Paulo Valadares Open to director roles

Paulo
Valadares

Manager Identity & Access Management Engineering

An engineering leader is paid for decisions, not for tickets. This is the log: what I decided, what it was meant to fix, and what it actually returned.

Today I run enterprise identity engineering at Sobeys: a team of 12 engineers, a multimillion dollar vendor portfolio, and the platforms that decide who can touch what. Nights and weekends, I ship security products of my own.

DR-003 2024 Delivered

Redeploy the platform instead of patching it

Context
Privileged access compliance sat at 27 percent on an inherited build. Every quarter of patching moved it by a point or two.
Decision
Rebuild the CyberArk SaaS estate from scratch, migrate legacy connectors to Secure Infrastructure Access, and automate account discovery so the platform stops depending on people remembering.
27%
Compliance 27% to 96%
risk critical to medium · 7,000+ accounts remediated
$8M+
Contracts closed
12
Engineers hired, 100% kept
700+
Hours automated away
7,000+
Privileged accounts fixed
0
Platform incidents last FY

Mandate

Build the team, then let the team build the machine

I took over a program that ran on contractors and goodwill. The fastest way to fix the platform was not to fix the platform. It was to hire people who could, write down how the work is done, and give them room to do it. Twelve engineers later, none of them have left.

I am happiest where the problem is messy and nobody wants to own it. I map it, break it into pieces, and turn it into something the whole team can run without me in the room. I think a few moves ahead, because the identity platform you design today is the one you live with for five years.

My default answer to repetitive work is to delete it. I would rather build the machine than run the errand, and I hold the small details, because in security the setting everyone overlooked is usually the one that matters.

Decisions, written down

Context, decision, consequence. If it is not written down, it will be re-litigated in a year by someone with less information.

Automation first

If it repeats, it becomes code. Every hour returned is an hour spent on something a machine cannot do.

Measured, not asserted

A control nobody verified is a control that does not exist. Every claim on this page has a number behind it.

Teams outlast programs

Platforms get replaced. The engineering culture you build is what survives the next reorg.

Decision log · Sobeys, 2024 to present

Five decisions and what they cost or returned

Written in the format engineering teams use for architecture decisions, because that is what they were. Filter by what was at stake.

DR-001PeopleDelivered

Hire the engineers before rebuilding the platform

Context
The identity program had no in-house engineering function. Delivery depended on contractors who were not accountable for what they left behind.
Decision
Build the team first. Hire 12 engineers across privileged access, directory, governance and automation, replace the contractors who were not performing, and lead 3 project managers and a business analyst alongside them.
Consequence
Documented architecture, peer reviewed changes, written SOPs, recorded training and shadowing rotations. Knowledge stopped living in one head.
12 engineers hired100% retention3 PMs and 1 BA ledTop performing leader, 2024 and 2025
What this looked like in practice
  • Four disciplines staffed: privileged access, Active Directory and Entra ID, identity governance, automation.
  • Training, certifications and recorded sessions built into the plan, not offered as a perk.
  • Trusted on enterprise decisions outside the identity program, including the CIAM migration.
DR-002MoneyDelivered

Reopen the vendor contract instead of signing the renewal

Context
A multimillion dollar renewal was on the table with inherited terms, an inherited architecture, and a support queue measured in weeks.
Decision
Renegotiate on a three year term rather than accept the renewal, and challenge the incumbent design at the same time. Own the review of the license contracts and the statements of work with partners including Deloitte and Accenture.
Consequence
The discount funded the next phase of the program. Machine identity, secrets management and endpoint protection were added with no new budget ask.
$6M+ in license discounts$8M+ contracts closedSupport SLA 3 weeks to 4 daysMillions in change orders avoided
What this looked like in practice
  • Architecture gaps in the inherited vendor design surfaced before implementation, not during it.
  • A defined escalation path and a direct line to the account team replaced ticket roulette.
  • Working partnerships maintained with CyberArk, SailPoint and CrowdStrike.
DR-003PlatformDelivered

Redeploy the platform instead of patching it

Context
Privileged access compliance sat at 27 percent on an inherited build, with a Critical risk rating and legacy connectors nobody wanted to touch.
Decision
Rebuild the CyberArk SaaS estate, migrate PSM to Secure Infrastructure Access, and automate discovery and onboarding so new privileged accounts are vaulted without anyone filing a request.
Consequence
Compliance moved from 27 to 96 percent, the risk rating dropped from Critical to Medium, and the number of users connecting securely more than tripled. Every upgrade since has shipped without downtime.
27% to 96% complianceCritical to Medium risk7,000+ accounts remediated3x secure users0 platform incidents
What this looked like in practice
  • Full SaaS redeployment run alongside live operations, with no service window taken from the business.
  • Automated discovery closes the gap between an account being created and an account being governed.
  • Venafi onboarded, with certificate renewal moved into workflows rather than calendar reminders.
DR-004RiskDelivered

Remove standing privilege everywhere, not only where it was easy

Context
Tier 0 and Tier 1 accounts held permanent rights across on-prem Active Directory and Entra ID. Legacy RSA MFA and years of directory drift sat underneath them.
Decision
Extend Just-in-Time access and Zero Standing Privilege to every Tier 0 and Tier 1 account, and run the multi-year directory hardening program at the same time rather than waiting for a quieter quarter.
Consequence
Standing privilege is gone from the tiers that matter, the directory has a tested recovery path, and there is a written Break Glass procedure for the day everything else fails.
700+ external users secured500+ internal users securedPasskeys replace RSA MFABreak Glass policy authored
What this looked like in practice
  • SMBv1 disabled, hardening GPOs written for service accounts, password policy strengthened, end-of-life systems decommissioned or upgraded.
  • DSRM and KRBTGT rotated, with a repeatable process and dedicated test domains on-prem and in the cloud.
  • Conditional Access rebuilt, self-service password reset enabled, incident response playbooks written and audit logging expanded into SIEM detections.
  • SailPoint governance delivered from pre-implementation through go-live, including custom workflows for systems the vendor does not support.
DR-005PlatformDelivered

Automate the work instead of hiring around it

Context
Joiners, movers and leavers were handled by people following a checklist. Volume was growing and the checklist was where the errors lived.
Decision
Stand up an Azure Automation platform for the group and move the lifecycle into code, driven by the HR system rather than by a ticket.
Consequence
More than 700 hours returned to Operations, Compliance and Engineering, and a recurring source of human error removed from the termination path.
10+ production automations500+ hours saved200+ hours in PowerShell toolingHR-driven terminations
What this looked like in practice
  • Terminations, onboarding, movers, inactivity handling and expired account cleanup all run without a human trigger.
  • Custom PowerShell tooling covers the cases the platform does not, and is documented for the team rather than kept as personal scripts.

Innovation · built off the clock

Products I ship on my own time, secured the way I argue for at work

Founder of DNA Technology. These are real codebases in production: product, architecture, security and code, all mine. They are also how I stay honest, because it is easy to demand a strict Content-Security-Policy when you are not the one who has to make the page work under it.

Identity at the Core

Publication and community for the identity industry · live

Articles, guest authors, a partner program and a member portal, on an end to end role model covering readers, members, authors, partners and administrators.

Security decisions
  • Passwordless by default: WebAuthn passkeys and magic links, OAuth as the fallback, Argon2id for anything hashed.
  • Strict nonce-based CSP with strict-dynamic, HSTS preload, COOP and CORP, and distributed rate limiting.
  • RFC 9116 security.txt and a published disclosure policy, because a product without a reporting path is a product hoping nobody looks.
Next.js 16TypeScriptAuth.js v5PasskeysPrismaPostgresStripe
identityatcore.org →

IAM X-ray and Automation

Identity vulnerability discovery and audit platform · pre-alpha

Discovers, investigates and reports identity vulnerabilities across Active Directory, with Entra ID, Okta and Ping on the roadmap. Read-only by default, because an audit tool that can write is a liability.

Architecture decisions
  • A connector abstraction lets the same scanners run live over LDAPS or offline against a snapshot, so an assessment never needs privileged write access.
  • Credentials live only in the OS keystore, DPAPI or Vault. Configuration is YAML validated against JSON Schema, so a typo fails at load rather than mid-scan.
  • One Finding evidence model feeds the HTML, xlsx, CSV and PDF renderers, so every report tells the same story.
Python 3.12Pydantic v2ldap3Plugin architecture
iam-x-ray-automation.web.app →

DNA Technology

Consulting site and digital marketplace · in development

Tiered subscriptions, downloadable products and an affiliate program on a hardened Supabase and Stripe core. The money paths are where the interesting bugs live.

Security decisions
  • Row-Level Security on every table, with SECURITY DEFINER helpers rather than trust in the client.
  • Stripe webhook signatures verified on the raw body, and retries made idempotent by UNIQUE constraints, so a redelivered event can never credit an account twice.
  • Signed download URLs with a 60 second lifetime, gated by an entitlements view.
Next.js 14SupabasePostgres RLSStripeZod
dnatechnology.ca →

This page, and the CV before it

Single file, zero third-party scripts · live

One HTML file, no cookies, no analytics, no external dependency of any kind, and everything still moves. The gauges are hand-drawn SVG. Nothing you do here leaves the page.

Security decisions
  • No third-party script means no supply chain to compromise. It is the argument I make at work, applied to my own site.
  • Strict Content-Security-Policy, every external link rel=noopener, honeypot and validation on the contact form.
  • Keyboard navigable, contrast checked in both themes, and prefers-reduced-motion respected.
HTML5CSS variablesVanilla JSPure SVGA11y
paulovaladares.web.app →

Track record

Nine years, four employers, one direction

Apr 2024 › now
IAM Engineering Manager
Sobeys Inc., Toronto
Built the engineering function, owns the platform roadmap, the vendor portfolio and the risk posture reported to senior leadership.
Apr 2021 › Apr 2024
IAM Technical Lead Engineer
Aviva Canada, Toronto
Technical lead for Operations and Engineering. Led the IGA transformation, the AD migration, MFA and SSPR, and the PIM rollout. Employee of the Year and Hackathon winner.
Sep 2019 › Apr 2021
Security Architect
Stikeman Elliott LLP, Toronto
Implemented PIM, network access control, next-gen antivirus and Defender ATP. Wrote the SecOps playbook and worked audits with Deloitte and major banks.
Mar 2018 › Sep 2019
Access Management Analyst
Aviva Canada, Markham
Ran a 5,000 user directory and wrote the automation that cut account administration time by an average of 95 percent.

What I bring

Depth in security, range in engineering

Security and identity platforms

  • Privileged access: CyberArk SaaS and SIA, BeyondTrust, PMP
  • Governance: SailPoint, lifecycle events, access reviews
  • Just-in-Time access and Zero Standing Privilege
  • Active Directory and Entra ID architecture, tiering, hardening
  • MFA, passkeys and Conditional Access design
  • CrowdStrike, Defender ATP, Venafi, Mimecast, FortiNAC
  • SIEM and detection engineering: Splunk, QRadar, SumoLogic

Engineering, cloud and delivery

  • Azure, Azure Automation, Microsoft Graph, Google Cloud, Firebase
  • PowerShell, Python, TypeScript, Node.js
  • Next.js, React, Express, REST API design
  • Postgres with Row-Level Security, Prisma, Firestore, Supabase
  • OAuth 2.0, OIDC, SAML, SCIM, WebAuthn
  • CI/CD, infrastructure as code, release engineering
  • Roadmap ownership, vendor negotiation, budget accountability

Contact

Tell me what is broken

If you are hiring someone to build an engineering function rather than inherit one, I would like to hear about it. The fastest route is email.

Phone
(416) 833-5315
Based in
Toronto, Ontario
CV
PDF  ·  Word