IAM Engineering Leader

Manoj
Kottam

I build and run enterprise identity platforms. That covers workforce login, privileged access, and the plumbing that keeps them honest.

At HEB Digital I lead IAM for 180K+ employees: Okta as the main IDP, a Teleport pilot for server access, and Terraform so app teams can onboard without waiting on a central queue.

CISSP MBA MS Computer Science
Manoj Kottam
20+
Years Experience
180K
Employees (IAM scope)
900+
Apps Migrated
6+
Years Leading

Hire people who can think. Give them context. Get out of the way when they're shipping.

What I’m working on

2026

At HEB Digital. Not a roadmap dump, just where most of my time goes.

01

Teleport pilot

Server access via Teleport for Linux and Windows VMs. Owners decide who gets in. Roles: basic, elevated, short-lived admin. Sessions recorded. Hosts tagged by service, env, compliance.

02

Privileged + machine access

Teleport, Clutch, CrowdStrike, OPA. Less “who is in AD,” more who can touch what host or API, and for how long. PCI MFA for privileged users is in this bucket too.

03

Non-human identity

Service accounts, API clients, OAuth for APIs. Also thinking about AI agents. Same NHI problem, with more chatter and more blast radius if you get it wrong.

04

Self-service onboarding

IAM in Terraform so app teams don’t wait on a central queue. Help-desk verification and day-2 tools for the stuff people used to email us about.

01

Selected work

A few HEB programs with enough detail to be useful. Full timeline is under Experience.

01 HEB Digital

900+ apps onto Okta

Workforce login was split across OneLogin, on-prem ADFS, and other paths. Hard to govern, hard to support.

Cut over in waves with inventory and app owners. ~500 apps from OneLogin, 200+ from ADFS. Goal was one primary IDP without a multi-year outage story.

ResultOkta is the primary workforce IDP for 900+ apps.

Okta SSO OneLogin ADFS
02 HEB Digital

Okta Identity Governance

Joiner/mover/leaver and access reviews were manual. Audits meant last-minute scrambles.

Stood up Okta IG for lifecycle, access requests, and certification campaigns so reviews and evidence live in one place.

ResultJML, requests, and cert campaigns run through Okta IG instead of spreadsheets and inbox threads.

Okta IG JML Access reviews
03 HEB Digital

Off broad AD for servers

Broad AD groups and domain joins for Linux access. Ownership was fuzzy; reviews and compliance proof were painful.

Teleport pilot first: inventory, enroll agents, owner access lists. Tighten only after it works. Exceptions written down.

ResultPilot live for Linux and Windows VMs, with owner-managed roles, session recording, and resource tags. Not a full estate flip overnight.

Teleport PAM Session recording
04 HEB Digital

Terraform for app onboarding

Every app onboard and a lot of day-2 changes hit a central IAM queue. Product teams waited; help desk emailed us constantly.

IAM config in Terraform. Self-service paths for onboarding. Verification tools for help desk so common checks don’t need an engineer.

ResultTeams can onboard without waiting on us for every change. Fewer “email IAM” tickets for routine work.

Terraform Self-service
02

Machines, services, agents

Most of the hard identity work now is not employees logging into apps. It’s services, API clients, and privileged paths. Soon it will also be agents acting on behalf of people or systems.

I don’t treat “AI agent identity” as a greenfield category. It’s non-human identity with worse PR: who is this, what can it do, how long does that last, who owns it, and can you show the trail later. Same questions we already ask for service accounts and break-glass admin. Volume and speed just punish lazy design faster.

On the ground that means Teleport/Clutch-style privileged access, OAuth for APIs, OPA where policy needs to be code, and not inventing a second identity program for agents that ignores the first one.

03

Experience

Most of my career has been identity: building it at Oracle, then modernizing it at HEB. The through-line is making access safer without making the business slower.

Present
HEB Digital
Senior Engineering Manager, IAM Platforms
2023 – Present
Dallas, TX

Multi-year IAM rebuild for a large retail workforce: one IDP, real governance, and a practical plan for privileged and machine access. Highlights below; deeper cuts under Selected work.

900+ apps on Okta as primary IDP (~500 from OneLogin, 200+ from ADFS).
Okta Identity Governance for JML, access requests, and certification campaigns.
Teleport pilot for Linux and Windows VMs; path off broad AD groups and domain joins.
Privileged and non-human identity with Teleport, Clutch, CrowdStrike, OPA; PCI DSS 4.0 MFA for privileged users; Okta OAuth for API protection.
IAM config in Terraform; help-desk verification and day-2 tools.
Hired and grew the security engineering team rebuilding the platform.
OktaOkta IGTeleport PAMNHI TerraformOPAPCI DSS 4.0
Oracle America
Manager, Software Development
2013 – 2023
Frisco, TX

Spent a decade on Oracle’s multi-tenant Identity Cloud. Work covered SSO, federation, MFA, and customer identity for apps across the cloud portfolio.

Built the IDaaS stack teams actually used: SSO into Oracle cloud apps, users and roles, OAuth / OIDC / SAML, MFA, audit, and analytics.
Got Health & Life Sciences product owners (20+) onto Identity Cloud and helped consulting land it for 300+ large customers.
Pushed SCIM provisioning and standard OAuth 2.0 / OIDC flows so every customer integration wasn't a custom project.
Federated with customer IDPs including Azure, Okta, Exostar, ForgeRock, Ping, and others.
Automated the boring parts: compliance checks, release reporting, fewer surprise handoffs between teams.
Hired and kept a solid engineering team. Several people I coached moved into tech lead or manager roles.
IDaaSCIAMSAML OAuth 2.0OIDCSCIM MFA
Homeward Residential
Enterprise Architect
2011 – 2013
Coppell, TX

Architecture work on loan servicing and investor reporting.

Automated loan onboarding for servicing and cut processing time by more than 40%.
Rebuilt the investor reporting portal so performance history and summaries lived in one place. That cut about $5MM/year in manual work.
ArchitectureAutomationReporting
Keste
Solutions Architect
2007 – 2011
Plano, TX

Consulting architect for enterprise clients.

Built a global B2B platform, product config rules engine, and quotes portal for Alcatel-Lucent. That work drove more than $10MM in revenue over two years.
Oracle ADF / SOA / WebCenter work for NetApp, Flowserve, SunGard, Ross Stores, and others. Wired a B2B landing experience to Salesforce with SAML.
B2B PlatformRules EngineSAML Oracle SOA
Earlier roles
Software Intern · Programmer Analyst
2004 – 2006
TX · India

WiQuest (intern, 2006): test automation for wireless devices and WHQL certification with Microsoft. Cognizant (2004–2005): support engineer on AMEX card services. Watched the network, fixed issues, hit the SLA.

04

Skills

Identity & Access
Okta & Identity Governance Teleport · server access PAM · Clutch · CyberArk OAuth 2.0 · OIDC · SAML · SCIM FIDO2 / WebAuthn · MFA Service-Scoped RBAC · Session Recording CIAM · NHI · Agent Identity OPA · CrowdStrike IDaaS · Federation
Compliance & Risk
PCI DSS 4.0 SOX · SOC 2 NIST CSF Audit Automation Access Certification Access Reviews
Cloud & Platform
AWS Terraform · IaC Kubernetes · Docker Kafka · REST APIs SQL / NoSQL Java / J2EE
Leadership
Engineering Management Roadmaps & Pilots Vendor Selection Hiring & Mentoring Working Across Teams Talking to Executives
05

Education

Master of Business Administration
The University of Texas at Austin, McCombs School of Business
May 2020
Master of Science, Computer Science
The University of Texas at Dallas
May 2007
Bachelor of Engineering, Information Technology
Osmania University, Hyderabad, India
May 2004
(ISC)² Certified Information Systems Security Professional (CISSP)
Oracle Access Management Suite Plus 11g Implementation Specialist
UT Dallas Information Assurance Program

Say
hello

IAM, eng leadership, or how identity programs land in a big org. Happy to talk.