Engineering Product Owner — Identity Graph, AD Connector Services, UI/UX
Elisity
Dec 2025 – Present
Owning the identity, integration, and UI core of a Zero Trust microsegmentation platform: Identity Graph, Active Directory / Entra connectors, and the control-center UI/UX.
Microsegmentation Without the Pain
Enterprise networks generate enormous volumes of traffic metadata — but raw flows and IP addresses don't answer the question that matters for Zero Trust: who is accessing what? Traditional microsegmentation requires agent deployment across every endpoint and extensive network redesign, creating friction that slows adoption and leaves gaps in coverage.
The challenge: enforce granular, identity-centric access controls at scale — without touching endpoints, without redesigning the network, and without creating a management burden that collapses under its own complexity.
IdentityGraph™: From Metadata to Identity
As Engineering Product Owner I own the product side of the part of the platform that decides what a device or user actually is: Identity Graph (the identity and enrichment engine behind every policy decision), the Active Directory / Entra ID connector stack (AD Agent, AD Connector Service), and, since May 2026, the UI/UX of the control center. In practice that means sitting between product management, distributed engineering in Poland, Sweden and the US, and design — and turning customer problems into epics engineers can actually build.
What I own
- Identity Graph + 15+ enrichment connectors — EDR (CrowdStrike, Defender, Cortex XDR), MDM (Intune), OT/IoMT (Claroty, Medigate, Nozomi, Dragos), vulnerability management (Tenable, Rapid7), endpoint management (Tanium), cloud (AWS, Azure) and custom. Roadmap from vendor API discovery through attribute mapping to what shows up as a policy criterion.
- Active Directory / Entra ID at scale — AD Agent High Availability (agent groups, domain-controller distribution, failover), per-DC health visibility with a flapping circuit breaker, Status V3, syslog forwarding for monitoring events.
- Control-center UI/UX since May 2026 — shared filter bar, connector and connector-health UX, and a design-companion (DES) process so every front-end epic ships with a designer already engaged.
How the work actually ran
- Microsoft multi-tenant. Decomposed a cross-cutting PRD for multi-tenant Intune / Defender / Entra ID into three sequenced engineering epics, including a shared OAuth token-cache defect that would have silently mixed tenants' data — treated as a release-blocking prerequisite before any tenant cap was raised. Same decomposition pattern for Tanium, Rapid7, and Asimily.
- An honest backlog. Inherited an 80+ item Identity Graph bug list and ran it through phased triage — close, downgrade, re-prioritise, assign — then a weekly bug-health cadence so the team works on what customers feel.
- Process that sticks. Co-defined the ePO→PM reporting standard (what "committed" means on a roadmap), the PM→EPO intake model, Definition-of-Ready with QA, and the design-companion practice for front-end work.
- AI in the workflow, for real. Built an AI-assisted operating layer on Jira, Slack and Confluence: daily board intelligence, ticket refinement against hard "don't invent" rules, and HTML UI mockups engineering can react to in an hour.
Zero Trust Without Agent Friction
A production platform that enforces identity-aware microsegmentation across enterprise networks — no agents, no network redesign, no operational paralysis. Identity Graph plus the connector stack give security teams a single view of identity-to-network relationships and the policy engine to act on it.
My side of that result is tickets a developer can start without opening another document, decisions with a named owner, and telling the truth about scope — across Identity Graph, ADCS and UI on the 26.x releases.