Technology Case Studies
Public versions of private work
These summaries are written for screening and interview preparation. They stay high-level where client details are protected, but each one keeps the useful hiring question visible: what was hard, what Jake did, and what changed because of the work.
Published summaries
AI systems architecture
Deterministic Guardrails & Model-Agnostic LLM Orchestration Toolkit
Role: Founder and principal architect for an AI-assisted engineering toolkit spanning application generation, DevOps orchestration, document conversion, data normalization, and infrastructure deployment.
Constraints: The work had to remain model-agnostic, auditable, platform-portable, and resistant to silent safety-control bypasses while still being practical enough for customer POCs and production workflows.
Approach: Built deterministic guardrails, codified approval points, immutable attribution, standardized data contracts, and reusable engines that separate model output from deployment authority.
Outcomes: Public metrics include 60-90% token reduction in document-generation workflows, 65% cloud-cost reduction in one customer environment, 25-30% lower interface code through shared components, and POC cycles compressed from months to weeks.
Sports decision support
Fumaro Sports Baseball Operations Decision-Support Product System
Role: Founder and principal architect actively developing Fumaro Sports as a sports-first predictive intelligence product system with MLB-first data surfaces, user feedback loops, and Azure Databricks supporting the analytics backend.
Constraints: The platform needs governed feature preparation, context-aware sports analytics, human-in-the-loop release controls, and clear separation between direct statistical signals and Second Order contextual factors.
Approach: Designed decision-support boundaries around analyst review, scout/evaluator context, telemetry-aware operations, model-ready analytics preparation, and lakehouse-oriented data patterns that can be explained to both technical and product stakeholders.
Outcomes: Public outcomes include MLB-first decision surfaces, Databricks-backed analytics, multi-sport runtime direction, feedback-aware operations, and governed predictive-intelligence workflows.
Cybersecurity modernization
Continuous Red-Team Capability and Privileged Access Overhaul
Role: Senior-most technical authority for a dedicated cybersecurity engineering team in a regulated public retirement environment.
Constraints: Security improvement had to occur without disrupting public-facing services, internal operations, governance workflows, or continuity exercises.
Approach: Eliminated standing privileged access through Entra PIM, paired continuous red-team testing with Defender / Purview operations, integrated security into change management, and made posture visible through dashboards.
Outcomes: Public metrics include 45 standing privileged accounts eliminated, critical and high findings closed inside the first month of change cycles, residual findings reduced to an average of 10-12 active items, and a two-order-of-magnitude reduction in Defender event volume.
Enterprise cloud security
Enterprise Cloud Security Standardization at Scale
Role: Cybersecurity architect helping unblock standardized public-cloud adoption in a highly regulated financial environment.
Constraints: Cloud adoption required repeatable patterns, security review scale, audit-ready cryptographic control, and executive-level agreement across resistant stakeholder groups.
Approach: Validated secure architecture patterns across cloud resource provider types, advanced policy-enforcement plans, and designed Hold-Your-Own-Key cryptography with external key providers.
Outcomes: Public metrics include 128 cloud resource provider types covered, review throughput increased from 3-12 application approvals per month to 40-50 per week, and third-party cryptographic dependencies removed for the relevant cloud adoption path.
Public-sector modernization
Public-Sector Modernization and AI Adoption Plan
Role: Principal architect for Bedrock-led modernization, compliance, records, AI adoption, and delivery work across public-sector and regulated customers.
Constraints: Work needed to respect budget limits, public records obligations, training needs, legacy systems, CJIS and NIST expectations, and small-team delivery realities.
Approach: Established repeatable security baselines, built audit automation, delivered Teams and modernization plans, applied deterministic AI-assisted development practices, and built tooling for high-volume records digitization.
Outcomes: Public metrics include municipal audit effort reduced from 40-120 staff hours to under 30 minutes, a 21-hour continuous microfilm digitization run replacing an estimated decade of manual effort, and a public-sector MDM migration completed in 45 days with one part-time engineer.
Additional public summaries
Global Identity Remediation and Critical Infrastructure Patch
Role: Senior Customer Engineer on Microsoft’s Global Tech Team, serving Fortune 500, public-sector, internal, and high-technology customers where normal escalation paths were exhausted.
Constraints: Public detail must avoid customer names and protected incident specifics while preserving the useful hiring signal: identity remediation, critical infrastructure diagnosis, customer engineering, and product-group influence.
Approach: Led post-containment identity remediation after a ransomware event, deployed stronger MFA and credential controls, diagnosed a Windows Server Storage Spaces Direct defect behind recurring high-availability failures, and published reusable customer engineering assets.
Outcomes: Public outcomes include global identity hardening across tens of thousands of users and endpoints, a Windows Server patch that resolved multi-year S2D-related outages for multiple dedicated customers and broader high-availability workloads, and reusable public Microsoft assets that reduced repeat support demand.
Hybrid Identity, Federation, and Certificate-Based Authentication
Role: Principal and senior consulting architect across Microsoft 365, banking remote access, managed services, PKI, and education-sector directory modernization.
Constraints: The work predated or crossed today’s IGA vocabulary, so the public evidence is expressed through legacy identity primitives: forests, realms, federation, RADIUS, certificates, AD CS, Azure AD tenants, and user/profile continuity.
Approach: Consolidated multi-forest identity estates, preserved user attributes and passwords during Microsoft 365 migrations, paired Ping Federate with Azure AD and Authenticator MFA for bank remote access, and designed HSM-backed Enterprise PKI with RADIUS certificate templates.
Outcomes: Public evidence includes 16,000 users consolidated from 27 Active Directory forests, 10,000 mailboxes migrated in seven weeks with less than 2% intervention, bank-wide remote-work identity continuity during COVID, PKI for 6,000+ users and devices, and six Kerberos realms consolidated into one AD forest.
Azure Landing Zone and Mission-Critical SQL Always On Migration
Role: Senior Solutions Architect through Infosys for a regulated healthcare cloud migration and landing-zone program.
Constraints: The work involved HIPAA-aligned controls, a large blended delivery team, petabyte-scale data, hundreds of applications, and a business-critical SQL Always On workload that needed a clean production cutover.
Approach: Designed Azure Landing Zone patterns, hybrid networking, Terraform-integrated infrastructure automation, security control integration, and a repeatable migration path by moving the most complex SQL workload first.
Outcomes: Public evidence includes roughly 16,000 production servers, more than 630 applications, over 2 PB of data, a 450 TB SQL Always On cluster with 2.7 TB daily transactions, about one quarter of the footprint migrated in the year, and a first production cutover that established a reusable pattern.
Redaction boundary
These writeups intentionally omit customer-sensitive architecture, incident detail, diagrams, screenshots, and internal process artifacts. Deeper evidence can be discussed only when confidentiality constraints, audience, and redaction boundaries are confirmed.