EXPERIENCE / SYSTEMS DELIVERED

Five years building the systems behind secure, productive work.

Halation Systems is built on hands-on delivery across identity, endpoint management, SaaS, security and automation—from environments without managed identity or devices to global migration programmes serving more than 1,100 users. I design the target state, build the working system and leave clear ownership behind.

  • 2021–PRESENT
  • UK AND GLOBAL ENVIRONMENTS
  • DIRECT ENGINEERING DELIVERY

Selected programme scale

  1. 1,100Users moved to passwordless accessFastPass rollout with managed-device assurance
  2. 110SSO applications in migration scopeEnterprise identity transformation
  3. 20,000+Endpoints in delivery estateUniversity software-delivery engineering
  4. 150Devices migrated in one week without user downtimeScripted client MDM migration

Selected programme scale from Joe's in-house and contract delivery. Figures describe the relevant environment or migration scope, not Halation Systems client totals.

01 / THE DELIVERY PATTERN

The platforms change. The operating model stays connected.

HR data, identity, access, devices, SaaS, security signals and operational processes cannot be designed independently. My work has repeatedly joined those layers into one controlled employee lifecycle—from the first approved record through access, device trust, productive work and a complete exit.

  1. SourceHRIS data, ownership, profile structure and validation
  2. IdentityOkta Universal Directory, mappings, group rules and lifecycle state
  3. AccessSSO, SCIM, adaptive MFA, FastPass and delegated requests
  4. DeviceJamf, Intune, enrolment, applications, patching and posture
  5. SecurityEndpoint protection, compliance controls, exceptions and evidence
  6. AutomationAPIs, workflows, Slack actions and custom business logic
  7. OperationsRunbooks, health checks, handover and named internal ownership

02 / DELIVERY RECORDS

Five delivery records

RECORD 01

Global enterprise software environment / 1,100 users

Identity architecture, lifecycle automation and passwordless migration.

STARTING POINT

The environment depended on UKG, SailPoint, Okta and Duo across a large SaaS estate. Identity data and provisioning logic were distributed across systems, profiles and mappings were inconsistent, and the migration had to preserve user access while the target architecture was built.

WHAT I DESIGNED AND DELIVERED

  • Mapped the target source-of-truth → Okta → service-provider architecture across four authoritative identity sources, integrating three custom source processes through Okta Workflows and Access Requests and connecting UKG through its supported integration.
  • Rebuilt the Okta data model with custom attributes, profile mappings, validation and Okta Expression Language logic.
  • Designed and delivered a migration programme covering 110 SSO applications and 31 provisioning integrations, using native SCIM where viable.
  • Built lifecycle management for pre-hire staging at T-7 (seven days before start), activation at T-1 (the day before) and controlled end-date deactivation, alongside delegated Slack and Access Request workflows with validation, logging and defined approvals.
  • Designed adaptive MFA and passwordless policies for managed internal devices, external access and mobile/BYOD use cases; rolled out FastPass to 1,100 Windows and macOS users with checks that the device meets defined management and security requirements through Intune and Kandji.
  • Planned and led the Okta organisation and subdomain cutover, including runbooks, communications, support preparation and rollback thinking.
  • Used Python and platform exports to correct identity data and make attributes dependable enough for dynamic access rules.
  • Produced architecture diagrams and technical proposals, led stakeholder reviews and delivery meetings, and supported junior engineers through implementation.

RECORD 02

Fast-growing digital business / Ground-up IT foundation

From unmanaged access and devices to a joined identity and endpoint environment.

STARTING POINT

The business had Google Workspace and Slack but no central identity platform or managed-device standard. It also needed to complete a company domain migration without leaving user accounts, applications and security controls fragmented.

WHAT I DESIGNED AND DELIVERED

  • Migrated Google Workspace, Slack and related services from the previous company domain into the new operating environment.
  • Established the HR process in HiBob, configured Okta as the identity and access layer, defined password, MFA, authentication and network-zone policies, and integrated more than 30 applications using SAML, SCIM and data-driven assignment.
  • Built the macOS platform with Jamf Pro, Apple Business Manager, automated enrolment, PreStage configuration, FileVault, PPPC profiles, application delivery and patching; connected Jamf Connect to Okta and added local administrator controls including LAPS where supported.
  • Built Windows management with Intune and Windows Autopilot, including vendor-assisted registration, configuration profiles and security settings.
  • Rebuilt Google Workspace organisational units and directory structure around dependable department data.
  • Deployed CrowdStrike across macOS and Windows using staged sensor and security-policy rollouts.
  • Built a contractor-onboarding system with Google Forms, an approval-controlled Google Sheet, Python and AWS Lambda to create approved Okta accounts without an ungoverned manual process.
  • Contributed separately to frontend and backend microservices using Node.js, React, Next.js, GraphQL, REST APIs and DynamoDB.
  • IT infrastructure build
  • Okta
  • Google Workspace
  • Jamf
  • Intune
  • CrowdStrike
  • Zero-touch deployment
  • SAML
  • SCIM
  • AWS Lambda
  • Node.js
  • APIs
  • Automation

RECORD 03

Fast-growing global AI company / Sole IT systems and security engineer

Global identity, SaaS and endpoint systems owned directly.

STARTING POINT

A rapidly growing distributed company needed one engineer to operate and improve identity, SaaS access, employee devices and day-to-day IT while maintaining security and supporting continued growth.

WHAT I DESIGNED AND DELIVERED

  • Rebuilt and administered Okta integrations, profile-driven group rules, lifecycle controls, SSO and SCIM provisioning.
  • Used role, level, department and custom attributes to assign access dynamically instead of relying on static group membership.
  • Designed the employee Mac platform with Jamf Pro, Jamf Connect, Jamf Protect and Apple Business Manager, including automated enrolment, configuration and application delivery.
  • Built and operated Windows management with Intune, application packaging, compliance controls and Microsoft Defender.
  • Managed a broad SaaS estate while keeping access tied to business role and lifecycle state.
  • Automated repetitive administration with Python, PowerShell, Bash and REST APIs.
  • Supported ISO 27001 and SOC 2 evidence requirements.
  • Managed global device ordering, replacement and leaver recovery through an international hardware provider.
  • Global IT
  • Okta
  • SaaS management
  • Jamf
  • Intune
  • Endpoint security
  • Compliance evidence support
  • Automation
  • Employee experience

RECORD 04

Large UK university / 20,000+ endpoint estate

Software delivery and endpoint controls at institutional scale.

STARTING POINT

Software and specialist engineering applications had to be delivered across a large, mixed Windows and macOS estate while meeting security requirements and avoiding manual packaging work at every update.

WHAT I DESIGNED AND DELIVERED

  • Automated application packaging and update delivery through Intune and Jamf using MSI workflows, scripts and maintained open-source packaging tools.
  • Worked with security teams to assess endpoint and application health using custom detection logic for outdated, non-reporting or non-compliant software.
  • Re-engineered Jamf and Intune configuration, compliance and application-delivery workflows.
  • Strengthened Microsoft Defender for Endpoint controls within the delivery scope.
  • Led projects designing Azure Virtual Desktop environments for engineering departments, including VM configuration, application requirements, rollout planning and security testing.
  • Created runbooks and rollout documentation and mentored other systems engineers.
  • Intune
  • Jamf
  • Application packaging
  • Endpoint compliance
  • Defender
  • Azure Virtual Desktop
  • PowerShell
  • Python
  • Security testing

RECORD 05

Client consulting / Three cross-platform environments

Scoped MDM and identity delivery with a complete handover.

STARTING POINT

Client organisations needed Jamf and Intune environments delivered against defined statements of work, with the required applications and controls implemented and the finished service transferred to their internal teams.

WHAT I DESIGNED AND DELIVERED

  • Designed and deployed Jamf Pro and Intune environments for three organisations with more than 100 endpoints each.
  • Configured automated enrolment, security profiles, application delivery and patch management across macOS and Windows.
  • Integrated HiBob and Okta to support a controlled joiner-mover-leaver lifecycle.
  • Delivered 20+ SSO and SCIM integrations to reduce manual account administration.
  • Completed a scripted migration of 150 devices within one week without user downtime.
  • Produced client-facing implementation guides, operating documentation and handover material.
  • IT consulting
  • Jamf
  • Intune
  • Okta
  • HiBob
  • SSO
  • SCIM
  • Device migration
  • Documentation
  • Handover

03 / BEYOND PLATFORM CONFIGURATION

When the standard workflow stopped short, I built the missing system.

The strongest automation is not a collection of disconnected scripts. It is a controlled business process with an authoritative input, validation, approvals, logging, failure handling and a named owner.

  • SOLUTION 01

    Contractor provisioning engine

    Connected a structured Google Form and approval-controlled Sheet to Python and AWS Lambda, creating approved contractor identities in Okta only after IT verification.

  • SOLUTION 02

    Delegated access from Slack

    Designed structured Slack request actions connected to Okta Access Requests and delegated Workflows, with fields, validation and approval paths tailored to the business action.

  • SOLUTION 03

    Governed internal email allocation

    Built logic that checked both the Okta directory and a controlled company-email table before allocating an internal address, then returned the result to HR through Slack and wrote it into the HR record without a second manual step.

  • SOLUTION 04

    Internal AI assistance

    Built internal AI agents for IT, security and legal Slack channels to make approved operational knowledge easier to retrieve.

These are custom business solutions: small, governed systems built around the actual operating requirement rather than forcing the business into a generic tool workflow.

04 / WHAT THE ENGINEERING CHANGES

Better systems create capacity, not another layer of administration.

  1. 01Lifecycle management

    Approved joiners, movers and leavers follow a consistent process with fewer repetitive IT actions.

  2. 02Adaptive access and device trust

    Access decisions use identity, authentication and managed-device context rather than a password alone.

  3. 03Automated device management

    Employees receive configured, encrypted and protected devices with the applications needed for their role.

  4. 04Custom business workflows

    Teams spend less time copying data between forms, directories, Slack and SaaS administration screens.

  5. Internal IT retains control of the finished service and can focus on higher-value business priorities.

Outcomes depend on the environment, available evidence and agreed scope.

EXPERIENCE APPLIED TO YOUR ENVIRONMENT

Bring the environment, the migration or the target state.

If identity, devices, SaaS and business workflows have grown separately, I can help establish what exists, define the target architecture and deliver the work needed to get there.