Special resume view

Cybersecurity Leadership Resume

Cybersecurity architecture, governance, detection, cloud security, and senior technical leadership for regulated teams that need risk reduction tied to operational reality.

Resume at a glance

Roles
16 public role records selected for Cybersecurity Leadership Resume.
Evidence
128 structured evidence points, selected and deduped by claim family.
Source
MDX renders this page; adjacent JSON artifacts beside the role MDX files supply the claims.

Work Experience

Selected professional experience

Profile-matched evidence using the best available variant for this resume lens.

Scoria Software Solutions | March 2025 – Present

Founder & Principal Software Architect

  • Established deterministic AI guardrails with codified approvals, immutable attribution, and explicit divergence controls, giving executive technology and security stakeholders auditable control boundaries for agent-enabled workflows.
  • Reduced security false positives by more than 50% and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing specialists to return to deferred SASE work.
  • Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
  • Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
  • Architected Fumaro Sports with Azure Databricks as the analytics backend showcase, using lakehouse-oriented data engineering patterns to support predictive sports intelligence, model-ready feature preparation, context-aware analytics, and governed human-in-the-loop release controls.
  • Designing Fumaro Sports around analyst and scout review, feedback capture, telemetry-aware runtime logging, staged private beta evaluation, and human-in-the-loop release controls so sports tools can improve without hiding uncertainty from users.
  • Created AI-assisted delivery guardrails and DevOps orchestration that reduced technical debt across 65-95% of the codebase while preserving controlled release paths for security-sensitive feature and patch delivery.
  • Developed a single canonical JSON schema front-end engine that deploys cohesive applications across web, native mobile, desktop, APIs, CLIs, and MCP toolkits, reducing each interface’s codebase 25–30% through shared components and enabling one team to manage all interfaces instead of dedicated teams per platform.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Open full role

Bedrock Information Systems LLC | January 2019 – Present

Principal Architect

  • Established NIST CSF 2.0 Tier 3 (Repeatable) as the security-governance baseline for onboarded municipal systems, replacing awareness-level practices with repeatable controls and single-click audit reporting.
  • Designed Microsoft 365 information-protection baselines for regulated public-sector environments, using Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas to support CJIS, PII, CUI, law-enforcement, and public-safety data governance.
  • Advanced CJIS compliance for multiple public-sector customers by strengthening security controls while reducing sworn-officer administrative burden by 1–2 hours per day.
  • Expanded a municipal Microsoft Teams implementation into a five-year city-wide security and modernization roadmap, aligning 26 priorities across compliance enforcement, Purview sensitivity labeling, DLP, user training, legacy phase-out, and measurable ROI milestones.
  • Implemented automated Purview DLP and information-protection controls that detected a generalized public-sector CJIS data exposure within five minutes, applied encryption and protection to copies outside Microsoft 365, and kept incident details NDA-safe.
  • Built and deployed a custom microfilm digitization tool that converted more than a century of legacy government records (dating to the 1800s) into OCR/ICR-optimized, PDF/A-compliant digital assets with full metadata in a single 21-hour continuous run—collapsing an estimated 10-year multi-person full-time effort—and reduced pre-digital public records request turnaround from weeks or months to days or hours.
  • Led small-team delivery by applying deterministic guardrails, code review, auditability, and release discipline to AI-assisted development, helping 2–3 person infrastructure and application teams accelerate delivery 50–75% without loosening control expectations.
  • Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Principal Cybersecurity Architect

  • Led a five-person cybersecurity engineering team under the CISO, turning reactive incident queues and Netskope alert noise into daily operating rhythms that cut user-reported disruptions from dozens per day to a handful per week and moved GRC from staff-chasing to dashboard-driven governance.
  • Governed privileged-access risk by eliminating 45 standing administrator accounts through Entra PIM, Just-in-Time access, monitored break-glass controls, M-of-N approvals, and change-management evidence that gave leadership a single auditable control path.
  • Owned information-protection outcomes across Purview DLP, sensitivity labels, retention, compliance workflows, and Defender operations, reducing unmanaged sensitive-data exposure across regulated data categories while giving security and compliance leaders usable control evidence.
  • Contained a phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no business-system impact, validating privileged-access monitoring and lockdown controls under real operating pressure.
  • Operationalized continuous red-team validation with Pentera and Defender correlation, converting hundreds of findings into a risk-ranked remediation program that closed Critical and High issues in the first month and drove the residual backlog to roughly 10-12 active findings.
  • Institutionalized red-team and blue-team exercises across Pentera, Defender, and Purview, driving Defender event volume down by two orders of magnitude and closing nearly all historical vulnerabilities within one quarter of joint operation.
  • Built DLP alert investigation and remediation workflows that connected Purview, Defender, GRC, and change-management evidence, giving compliance and security stakeholders practical dashboards for policy effectiveness, false-positive reduction, and audit readiness.
  • Integrated security tooling and high-privilege lockdown procedures into fire-drill and disaster-recovery exercises, proving the incident-readiness cadence could preserve continuity for internal users, external consumers, and public-facing services.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Open full role

Wells Fargo Bank | July 2022 – July 2023

Senior Cybersecurity Architect

  • Led the Service Enablement Task Force for regulated cloud security architecture across 128 resource provider types, converting bespoke infrastructure decisions into pre-approved Azure patterns that gave thousands of downstream applications governed adoption paths while preserving cybersecurity and GRC review gates.
  • Standardized regulated cloud security review gates that accelerated approvals from 3-12 applications per month to 40-50 completed reviews per week, helping thousands of application teams move into Azure architectures without bypassing security, infrastructure, or GRC requirements.
  • Designed multi-layer HYOK/BYOK and external-key-provider governance that removed third-party cryptographic dependency risk, preserved bank-controlled key operations, and made encryption assurance a decisive cloud-adoption control for regulated architecture review.
  • Developed SDLC and security-governance roadmaps that shifted regulated cloud architecture approval from exception-driven review to standardized control selection, reducing application-team effort to roughly one to two asynchronous hours while making review gates more consistent and repeatable.
  • Translated cybersecurity, compliance, cryptography, and platform trade-offs into executive and provider decision support, aligning 12 to 100+ engineers and specialists behind a cloud-provider choice that reduced security risk across a bank-scale endpoint and ATM footprint.
  • Conducted comparative Azure and Google Cloud security analysis, translating provider gaps into closure plans, compliance scoring inputs, and control-model decisions that balanced platform capability, residual risk, and regulated cloud adoption requirements.
  • Developed standardized compliance scoring for cloud services and resource-provider gaps, giving cybersecurity, infrastructure, and GRC leaders a repeatable evidence model for risk review, closure planning, provider comparison, and governed approval decisions.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints so cloud security requirements became repeatable deployment standards, reducing configuration drift and making control enforcement more reliable for governed Azure adoption across high-volume application portfolios.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Open full role

Microsoft Corporation | March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

  • Led Microsoft-scale customer engineering for Fortune 500, U.S. government, high-technology, and Microsoft internal customers as a Global Tech Team escalation authority, managing 37 dedicated accounts while resolving identity, cybersecurity, cloud, and product-group issues that had no remaining internal escalation path.
  • Led enterprise customer engineering for Microsoft 365 information-protection programs across MIP, Purview, sensitivity labeling, regulated-data discovery, and DLP policy tuning, translating compliance obligations and operational risk into usable security controls.
  • Mentored approximately a dozen engineers and contributed to internal training plus standardized customer-delivery programs, turning high-consequence security, identity, and compliance lessons into repeatable field guidance and product-group feedback loops.
  • Led post-DART cybersecurity remediation after a global ransomware response, sequencing a worldwide identity and security overhaul across directory, Microsoft 365, Azure, and private-cloud dependencies while closing leaked-privilege lateral movement and deploying phishing-resistant MFA at enterprise scale.
  • Handled one to two critical-situation escalations per week across strategic accounts, proactively joining high-risk outages and translating root-cause evidence into customer-safe remediation paths, global patch influence, and durable security and reliability guidance.
  • Contributed to customer-facing and Microsoft-internal postmortems for a major global service outage, turning incident evidence into safer rollout controls, geo-resiliency protections, and disaster-recovery guidance for Premier and Unified Support customers.
  • Led customized Azure Well-Architected engagements for complex enterprise customers whose security, governance, resilience, and operating constraints exceeded standard guidance, translating executive priorities into cloud-security architecture decisions that supported major multi-year Azure commitments.
  • Published reusable PowerShell, ARM-template, GitHub, Microsoft Learn, and field-delivery assets for cybersecurity, identity, Microsoft 365, and Azure infrastructure scenarios, converting repeated escalation patterns into reusable security guidance that freed customer-engineering capacity for higher-value architecture work.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Senior Cybersecurity Architect

  • Architected LACERA's first dedicated cybersecurity engineering program and board-adopted three-year security maturity roadmap, converting a NIST CSF Level 1 baseline into a funded Level 3 target state with executive sponsorship and three new security engineering roles.
  • Led risk remediation for hidden super-privileged Active Directory and Microsoft 365 Global Administrator access, eliminating unaudited Tier 0 exposure within two weeks while preserving the evidence boundary around suspected destructive associations.
  • Governed Entra and Netskope deployment across approximately 550-600 users and endpoints, replacing VPN-only remote-work visibility with identity-aware access, full-tunnel inspection, firewall, web-filtering, and endpoint-security controls.
  • Led crisis-period remote-access hardening across identity, VPN, endpoint, firewall, and web-filtering controls, eliminating recurring unexpected downtime and restoring pre-crisis service metrics for the organization served.
  • Converted shadow IT and high-risk access findings into program ownership by initiating five formal RFPs for ServiceNow, PMO tooling, and Microsoft security solutions, tying platform decisions to risk remediation and the next security-maturity phase.
  • Led senior security architecture for the Secure Productive Enterprise initiative across Active Directory, networking, Microsoft 365, Azure, landing zones, and core services so implementation teams had a coherent security and cloud-governance foundation.
  • Created an identity, endpoint, cloud, and data-protection roadmap that kept business-service migration tied to security governance before individual tool selections could narrow architecture or raise residual risk.
  • Planned information-security and compliance controls for future business services, keeping modernization decisions aligned to data protection, control evidence, and required security standards instead of only short-term stabilization pressure.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

City National Bank | March 2020 – July 2020

Vice President, Azure Infrastructure

  • Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized secure remote-access continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams behind federated identity, MFA, and continuous RADIUS validation, preserving workforce access without relaxing regulated control expectations during emergency facility closures.
  • Preserved Active Directory as the auditable source of authority for emergency remote-access authentication while integrating Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing authentication-fragmentation risk as VPN and VDI expanded at crisis speed.
  • Drove Azure foundational-infrastructure strategy for a regulated bank with identity, access management, virtual networking, monitoring, and migration planning built into the roadmap, giving engineering teams security architecture guidance before workloads moved into cloud execution.
  • Reviewed cloud-migration design documents for secure access, service refactoring, post-cutover cost control, and operational risk, reducing one-off security decisions during a compressed regulated-bank transformation window.
  • Implemented standardized project and service-management practices for cloud migration work, giving technical staff and business units clearer visibility into security-relevant deliverables, risks, adoption support, and operational readiness under regulated-bank constraints.
  • Coordinated with security and compliance stakeholders on zero trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster recovery, keeping emergency remote-work delivery aligned with regulated banking control and audit expectations.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Open full role

Molina Healthcare | February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

  • Led security architecture for a HIPAA-aligned Azure Landing Zone and hybrid-cloud migration across roughly 16,000 production servers, 630 applications, and more than 2 PB of healthcare data, keeping identity, privileged access, auditability, zero-trust networking, and cloud-security controls in the program design from the start.
  • Reframed a stalled regulated-healthcare migration into an executable Azure security and delivery model by aligning executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around migration governance, shared risk decisions, and a common execution plan.
  • Chose the organization’s most business-critical SQL Always On workload as the first major migration, using a 450 TB healthcare data platform with 2.7 TB of daily transactions and 12-15 SDLC environments to prove security controls, migration governance, and repeatability decisions before broader cloud adoption.
  • Authored Terraform-integrated landing-zone and cutover automation for networking, gateways, firewalls, Zero Trust network security, and SQL operations, improving control consistency while keeping high-impact healthcare infrastructure changes reviewable by security, operations, and migration teams.
  • Embedded HIPAA controls, comprehensive audit trails, and SIEM/SOAR integration points into the landing-zone architecture, securing security-team approval by converting regulatory, detection, identity, and privileged-access requirements into architecture decisions migration teams could execute.
  • Coordinated roughly twelve onshore consultants, two dozen offshore consultants, permanent Molina stakeholders, application teams, and platform engineers through a clean migration of the organization’s most complex workload, keeping security architecture, infrastructure automation, SQL modernization, and stakeholder decisions aligned across a large blended delivery model.
  • Developed Secure Healthcare Cloud Program patterns that turned migration governance, zero-trust networking, automation, auditability, security communication, and equal-or-better cloud security principles into reusable guidance for future regulated healthcare programs.
  • Wrote a proprietary PowerShell migration-orchestration module that reduced repetitive lift-and-shift work and gave teams a more consistent, reviewable control plane for regulated infrastructure execution.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Open full role

Coretek Services | August 2018 – January 2019

Senior Solutions Architect

  • Consolidated a 16,000-user merger environment into one Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, reducing identity and messaging fragmentation that complicated security governance after the merger.
  • Migrated 10,000 on-premises mailboxes from Exchange 2007/2013 to Exchange Online in seven weeks with less than 2% failure and minimal user impact, converting a high-risk mail migration into a controlled execution pattern.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
  • Implemented Microsoft 365 Conditional Access controls for device and user compliance, strengthening identity security while keeping cloud productivity adoption viable for users and administrators.
  • Consolidated user and desktop infrastructure after 19 company acquisitions, preserving user attributes and configurations while standardizing Active Directory, print, DNS, DHCP, VPN, and MPLS patterns.
  • Created a Microsoft 365 managed-service program and onboarded a pilot customer with more than 10,000 seats, turning project delivery lessons into a repeatable service offering.
  • Architected Project Online onboarding, offboarding, and access provisioning automation, turning PMO role access into a repeatable governance control instead of informal project-team requests.
  • Designed a secure, highly available file-sharing and virtual-desktop data solution, balancing collaborative access, patching, backup, disaster recovery, and cost constraints for sensitive media and digital content workflows.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Obsidian Availability Solutions | September 2016 – December 2018

Principal Consultant

  • Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.
  • Secured Microsoft Tier 1 / Direct CSP partner status, expanding managed cloud and security offerings while giving customer environments a stronger direct-adoption path for governed Microsoft services.
  • Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
  • Implemented hybrid-cloud, identity, collaboration, communication, and security systems across customer environments, aligning Microsoft cloud platforms and security policies into governed operating patterns.
  • Led a 16,000+ user Skype for Business Online and Cloud PBX migration across 67 sites, consolidating more than 100 telecom contracts while delivering end-user training and unified communications support.
  • Implemented Enterprise PKI with offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening authentication controls for regulated customer environments.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for SCCM, RADIUS, and general access use cases, turning certificate authentication into an operable security-control service.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Open full role

Orion Technology Services | June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

  • Led a 12-month ITIL managed-services overhaul that brought onboarding, SLA discipline, access requests, escalation paths, and service commitments into a repeatable control-oriented operating model.
  • Designed incident, event, request, identity-access, and problem-management processes as managed-service control patterns, improving escalation, access operations, and security-service consistency.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, change, and identity-access workflows, strengthening cross-system tracking for shared managed-service control commitments.
  • Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into more governable tenant and access-control structures.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, visibility, and portfolio discipline for customer delivery teams.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, improving hybrid infrastructure resilience, recovery, and customer-environment isolation patterns.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, helping the Network Operations Center detect integration and automation failures before they became service-risk events.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new processes and reducing knowledge gaps across audiences with mixed technical depth.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Detroit IT / Core 3 Solutions | June 2014 – February 2015

Senior Systems Administrator

  • Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365 while preserving identity, document access, and collaboration continuity across customer environments.
  • Planned a multi-state network overhaul across ISPs, Cisco UCM voice, VPN, MPLS, hardware refresh, and disaster-recovery services, coordinating infrastructure controls that reduced customer operating fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
  • Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.
  • Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving visibility into active customer work and enabling earlier escalation of delivery concerns.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

Detroit Country Day School | June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

  • Refreshed Track-It! ITSM usage by defining classification, escalation, and prioritization standards, building the service-governance discipline that later security operations and risk escalation depend on.
  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported Office 365 and classroom-software adoption with account migration assistance, user training, and knowledge resources, reducing identity and collaboration rollout risk for school users.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
  • Collaborated with academic and administrative departments to identify technology needs, improving the alignment between classroom support, operational productivity, and educational delivery.
  • Managed implementation work for student-information system improvements, strengthening data accessibility for staff and faculty who depended on accurate academic and administrative records.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
Open full role

University of Michigan, Information & Technology Services | June 2011 – September 2012

IT Engineer

  • Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.
  • Managed asset governance and lifecycle processes for more than 25,000 university endpoints and peripherals, improving leadership visibility into assignment, use, location, and disposition across a 100,000-user environment.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
  • Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
  • Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
  • Developed procurement, lifecycle-management, and disposition processes for end-user assets, giving university IT a cleaner chain of custody from purchase through retirement.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Open full role

Battery Giant / Energy Products | January 2007 – December 2010

IT Manager

  • Directed security, identity, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, establishing early ownership of access, infrastructure controls, and operational risk across branch and franchise systems.
  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after assuming responsibility for availability and recovery systems.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational and compliance risk without overstating the early-role scope beyond practical control ownership.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Open full role

Detroit Country Day School | June 2005 – August 2006

Systems Analyst

  • Helped consolidate six Kerberos realms into one Active Directory forest, creating an early identity-control foundation for a multi-campus school environment while keeping the claim grounded in hands-on directory design rather than formal security leadership.
  • Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.
  • Led incident, request, and change-management practices for end-user systems during early identity and endpoint modernization, giving users a clearer path for support while the environment shifted from legacy platforms.
  • Developed security-focused service workflows and endpoint protocols for classroom technology, improving escalation, prioritization, and access-control practices in a high-touch academic environment.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture
Open full role

Education

Education

The University of Michigan, Ann Arbor, MI

  • College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
  • School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

Detroit Country Day School, Beverly Hills, MI

  • High School Diploma | College Preparatory Curriculum

Skills

Selected skills

Skills are selected from shared JSON skill records referenced by the selected role evidence.

AI Systems, Safety & Applied LLM Engineering

Deterministic guardrails (Expert), immutable attribution (Expert), continuous red-team/blue-team exercises (Expert), adversarial safety-control testing (Expert), prompt-injection and jailbreak evaluation (Expert), model evaluation frameworks (Expert), secure LLM deployment patterns (Expert), Azure AI Foundry (Expert), AI-assisted development guardrails (Expert), Model- and platform-agnostic XLM (LLM/SLM) orchestration (Advanced), MCP toolkits (Advanced), Ollama/local models (Advanced)

Product Design, Technical UX & Sports Decision Support

Stakeholder interviews (Expert), workflow mapping (Expert), information architecture (Expert), product requirements (Expert), cross-functional design reviews (Expert), technical-user experience (Expert), product strategy (Expert), design-to-production delivery (Expert), executive-ready tradeoff framing (Expert), design systems (Advanced), component systems (Advanced), sports decision support (Advanced)

Soft Skills & Cross-Functional Practice

Executive communication (Expert), stakeholder alignment (Expert), technical mentoring (Expert), non-technical stakeholder training (Expert), project and program coordination (Expert), vendor evaluation (Expert), RFP demonstration leadership (Expert), proof-of-concept facilitation (Expert), change adoption (Advanced)

Azure Data, Analytics & AI Platforms

Azure Databricks (Expert), Databricks lakehouse architecture (Expert), data landing zones (Expert), governed analytics platforms (Expert), reusable reference architectures (Expert), workload modernization (Expert), production readiness (Expert), Cloud Adoption Framework (Expert), Azure Well-Architected Framework for analytics and AI workloads (Expert), feature preparation (Advanced), lakehouse-oriented sports analytics (Advanced)

Identity, Access & Cryptography

Microsoft Entra ID / Azure AD (Expert), Entra ID Governance (Expert), access reviews (Expert), entitlement management (Expert), Privileged Identity Management (PIM) (Expert), Just-in-Time access (Expert), Conditional Access (Expert), FIDO / MFA (Expert), workload identities (Expert), managed identities (Expert), service principals at scale (Expert), RBAC and least-privilege design (Expert)

Cybersecurity Architecture, Detection & Operations

Cybersecurity architecture (Expert), cloud security architecture (Expert), Zero Trust architecture (Expert), Microsoft Defender (Expert), Microsoft Purview (Expert), SIEM (Expert), SOAR (Expert), SASE (Expert), XDR and vulnerability management (Expert), endpoint protection (Expert), incident response (Expert), post-incident remediation (Expert)

Microsoft Purview, DLP & Information Protection

Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints (Expert), Teams DLP (Expert), sensitivity labels (Expert), auto-labeling (Expert), retention labels and policies (Expert), data classification (Expert), sensitive-data discovery and mapping (Expert), DLP policy authoring (Expert), AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization (Expert)

Cloud, Network & Enterprise Infrastructure

Microsoft Azure (Expert), private cloud architecture (Expert), Azure Landing Zones (Expert), Azure Policy (Expert), Landing Zone Accelerator patterns (Expert), hybrid cloud architecture (Expert), Azure Well-Architected Framework (Expert), geo-resiliency (Expert), high-availability patterns (Expert), vendor-agnostic infrastructure schemas (Expert), Google Cloud Platform (GCP) (Advanced), Azure / GCP security and third-party-risk comparisons (Advanced)