Special resume view

Enterprise and Cloud Architecture Resume

Enterprise architecture, cloud modernization, platform engineering, resilience, security architecture, and governance for organizations that need systems to be durable, legible, and operable.

Resume at a glance

Roles
16 public role records selected for Enterprise and Cloud Architecture Resume.
Evidence
128 structured evidence points, selected and deduped by claim family.
Source
MDX renders this page; adjacent JSON artifacts beside the role MDX files supply the claims.

Work Experience

Selected professional experience

Profile-matched evidence using the best available variant for this resume lens.

Scoria Software Solutions | March 2025 – Present

Founder & Principal Software Architect

  • Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence, producing clearer audit trails, faster incident response (seconds or milliseconds instead of minutes), and a 1–2 order-of-magnitude reduction in attempts to bypass safety controls.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Architected the XLM engine and MCP toolkit family as a model- and platform-agnostic application architecture, converting natural-language intent into deterministic cloud, web, API, CLI, and MCP delivery patterns that shortened early-adopter POC cycles from months to weeks.
  • Designed model- and platform-agnostic cloud architecture across Azure AI Foundry, Ollama, local models, consumer apps, and enterprise platforms, improving workload portability while one customer cut Azure spend 65% and reduced application latency from 3-5 seconds to 10-150 ms.
  • Architected Fumaro Sports as an Azure Databricks-backed cloud and data-platform showcase, using lakehouse patterns for feature preparation, predictive analytics, PostgreSQL-backed application routes, and governed release controls that translate a sports analytics workload into reusable enterprise architecture.
  • Designing Fumaro Sports around analyst and scout review, feedback capture, telemetry-aware runtime logging, staged private beta evaluation, and human-in-the-loop release controls so sports tools can improve without hiding uncertainty from users.
  • Created a DevOps orchestration platform for governed cloud and application delivery, reducing technical debt across 65-95% of the codebase while compressing feature and patch delivery from weeks or months to days or hours and preserving controlled release paths.
  • Developed a canonical JSON schema application engine as an enterprise platform layer, deploying cohesive web, native mobile, desktop, API, CLI, and MCP surfaces from one shared contract while reducing each interface codebase 25-30% through reusable architecture.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Open full role

Bedrock Information Systems LLC | January 2019 – Present

Principal Architect

  • Established NIST CSF 2.0 Tier 3 (Repeatable) as a platform-governance baseline for onboarded municipal systems, turning scattered control practices into repeatable architecture evidence and single-click audit reporting.
  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Expanded a municipal Microsoft Teams implementation into a five-year city-wide AI adoption and modernization roadmap, sequencing 26 priorities across security, compliance, user training, data protection, legacy phase-out, and ROI milestones so AI work rested on governed collaboration and information-protection foundations.
  • Implemented automated DLP and information-protection controls that detected a public-sector CJIS data exposure within five minutes of availability and applied extreme encryption and protection through Purview, including to copies stored outside Microsoft 365, while preserving NDA-safe disclosure of the incident.
  • Modernized a century-scale government records platform by converting legacy microfilm into OCR/ICR-optimized, PDF/A-compliant digital assets with metadata in one 21-hour run, reducing public-records turnaround from weeks or months to days or hours.
  • Applied structured guardrails and deterministic processes to AI-assisted development, enabling non-developer infrastructure and application engineers to safely expand into development work; accelerated project timelines 50–75%, allowed teams of 2–3 to deliver what previously required teams of 6–12, eliminated engineer overtime (previously 50–60 hours/week), and increased per-engineer revenue and profitability while expanding overall market footprint without added headcount.
  • Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Principal Cybersecurity Architect

  • Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
  • Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
  • Paired Pentera (red team) with the Microsoft Defender / Purview suite (blue team) to institutionalize regular red-team / blue-team war-game exercises, producing a two-order-of-magnitude drop in Defender events (from hundreds of thousands to thousands per week across the enterprise) and closing nearly all historical vulnerabilities within one quarter of joint operation.
  • Built DLP alert investigation and remediation workflows that connected Purview, Defender, GRC, and change-management evidence, giving compliance and security stakeholders practical dashboards for policy effectiveness, false-positive reduction, and audit readiness.
  • Integrated security tooling and processes into existing fire-drill and disaster-recovery exercises, creating a unified operational cadence that enabled full business continuity during a real high-privilege account lockdown with zero impact to internal users, external consumers, or public-facing services.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Open full role

Wells Fargo Bank | July 2022 – July 2023

Senior Cybersecurity Architect

  • Led the Service Enablement Task Force for enterprise cloud architecture across 128 resource provider types, converting custom infrastructure decisions into reusable Azure blueprints and pre-approved service patterns that let bank application teams adopt standardized designs at migration scale.
  • Accelerated enterprise cloud architecture approvals from 3-12 applications per month to 40-50 completed reviews per week, unblocking the bank's first successful large-scale public-cloud migration program through standardized Azure infrastructure solution patterns.
  • Designed HYOK and external-key-provider architecture as the enterprise cloud adoption unblocker, removing third-party cryptographic dependencies and giving the bank a 100% bank-controlled key-management model for regulated public-cloud migration.
  • Developed enterprise cloud governance roadmaps that moved application teams from exception-driven architecture review to standardized blueprint selection, reducing review effort from weeks or months to roughly one to two asynchronous hours while preserving platform approval gates.
  • Framed Azure and Google Cloud platform trade-offs for senior executives, translating engineering, compliance, cryptography, infrastructure, and operating-model constraints into an enterprise provider decision across bank-scale endpoint and ATM environments.
  • Conducted comparative Azure and Google Cloud platform analysis, turning provider capability gaps into closure plans, compliance-scoring inputs, and control-model decisions for enterprise cloud service selection and migration governance.
  • Developed standardized compliance scoring for cloud services and resource-provider gaps, giving infrastructure, architecture, and GRC teams a repeatable evidence model for Azure/GCP closure plans, provider decisions, and governed cloud adoption.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints as enterprise deployment standards, reducing configuration drift and turning cloud platform requirements into repeatable infrastructure-as-code blueprints for high-volume application migration.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Open full role

Microsoft Corporation | March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

  • Led Microsoft-scale customer engineering across Fortune 500, public-sector, high-technology, and internal Microsoft environments, managing 37 dedicated accounts while serving as the final architecture escalation path for global cloud, data, identity, reliability, and product-group issues.
  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Led post-DART enterprise architecture remediation after a global ransomware response, sequencing recovery across Active Directory forests, Microsoft 365 tenants, Azure, Azure Stack, and private-cloud dependencies while closing privilege-risk paths without losing platform modernization momentum.
  • Resolved one to two critical-situation escalations per week across strategic accounts, including a Windows Server 2016 Storage Spaces Direct defect that cascaded through SQL Always On, Exchange Online, RDS, DFS, and failover clustering before a global patch restored high-availability architecture reliability worldwide.
  • Helped remediate a hyperscale service outage by tracing an infrastructure-as-code workflow to the failure path, guiding rollback and permanent-fix architecture decisions, and converting postmortem evidence into geo-resiliency, disaster-recovery, and safer global rollout guidance for Premier and Unified Support customers.
  • Delivered custom Azure Well-Architected engagements for complex enterprise customers whose scale exceeded standard guidance, translating cloud, data, resilience, governance, and platform-engineering constraints into reference architecture decisions that supported major multi-year Azure commitments.
  • Published reusable PowerShell, ARM-template, GitHub, Microsoft Learn, and field-delivery assets for Azure infrastructure, Microsoft 365, identity, and cloud operations, converting repeated customer architecture and escalation patterns into public-safe reference guidance that reduced repeat demand and freed capacity for higher-value reliability architecture work.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Senior Cybersecurity Architect

  • Architected a board-adopted three-year enterprise technology and security roadmap across eight domains, converting a NIST CSF Level 1 baseline into a funded Level 3 target state that sequenced cloud foundations, platform modernization, staffing, and risk reduction for executive decision-makers.
  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Modernized the remote-work platform across approximately 550-600 users and endpoints, replacing VPN-only visibility with Entra, Netskope, full-tunnel inspection, firewall, web-filtering, and endpoint controls that gave cloud and infrastructure teams an operable visibility foundation for distributed service delivery.
  • Stabilized enterprise remote access during the COVID crisis by sequencing VPN, identity, endpoint, firewall, and web-filtering work, eliminating recurring unexpected downtime and restoring service metrics while preserving the longer-term cloud enablement and platform modernization path.
  • Converted shadow IT, access-risk, and visibility findings into five formal platform RFP lifecycles for ServiceNow, PMO tooling, and Microsoft security solutions, using service-management and governance platforms to lock in the next phase of enterprise modernization.
  • Defined landing-zone and core-service architecture across Active Directory, networking, Microsoft 365, and Azure so implementation teams had a coherent foundation, transferable to club-scale systems where analytics, collaboration, and security services must share governed platform patterns.
  • Created an enterprise modernization roadmap aligning cloud enablement, endpoint provider and management systems, business-service migration, and data-protection requirements so business services and LOB systems could move through planned architecture instead of tool-led drift.
  • Planned data and information-security compliance controls for future business services, ensuring cloud enablement and service migration decisions were evaluated against security standards before implementation choices narrowed the architecture.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

City National Bank | March 2020 – July 2020

Vice President, Azure Infrastructure

  • Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Scaled VPN, VDI, Microsoft 365, and Teams access as enterprise continuity infrastructure for a national bank, preserving workforce availability during emergency facility closures while federated identity, MFA, and RADIUS validation remained supporting control-plane requirements.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
  • Drove Azure foundational-infrastructure strategy with enterprise engineering teams, shaping roadmap and design guidance for virtual networks, monitoring, access patterns, and application migration planning before workloads moved into cloud execution.
  • Reviewed infrastructure design documents with application teams for cloud migration, service refactoring, post-cutover cost control, secure access, and operational readiness, reducing one-off architecture decisions during a compressed transformation window.
  • Implemented infrastructure governance and service-management practices for cloud migration work, giving technical staff and business stakeholders clearer visibility into deliverables, risks, adoption support, and operational readiness.
  • Consulted with security and compliance stakeholders on zero-trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster-recovery considerations, aligning remote-work urgency with regulated banking control expectations.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Open full role

Molina Healthcare | February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

  • Architected the Azure Landing Zone and hybrid-cloud migration program for a regulated healthcare estate of roughly 16,000 production servers, 40,000 total environments, 630 applications, and more than 2 PB of data, giving application and infrastructure teams a governed enterprise-cloud foundation for platform modernization at production scale.
  • Reframed a stalled healthcare cloud-migration program into an executable enterprise architecture by aligning executives, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around shared platform decisions, restoring delivery momentum for LOB modernization.
  • Sequenced the first major migration around the highest-value LOB workload: a 450 TB SQL Always On platform with 2.7 TB of daily transactions and 12-15 SDLC environments, proving the workload-migration architecture, cost model, risk posture, and repeatable pattern before broader enterprise-cloud adoption.
  • Authored Terraform-integrated Infrastructure-as-Code and orchestration frameworks for landing-zone resources including networking, Virtual WAN, storage, gateways, firewalls, SQL Always On operations, and automated cutovers, preserving familiar operations workflows while standardizing enterprise platform governance and repeatable migration execution.
  • Treated security and compliance as first-class requirements from the outset, embedding HIPAA controls, comprehensive audit trails, and ready integration points for existing SIEM/SOAR tooling; the design received full security-team approval and satisfied 100 percent of the security organization’s stated requirements.
  • Led onshore consultants, offshore delivery teams, Molina stakeholders, application developers, platform engineers, and vendor support through the clean migration of the most complex workload, keeping architecture decisions, SQL modernization, infrastructure automation, and service handoffs aligned across the enterprise program.
  • Developed reusable Secure Healthcare Cloud Program patterns from the Azure Landing Zone engagement, packaging migration governance, Terraform automation, security approvals, communication practices, and operating models into a healthcare cloud platform modernization pattern future regulated organizations could reuse.
  • Wrote a proprietary PowerShell module for virtual-machine migration orchestration, reducing repetitive migration work and giving teams a more consistent control plane for lift-and-shift execution.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Open full role

Coretek Services | August 2018 – January 2019

Senior Solutions Architect

  • Architected a 16,000-user Exchange Online and Azure AD tenant consolidation across 32 Exchange environments and 27 Active Directory forests after a merger, reducing platform fragmentation for administrators and business users.
  • Migrated 10,000 on-premises Exchange mailboxes to Exchange Online in seven weeks with less than 2% failure, converting legacy collaboration migration risk into a controlled cloud-platform execution pattern.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
  • Consolidated user and desktop infrastructure after 19 company acquisitions, preserving user attributes and configurations while standardizing Active Directory, print, DNS, DHCP, VPN, and MPLS patterns.
  • Created a Microsoft 365 managed-service architecture and onboarded a 10,000-plus-seat pilot customer, turning migration delivery lessons into a repeatable operating model for governed cloud adoption.
  • Architected a Project Online PMO solution with automated onboarding, offboarding, and access provisioning, turning project governance into repeatable cloud-service architecture without adding manual administrative overhead.
  • Designed a highly available file-sharing and virtual-desktop data architecture for collaborative media and digital content, balancing performance-to-cost ratio, uptime, patching, backup, disaster recovery, and secure access.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Obsidian Availability Solutions | September 2016 – December 2018

Principal Consultant

  • Co-founded an IT consulting firm and built Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendor partnerships into a managed-cloud service portfolio for customer tenant, infrastructure, collaboration, and security environments.
  • Secured Microsoft Tier 1 / Direct CSP partner status, strengthening the firm's managed cloud architecture model for direct customer tenant onboarding, Microsoft service adoption, and CSP-backed delivery.
  • Built repeatable customer and tenant onboarding patterns for managed cloud lifecycle entry, turning sales handoff, implementation scope, delegated access, and Microsoft tenant readiness into a predictable operating model.
  • Developed a per-unit managed-services cost model that connected cloud tenant, infrastructure, collaboration, and platform delivery scope to more accurate contract pricing and financially sustainable customer operations.
  • Implemented hybrid-cloud, productivity, collaboration, and communications platforms across customer environments, aligning Azure subscriptions, virtual networks, Hyper-V, System Center, Exchange, Skype, SharePoint, Teams, and policy controls into managed infrastructure solutions.
  • Led a 16,000+ user Skype for Business Online and Cloud PBX migration across 67 sites, consolidating more than 100 telecom contracts while moving communications architecture into a managed Microsoft cloud operating model.
  • Implemented Enterprise PKI with offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, establishing certificate trust fabric for enterprise infrastructure and cloud-adjacent services.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for SCCM, RADIUS, and general access use cases, making PKI an operable trust service for cloud-adjacent infrastructure instead of a one-time build.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Open full role

Orion Technology Services | June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

  • Led a 12-month ITIL managed-services architecture overhaul that turned onboarding, SLA discipline, support efficiency, and escalation paths into a repeatable operating model for enterprise cloud and infrastructure services.
  • Designed incident, event, standard request, access, and problem-management processes as reusable service-operation architecture, converting reactive support patterns into more predictable managed cloud delivery and escalation control.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the shared service-data foundation for managed cloud and infrastructure operations.
  • Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a 150-plus-site-collection environment, moving collaboration workloads into more governable tenant structures for enterprise cloud operations.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, improving portfolio visibility and delivery governance for customer teams managing cloud, migration, and managed-service work.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, giving customers period-appropriate hybrid-cloud options with clearer resilience, recovery, and workload-isolation patterns.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, giving the Network Operations Center earlier visibility into integration and automation failures before they affected managed cloud-service commitments.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new processes and reducing knowledge gaps across audiences with mixed technical depth.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Detroit IT / Core 3 Solutions | June 2014 – February 2015

Senior Systems Administrator

  • Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365, including Exchange Online, SharePoint Online, and Skype for Business collaboration services.
  • Planned a multi-state network overhaul for six offices across five states, coordinating ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving reliable collaboration and experimentation capacity.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
  • Implemented availability-management and disaster-recovery practices for customer environments, keeping mission-critical systems aligned with SLA expectations through more reliable operating patterns.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.
  • Managed build-out, quality assurance, and deployment of client infrastructure engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving visibility into active customer work and enabling earlier escalation of delivery concerns.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

Detroit Country Day School | June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

  • Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, turning recurring helpdesk work into clearer service operations for a multi-campus school environment.
  • Developed SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, turning endpoint support into repeatable platform operations instead of manual remediation.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding digital-learning access through a fit-for-facilities endpoint platform.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported school-issued and sponsored software adoption, including Office 365 and classroom solutions, with account migration assistance, user training, and knowledge resources that reduced adoption friction.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
  • Collaborated with academic and administrative departments to identify technology needs, improving the alignment between classroom support, operational productivity, and educational delivery.
  • Managed student-information system improvements that strengthened data accessibility for staff and faculty, improving a line-of-business platform used for academic and administrative records.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
Open full role

University of Michigan, Information & Technology Services | June 2011 – September 2012

IT Engineer

  • Built a University of Michigan School of Music, Theatre, and Dance production background across 18 theatre productions from 2011-2015, spanning lighting design, sound design, stage management, assistant master electrician work, light-board operation, sound-board operation, live sound, and music-production training.
  • Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved service operations context.
  • Managed asset governance and lifecycle processes for more than 25,000 university endpoints, classroom technologies, and peripherals, giving leadership clearer visibility across a 100,000-user environment.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, turning endpoint and asset data into governed decision support for university IT operations.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
  • Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments during enterprise service consolidation.
  • Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
Operations/service deliveryTraining/knowledge managementEntertainment ProductionEntertainment Live Venue TechnologyEntertainment ProductionAvailability Resilience
Open full role

Battery Giant / Energy Products | January 2007 – December 2010

IT Manager

  • Directed infrastructure, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, giving branch offices and franchisees a standard platform foundation for growth instead of ad hoc local systems.
  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths, helping the retail platform expand from 2 stores to 11 in 18 months with a repeatable branch rollout model.
  • Built a centralized ecommerce and product-information platform spanning 250,000 products and 3,000,000+ applications, giving franchise operations a shared platform for lookup, pricing, inventory, and cross-reference workflows.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, standardizing multi-location retail operations around shared financial and inventory platforms.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after taking ownership of availability and recovery architecture.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Open full role

Detroit Country Day School | June 2005 – August 2006

Systems Analyst

  • Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
  • Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency through a repeatable device-platform model.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while moving classrooms and administrative teams onto a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.
  • Led incident, request, and change-management practices for end-user systems during early identity and endpoint modernization, giving users a clearer path for support while the environment shifted from legacy platforms.
  • Developed security-focused service workflows and endpoint protocols for classroom technology, improving prioritization, escalation, and access-control practices in a high-touch academic setting.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture
Open full role

Education

Education

The University of Michigan, Ann Arbor, MI

  • College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
  • School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

Detroit Country Day School, Beverly Hills, MI

  • High School Diploma | College Preparatory Curriculum

Skills

Selected skills

Skills are selected from shared JSON skill records referenced by the selected role evidence.

AI Systems, Safety & Applied LLM Engineering

Deterministic guardrails (Expert), immutable attribution (Expert), continuous red-team/blue-team exercises (Expert), adversarial safety-control testing (Expert), prompt-injection and jailbreak evaluation (Expert), model evaluation frameworks (Expert), secure LLM deployment patterns (Expert), Azure AI Foundry (Expert), AI-assisted development guardrails (Expert), Model- and platform-agnostic XLM (LLM/SLM) orchestration (Advanced), MCP toolkits (Advanced), Ollama/local models (Advanced)

Product Design, Technical UX & Sports Decision Support

Stakeholder interviews (Expert), workflow mapping (Expert), information architecture (Expert), product requirements (Expert), cross-functional design reviews (Expert), technical-user experience (Expert), product strategy (Expert), design-to-production delivery (Expert), executive-ready tradeoff framing (Expert), design systems (Advanced), component systems (Advanced), sports decision support (Advanced)

Soft Skills & Cross-Functional Practice

Executive communication (Expert), stakeholder alignment (Expert), technical mentoring (Expert), non-technical stakeholder training (Expert), project and program coordination (Expert), vendor evaluation (Expert), RFP demonstration leadership (Expert), proof-of-concept facilitation (Expert), change adoption (Advanced)

Azure Data, Analytics & AI Platforms

Azure Databricks (Expert), Databricks lakehouse architecture (Expert), data landing zones (Expert), governed analytics platforms (Expert), reusable reference architectures (Expert), workload modernization (Expert), production readiness (Expert), Cloud Adoption Framework (Expert), Azure Well-Architected Framework for analytics and AI workloads (Expert), feature preparation (Advanced), lakehouse-oriented sports analytics (Advanced)

Identity, Access & Cryptography

Microsoft Entra ID / Azure AD (Expert), Entra ID Governance (Expert), access reviews (Expert), entitlement management (Expert), Privileged Identity Management (PIM) (Expert), Just-in-Time access (Expert), Conditional Access (Expert), FIDO / MFA (Expert), workload identities (Expert), managed identities (Expert), service principals at scale (Expert), RBAC and least-privilege design (Expert)

Cybersecurity Architecture, Detection & Operations

Cybersecurity architecture (Expert), cloud security architecture (Expert), Zero Trust architecture (Expert), Microsoft Defender (Expert), Microsoft Purview (Expert), SIEM (Expert), SOAR (Expert), SASE (Expert), XDR and vulnerability management (Expert), endpoint protection (Expert), incident response (Expert), post-incident remediation (Expert)

Microsoft Purview, DLP & Information Protection

Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints (Expert), Teams DLP (Expert), sensitivity labels (Expert), auto-labeling (Expert), retention labels and policies (Expert), data classification (Expert), sensitive-data discovery and mapping (Expert), DLP policy authoring (Expert), AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization (Expert)

Cloud, Network & Enterprise Infrastructure

Microsoft Azure (Expert), private cloud architecture (Expert), Azure Landing Zones (Expert), Azure Policy (Expert), Landing Zone Accelerator patterns (Expert), hybrid cloud architecture (Expert), Azure Well-Architected Framework (Expert), geo-resiliency (Expert), high-availability patterns (Expert), vendor-agnostic infrastructure schemas (Expert), Google Cloud Platform (GCP) (Advanced), Azure / GCP security and third-party-risk comparisons (Advanced)