Asif Zia Butt
@asifziabutt
Senior IAM & Cloud Security Engineer specializing in Zero Trust, IGA, and audit-ready cloud defenses.
What I'm looking for
I’m an SC-100 certified identity and cloud security engineer with over 10 years in enterprise IT and 5+ years running IAM operations across Active Directory, Entra ID, and hybrid environments. My day-to-day ownership spans IGA (joiner/mover/leaver, access reviews, RBAC), Conditional Access, PIM, and certificate lifecycle management through Key Vault and ADCS.
I build audit-ready IAM and cloud security programs with a SOC 2, ISO 27001, and PCI-DSS posture. As the IAM operations lead, I work directly with business stakeholders to translate access requirements into governance workflows, and I serve as the primary escalation point for identity incidents, access issues, and audit queries.
I’m hands-on with outcomes: I placed privileged roles behind PIM with just-in-time elevation and approval workflows, cutting the identity attack surface by roughly 40%. I also stood up Microsoft Sentinel from scratch (KQL analytics rules and SOAR playbooks), used PowerShell/Python automation to cut MTTR by about 60%, and mentored junior engineers with runbooks so Tier 1/2 incidents don’t stall.
Experience
Work history, roles, and key accomplishments
Led IAM operations across a hybrid Azure environment for Rogers Retail IT, managing identity lifecycle on Active Directory and Entra ID for ~2,400 endpoints across 350 retail stores. Built Conditional Access and PIM for privileged roles, cutting the identity attack surface by ~40%, and reduced MTTR by ~60% via PowerShell/Python automation; stood up Microsoft Sentinel from scratch for KQL detection
Senior Cloud Infrastructure Engineer
Pernod Ricard S.A.
May 2020 - Jan 2022 (1 year 8 months)
Operated Entra ID and hybrid identity for 500+ global users, managing Conditional Access, RBAC, group lifecycle, and SaaS federation while running joiner/mover/leaver provisioning for prompt access revocation. Delivered Tier 2/3 identity and endpoint support with 95% first-call resolution and automated identity provisioning and deployments, saving ~15 hours/week.
Designed and managed Windows imaging and endpoint deployments for hundreds of retail stores using MDT, WDS, and Quest KACE, with Active Directory as the identity backbone. Built and operated Windows Server (2008/2012/2016) and VMware/Hyper-V environments on Cisco UCS, consolidated retail servers into the datacenter with VMware Converter, and rolled out CrowdStrike while improving change workflows
Wintel Administrator
Bell Canada
Apr 2012 - May 2015 (3 years 1 month)
Configured Hyper-V 2008/2012 clusters and designed multi-site Active Directory forest structures to support core identity infrastructure. Deployed Exchange 2010 for 5,000+ mailboxes and rolled out SCCM 2012/MDT for software deployment and imaging.
Education
Degrees, certifications, and relevant coursework
London, United Kingdom
Master of Science, Innovative Technology
Earned an MSc in Innovative Technology while studying in London.
London, United Kingdom
Bachelor of Science, Technology & E-Commerce
Earned a BSc in Technology & E-Commerce while studying in London.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Asif Zia?
You can contact Asif Zia and 90k+ other talented remote workers on Himalayas.
Message Asif ZiaFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
