility Advancement Badge
Signet Jewelers
Academic background
Master · Artificial Intelligence
Khaje Nasir University
Tehran, Iran
Certificate pending — coursework in advanced AI and machine learning.
Bachelor of Science · Computer Engineering
Azad University
Malayer, Iran
Software engineering principles, programming, and development methodologies.
Ready to secure your identity foundation?
Book a free 30-minute discovery call. We'll talk through your environment and where the biggest wins are — no obligation.