Virtual resume view

Technology Resume

Twenty-two years of technology work for teams that needed difficult systems to become reliable, secure, understandable, and useful under real constraints.

Resume at a glance

Roles
16 public role records selected for Standard Technology Resume.
Evidence
128 structured evidence points, selected and deduped by claim family.
Source
MDX renders this page; adjacent JSON artifacts beside the role MDX files supply the claims.

Special Profiles

Focused resume lenses

Each web resume renders selected variants from the same structured evidence records as the full technology resume. The profile pages remain the canonical artifact index.

Identity Management Resume

Identity Access, Privileged Access, Information Protection

AI Systems and Agent Architecture Resume

Ai Systems Safety, Ai Guardrails, Data Platforms

Cybersecurity Leadership Resume

Cybersecurity Architecture, Executive Technology Leadership, Cloud Security

Sports and MLB Technology Resume

Sports Technology, Sports Analytics, Product Research

Entertainment and Live Venue Technology Resume

Entertainment Production, Availability Resilience, Service Delivery

Product Engineering and Product Design Resume

Technical Product Design, Product Research, Technical Ux

Enterprise and Cloud Architecture Resume

Enterprise Architecture, Cloud Infrastructure, Cloud Security

Work Experience

Selected professional experience

Reverse-chronological role history selected from canonical structured resume evidence.

Scoria Software Solutions | March 2025 – Present

Founder & Principal Software Architect

  • Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence, producing clearer audit trails, faster incident response (seconds or milliseconds instead of minutes), and a 1–2 order-of-magnitude reduction in attempts to bypass safety controls.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
  • Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
  • Architected Fumaro Sports with Azure Databricks as the analytics backend showcase, using lakehouse-oriented data engineering patterns to support predictive sports intelligence, model-ready feature preparation, context-aware analytics, and governed human-in-the-loop release controls.
  • Designing Fumaro Sports around analyst and scout review, feedback capture, telemetry-aware runtime logging, staged private beta evaluation, and human-in-the-loop release controls so sports tools can improve without hiding uncertainty from users.
  • Building Fumaro Sports as a live sports analytics proof of concept with a public multi-sport Next.js runtime, strict TypeScript, PostgreSQL-backed routes, Azure Databricks analytics, and MLB-first decision surfaces for governed evaluation.
  • Created the DevOps orchestration engine with built-in AI-development guardrails that reduced technical debt 65–95% of the codebase and compressed feature and patch delivery from weeks or months to days or hours, supporting daily stable releases at one client.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Open full role

Bedrock Information Systems LLC | January 2019 – Present

Principal Architect

  • Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.
  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Led a Microsoft Teams implementation for a municipal customer that expanded into a five-year city-wide AI adoption roadmap, aligning 26 major IT priorities across modernization, security enhancement, compliance enforcement, user training, AI adoption, and legacy phase-out; prioritized Purview sensitivity labeling and DLP as immediate data-protection work, projected initial ROI within 6–8 months and full ROI by year three, with seven-figure annual savings expected from year four onward.
  • Implemented automated DLP and information-protection controls that detected a public-sector CJIS data exposure within five minutes of availability and applied extreme encryption and protection through Purview, including to copies stored outside Microsoft 365, while preserving NDA-safe disclosure of the incident.
  • Built and deployed a custom microfilm digitization tool that converted more than a century of legacy government records (dating to the 1800s) into OCR/ICR-optimized, PDF/A-compliant digital assets with full metadata in a single 21-hour continuous run—collapsing an estimated 10-year multi-person full-time effort—and reduced pre-digital public records request turnaround from weeks or months to days or hours.
  • Applied structured guardrails and deterministic processes to AI-assisted development, enabling non-developer infrastructure and application engineers to safely expand into development work; accelerated project timelines 50–75%, allowed teams of 2–3 to deliver what previously required teams of 6–12, eliminated engineer overtime (previously 50–60 hours/week), and increased per-engineer revenue and profitability while expanding overall market footprint without added headcount.
  • Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Principal Cybersecurity Architect

  • Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
  • Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
  • Paired Pentera (red team) with the Microsoft Defender / Purview suite (blue team) to institutionalize regular red-team / blue-team war-game exercises, producing a two-order-of-magnitude drop in Defender events (from hundreds of thousands to thousands per week across the enterprise) and closing nearly all historical vulnerabilities within one quarter of joint operation.
  • Built DLP alert investigation and remediation workflows that connected Purview, Defender, GRC, and change-management evidence, giving compliance and security stakeholders practical dashboards for policy effectiveness, false-positive reduction, and audit readiness.
  • Integrated security tooling and processes into existing fire-drill and disaster-recovery exercises, creating a unified operational cadence that enabled full business continuity during a real high-privilege account lockdown with zero impact to internal users, external consumers, or public-facing services.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Open full role

Wells Fargo Bank | July 2022 – July 2023

Senior Cybersecurity Architect

  • Led the Service Enablement Task Force that validated and approved secure architecture and infrastructure blueprints across 128 cloud resource provider types, creating a library of pre-approved patterns that allowed thousands of downstream business applications to adopt standardized designs and largely eliminated the need for custom infrastructure architecture.
  • Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
  • Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
  • Developed SDLC policy-enforcement roadmaps that shifted the organization from an exception-driven culture to standardized architecture selection; application teams’ effort dropped from dozens of hours spread over weeks or months to roughly one to two hours of asynchronous work, while security and infrastructure teams achieved substantially higher output volume with near-universal consistency of results.
  • Operated as a cross-functional cybersecurity resource influencing groups of 12 to 100+ engineers, GRC specialists, product teams, and cryptography experts; drove the senior-most executive decision to select the cloud provider and compel organization-wide adoption, eliminating longstanding resistance and entire categories of security and compliance risk across tens of thousands of endpoints and approximately 12,000 ATMs globally.
  • Conducted comparative cybersecurity analysis of Azure and Google Cloud Platform services, identifying provider and platform gaps and converting the findings into closure plans that informed the bank’s cloud-security control model.
  • Developed standardized compliance-scoring approaches for cloud services, making architecture and configuration review more consistent, repeatable, reliable, and quantifiable across teams that previously evaluated risk through bespoke review paths.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints for deployment standardization, reducing configuration drift and making security requirements easier to enforce through repeatable infrastructure-as-code patterns.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Open full role

Microsoft Corporation | March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

  • Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
  • Averaged one to two critical-situation escalations per week (frequently joining proactively); most notably diagnosed a Windows Server 2016 Storage Spaces Direct (S2D) bug that was causing cascading SQL Always-On, Exchange Online, Remote Desktop Services, DFS, and failover-cluster outages; the resulting global patch resolved long-standing, multi-year issues for six of twelve dedicated customers and every organization running high-availability Windows Server workloads on S2D worldwide.
  • Participated in the critical remediation team for a major global service outage at a hyperscale technology company, helping identify an infrastructure-as-code workflow that triggered the event, providing guidance for the rollback and permanent fix, and contributing to both customer-facing and Microsoft-internal postmortems; the internal postmortem drove backend process changes that improved geo-resiliency protections against rapid global rollouts and influenced standardized geo-resiliency and disaster-recovery planning for Premier and Unified Support customers.
  • Delivered customized Well-Architected Framework engagements for the complex minority of customers whose scale or operating model exceeded the standard program (ten of twelve dedicated accounts), driving nearly nine figures in multi-year Azure commitments (including one customer above eight figures), Azure Reserve Instance purchases, and multiple Unified Support renewals and expansions.
  • Authored and published reusable PowerShell and ARM-template assets to Microsoft’s public GitHub repositories and learn.microsoft.com (cybersecurity, identity, Azure infrastructure, Modern Workplace, and Microsoft 365); these assets were systematically linked from the AskJake.ms technical blog, which reduced repeat customer request volume and freed capacity for higher-value escalation and architecture work.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Senior Cybersecurity Architect

  • Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap spanning eight domains that was formally adopted by the CISO, IT leadership, and the Board; established a NIST CSF baseline at Level 1 with a formal target of Level 3 and secured a funded multi-year program that immediately opened three new security engineering roles.
  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
  • Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
  • Established the initial identity, access, and visibility foundations that produced the organization’s first clear view of previously unknown shadow IT and high-risk access patterns, and initiated five formal RFP processes for core platforms (including ServiceNow, PMO tooling, and Microsoft security solutions) that locked in the next phase of the maturity program.
  • Led architecture and planning for the Secure Productive Enterprise initiative, defining greenfield landing-zone and core-service direction across Active Directory, networking, Microsoft 365, and Azure so later implementation work had a coherent foundation.
  • Created the strategic roadmap for modernizing identity and endpoint provider/management systems, aligning cloud enablement, business-service migration, and data-protection requirements before individual tool projects were allowed to drive the architecture.
  • Planned data and information-security compliance controls for future business services, ensuring modernization work was evaluated against required security standards instead of only short-term remote-work stabilization.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

City National Bank | March 2020 – July 2020

Vice President, Azure Infrastructure

  • Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
  • Drove Azure foundational-infrastructure strategy with enterprise engineering teams, producing roadmap and design guidance for virtual networks, identity, access management, monitoring, and application-team migration planning.
  • Reviewed infrastructure design documents and guided application teams through cloud migration, service refactoring, post-cutover cost control, and secure-access considerations, reducing the risk of one-off designs during a compressed transformation window.
  • Implemented standardized project and service-management practices for cloud migration work, giving technical staff and business units clearer visibility into deliverables, risks, adoption support, and operational readiness.
  • Consulted with security and compliance stakeholders on zero-trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster-recovery considerations, aligning remote-work urgency with regulated banking control expectations.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Open full role

Molina Healthcare | February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

  • Architected and led the Azure Landing Zone and hybrid-cloud migration program for a healthcare environment of approximately 16,000 production servers (≈40,000 total environments including non-production), more than 630 business applications, and a data footprint exceeding 2 petabytes; completed migration of roughly one-quarter of the footprint within the year.
  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.
  • Authored the majority of the Infrastructure-as-Code and orchestration frameworks that provisioned and governed all Landing Zone resources (networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security) as well as the ongoing deployment and maintenance of the critical SQL Always On workload; integrated the frameworks into the organization’s existing Terraform processes so that operational teams experienced zero change to day-to-day maintenance and management, while end-to-end automated cutovers (including a perfectly clean production SQL Always On migration) required only human monitoring.
  • Treated security and compliance as first-class requirements from the outset, embedding HIPAA controls, comprehensive audit trails, and ready integration points for existing SIEM/SOAR tooling; the design received full security-team approval and satisfied 100 percent of the security organization’s stated requirements.
  • Led a combined delivery team of approximately twelve onshore and two dozen offshore Infosys consultants plus a core group of fifteen permanent Molina stakeholders, coordinating Infrastructure-as-Code work with application refactoring (including a significant SQL version upgrade) performed by team developers to make the critical workload cloud-native; the coordinated effort delivered a successful, clean migration of the organization’s most complex and business-critical application while maintaining influence across the full server, data-center, and application footprint.
  • Developed Secure Healthcare Cloud Program patterns from the engagement’s lessons, turning migration, governance, automation, security, and communication practices into reusable material for future healthcare organizations seeking equal-or-better security in public or hybrid cloud.
  • Wrote a proprietary PowerShell module for virtual-machine migration orchestration, reducing repetitive migration work and giving teams a more consistent control plane for lift-and-shift execution.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Open full role

Coretek Services | August 2018 – January 2019

Senior Solutions Architect

  • Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a merger, reducing fragmentation in identity and email operations.
  • Migrated 10,000 on-premises mailboxes from Exchange 2007/2013 to Exchange Online in seven weeks with less than 2% failure and minimal user impact, converting a high-risk mail migration into a controlled execution pattern.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
  • Consolidated user and desktop infrastructure after 19 company acquisitions, preserving user attributes and configurations while standardizing Active Directory, print, DNS, DHCP, VPN, and MPLS patterns.
  • Created a Microsoft 365 managed-service program and onboarded a pilot customer with more than 10,000 seats, turning project delivery lessons into a repeatable service offering.
  • Architected a Project Online PMO solution with automated onboarding, offboarding, and access provisioning, improving project governance without adding manual administrative overhead.
  • Designed a secure, highly available file-sharing and virtual-desktop data solution for collaborative media and digital content, balancing performance-to-cost ratio, availability, patching, backup, and disaster-recovery requirements.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Obsidian Availability Solutions | September 2016 – December 2018

Principal Consultant

  • Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.
  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
  • Implemented hybrid-cloud, productivity, collaboration, communication, identity, and security systems across customer environments, including Azure subscriptions, virtual networks, Hyper-V, System Center, Exchange, Skype, SharePoint, Teams, and security policies.
  • Led a 16,000+ user Skype for Business Online and Cloud PBX migration across 67 sites, consolidating more than 100 telecom contracts while delivering end-user training and unified communications support.
  • Implemented an Enterprise PKI hierarchy with an offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening authentication and regulatory-aligned identity controls.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for general, SCCM, and RADIUS use cases, turning certificate-based authentication from a one-time infrastructure build into an operable identity-control service.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Open full role

Orion Technology Services | June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

  • Served as lead architect and project manager for a 12-month ITIL implementation that overhauled managed-services offerings, improved SLA discipline, streamlined onboarding, and increased support-staff efficiency.
  • Designed service-operation processes for incident, event, standard request, identity and access, and problem management, converting reactive support patterns into more consistent managed-service delivery.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change-management workflows, improving the data foundation for shared managed-services tracking across provider and customer systems.
  • Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a SharePoint environment with more than 150 site collections, helping customers move collaboration content into more governable cloud structures.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, visibility, and portfolio discipline for customer delivery teams.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, giving customers hybrid infrastructure options with clearer disaster-recovery and availability patterns.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, helping the Network Operations Center detect integration and automation failures before they undermined service commitments.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new processes and reducing knowledge gaps across audiences with mixed technical depth.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Detroit IT / Core 3 Solutions | June 2014 – February 2015

Senior Systems Administrator

  • Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.5 TB of Windows file services to SharePoint Online, and Skype for Business for internal and external communication.
  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
  • Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.
  • Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving visibility into active customer work and enabling earlier escalation of delivery concerns.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

Detroit Country Day School | June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

  • Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.
  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported school-issued and sponsored software adoption, including Office 365 and classroom solutions, with account migration assistance, user training, and knowledge resources that reduced adoption friction.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
  • Collaborated with academic and administrative departments to identify technology needs, improving the alignment between classroom support, operational productivity, and educational delivery.
  • Managed implementation work for student-information system improvements, strengthening data accessibility for staff and faculty who depended on accurate academic and administrative records.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
Open full role

University of Michigan, Information & Technology Services | June 2011 – September 2012

IT Engineer

  • Built a University of Michigan School of Music, Theatre, and Dance production background across 18 theatre productions from 2011-2015, spanning lighting design, sound design, stage management, assistant master electrician work, light-board operation, sound-board operation, live sound, and music-production training.
  • Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.
  • Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
  • Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
  • Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
Operations/service deliveryTraining/knowledge managementEntertainment ProductionEntertainment Live Venue TechnologyEntertainment ProductionAvailability Resilience
Open full role

Battery Giant / Energy Products | January 2007 – December 2010

IT Manager

  • Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.
  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after assuming responsibility for availability and recovery systems.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Open full role

Detroit Country Day School | June 2005 – August 2006

Systems Analyst

  • Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
  • Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.
  • Led incident, request, and change-management practices for end-user systems during early identity and endpoint modernization, giving users a clearer path for support while the environment shifted from legacy platforms.
  • Developed security-focused service workflows and endpoint protocols for classroom technology, improving prioritization, escalation, and access-control practices in a high-touch academic setting.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture
Open full role

Education

Education

The University of Michigan, Ann Arbor, MI

  • College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
  • School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

Detroit Country Day School, Beverly Hills, MI

  • High School Diploma | College Preparatory Curriculum

Skills

Selected skills

Skills are selected from shared JSON skill records referenced by the selected role evidence.

AI Systems, Safety & Applied LLM Engineering

Deterministic guardrails (Expert), immutable attribution (Expert), continuous red-team/blue-team exercises (Expert), adversarial safety-control testing (Expert), prompt-injection and jailbreak evaluation (Expert), model evaluation frameworks (Expert), secure LLM deployment patterns (Expert), Azure AI Foundry (Expert), AI-assisted development guardrails (Expert), Model- and platform-agnostic XLM (LLM/SLM) orchestration (Advanced), MCP toolkits (Advanced), Ollama/local models (Advanced)

Product Design, Technical UX & Sports Decision Support

Stakeholder interviews (Expert), workflow mapping (Expert), information architecture (Expert), product requirements (Expert), cross-functional design reviews (Expert), technical-user experience (Expert), product strategy (Expert), design-to-production delivery (Expert), executive-ready tradeoff framing (Expert), design systems (Advanced), component systems (Advanced), baseball analytics (Advanced)

Soft Skills & Cross-Functional Practice

Executive communication (Expert), stakeholder alignment (Expert), technical mentoring (Expert), non-technical stakeholder training (Expert), project and program coordination (Expert), vendor evaluation (Expert), RFP demonstration leadership (Expert), proof-of-concept facilitation (Expert), change adoption (Advanced)

Azure Data, Analytics & AI Platforms

Azure Databricks (Expert), Databricks lakehouse architecture (Expert), data landing zones (Expert), governed analytics platforms (Expert), reusable reference architectures (Expert), workload modernization (Expert), production readiness (Expert), Cloud Adoption Framework (Expert), Azure Well-Architected Framework for analytics and AI workloads (Expert), Data engineering (Advanced), feature preparation (Advanced), lakehouse-oriented sports analytics (Advanced)

Identity, Access & Cryptography

Microsoft Entra ID / Azure AD (Expert), Entra ID Governance (Expert), access reviews (Expert), entitlement management (Expert), Privileged Identity Management (PIM) (Expert), Just-in-Time access (Expert), Conditional Access (Expert), FIDO / MFA (Expert), workload identities (Expert), managed identities (Expert), service principals at scale (Expert), RBAC and least-privilege design (Expert)

Cybersecurity Architecture, Detection & Operations

Cybersecurity architecture (Expert), cloud security architecture (Expert), Zero Trust architecture (Expert), Microsoft Defender (Expert), Microsoft Purview (Expert), SIEM (Expert), SOAR (Expert), SASE (Expert), XDR and vulnerability management (Expert), endpoint protection (Expert), incident response (Expert), post-incident remediation (Expert)

Microsoft Purview, DLP & Information Protection

Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints (Expert), Teams DLP (Expert), sensitivity labels (Expert), auto-labeling (Expert), retention labels and policies (Expert), data classification (Expert), sensitive-data discovery and mapping (Expert), DLP policy authoring (Expert), AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization (Expert)

Cloud, Network & Enterprise Infrastructure

Microsoft Azure (Expert), private cloud architecture (Expert), Azure Landing Zones (Expert), Azure Policy (Expert), Landing Zone Accelerator patterns (Expert), hybrid cloud architecture (Expert), Azure Well-Architected Framework (Expert), geo-resiliency (Expert), high-availability patterns (Expert), vendor-agnostic infrastructure schemas (Expert), Google Cloud Platform (GCP) (Advanced), Azure / GCP security and third-party-risk comparisons (Advanced)