Special resume view

Product Engineering and Product Design Resume

Product engineering, technical UX, schema-driven interface design, product research, and platform implementation for expert users and dense operational tools.

Resume at a glance

Roles
16 public role records selected for Product Engineering and Product Design Resume.
Evidence
128 structured evidence points, selected and deduped by claim family.
Source
MDX renders this page; adjacent JSON artifacts beside the role MDX files supply the claims.

Work Experience

Selected professional experience

Profile-matched evidence using the best available variant for this resume lens.

Scoria Software Solutions | March 2025 – Present

Founder & Principal Software Architect

  • Designed AI-enabled product workflows around explicit trust boundaries, approval paths, and immutable attribution so expert users can review, challenge, and safely act on generated recommendations instead of treating model output as opaque authority.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Productized AI-assisted software delivery through the XLM engine and MCP toolkit family, turning natural-language intent into deterministic multi-platform application stacks that let early adopters move from concept to hands-on prototype evaluation in weeks instead of months.
  • Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
  • Shaped Fumaro Sports as an expert-user decision-support product, pairing Azure Databricks-backed feature preparation with schema-driven product surfaces, context-aware explanation, governed model context, and human-reviewed predictive intelligence for analyst and scout workflows.
  • Designed Fumaro Sports feedback loops, telemetry-aware logging, staged beta practices, and prediction/explanation boundaries around analyst and scout review so expert-user workflows can improve while preserving trust in uncertain model output.
  • Building Fumaro Sports from prototype to public product runtime with Next.js, strict TypeScript, PostgreSQL-backed routes, Azure Databricks analytics, and MLB-first decision surfaces that make sports intelligence testable by expert users before broader productization.
  • Created developer and operator tooling for productized AI-assisted delivery, combining DevOps orchestration with release guardrails so product teams could move from feature intent to stable patches in days or hours without uncontrolled production changes.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Open full role

Bedrock Information Systems LLC | January 2019 – Present

Principal Architect

  • Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.
  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Turned a municipal Microsoft Teams rollout into a five-year product and operations roadmap, translating 26 modernization, security, compliance, training, AI adoption, and legacy phase-out requirements into sequenced delivery priorities with clear ROI milestones.
  • Implemented automated DLP and information-protection controls that detected a public-sector CJIS data exposure within five minutes of availability and applied extreme encryption and protection through Purview, including to copies stored outside Microsoft 365, while preserving NDA-safe disclosure of the incident.
  • Productized a public-sector records digitization workflow that connected legacy microfilm handling, OCR/ICR quality, PDF/A metadata, and public-records fulfillment, reducing pre-digital request turnaround from weeks or months to days or hours after a single 21-hour conversion run.
  • Operationalized AI-assisted development guardrails as a product-engineering system for small technical teams, giving non-developer engineers controlled patterns for requirements, prototypes, code review, auditability, and release discipline while accelerating delivery 50–75%.
  • Designed the rollout, training, and support path for a 2,300-user MDM workflow migration, translating device-governance requirements into an adoption path that landed with 100% success, zero data loss or service interruption, and only five support requests after a 15-minute training session.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Principal Cybersecurity Architect

  • Productized SecOps and GRC operating rhythms for a five-person cybersecurity engineering team, turning reactive user reports, Netskope alerts, and staff-chasing into dashboard-driven workflows that reduced disruptions and made audit work manageable through routine checkpoints.
  • Redesigned privileged-access workflows around Entra PIM, Just-in-Time access, monitored break-glass governance, M-of-N approvals, and change-management evidence so administrators could complete high-risk work through clear approval paths instead of standing access.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
  • Rolled out Pentera as an internal security tooling product, converting noisy exposure data into MITRE-aligned triage, risk-ranked remediation queues, and change-cycle workflows that helped technical users move from findings to closed risk instead of one-off scan reports.
  • Productized the red-team and blue-team feedback loop across Pentera, Defender, and Purview, turning adversarial findings and telemetry reduction into recurring technical-user workflows for security operations, remediation prioritization, and evidence-backed change.
  • Built decision-support workflows that connected Purview, Defender, GRC, and change-management evidence into practical dashboards, helping compliance, security, and operational users interpret policy effectiveness, false positives, and audit readiness without chasing raw tool output.
  • Integrated security tooling, high-privilege lockdown procedures, fire drills, and disaster-recovery exercises into a coherent operating workflow, helping technical teams practice incident response while preserving continuity for users and public-facing services.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Open full role

Wells Fargo Bank | July 2022 – July 2023

Senior Cybersecurity Architect

  • Designed the architecture-review process as an internal product workflow across 128 cloud resource-provider types, turning bespoke security and infrastructure decisions into reusable reference patterns that let application teams choose standardized Azure designs without restarting custom review cycles.
  • Redesigned cloud platform review as a standardized approval pattern, increasing throughput from 3-12 application approvals per month to 40-50 completed reviews per week while giving application teams a faster path into Azure architectures without removing expert review gates.
  • Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
  • Developed SDLC policy-enforcement roadmaps as an expert-user workflow for application teams, moving cloud architecture approval from exception-driven review to standardized control selection and reducing effort from weeks or months to roughly one to two asynchronous hours.
  • Framed cloud-provider trade-offs as an expert-user decision system, translating engineering, compliance, cryptography, and platform constraints into decision-support language that aligned 12 to 100+ specialists behind organization-wide adoption.
  • Synthesized Azure and Google Cloud provider gaps into closure plans, compliance-scoring inputs, and control-model decisions, creating an expert-user decision workflow for application and platform teams choosing cloud services under regulated delivery constraints.
  • Translated cloud-service controls and resource-provider gaps into a standardized compliance-scoring model, giving expert review teams a shared product workflow for closure plans, audit evidence, provider-selection trade-offs, and repeatable approval decisions.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints as reusable deployment-pattern design guides, reducing configuration drift and turning cloud requirements into production-ready standards that application teams could adopt consistently.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Open full role

Microsoft Corporation | March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

  • Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Translated high-volume customer-engineering demand into product-group feedback loops, mentoring roughly a dozen engineers and contributing to more than twenty standardized delivery programs while shaping shipped Bookings behavior for expert-user scheduling workflows.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
  • Averaged one to two critical-situation escalations per week (frequently joining proactively); most notably diagnosed a Windows Server 2016 Storage Spaces Direct (S2D) bug that was causing cascading SQL Always-On, Exchange Online, Remote Desktop Services, DFS, and failover-cluster outages; the resulting global patch resolved long-standing, multi-year issues for six of twelve dedicated customers and every organization running high-availability Windows Server workloads on S2D worldwide.
  • Converted customer-facing and Microsoft-internal postmortem evidence from a hyperscale outage into supportability improvements, safer rollout controls, and reusable geo-resiliency guidance that product and field teams could apply across Premier and Unified Support delivery.
  • Adapted Azure Well-Architected guidance for customers whose scale exceeded standard programs, translating cloud, data, resilience, governance, and platform constraints into reusable decision-support UX, architecture guidance, and customer delivery patterns for product and field teams.
  • Converted repeated expert-user requests into reusable PowerShell, ARM-template, GitHub, Microsoft Learn, and field-delivery assets, reducing repeat customer demand while giving engineers, product groups, and delivery teams public-safe implementation patterns they could apply without exposing protected customer details.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Open full role

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Senior Cybersecurity Architect

  • Translated an eight-domain maturity baseline into a board-adopted three-year roadmap, turning executive, IT, and security priorities into a decision-support product for sequencing funded modernization work and staffing needs.
  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
  • Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
  • Converted identity, access, visibility, shadow-IT, and high-risk access findings into five formal platform RFPs, shaping ServiceNow, PMO tooling, and Microsoft solution selection around workflow visibility and decision readiness.
  • Defined the Secure Productive Enterprise foundation as a coherent adoption product across Active Directory, networking, Microsoft 365, Azure, landing zones, and core services, giving implementation teams a shared path instead of fragmented tool decisions.
  • Created a modernization roadmap that aligned identity, endpoint management, cloud enablement, business-service migration, and data-protection requirements before tool projects could dictate the user and operating model.
  • Planned data and information-security compliance controls for future business services, ensuring modernization work was evaluated against required security standards instead of only short-term remote-work stabilization.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

City National Bank | March 2020 – July 2020

Vice President, Azure Infrastructure

  • Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
  • Drove Azure foundational-infrastructure strategy as a migration decision workflow, giving enterprise engineering and application teams roadmap guidance for virtual networks, identity, access, monitoring, and workload planning before designs fragmented.
  • Guided application teams through cloud-migration design reviews for service refactoring, post-cutover cost control, secure access, and operational risk, reducing one-off decisions during a compressed transformation window.
  • Implemented project and service-management workflows for cloud migration, making deliverables, risks, adoption support, and operational readiness visible to technical staff and business stakeholders.
  • Consulted with security and compliance stakeholders on zero-trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster-recovery considerations, aligning remote-work urgency with regulated banking control expectations.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Open full role

Molina Healthcare | February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

  • Designed the Azure migration as a productized control plane for expert technical users, translating a healthcare estate of roughly 16,000 production servers, 630 applications, and more than 2 PB of data into governed landing-zone patterns, migration workflows, and repeatable adoption paths for application owners and platform engineers.
  • Reframed a stalled cloud-migration program into an executable delivery model by aligning executives, application owners, platform engineers, project managers, Microsoft, and ServiceNow support around shared migration decisions, owner handoffs, and delivery rituals that restored momentum.
  • Sequenced the first major migration around the hardest expert-user workflow: a 450 TB SQL Always On platform with 2.7 TB of daily transactions and 12-15 SDLC environments, proving the migration pattern, control gates, handoffs, and repeatability model before asking application teams to adopt it broadly.
  • Authored Terraform-integrated orchestration frameworks as an internal platform product, giving application owners and operations teams familiar workflows while automating landing-zone provisioning, SQL workload maintenance, control checks, and human-monitored cutovers for repeatable healthcare-cloud adoption.
  • Treated security and compliance as first-class requirements from the outset, embedding HIPAA controls, comprehensive audit trails, and ready integration points for existing SIEM/SOAR tooling; the design received full security-team approval and satisfied 100 percent of the security organization’s stated requirements.
  • Coordinated consultants, Molina stakeholders, application teams, platform engineers, and vendor support through the most complex workload migration, turning cross-functional dependencies into clear ownership boundaries, application-owner handoffs, adoption decisions, and production-ready delivery accountability.
  • Productized the engagement lessons into reusable healthcare cloud program patterns, packaging migration workflows, governance decisions, automation, stakeholder communication, and runbook-ready operating practices for future teams to adopt without rediscovering the model.
  • Wrote a proprietary PowerShell module for virtual-machine migration orchestration, reducing repetitive migration work and giving teams a more consistent control plane for lift-and-shift execution.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Open full role

Coretek Services | August 2018 – January 2019

Senior Solutions Architect

  • Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a merger, reducing fragmentation in identity and email operations.
  • Productized a 10,000-mailbox Exchange Online migration into controlled runbooks, exception handling, and user-impact workflows, keeping a seven-week cutover below 2% failure while preserving collaboration continuity.
  • Turned user attributes, SIDs, passwords, groups, and profile data into explicit migration acceptance criteria, framing access continuity as a product requirement for administrators and business users during consolidation.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
  • Standardized user, desktop, print, DNS, DHCP, VPN, and MPLS patterns after 19 acquisitions, turning fragmented access and workplace workflows into a repeatable migration experience for administrators and users.
  • Productized Microsoft 365 migration and adoption lessons into a managed-service program for a 10,000-plus-seat pilot customer, converting delivery runbooks, operational feedback, and client enablement into a repeatable service workflow.
  • Designed Project Online onboarding, offboarding, and access-provisioning workflows as an expert-user product, translating PMO governance, role lifecycle, and administrator feedback into repeatable automation without adding manual overhead.
  • Designed collaborative media and digital-content data workflows across file sharing and virtual desktops, balancing user experience, secure access, availability, patching, backup, disaster recovery, and cost as product requirements.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Obsidian Availability Solutions | September 2016 – December 2018

Principal Consultant

  • Co-founded an IT consulting firm and shaped the early service portfolio through Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendor partnerships, expanding the managed-service products available to customer environments.
  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Designed repeatable customer and tenant onboarding flows for managed-service entry, turning sales handoff, implementation strategy, and operating-service readiness into a clearer expert-user workflow.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
  • Implemented hybrid-cloud, productivity, collaboration, communication, identity, and security systems across customer environments, including Azure subscriptions, virtual networks, Hyper-V, System Center, Exchange, Skype, SharePoint, Teams, and security policies.
  • Led a 16,000-plus-user communications migration across 67 sites while delivering end-user training and support, helping technical and nontechnical users adopt the new collaboration workflow after telecom consolidation.
  • Implemented an Enterprise PKI hierarchy with an offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening authentication and regulatory-aligned identity controls.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for SCCM, RADIUS, and general access use cases, making PKI an operable trust service for cloud-adjacent infrastructure instead of a one-time build.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Open full role

Orion Technology Services | June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

  • Led a 12-month ITIL managed-services overhaul that redesigned onboarding, SLA discipline, support efficiency, and escalation paths into a repeatable operating model for expert support users and customer-facing service commitments.
  • Designed incident, event, standard request, access, and problem-management workflows as reusable service-operation patterns, converting reactive support behavior into clearer expert-user paths for managed-service delivery.
  • Modeled ServiceNow and ConnectWise workflows for incident, event, problem, change, and shared service tracking, improving the data foundation for provider and customer teams operating the same service commitments.
  • Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into clearer tenant structures for knowledge, governance, and user workflow adoption.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, portfolio visibility, and delivery workflows for customer teams managing complex work.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, giving customers hybrid infrastructure options with clearer disaster-recovery and availability patterns.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, giving Network Operations Center users earlier visibility into integration and automation failures before they affected service commitments.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new service processes across audiences with mixed technical depth.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Open full role

Detroit IT / Core 3 Solutions | June 2014 – February 2015

Senior Systems Administrator

  • Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.5 TB of Windows file services to SharePoint Online, and Skype for Business for internal and external communication.
  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered VMware private-cloud VDI and sandbox environments for multiple software-development teams, treating developer workspaces as an internal product surface for experimentation, collaboration, and reliable delivery work.
  • Translated recurring Tier 2 and Tier 3 incidents into durable fixes and clearer support paths for service-desk resources and managed-services customers, improving the technical-user support workflow rather than only closing tickets.
  • Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables so internal leadership and customer stakeholders had clearer visibility into active engagement status and trade-offs.
  • Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving decision visibility into active customer work and enabling earlier escalation of delivery concerns.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Open full role

Detroit Country Day School | June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

  • Redesigned Track-It! ITSM workflows by defining ticket classification, escalation, and prioritization standards, turning recurring helpdesk work into clearer service expectations for a high-touch school user community.
  • Productized SCCM-based imaging and systems-management for approximately 2,500 workstations, turning endpoint support into repeatable fleet operations instead of manual one-off remediation.
  • Designed and deployed mobile laptop fleets for campuses with limited dedicated technology-center space, expanding classroom access to digital learning by adapting the solution to user and facilities constraints.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported school-issued software adoption with account migration assistance, user training, and knowledge resources, reducing friction for faculty and staff adopting Office 365 and classroom solutions.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting endpoint decisions to educational delivery, operational productivity, and user adoption constraints.
  • Collaborated with academic and administrative departments to identify technology needs, improving alignment between classroom support workflows, operational productivity, and educational delivery.
  • Managed student-information system improvements that strengthened data accessibility for staff and faculty, improving an internal administrative product surface used for accurate academic and operational records.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
Open full role

University of Michigan, Information & Technology Services | June 2011 – September 2012

IT Engineer

  • Led asset and configuration data workflows for the BMC Remedy to ServiceNow transition, defining import logic and relationship models so technical support users retained reliable service context during ITSM cutover.
  • Managed asset-governance workflows for more than 25,000 university endpoints, classroom technologies, and peripherals, giving leadership clearer decision support for assignment, use, location, and disposition across a 100,000-user environment.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, shaping endpoint and asset data into decision-support views for university IT operators and leaders.
  • Onboarded critical university departments into a shared-services support model, translating technical-user workflows for high-visibility groups into a more consistent end-user systems administration experience.
  • Helped plan touchless migration, application upgrade, workstation refresh, and support-model workflows for 25,000 users across more than 100 departments, reducing disruption during enterprise service consolidation.
  • Developed and delivered ITIL training and help-desk knowledge content that standardized incident, request, service-transition, and operational practices for technical support users adopting shared service workflows.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, preserving public-facing service readiness for academic and administrative users at institutional scale.
  • Developed procurement, lifecycle-management, and disposition workflows for end-user assets, giving university IT a cleaner product-operations path from purchase through retirement.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Open full role

Battery Giant / Energy Products | January 2007 – December 2010

IT Manager

  • Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.
  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized ecommerce and product-information platform spanning 250,000 products and 3,000,000+ applications, improving expert-user lookup, cross-reference, pricing, and inventory workflows for franchise operations.
  • Implemented centralized ledger, inventory-control, and POS workflows across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, shaping internal retail product operations around cleaner transaction integrity, loss prevention, and multi-location use.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after assuming responsibility for availability and recovery systems.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Open full role

Detroit Country Day School | June 2005 – August 2006

Systems Analyst

  • Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
  • Treated the four-campus workstation fleet as an internal product surface, developing imaging and systems-management practices that improved endpoint consistency and reduced manual rebuild friction for classroom users.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies by connecting infrastructure choices to the academic user experience instead of treating support as a purely back-office function.
  • Designed incident, request, and change-management workflows for end-user systems during endpoint modernization, giving technical and nontechnical users clearer support paths while shared technology platforms changed.
  • Developed service workflows and endpoint protocols for classroom technology, improving prioritization, escalation, and access-control practices for a high-touch academic user community.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture
Open full role

Education

Education

The University of Michigan, Ann Arbor, MI

  • College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
  • School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

Detroit Country Day School, Beverly Hills, MI

  • High School Diploma | College Preparatory Curriculum

Skills

Selected skills

Skills are selected from shared JSON skill records referenced by the selected role evidence.

AI Systems, Safety & Applied LLM Engineering

Deterministic guardrails (Expert), immutable attribution (Expert), continuous red-team/blue-team exercises (Expert), adversarial safety-control testing (Expert), prompt-injection and jailbreak evaluation (Expert), model evaluation frameworks (Expert), secure LLM deployment patterns (Expert), Azure AI Foundry (Expert), AI-assisted development guardrails (Expert), Model- and platform-agnostic XLM (LLM/SLM) orchestration (Advanced), MCP toolkits (Advanced), Ollama/local models (Advanced)

Product Design, Technical UX & Sports Decision Support

Stakeholder interviews (Expert), workflow mapping (Expert), information architecture (Expert), product requirements (Expert), cross-functional design reviews (Expert), technical-user experience (Expert), product strategy (Expert), design-to-production delivery (Expert), executive-ready tradeoff framing (Expert), design systems (Advanced), component systems (Advanced), baseball analytics (Advanced)

Soft Skills & Cross-Functional Practice

Executive communication (Expert), stakeholder alignment (Expert), technical mentoring (Expert), non-technical stakeholder training (Expert), project and program coordination (Expert), vendor evaluation (Expert), RFP demonstration leadership (Expert), proof-of-concept facilitation (Expert), change adoption (Advanced)

Azure Data, Analytics & AI Platforms

Azure Databricks (Expert), Databricks lakehouse architecture (Expert), data landing zones (Expert), governed analytics platforms (Expert), reusable reference architectures (Expert), workload modernization (Expert), production readiness (Expert), Cloud Adoption Framework (Expert), Azure Well-Architected Framework for analytics and AI workloads (Expert), Data engineering (Advanced), feature preparation (Advanced), lakehouse-oriented sports analytics (Advanced)

Identity, Access & Cryptography

Microsoft Entra ID / Azure AD (Expert), Entra ID Governance (Expert), entitlement management (Expert), Privileged Identity Management (PIM) (Expert), Just-in-Time access (Expert), Conditional Access (Expert), FIDO / MFA (Expert), workload identities (Expert), managed identities (Expert), service principals at scale (Expert), RBAC and least-privilege design (Expert), Just Enough Administration (JEA) (Expert)

Cybersecurity Architecture, Detection & Operations

Cybersecurity architecture (Expert), cloud security architecture (Expert), Zero Trust architecture (Expert), Microsoft Defender (Expert), Microsoft Purview (Expert), SIEM (Expert), SOAR (Expert), SASE (Expert), XDR and vulnerability management (Expert), endpoint protection (Expert), incident response (Expert), post-incident remediation (Expert)

Microsoft Purview, DLP & Information Protection

Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints (Expert), Teams DLP (Expert), sensitivity labels (Expert), auto-labeling (Expert), retention labels and policies (Expert), data classification (Expert), sensitive-data discovery and mapping (Expert), DLP policy authoring (Expert), AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization (Expert)

Cloud, Network & Enterprise Infrastructure

Microsoft Azure (Expert), private cloud architecture (Expert), Azure Landing Zones (Expert), Azure Policy (Expert), Landing Zone Accelerator patterns (Expert), hybrid cloud architecture (Expert), Azure Well-Architected Framework (Expert), geo-resiliency (Expert), high-availability patterns (Expert), vendor-agnostic infrastructure schemas (Expert), Google Cloud Platform (GCP) (Advanced), Azure / GCP security and third-party-risk comparisons (Advanced)