Special resume view

Identity & Access / Identity Security Resume

Identity infrastructure, trusted access controls, and enterprise IAM governance for high-stakes, regulated, and AI-adjacent systems, grounded in Microsoft-scale delivery of Entra ID, Conditional Access, PIM/JIT, least privilege, HYOK, Zero Trust, Purview, and audit-ready control patterns.

Resume at a glance

Roles
16 public role records selected for Identity Management Resume.
Evidence
128 structured evidence points, selected and deduped by claim family.
Source
MDX renders this page; adjacent JSON artifacts beside the role MDX files supply the claims.

Work Experience

Selected professional experience

Profile-matched evidence using the best available variant for this resume lens.

Scoria Software Solutions | March 2025 – Present

Founder & Principal Software Architect

  • Designed deterministic AI and automation guardrails for agentic and non-human workflows, using codified approvals, immutable attribution, and explicit divergence controls to strengthen audit trails and reduce attempts to bypass safety controls by 1–2 orders of magnitude.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
  • Kept AI-enabled tooling model- and platform-agnostic across consumer, enterprise, Azure AI Foundry, Ollama, and local-model runtimes, preserving portable control boundaries so governance did not depend on one identity or cloud provider interface.
  • Architected Fumaro Sports with Azure Databricks as the analytics backend showcase, using lakehouse-oriented data engineering patterns to support predictive sports intelligence, model-ready feature preparation, context-aware analytics, and governed human-in-the-loop release controls.
  • Designing Fumaro Sports around analyst and scout review, feedback capture, telemetry-aware runtime logging, staged private beta evaluation, and human-in-the-loop release controls so sports tools can improve without hiding uncertainty from users.
  • Led cloud, software-delivery, data, and security architecture for client environments, tying assessment findings to deployable governance and risk-control patterns instead of leaving identity and compliance requirements as policy abstractions.
  • Translated cybersecurity, compliance, and sensitive-data protection requirements into deployable architecture patterns for client systems, keeping governance evidence connected to practical security controls.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Open full role

Bedrock Information Systems LLC | January 2019 – Present

Principal Architect

  • Established NIST CSF 2.0 Tier 3 (Repeatable) as the baseline for onboarded systems, turning governance, compliance, and audit evidence into a repeatable control model with single-click reporting for municipal IT environments.
  • Designed Microsoft 365 information-protection controls with Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas for public-sector and regulated client data, including CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, and public-safety records.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Expanded a municipal Microsoft Teams implementation into a five-year city-wide modernization and AI roadmap, prioritizing Purview sensitivity labeling and DLP as immediate data-protection controls across 26 IT priorities.
  • Implemented automated Purview DLP and information-protection controls that detected a public-sector CJIS exposure within five minutes and applied encryption and protection to copies stored outside Microsoft 365.
  • Built and deployed a custom microfilm digitization tool that converted more than a century of legacy government records (dating to the 1800s) into OCR/ICR-optimized, PDF/A-compliant digital assets with full metadata in a single 21-hour continuous run—collapsing an estimated 10-year multi-person full-time effort—and reduced pre-digital public records request turnaround from weeks or months to days or hours.
  • Applied structured guardrails and deterministic processes to AI-assisted development, enabling non-developer infrastructure and application engineers to safely expand into development work; accelerated project timelines 50–75%, allowed teams of 2–3 to deliver what previously required teams of 6–12, eliminated engineer overtime (previously 50–60 hours/week), and increased per-engineer revenue and profitability while expanding overall market footprint without added headcount.
  • Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Principal Cybersecurity Architect

  • Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
  • Eliminated 45 standing privileged accounts by implementing Entra PIM and Just-in-Time access, leaving only one monitored break-glass account while enforcing M-of-N approvals, change-management evidence, and a single privileged-access audit trail.
  • Extended identity-aware information protection by tuning Microsoft Purview DLP policies, sensitivity labels, retention controls, and compliance workflows with Defender operations for regulated data categories.
  • Contained a phishing compromise of a high-value executive identity with zero data extraction, zero lateral movement, and no business impact, validating the Entra privileged-access, monitoring, and lockdown controls built for high-risk accounts.
  • Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
  • Paired Pentera (red team) with the Microsoft Defender / Purview suite (blue team) to institutionalize regular red-team / blue-team war-game exercises, producing a two-order-of-magnitude drop in Defender events (from hundreds of thousands to thousands per week across the enterprise) and closing nearly all historical vulnerabilities within one quarter of joint operation.
  • Built Purview DLP investigation workflows that connected Defender, GRC, and change-management evidence so security and compliance teams could govern sensitive-data access, policy effectiveness, false positives, and audit readiness from practical dashboards.
  • Integrated privileged-account lockdown procedures into fire-drill and disaster-recovery exercises, proving that high-privilege identity containment could preserve continuity for internal users, external consumers, and public-facing services.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Open full role

Wells Fargo Bank | July 2022 – July 2023

Senior Cybersecurity Architect

  • Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity, policy, and GRC review gates.
  • Accelerated regulated cloud-security approvals from 3-12 applications per month to 40-50 reviews per week, replacing bespoke access-to-cloud review paths with standardized control gates that let application teams adopt Azure architectures at banking scale.
  • Designed Hold-Your-Own-Key (HYOK) cryptography and external key-provider controls as a bank-owned cryptographic access boundary, eliminating third-party key dependencies while preserving auditable cloud adoption under securities-regulation and FISA scrutiny.
  • Developed SDLC policy-enforcement roadmaps that moved cloud access and architecture approval from exception handling to standardized control selection, cutting application-team review effort from weeks or months to roughly one to two asynchronous hours while preserving review gates.
  • Influenced 12 to 100+ engineers, GRC specialists, product teams, and cryptography experts to align cloud-provider selection and adoption with bank-wide security and compliance controls across tens of thousands of endpoints and approximately 12,000 ATMs.
  • Conducted comparative Azure and Google Cloud cybersecurity analysis, translating provider gaps into closure plans that shaped the bank's cloud-security control model, policy enforcement expectations, and governed application adoption decisions.
  • Developed standardized compliance scoring for cloud services and resource-provider gaps, giving cybersecurity, infrastructure, and GRC teams a shared evidence model for regulated cloud approvals, audit defensibility, and consistent control review.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints so cloud security requirements could be encoded as repeatable deployment patterns, reducing configuration drift and strengthening policy-enforced access to approved Azure service designs.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Open full role

Microsoft Corporation | March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

  • Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
  • Guided enterprise Microsoft 365 customers through Zero Trust-aligned information-protection controls across AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, connecting sensitivity labeling, regulated-data discovery, DLP policy tuning, and compliance operations to identity-aware governance outcomes.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Led post-DART identity recovery for a global ransomware response, rebuilding Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack identity dependencies, and private-cloud access paths while closing leaked-privilege lateral movement and deploying FIDO plus Microsoft Authenticator MFA across the global user base.
  • Launched the first year of LACERA's three-year identity and endpoint modernization roadmap as their Microsoft engineer, standing up greenfield Active Directory and Microsoft 365 environments that closed a prior backdoor-account incident and gave the multi-year program durable operational momentum.
  • Supported MSIT, LinkedIn, GitHub, and Microsoft product organizations on identity, cybersecurity, migration, incident, and critical-situation work, applying customer-facing escalation discipline to internal Microsoft identity and cloud operations.
  • Translated red-team, blue-team, lab, customer-submission, bug, and vulnerability evidence into product-group signal for identity, compliance, security, and cloud services, helping Microsoft convert strategic-customer findings into safer platform behavior.
  • Authored reusable Graph, PowerShell, ARM-template, Microsoft Learn, and field-delivery assets for identity, privileged access, Azure infrastructure, Microsoft 365, and cybersecurity scenarios, converting high-consequence customer lessons into public-safe guidance for customer engineers and product groups.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Senior Cybersecurity Architect

  • Established LACERA’s first dedicated security engineering function and three-year roadmap, grounding identity, access, governance, endpoint visibility, and security maturity work in a board-adopted NIST CSF plan that funded the next security engineering roles.
  • Remediated a Tier 0 identity-control failure by eliminating hidden super-privileged Active Directory accounts with built-in administrator, domain, enterprise, schema, and synchronized Microsoft 365 Global Administrator rights within two weeks of discovery.
  • Designed and deployed Entra and Netskope controls across approximately 550–600 users and endpoints, replacing legacy VPN-only visibility with identity-aware remote access, full-tunnel traffic inspection, firewall, web filtering, and endpoint security coverage.
  • Hardened workforce remote access during the COVID crisis, sequencing identity, VPN, endpoint, firewall, and web-filtering controls to eliminate recurring unexpected downtime and restore pre-crisis service metrics.
  • Established identity, access, and visibility foundations that exposed previously unknown shadow IT and high-risk access patterns, then initiated five formal platform RFPs to turn the findings into funded modernization work.
  • Led Secure Productive Enterprise architecture across Active Directory, Microsoft 365, Azure, networking, and landing-zone services so identity and cloud-control decisions were set before implementation projects fragmented the foundation.
  • Created the roadmap for modernizing identity and endpoint provider systems, aligning cloud enablement, business-service migration, and data-protection requirements before tool projects could dictate access architecture.
  • Planned data and information-security compliance controls for future business services, ensuring modernization work was evaluated against required security standards instead of only short-term remote-work stabilization.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

City National Bank | March 2020 – July 2020

Vice President, Azure Infrastructure

  • Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access through Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
  • Preserved Active Directory as the source of authority for emergency remote-access authentication while integrating Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, keeping VPN and VDI scale-up auditable under crisis conditions.
  • Drove Azure infrastructure strategy that treated identity and access management as landing-zone design inputs, giving enterprise engineering and application teams roadmap guidance for secure migration planning, virtual networks, monitoring, and access control.
  • Reviewed cloud-migration design documents for secure-access, service-refactoring, and post-cutover risk considerations, reducing one-off identity and infrastructure decisions during a compressed regulated-bank transformation window.
  • Implemented standardized project and service-management practices for cloud migration work, giving technical staff and business units clearer visibility into deliverables, risks, adoption support, and operational readiness.
  • Aligned emergency remote-work identity and endpoint-control decisions with regulated banking expectations by consulting security and compliance stakeholders on zero trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster recovery.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Open full role

Molina Healthcare | February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

  • Led Azure Landing Zone and hybrid-cloud migration architecture for a HIPAA-aligned healthcare estate of roughly 16,000 production servers, 630 applications, and more than 2 PB of data, keeping identity, privileged access, auditability, and cloud-security controls inside the migration model from the start.
  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.
  • Authored Terraform-integrated landing-zone automation for networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security, giving operations teams repeatable Azure guardrails while preserving reviewable control over privileged, high-impact infrastructure changes.
  • Embedded HIPAA controls, comprehensive audit trails, and SIEM/SOAR integration points into the landing-zone design, earning security-team approval by making identity, privileged-access activity, and compliance evidence reviewable from the architecture layer rather than a late-stage checkpoint.
  • Led a combined delivery team of approximately twelve onshore and two dozen offshore Infosys consultants plus a core group of fifteen permanent Molina stakeholders, coordinating Infrastructure-as-Code work with application refactoring (including a significant SQL version upgrade) performed by team developers to make the critical workload cloud-native; the coordinated effort delivered a successful, clean migration of the organization’s most complex and business-critical application while maintaining influence across the full server, data-center, and application footprint.
  • Translated the engagement into Secure Healthcare Cloud Program patterns that packaged migration, identity governance, privileged-access alignment, automation, auditability, and security communication practices for future regulated healthcare cloud programs.
  • Wrote a proprietary PowerShell module for virtual-machine migration orchestration, reducing repetitive migration work and giving teams a more consistent control plane for lift-and-shift execution.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Open full role

Coretek Services | August 2018 – January 2019

Senior Solutions Architect

  • Consolidated a 16,000-user merger environment into a single Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, reducing identity and email fragmentation for administrators and business users.
  • Migrated 10,000 on-premises mailboxes to Exchange Online in seven weeks with less than 2% failure, preserving user access continuity while legacy Exchange workloads moved into Microsoft 365.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
  • Implemented Microsoft 365 Conditional Access controls for device and user compliance, strengthening Azure AD identity security while preserving cloud productivity adoption.
  • Consolidated identity-adjacent desktop services after 19 acquisitions, preserving user attributes and configurations while standardizing Active Directory, VPN, DNS, DHCP, print, and network access patterns.
  • Created a Microsoft 365 managed-service program and onboarded a pilot customer with more than 10,000 seats, turning project delivery lessons into a repeatable service offering.
  • Architected Project Online onboarding, offboarding, and access provisioning patterns that made role access repeatable and auditable without expanding manual administration.
  • Designed a secure, highly available file-sharing and virtual-desktop data solution for collaborative media and digital content, balancing performance-to-cost ratio, availability, patching, backup, and disaster-recovery requirements.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Obsidian Availability Solutions | September 2016 – December 2018

Principal Consultant

  • Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.
  • Secured Microsoft Tier 1 / Direct CSP partner status, strengthening the firm's ability to support governed Microsoft tenant adoption and customer-facing identity operations directly.
  • Built tenant onboarding patterns for managed-services entry, giving customer environments clearer access boundaries and a more predictable path from sale through identity-aware operating service.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
  • Implemented Microsoft cloud identity and security foundations across customer environments, aligning Azure subscriptions, productivity platforms, collaboration systems, and security policies into identity-aware managed-service operating patterns.
  • Led a 16,000+ user Skype for Business Online and Cloud PBX migration across 67 sites, consolidating more than 100 telecom contracts while delivering end-user training and unified communications support.
  • Implemented Enterprise PKI with an offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening certificate-based authentication and regulatory-aligned identity controls.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for general, SCCM, and RADIUS use cases, turning certificate-based authentication from a one-time infrastructure build into an operable identity-control service.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Open full role

Orion Technology Services | June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

  • Led a 12-month ITIL managed-services overhaul that brought identity and access requests, customer onboarding, SLA discipline, and escalation paths into a repeatable service-operation model.
  • Designed managed-service identity and access processes alongside incident, standard request, event, and problem management, giving customers clearer provisioning, access-issue, escalation, and operational-control paths.
  • Modeled ServiceNow and ConnectWise workflows for incident, request, change, and identity-access operations, improving cross-system visibility for provider and customer teams managing shared access and service commitments.
  • Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a 150-plus-site-collection SharePoint environment, moving collaboration content into more governable tenant and access-control structures.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, visibility, and portfolio discipline for customer delivery teams.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, giving customers hybrid infrastructure options with clearer disaster-recovery and availability patterns.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, helping the Network Operations Center detect integration and automation failures before they undermined service commitments.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new processes and reducing knowledge gaps across audiences with mixed technical depth.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Detroit IT / Core 3 Solutions | June 2014 – February 2015

Senior Systems Administrator

  • Designed and delivered migration from hosted Exchange and Windows file services into Office 365, preserving user identity, document access, and collaboration continuity across Exchange Online, SharePoint Online, and Skype for Business.
  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
  • Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.
  • Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving visibility into active customer work and enabling earlier escalation of delivery concerns.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

Detroit Country Day School | June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

  • Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.
  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported Office 365 and classroom-software adoption with account migration assistance, user training, and knowledge resources, reducing account and collaboration adoption friction for school users.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
  • Collaborated with academic and administrative departments to identify technology needs, improving the alignment between classroom support, operational productivity, and educational delivery.
  • Managed implementation work for student-information system improvements, strengthening data accessibility for staff and faculty who depended on accurate academic and administrative records.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
Open full role

University of Michigan, Information & Technology Services | June 2011 – September 2012

IT Engineer

  • Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.
  • Managed asset governance and lifecycle processes for more than 25,000 university endpoints and peripherals, giving leadership clearer visibility into assignment, use, location, and disposition across a 100,000-user environment.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
  • Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
  • Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
  • Developed procurement, lifecycle-management, and disposition processes for end-user assets, giving university IT a cleaner chain of custody from purchase through retirement.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Open full role

Battery Giant / Energy Products | January 2007 – December 2010

IT Manager

  • Directed security, identity, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, giving branch offices and franchisees a more consistent access and infrastructure operating model.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing access and compliance risk while giving franchisees clearer support expectations.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after assuming responsibility for availability and recovery systems.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Open full role

Detroit Country Day School | June 2005 – August 2006

Systems Analyst

  • Established the school's Active Directory foundation by helping consolidate six Kerberos realms into one AD forest, giving students, faculty, and administrators a simpler authentication model and stronger directory operating base.
  • Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency so account and directory changes landed on a more predictable workstation fleet.
  • Modernized legacy Windows NT servers and Windows 98 SE workstations onto Windows Server 2003 and Windows XP, giving the new Active Directory environment a more supportable server and desktop base for daily account access.
  • Supported account and data migration into the new Active Directory environment, pairing identity rollout with training and knowledge resources so classroom users could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.
  • Led incident, request, and change-management practices for end-user systems during identity and endpoint modernization, giving students and faculty a clearer support path while account access and workstation platforms changed.
  • Developed security-focused service workflows and endpoint protocols for classroom technology, improving escalation and access-control practices in a high-touch academic identity environment.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture
Open full role

Education

Education

The University of Michigan, Ann Arbor, MI

  • College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
  • School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

Detroit Country Day School, Beverly Hills, MI

  • High School Diploma | College Preparatory Curriculum

Skills

Selected skills

Skills are selected from shared JSON skill records referenced by the selected role evidence.

AI Systems, Safety & Applied LLM Engineering

Deterministic guardrails (Expert), immutable attribution (Expert), continuous red-team/blue-team exercises (Expert), adversarial safety-control testing (Expert), prompt-injection and jailbreak evaluation (Expert), model evaluation frameworks (Expert), secure LLM deployment patterns (Expert), Azure AI Foundry (Expert), AI-assisted development guardrails (Expert), Model- and platform-agnostic XLM (LLM/SLM) orchestration (Advanced), MCP toolkits (Advanced), Ollama/local models (Advanced)

Product Design, Technical UX & Sports Decision Support

Stakeholder interviews (Expert), workflow mapping (Expert), information architecture (Expert), product requirements (Expert), cross-functional design reviews (Expert), technical-user experience (Expert), product strategy (Expert), design-to-production delivery (Expert), executive-ready tradeoff framing (Expert), design systems (Advanced), component systems (Advanced), sports decision support (Advanced)

Soft Skills & Cross-Functional Practice

Executive communication (Expert), stakeholder alignment (Expert), technical mentoring (Expert), non-technical stakeholder training (Expert), project and program coordination (Expert), vendor evaluation (Expert), RFP demonstration leadership (Expert), proof-of-concept facilitation (Expert), change adoption (Advanced)

Azure Data, Analytics & AI Platforms

Azure Databricks (Expert), Databricks lakehouse architecture (Expert), data landing zones (Expert), governed analytics platforms (Expert), reusable reference architectures (Expert), workload modernization (Expert), production readiness (Expert), Cloud Adoption Framework (Expert), Azure Well-Architected Framework for analytics and AI workloads (Expert), feature preparation (Advanced), lakehouse-oriented sports analytics (Advanced)

Identity, Access & Cryptography

Microsoft Entra ID / Azure AD (Expert), Entra ID Governance (Expert), access reviews (Expert), entitlement management (Expert), Privileged Identity Management (PIM) (Expert), Just-in-Time access (Expert), Conditional Access (Expert), FIDO / MFA (Expert), workload identities (Expert), managed identities (Expert), service principals at scale (Expert), RBAC and least-privilege design (Expert)

Cybersecurity Architecture, Detection & Operations

Cybersecurity architecture (Expert), cloud security architecture (Expert), Zero Trust architecture (Expert), Microsoft Defender (Expert), Microsoft Purview (Expert), SIEM (Expert), SOAR (Expert), SASE (Expert), XDR and vulnerability management (Expert), endpoint protection (Expert), incident response (Expert), post-incident remediation (Expert)

Microsoft Purview, DLP & Information Protection

Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints (Expert), Teams DLP (Expert), sensitivity labels (Expert), auto-labeling (Expert), retention labels and policies (Expert), data classification (Expert), sensitive-data discovery and mapping (Expert), DLP policy authoring (Expert), AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization (Expert)

Cloud, Network & Enterprise Infrastructure

Microsoft Azure (Expert), private cloud architecture (Expert), Azure Landing Zones (Expert), Azure Policy (Expert), Landing Zone Accelerator patterns (Expert), hybrid cloud architecture (Expert), Azure Well-Architected Framework (Expert), geo-resiliency (Expert), high-availability patterns (Expert), vendor-agnostic infrastructure schemas (Expert), Google Cloud Platform (GCP) (Advanced), Azure / GCP security and third-party-risk comparisons (Advanced)