Cybersecurity, Cloud, Identity, and AI Safety Profile
Security and technology leadership
Use this page when the hiring question is security, cloud, identity, AI safety, or senior technology leadership. It gives the short version of why Jake belongs in principal-level conversations while the full resume keeps the chronology and downloads.
Where Jake is strongest
Jake is strongest where security architecture, cloud modernization, identity, governance, AI-enabled tooling, and operational delivery have to work together. The pattern is translating risk, business constraints, engineering reality, and executive decisions into systems teams can actually operate.
Hiring-manager read
The most relevant roles are principal or staff security architect, cloud security architect, identity and access architecture leader, AI safety or red-team architect, enterprise architecture leader, fractional or interim CISO, and technology program lead for regulated or high-trust environments.
What to look for
Role-level evidence is strongest for Microsoft Entra ID / Azure AD, Active Directory, PIM/JIT, Conditional Access, FIDO/MFA, federation, RADIUS, PKI, HYOK/BYOK-style key-control decisions, ServiceNow GRC/change integration, and custom policy guardrails for AI/tool systems. Broader IAM vocabulary is preserved in the skills inventory, but the work-history pages separate proven ownership from platform familiarity.
Identity and privileged access
Entra ID, Active Directory, PIM, Conditional Access, MFA, B2C/CIAM patterns, Okta and Ping support, privileged-account cleanup, access reviews, and executive-account protection.
Cloud and platform security
Azure landing zones, hybrid cloud, cloud security standards, policy patterns, private endpoints, key-management decisions, architecture review libraries, and regulated adoption paths.
AI safety and guardrails
Deterministic controls, model-agnostic orchestration, audit trails, prompt-injection evaluation, human approval paths, immutable attribution, and safe AI-assisted delivery practices.
Security operations and governance
SIEM/SOAR/SASE evaluation, continuous red-team validation, ServiceNow GRC, control evidence, dashboards, vulnerability remediation, and operational cadence design.
Edge and application security
WAF, DDoS, anti-bot and anti-fraud patterns, REST and GraphQL API security, secure SDLC, policy as code, CI/CD governance, and high-demand internet-facing systems.
Executive due diligence
RFP leadership, investment shaping, cost and risk tradeoffs, board-ready roadmaps, architecture decision records, and translation between executives, engineers, governance teams, and operators.
Work worth discussing
Cybersecurity modernization
LACERA security maturity and privileged access overhaul
Role: Senior-most cybersecurity architect and engineering lead under the CISO in a regulated public-pension environment.
What changed: Eliminated 45 standing privileged accounts, deployed continuous red-team validation, integrated ServiceNow GRC and change management, and helped move the operating model from reactive alert handling into daily risk reduction.
Enterprise cloud security
Wells Fargo cloud security standardization
Role: Cybersecurity architect helping unblock standardized public-cloud adoption in a regulated financial environment.
What changed: Validated secure architecture patterns across 128 cloud resource provider types, increased review throughput from 3-12 approvals per month to 40-50 per week, and shaped Azure/GCP third-party-risk decisions.
Microsoft escalation and identity
Global customer engineering and identity remediation
Role: Microsoft Global Tech Team Senior Customer Engineer serving 37 dedicated accounts across Fortune 500, public-sector, internal, and high-technology customers.
What changed: Led post-containment identity remediation after ransomware, supported high-visibility media technology operations around the 2021 Olympic Games, diagnosed a global Storage Spaces Direct defect, and authored reusable Microsoft assets.
Hybrid identity lineage
Federation, PKI, and directory consolidation before the labels changed
Role: Consulting and infrastructure architecture work across banking, managed services, education, and regulated customer environments.
What changed: Delivered Ping/Azure AD MFA with RADIUS continuity during a bank-wide remote-work transition, consolidated a 27-forest Microsoft 365 identity estate, implemented HSM-backed Enterprise PKI and RADIUS certificate templates, and earlier moved six Kerberos realms into one AD forest.
AI systems safety
Deterministic guardrails for AI-assisted delivery
Role: Founder and principal architect for model-agnostic tooling spanning application generation, DevOps orchestration, document conversion, data normalization, and infrastructure deployment.
What changed: Designed explicit guardrails, approval paths, and immutable attribution so AI-assisted work can remain auditable, portable, and resistant to silent bypasses.
MLB and sports-enterprise relevance
For MLB central and club technology roles, the relevant security story is high-demand public platforms, identity, edge protection, analytics trust, game-day operating discipline, cloud reliability, and secure development practices that do not slow the business to a crawl. The sports context is supported by Fumaro Sports, entertainment-production discipline, Olympic-broadcaster support, and current MLB-targeted role research without overstating prior club employment.