Special resume view

AI Systems and Agent Architecture Resume

AI systems, agent architecture, deterministic guardrails, governed data platforms, and practical deployment patterns for teams that need useful AI without losing control of the operating environment.

Resume at a glance

Roles
16 public role records selected for AI Systems and Agent Architecture Resume.
Evidence
128 structured evidence points, selected and deduped by claim family.
Source
MDX renders this page; adjacent JSON artifacts beside the role MDX files supply the claims.

Work Experience

Selected professional experience

Profile-matched evidence using the best available variant for this resume lens.

Scoria Software Solutions | March 2025 – Present

Founder & Principal Software Architect

  • Architected deterministic agent guardrails with codified approval paths, immutable attribution, and explicit divergence controls, giving AI-enabled tools auditable safety boundaries instead of relying on prompt intent alone.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Built the XLM engine and MCP toolkit family as a model-agnostic agent architecture that converts a single prompt into deterministic multi-platform application stacks, compressing early-adopter POC cycles from months to weeks.
  • Designed model- and platform-agnostic routing across Azure AI Foundry, Ollama, local models, consumer apps, and enterprise platforms, improving portability while one customer reduced Azure spend 65% and cut latency from 3–5 seconds to 10–150 ms.
  • Architected Fumaro Sports on Azure Databricks lakehouse patterns for model-ready feature preparation, predictive analytics, and governed human-in-the-loop release controls, translating sports intelligence into a reusable AI data-platform pattern.
  • Designed Fumaro Sports evaluation loops around analyst review, scout feedback, telemetry-aware runtime logging, staged beta validation, and human-in-the-loop release governance so model output can improve without concealing uncertainty from users.
  • Building Fumaro Sports as a live sports analytics proof of concept with a public multi-sport Next.js runtime, strict TypeScript, PostgreSQL-backed routes, Azure Databricks analytics, and MLB-first decision surfaces for governed evaluation.
  • Created a DevOps orchestration engine with AI-development guardrails that reduced technical debt across 65–95% of the codebase and compressed feature and patch delivery from weeks or months to days or hours.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Open full role

Bedrock Information Systems LLC | January 2019 – Present

Principal Architect

  • Established NIST CSF 2.0 Tier 3 (Repeatable) as a governance substrate for municipal AI adoption, turning control evidence, compliance workflows, and audit reporting into repeatable architecture guardrails before introducing higher-risk automation.
  • Designed Microsoft 365 information-protection and classification guardrails for public-sector AI readiness, using Purview sensitivity labels, DLP patterns, retention controls, and regulated-data schemas to keep CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, and public-safety data governed before automation.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Expanded a municipal Microsoft Teams implementation into a five-year city-wide AI adoption and modernization roadmap, sequencing 26 priorities across security, compliance, user training, data protection, legacy phase-out, and ROI milestones so AI work rested on governed collaboration and information-protection foundations.
  • Implemented automated DLP and information-protection controls that detected a public-sector CJIS data exposure within five minutes of availability and applied extreme encryption and protection through Purview, including to copies stored outside Microsoft 365, while preserving NDA-safe disclosure of the incident.
  • Built a government records digitization workflow that converted century-scale microfilm into OCR/ICR-optimized, PDF/A-compliant assets with full metadata, creating a searchable data substrate for future analytics and AI-assisted public-records workflows without overstating autonomous system deployment.
  • Operationalized deterministic guardrails for AI-assisted development so infrastructure and application engineers could use agentic tooling within controlled delivery patterns, accelerating timelines 50–75% while preserving team capacity, auditability, and release discipline.
  • Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Principal Cybersecurity Architect

  • Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
  • Converted privileged administration into deterministic Entra PIM, Just-in-Time access, M-of-N approval, break-glass monitoring, and change-evidence flows, creating the auditable access substrate future security automation or agent workflows would need before acting on high-risk systems.
  • Tuned Purview DLP, sensitivity-labeling, retention, and compliance controls for regulated data categories, creating deterministic data-classification and access-governance foundations that support safe AI and agent platform adoption without exposing sensitive information.
  • Validated the privileged-access and monitoring substrate during a real high-value phishing compromise, proving that governed identity controls, telemetry, and lockdown workflows could contain risk with zero data extraction, lateral movement, or business impact before any higher-risk automation depended on them.
  • Operationalized continuous adversarial control testing with Pentera and Defender correlation, turning hundreds of findings into a governed remediation feedback loop that validated security guardrails, zero-day response, and change-cycle execution under production constraints before automation could safely consume those signals.
  • Institutionalized continuous red-team and blue-team exercises across Pentera, Defender, and Purview, using adversarial feedback loops and telemetry reduction to harden deterministic security controls before higher-risk automation or agent workflows could rely on them.
  • Connected Purview, Defender, GRC, and change-management evidence into DLP investigation workflows, giving stakeholders audit-ready classification, policy-effectiveness, false-positive, and remediation signals needed before governed automation or agent-assisted security workflows can be trusted.
  • Integrated security tooling and processes into existing fire-drill and disaster-recovery exercises, creating a unified operational cadence that enabled full business continuity during a real high-privilege account lockdown with zero impact to internal users, external consumers, or public-facing services.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Open full role

Wells Fargo Bank | July 2022 – July 2023

Senior Cybersecurity Architect

  • Led governed architecture review across 128 cloud resource provider types, turning bespoke infrastructure decisions into reusable control-plane patterns for regulated cloud platforms, including future policy-bound AI, agent, and data workload foundations that still require cybersecurity and GRC gates.
  • Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
  • Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
  • Developed SDLC policy-enforcement roadmaps that replaced exception-driven cloud architecture review with standardized control selection, creating a repeatable guardrail operating model for governed AI, agent-tool, and data-platform delivery without implying direct AI deployment.
  • Operated as a cross-functional cybersecurity resource influencing groups of 12 to 100+ engineers, GRC specialists, product teams, and cryptography experts; drove the senior-most executive decision to select the cloud provider and compel organization-wide adoption, eliminating longstanding resistance and entire categories of security and compliance risk across tens of thousands of endpoints and approximately 12,000 ATMs globally.
  • Conducted comparative Azure and Google Cloud security analysis, translating provider gaps into closure plans and control-model decisions that establish governed multi-cloud foundations for data, AI-platform, and agent-tool evaluation.
  • Developed standardized compliance scoring for cloud services and resource-provider gaps, giving security, infrastructure, and GRC teams a quantifiable evidence model for governed AI/data workload readiness, agent-tool review, closure planning, and audit-defensible platform decisions.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints so security requirements could be encoded as repeatable cloud landing patterns, reducing drift and creating governed foundations suitable for future AI, agent-service, and data workloads.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Open full role

Microsoft Corporation | March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

  • Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
  • Advised enterprise Microsoft 365 customers on governed information-protection and DLP control patterns across Purview, sensitivity labeling, regulated-data discovery, and policy tuning, grounding agent and AI governance claims in deterministic data-access, classification, and compliance controls rather than model-specific promises.
  • Converted repeated customer-engineering demand into reusable delivery programs, engineer mentoring, and product-group feedback loops, an AI-substrate pattern for turning field evidence into governed platform behavior without claiming direct model delivery.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
  • Averaged one to two critical-situation escalations per week (frequently joining proactively); most notably diagnosed a Windows Server 2016 Storage Spaces Direct (S2D) bug that was causing cascading SQL Always-On, Exchange Online, Remote Desktop Services, DFS, and failover-cluster outages; the resulting global patch resolved long-standing, multi-year issues for six of twelve dedicated customers and every organization running high-availability Windows Server workloads on S2D worldwide.
  • Helped remediate a hyperscale service outage by tracing an infrastructure-as-code workflow to the failure path, guiding rollback and permanent-fix planning, and turning postmortem evidence into safer geo-resiliency and rollout controls that map directly to deterministic agent/tool governance patterns.
  • Delivered custom Azure Well-Architected engagements for complex enterprise customers whose scale exceeded standard guidance, translating cloud, data, resilience, governance, and platform-engineering constraints into reference architecture decisions that supported major multi-year Azure commitments.
  • Published reusable PowerShell, ARM-template, GitHub, Microsoft Learn, and field-delivery assets that converted repeated Azure infrastructure, Microsoft 365, identity, and cybersecurity escalation patterns into governed tooling and reference guidance for customer engineers and product groups.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Senior Cybersecurity Architect

  • Architected a board-adopted security maturity roadmap across eight domains, establishing governance, control evidence, identity, endpoint-visibility, and secure-delivery foundations that later AI and automation programs would need before trusted rollout.
  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
  • Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
  • Established the initial identity, access, and visibility foundations that produced the organization’s first clear view of previously unknown shadow IT and high-risk access patterns, and initiated five formal RFP processes for core platforms (including ServiceNow, PMO tooling, and Microsoft security solutions) that locked in the next phase of the maturity program.
  • Led architecture and planning for the Secure Productive Enterprise initiative, defining greenfield landing-zone and core-service direction across Active Directory, networking, Microsoft 365, and Azure so later implementation work had a coherent foundation.
  • Created a modernization roadmap that aligned identity, endpoint management, cloud enablement, business-service migration, and data-protection requirements before platform tooling could shape the control architecture for automation-ready services.
  • Planned data and information-security compliance controls for future business services, grounding modernization decisions in classification, protection, and control-evidence requirements before higher-trust automation or AI-adjacent workflows could be considered safe.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

City National Bank | March 2020 – July 2020

Vice President, Azure Infrastructure

  • Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
  • Drove Azure foundational-infrastructure strategy across virtual networks, identity, access management, monitoring, and application migration planning, establishing cloud substrate patterns that later AI and agent systems depend on for secure platform execution.
  • Reviewed cloud-migration design documents for service refactoring, post-cutover cost control, and secure-access considerations, translating architecture review into reusable guardrails for regulated platform delivery rather than one-off workload exceptions.
  • Implemented standardized project and service-management practices for cloud migration work, making deliverables, risks, adoption support, and operational readiness visible enough for governed platform delivery under regulated-bank constraints.
  • Consulted security and compliance stakeholders on zero trust, SIEM/SOAR, endpoint encryption, RBAC, and disaster recovery, preserving the control-plane guardrails that governed AI-enabled and agentic systems require before sensitive workflows can be automated safely.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Open full role

Molina Healthcare | February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

  • Architected a HIPAA-aligned Azure Landing Zone and hybrid-cloud migration model for roughly 16,000 production servers, 630 applications, and more than 2 PB of data, establishing the governed cloud, data, API, and automation substrate required before regulated AI systems can be trusted.
  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Sequenced the first major cloud workload around a 450 TB SQL Always On cluster with 2.7 TB of daily transactions and 12-15 SDLC environments, turning the highest-risk data platform into a repeatable migration pattern for governed analytics, automation, and future AI-adjacent workloads.
  • Authored Terraform-integrated Infrastructure-as-Code and orchestration frameworks for landing-zone resources, security guardrails, and SQL workload operations, creating deterministic platform controls and human-monitored cutovers that regulated data and AI systems need before higher-level automation is introduced.
  • Embedded HIPAA controls, audit trails, and SIEM/SOAR integration points into the landing-zone architecture, creating the deterministic governance, compliance evidence, and security-review gates required for regulated data platforms and AI-adjacent systems.
  • Led a combined delivery team of approximately twelve onshore and two dozen offshore Infosys consultants plus a core group of fifteen permanent Molina stakeholders, coordinating Infrastructure-as-Code work with application refactoring (including a significant SQL version upgrade) performed by team developers to make the critical workload cloud-native; the coordinated effort delivered a successful, clean migration of the organization’s most complex and business-critical application while maintaining influence across the full server, data-center, and application footprint.
  • Developed reusable secure-healthcare-cloud patterns from migration, governance, automation, auditability, security, and communication lessons, packaging the operating foundations regulated data and AI-adjacent programs need before system-specific implementation work begins.
  • Wrote a proprietary PowerShell migration-orchestration module that reduced repetitive lift-and-shift work and gave teams a consistent control plane for repeatable workload movement, a prerequisite operating pattern for governed data and AI-adjacent platform modernization.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Open full role

Coretek Services | August 2018 – January 2019

Senior Solutions Architect

  • Consolidated a 16,000-user merger environment into a single Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, establishing the identity and messaging control-plane substrate needed for governed cloud and future AI-enabled service adoption.
  • Converted a high-risk 10,000-mailbox Exchange Online migration into a controlled execution pattern with less than 2% failure, demonstrating the production-readiness discipline needed before AI-adjacent services depend on cloud collaboration data and identity continuity.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
  • Consolidated user and desktop infrastructure after 19 company acquisitions, preserving user attributes and configurations while standardizing Active Directory, print, DNS, DHCP, VPN, and MPLS patterns.
  • Turned Microsoft 365 project delivery lessons into a repeatable managed-service program for a 10,000-plus-seat pilot customer, creating an operating pattern for governed cloud adoption that can support later AI-enabled workplace services.
  • Architected Project Online onboarding, offboarding, and access provisioning automation, turning PMO role access into a repeatable governance pattern relevant to policy-bound agent and workflow systems.
  • Designed a secure, highly available file-sharing and virtual-desktop data solution for collaborative media and digital content, balancing performance-to-cost ratio, availability, patching, backup, and disaster-recovery requirements.
  • Trained administrators and champions to own cloud systems after production release, reducing dependency on project resources and strengthening the adoption model needed for governed AI-adjacent platform changes.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Obsidian Availability Solutions | September 2016 – December 2018

Principal Consultant

  • Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.
  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Built repeatable customer and tenant onboarding patterns for managed-services lifecycle entry, establishing the multitenant operating substrate and access-boundary discipline that secure agent and automation platforms later depend on.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
  • Implemented hybrid-cloud, identity, collaboration, communication, and security platforms across customer environments, creating the governed infrastructure substrate that future automation, data, and AI-adjacent systems require.
  • Led a 16,000+ user Skype for Business Online and Cloud PBX migration across 67 sites, consolidating more than 100 telecom contracts while delivering end-user training and unified communications support.
  • Implemented Enterprise PKI with offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, providing cryptographic trust fabric for secure identity, device, service, and automation control planes.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for SCCM, RADIUS, and general access use cases, turning certificate authentication into an operable security-control service.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Open full role

Orion Technology Services | June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

  • Led a 12-month ITIL managed-services overhaul that turned onboarding, SLA discipline, support efficiency, and service commitments into the kind of repeatable operating model needed for governed AI-adjacent platform services.
  • Designed incident, event, request, identity-access, and problem-management processes as reusable service-control patterns, establishing an operating substrate for governed automation and AI-adjacent platform workflows.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the cross-system service-data foundation that governed automation and AI-adjacent support agents would need.
  • Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into governable tenant structures that support knowledge, retrieval, and access-control patterns for AI-adjacent systems.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, portfolio visibility, and delivery governance patterns relevant to human-supervised AI and agentic work queues.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, establishing hybrid infrastructure and resilience patterns that later AI-adjacent platform services depend on.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, creating observability and failure-detection patterns that support dependable automation and AI-adjacent service operations.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new processes and reducing knowledge gaps across audiences with mixed technical depth.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Detroit IT / Core 3 Solutions | June 2014 – February 2015

Senior Systems Administrator

  • Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365, creating cloud collaboration, document, and identity substrate for later governed automation and agent-assisted knowledge workflows.
  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered VMware private-cloud VDI and sandbox environments for multiple software-development teams, supporting the isolated experimentation and platform reliability patterns later needed by complex AI and agent systems.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
  • Implemented availability-management and disaster-recovery practices for customer environments, strengthening the reliability substrate that governed automation and agent-supported service workflows depend on.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.
  • Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving visibility into active customer work and enabling earlier escalation of delivery concerns.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

Detroit Country Day School | June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

  • Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.
  • Developed SCCM-based imaging and systems-management practices for approximately 2,500 workstations, turning endpoint support into repeatable platform operations instead of manual one-off remediation.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported school-issued and sponsored software adoption, including Office 365 and classroom solutions, with account migration assistance, user training, and knowledge resources that reduced adoption friction.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
  • Collaborated with academic and administrative departments to identify technology needs, improving the alignment between classroom support, operational productivity, and educational delivery.
  • Managed student-information system improvements that strengthened data accessibility for staff and faculty, reinforcing the governed records substrate needed for later analytics and agent-assisted administrative workflows.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
Open full role

University of Michigan, Information & Technology Services | June 2011 – September 2012

IT Engineer

  • Led asset and configuration data work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships that preserved operational context for reliable service workflows and later agent-ready ITSM reasoning.
  • Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, converting endpoint and asset data into governed business intelligence for university IT decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
  • Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
  • Developed and delivered ITIL training that standardized incident, request, service-transition, and operational practices, building the governed service substrate needed before automation can safely reshape support workflows.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
  • Developed procurement, lifecycle-management, and disposition processes for end-user assets, giving university IT a cleaner chain of custody from purchase through retirement.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Open full role

Battery Giant / Energy Products | January 2007 – December 2010

IT Manager

  • Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.
  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized product-information platform spanning 250,000 products and 3,000,000+ applications, creating governed lookup, cross-reference, pricing, and inventory data substrate for later decision-support and agent-style workflows.
  • Implemented centralized ledger, inventory-control, and POS data patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, grounding multi-location retail decisions in cleaner operational and financial data.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical systems, proving the availability and recovery substrate that dependable AI-enabled business workflows require before higher-level automation can be trusted.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Open full role

Detroit Country Day School | June 2005 – August 2006

Systems Analyst

  • Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
  • Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, building early endpoint consistency and automation substrate for reliable platform operations.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.
  • Led incident, request, and change-management practices for end-user systems during early identity and endpoint modernization, giving users a clearer path for support while the environment shifted from legacy platforms.
  • Developed security-focused service workflows and endpoint protocols for classroom technology, improving prioritization, escalation, and access-control practices in a high-touch academic setting.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture
Open full role

Education

Education

The University of Michigan, Ann Arbor, MI

  • College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
  • School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

Detroit Country Day School, Beverly Hills, MI

  • High School Diploma | College Preparatory Curriculum

Skills

Selected skills

Skills are selected from shared JSON skill records referenced by the selected role evidence.

AI Systems, Safety & Applied LLM Engineering

Deterministic guardrails (Expert), immutable attribution (Expert), continuous red-team/blue-team exercises (Expert), adversarial safety-control testing (Expert), prompt-injection and jailbreak evaluation (Expert), model evaluation frameworks (Expert), secure LLM deployment patterns (Expert), Azure AI Foundry (Expert), AI-assisted development guardrails (Expert), Model- and platform-agnostic XLM (LLM/SLM) orchestration (Advanced), MCP toolkits (Advanced), Ollama/local models (Advanced)

Product Design, Technical UX & Sports Decision Support

Stakeholder interviews (Expert), workflow mapping (Expert), information architecture (Expert), product requirements (Expert), cross-functional design reviews (Expert), technical-user experience (Expert), product strategy (Expert), design-to-production delivery (Expert), executive-ready tradeoff framing (Expert), design systems (Advanced), component systems (Advanced), baseball analytics (Advanced)

Soft Skills & Cross-Functional Practice

Executive communication (Expert), stakeholder alignment (Expert), technical mentoring (Expert), non-technical stakeholder training (Expert), project and program coordination (Expert), vendor evaluation (Expert), RFP demonstration leadership (Expert), proof-of-concept facilitation (Expert), change adoption (Advanced)

Azure Data, Analytics & AI Platforms

Azure Databricks (Expert), Databricks lakehouse architecture (Expert), data landing zones (Expert), governed analytics platforms (Expert), reusable reference architectures (Expert), workload modernization (Expert), production readiness (Expert), Cloud Adoption Framework (Expert), Azure Well-Architected Framework for analytics and AI workloads (Expert), Data engineering (Advanced), feature preparation (Advanced), lakehouse-oriented sports analytics (Advanced)

Identity, Access & Cryptography

Microsoft Entra ID / Azure AD (Expert), Entra ID Governance (Expert), access reviews (Expert), entitlement management (Expert), Privileged Identity Management (PIM) (Expert), Just-in-Time access (Expert), Conditional Access (Expert), FIDO / MFA (Expert), workload identities (Expert), managed identities (Expert), service principals at scale (Expert), RBAC and least-privilege design (Expert)

Cybersecurity Architecture, Detection & Operations

Cybersecurity architecture (Expert), cloud security architecture (Expert), Zero Trust architecture (Expert), Microsoft Defender (Expert), Microsoft Purview (Expert), SIEM (Expert), SOAR (Expert), SASE (Expert), XDR and vulnerability management (Expert), endpoint protection (Expert), incident response (Expert), post-incident remediation (Expert)

Microsoft Purview, DLP & Information Protection

Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints (Expert), Teams DLP (Expert), sensitivity labels (Expert), auto-labeling (Expert), retention labels and policies (Expert), data classification (Expert), sensitive-data discovery and mapping (Expert), DLP policy authoring (Expert), AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization (Expert)

Cloud, Network & Enterprise Infrastructure

Microsoft Azure (Expert), private cloud architecture (Expert), Azure Landing Zones (Expert), Azure Policy (Expert), Landing Zone Accelerator patterns (Expert), hybrid cloud architecture (Expert), Azure Well-Architected Framework (Expert), geo-resiliency (Expert), high-availability patterns (Expert), vendor-agnostic infrastructure schemas (Expert), Google Cloud Platform (GCP) (Advanced), Azure / GCP security and third-party-risk comparisons (Advanced)