Jatin Madan
Engineering Manager 2 · Enterprise AI Program Architect
Enterprise AI Security & Identity Governance
11x Microsoft Certified · 2x Claude Certified
Leading Entra ID modernization, enterprise AI security governance, and agentic solution delivery across Azure, Copilot Studio, Microsoft Foundry, and hybrid identity programs at Deloitte.
About
Engineering Manager 2 and Enterprise AI Program Architect at Deloitte, specializing in AI security & governance, agentic systems, and Microsoft Entra ID identity modernization. I work across agentic threat detection, OWASP Agentic-AI-aligned governance frameworks, large-scale migration accelerators, and hybrid identity architecture for complex Azure estates.
11 MS + 2 Claude
Certifications
7+
Years Experience
5
Research Publications
OWASP ASI · CIS · MCSB
Security Frameworks
Cloud Security Architecture
Designing secure Azure and hybrid architectures with strong tenant controls, secure ingress, network boundaries, and resilient identity-aware access.
Identity Modernization
Migrating enterprise applications from Okta to Entra ID and Entra External ID with SSO, MFA, HRD, JIT user migration, hybrid identity patterns, and accelerator-led onboarding.
AI Security & Governance
Designing enterprise AI security frameworks aligned to the OWASP Top 10 for Agentic Applications and MITRE ATLAS, plus Azure Policy and AI configuration controls for Copilot Studio, Microsoft Foundry, Purview, Agent365, and Agent ID.
Agentic Systems & Automation
Building multi-agent systems on the Microsoft Agent Framework and Azure AI Foundry Agent Service — SecOps threat detection, SIEM remediation, and MCP-based automation — alongside executive reporting and operational coordination.
Education
University of California, Irvine
Irvine, CA, USAMaster of Computer Science
GPA: 4.0Sept 2023 — Dec 2024
Vellore Institute of Technology
Vellore, IndiaB.Tech Computer Science and Engineering
GPA: 3.58July 2016 — June 2020
Tech Stack
My stack is centered on identity modernization, enterprise AI governance, hybrid access, and the automation layers that make cloud security and agentic delivery programs operationally sustainable.
Identity Platforms
Security & Governance
AI Platforms
Agentic AI & Threat Detection
Cloud & Infrastructure
Data & Reporting
DevSecOps & Automation
Languages
Frameworks & Libraries
Experience
Deloitte
CurrentJan 2020 — Present · 6 roles
Engineering Manager 2
Leading identity modernization, enterprise AI security governance, and cloud control engineering across Microsoft Entra, Azure, and agentic platforms.
- Directed the Okta-to-Entra migration workstream for approximately 2,000 application instances, establishing Power BI and SharePoint reporting for executive visibility and delivery governance
- Spearheaded Microsoft Entra External ID rollout, orchestrating the migration of applications, users, and groups into a production-ready customer identity platform
- Designed Okta-to-Entra migration accelerators to copy applications, users, groups, and policies into Entra ID and Entra External ID tenants, reducing friction for IDP modernization programs
- Standardized SSO and user-flow patterns across SAML, OIDC, and native authentication workloads to reduce migration risk and accelerate onboarding
- Delivered critical External ID capabilities including JIT migration, native authentication, WAF, tenant monitoring, alerting, and MFA to strengthen security posture from day one
- Architected hybrid identity infrastructure with Application Proxy, Entra ID Connect, firewall, F5 load balancing, and DNS routing for secure and seamless application access
- Implemented domain hints and HRD policies that streamlined sign-in journeys and reduced user friction across migrated applications
- Built Azure Policy and AI configuration controls for Copilot Studio, Microsoft Foundry, Purview, Agent365, and Agent ID to improve enterprise AI governance and guardrail enforcement
- Designed an enterprise AI security and governance framework aligned to the OWASP Top 10 for Agentic Applications and MITRE ATLAS/ATT&CK, closing architecture gaps across agent identity, connector secrets, and human-in-the-loop controls
- Specified a six-agent, vendor-agnostic remediation pipeline (discovery correlation, risk-based prioritization, patch orchestration, remediation verification, continuous agentic pentest, machine-speed containment) sequenced across a 30/60/90-day rollout
- Deployed agentic solutions that automated client communication and project coordination workflows across Teams and Outlook
- Produced security gap assessments and remediation recommendations aligned to CIS, MCSB, and CISA, giving leadership a prioritized roadmap for posture improvement
Cloud Security Senior Consultant
Built multi-cloud security assessment and governance capabilities for cloud migration programs.
- Engineered a multi-cloud security assessment capability that surfaced vulnerabilities and compliance gaps across tenant resources against NIST and CIS
- Defined cloud governance processes, operating procedures, and RACI models that gave migration programs clearer accountability and control boundaries
Advisory Solution Advisor
Drove organizational IAM strategy development and led tabletop exercises for Microsoft Sentinel real-time alert response.
- Built organizational IAM strategy frameworks to align identity governance with enterprise security objectives
- Led tabletop exercises for Microsoft Sentinel real-time alerts, improving incident response readiness and team coordination
Advisory Associate Solution Advisor
Focused on identity modernization, controls assessment, and access automation across Azure platforms.
- Automated IAM for PaaS databases and Kubernetes namespaces through Azure AD group-to-role mappings, improving consistency and least-privilege enforcement
- Performed Azure controls assessments against CIS 1.5 and Azure Security Benchmark v3, translating findings into actionable remediation priorities
- Supported client application migration to Azure Active Directory, helping modernize authentication and authorization patterns across the estate
Advisory Analyst
Delivered Azure automation, ETL reporting, tenant assessment tooling, and resource security controls.
- Built ETL workflows with Azure services to power Power BI dashboards that improved client reporting and operational visibility
- Developed a dynamic Azure assessment tool that identified tenant-level security configuration and policy gaps at scale
- Contributed to application migrations toward Azure Active Directory to improve identity standardization and access governance
- Implemented automation to keep Azure resources aligned with required security baselines and reduce configuration drift
Cyber Security Advisor Intern
Built Azure security and compliance automation during an early cybersecurity internship.
- Created ETL workflows with Azure Synapse and Azure SQL Server that enabled richer Power BI reporting and analysis
- Engineered an Azure DevOps extension to pre-scan Terraform templates for compliance, risk, and security issues before deployment
- Developed a proof of concept for workload migration aligned to China's data regulations, supporting early regulatory compliance planning
Data and Technology Fellow
UC Irvine
Irvine, CA
Built an Apple Vision OS application enabling immersive remote development with SSH and VS Code Server.
- Built a Vision OS application that enabled secure SSH connectivity to VS Code Servers inside an immersive developer environment
- Created a VR-native workflow that improved the accessibility and usability of remote development in spatial computing contexts
- Designed the SwiftUI experience to balance usability, responsiveness, and visual clarity for day-to-day developer tasks
- Integrated SSH libraries and executed end-to-end testing to raise connection reliability and overall application stability
Business Technology Solutions Associate Consultant
ZS
Philadelphia, PA
Designed Azure data engineering foundations for scalable ETL, analytics, governance, and secrets management.
- Converted 3,000 Parquet tables to Delta tables using Apache Spark and Databricks, leveraging Delta's ACID transactions and scalable metadata handling to enhance data management efficiency
- Built a custom Docker image for Databricks clusters with preinstalled packages, reducing cluster run time by 14% by eliminating runtime installations
- Established Azure Data Lake foundations that gave the client a secure and scalable storage layer for analytics workloads
- Built Azure Data Factory pipelines that reduced manual data movement and improved the consistency of transformation workflows
- Implemented Unity Catalog and Azure Key Vault to strengthen governance, secrets management, and audit readiness
Azure Architect
Indian Institute of Technology, Bombay
Mumbai, India
Designed Azure-hosted collaboration and SSO solutions for IIT Bombay use cases.
- Designed a video conferencing platform on Azure using Jitsi and BigBlueButton, combining VMSS, App Service, Storage Account, and Cosmos DB for scalable collaboration
- Created secure SSO API architecture for IIT Bombay applications using Azure App Service, Redis Cache, and Application Gateway
- Implemented CDN capabilities for deployed storage accounts to improve content delivery and end-user performance
Intern
Aam Aadmi Party
New Delhi, India
Built data collection and preprocessing pipelines for citizen complaint analytics.
- Built a social media scraping tool across Facebook, WhatsApp, and Twitter to support complaint analytics and Power BI reporting
- Created a preprocessing approach for bulk record updates using binning and partitioning to improve data handling efficiency
Intern
HPCL-Mittal Energy Limited
Punjab, India
Supported SAP modernization and Azure deployment initiatives for enterprise workloads.
- Supported deployment of SAP HANA and SAP BTP on Azure with customized modules aligned to organizational requirements
Projects
Selected programs across identity modernization, enterprise AI governance, hybrid access, cloud security, and agentic automation.
Filter by Technology
Sort By
Enterprise AI Security & Governance Program
Built an enterprise framework for securing agentic AI, aligned to the OWASP Top 10 for Agentic Applications (ASI01–ASI10) and MITRE ATLAS/ATT&CK, closing architecture gaps across identity, secrets, supply-chain, and human-in-the-loop controls.
Impact: 10 controls mapped to Microsoft-native fixes
Performance: 6-agent vendor-agnostic remediation pipeline
Scale: 30/60/90-day enterprise rollout
Microsoft SecOps Multi-Agent Fleet
Built a 7-agent SecOps investigation fleet on the Microsoft Agent Framework and Azure AI Foundry Agent Service, detecting 17 MITRE ATLAS/OWASP-tagged AI-runtime and identity threats.
Impact: 17 MITRE ATLAS / OWASP LLM-tagged detections
Performance: Live SSE investigation streaming
Scale: 7-agent orchestrated fleet
Entra Security Analytics — M365 SIEM
Built a self-hosted SIEM for Microsoft 365 tenants with 90 detection rules across 13 categories, plus AI-powered investigation and autonomous remediation.
Impact: 90 rules + 10 meta-rules across 13 categories
Performance: AI-driven investigation & remediation (GPT-4o)
Scale: 10 Microsoft 365 data collectors
Agent Activity Log Monitor
Built a real-time local monitor that normalizes and streams AI agent activity across Claude Code, Azure AI Foundry, and Copilot Studio into one live dashboard.
Impact: Unified visibility across 3 agent platforms
Performance: Real-time WebSocket streaming
Scale: Claude Code · Foundry · Copilot Studio
Personal Outlook Agent
Built a local-first Outlook automation platform exposing mail, calendar, and an AI agent layer through three equal interfaces — MCP, REST, and CLI — sharing one service layer.
Impact: 89% test coverage, mypy --strict clean
Performance: 3 interfaces, 1 shared service layer
Scale: 28-tool MCP catalog
Enterprise AI Security Board
Built an internal enterprise AI portfolio and vendor intelligence platform giving AI program teams one place to manage use cases, inspect vendor capabilities, consult a security reference, and ask a streaming AI advisor questions about the portfolio.
Impact: 4-stage multi-agent vendor research pipeline
Performance: Streaming AI chat advisor (SSE)
Scale: Private / internal initiative
Okta to Entra Migration Accelerator
Built accelerator workflows that copy applications, users, groups, and policies from Okta into Entra ID or Entra External ID to simplify identity provider migration.
Impact: Reduced migration effort
Performance: Accelerated tenant onboarding
Scale: Object and policy migration
Enterprise Identity Modernization Program
Led a large-scale migration program moving approximately 2,000 application instances from Okta to Microsoft Entra ID with governance, reporting, and phased onboarding controls.
Impact: ~2,000 application instances
Performance: Executive reporting cadence
Scale: Enterprise migration factory
Entra External ID Platform
Designed and deployed a customer identity platform on Microsoft Entra External ID with secure onboarding, JIT migration, native authentication, and tenant-level protections.
Impact: Production identity platform
Performance: Policy-driven onboarding
Scale: Multi-app migration readiness
Hybrid Identity Access Architecture
Architected secure hybrid access patterns using Application Proxy, Entra ID Connect, F5 load balancing, and DNS routing for seamless enterprise authentication.
Impact: Seamless hybrid access
Performance: Reduced sign-in friction
Scale: Enterprise routing patterns
Cloud Security Assessment Engine
Built a multi-cloud assessment capability that measures security posture against CIS, NIST, and client-specific control requirements.
Impact: Framework-mapped findings
Performance: Repeatable assessments
Scale: Multi-environment coverage
IAM Automation & Least-Privilege Controls
Automated identity-to-role mapping patterns for PaaS databases and Kubernetes namespaces to improve access consistency and least-privilege enforcement.
Impact: Consistent access models
Performance: Reduced manual provisioning
Scale: Cross-platform role mapping
Security Reporting & Remediation Dashboard
Built executive-ready reporting that translated control gaps, migration progress, and remediation priorities into actionable dashboards for stakeholders.
Impact: Leadership decision support
Performance: Near real-time visibility
Scale: Cross-workstream reporting
Emergency Response Assist (ERA)
Developed an audio detection system using MFCC Feature Extraction and LSTM/CNN models, achieving 95.6% accuracy in identifying gunshot sounds for real-time emergency response.
Impact: 95.6% detection accuracy
Performance: Real-time audio classification
Scale: MFCC + LSTM/CNN pipeline
Open Source & GitHub
Personal projects, experiments, and open-source contributions across security, ML, web development, and more.
Filter by Language
Security-Agents-MS
Entra-Security-Analytics
Entra-Security-Analytics
Agents-Log-Monitor
Personal-Outlook-Agent
client-dossier
AI-powered client intelligence agent — indexes OneDrive and Sharepoint documents into a knowledge base and provides an agentic chat interface with file browsing, source citations, and client memory. Built on Azure AI Foundry, Semantic Kernel, and Azure Container Apps.
Entra-Privilege-Analyzer
Entra ID least privilege analyzer — profiles identity actions, recommends custom roles, and detects permission drift across users, service principals, and managed identities.
agent-skills-sync
Postman-API-Collections
Certifications
11× Microsoft Certified across architecture, security, development, and data — plus 2× Claude Certified (Associate & Architect).
ExpertAzure Solutions Architect Expert
ExpertDevOps Engineer Expert
AssociateAzure Security Engineer Associate
AssociateAzure Developer Associate
AssociateAzure Data Engineer Associate
AssociateAzure Network Engineer Associate
AssociateAzure Database Administrator Associate
SpecialtyAzure IoT Developer Specialty
FundamentalsAzure AI Fundamentals
FundamentalsAzure Data Fundamentals
FundamentalsAzure Fundamentals
Claude Certified Associate — Foundations
Claude Certified Architect — Foundations
Research & Publications
Published across Springer, IEEE, and CRC Press — covering cryptography, digital forensics, NLP, cloud computing, and IoT.
HCS: A Hybrid Data Security Enhancing Model Based on Cryptography Algorithms
Enhances data security at scale using cryptographic algorithms, Pan-Tompkins for QRS detection, and MLP for cardiac arrhythmia classification.
Critical Analysis of Digital Forensics in Offense Investigation
Analyzes the digital forensics process and reviews the OSForensics tool, covering its features, implementation, and future directions.
Intelligent and Personalized Factoid Question & Answer System
Proposes a face-recognition-based chatbot using NLP and ML (Local Binary Patterns, HAAR) for personalized question-answering with biometric identification.
Integrating Big Data and Cloud Computing
Surveys big data implementation in cloud computing, covering analytics, integration technologies, security considerations, and Hadoop.
Analyzing and Evaluating IoT Platforms for Smart Cities
Evaluates IoT applications in smart city contexts including transportation, healthcare, waste management, and defense.