Scoria Software Solutions · March 2025 – Present
Founder & Principal Software Architect
Selected claim: Architected deterministic agent guardrails with codified approval paths, immutable attribution, and explicit divergence controls, giving AI-enabled tools auditable safety boundaries instead of relying on prompt intent alone.
- Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
- Built the XLM engine and MCP toolkit family as a model-agnostic agent architecture that converts a single prompt into deterministic multi-platform application stacks, compressing early-adopter POC cycles from months to weeks.
- Designed model- and platform-agnostic routing across Azure AI Foundry, Ollama, local models, consumer apps, and enterprise platforms, improving portability while one customer reduced Azure spend 65% and cut latency from 3–5 seconds to 10–150 ms.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Bedrock Information Systems LLC · January 2019 – Present
Principal Architect
Selected claim: Established NIST CSF 2.0 Tier 3 (Repeatable) as a governance substrate for municipal AI adoption, turning control evidence, compliance workflows, and audit reporting into repeatable architecture guardrails before introducing higher-risk automation.
- Designed Microsoft 365 information-protection and classification guardrails for public-sector AI readiness, using Purview sensitivity labels, DLP patterns, retention controls, and regulated-data schemas to keep CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, and public-safety data governed before automation.
- Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
- Expanded a municipal Microsoft Teams implementation into a five-year city-wide AI adoption and modernization roadmap, sequencing 26 priorities across security, compliance, user training, data protection, legacy phase-out, and ROI milestones so AI work rested on governed collaboration and information-protection foundations.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024
Principal Cybersecurity Architect
Selected claim: Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
- Converted privileged administration into deterministic Entra PIM, Just-in-Time access, M-of-N approval, break-glass monitoring, and change-evidence flows, creating the auditable access substrate future security automation or agent workflows would need before acting on high-risk systems.
- Tuned Purview DLP, sensitivity-labeling, retention, and compliance controls for regulated data categories, creating deterministic data-classification and access-governance foundations that support safe AI and agent platform adoption without exposing sensitive information.
- Validated the privileged-access and monitoring substrate during a real high-value phishing compromise, proving that governed identity controls, telemetry, and lockdown workflows could contain risk with zero data extraction, lateral movement, or business impact before any higher-risk automation depended on them.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Wells Fargo Bank · July 2022 – July 2023
Senior Cybersecurity Architect
Selected claim: Led governed architecture review across 128 cloud resource provider types, turning bespoke infrastructure decisions into reusable control-plane patterns for regulated cloud platforms, including future policy-bound AI, agent, and data workload foundations that still require cybersecurity and GRC gates.
- Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
- Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
- Developed SDLC policy-enforcement roadmaps that replaced exception-driven cloud architecture review with standardized control selection, creating a repeatable guardrail operating model for governed AI, agent-tool, and data-platform delivery without implying direct AI deployment.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Microsoft Corporation · March 2021 – November 2021
Senior Customer Engineer, Global Tech Team
Selected claim: Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
- Advised enterprise Microsoft 365 customers on governed information-protection and DLP control patterns across Purview, sensitivity labeling, regulated-data discovery, and policy tuning, grounding agent and AI governance claims in deterministic data-access, classification, and compliance controls rather than model-specific promises.
- Converted repeated customer-engineering demand into reusable delivery programs, engineer mentoring, and product-group feedback loops, an AI-substrate pattern for turning field evidence into governed platform behavior without claiming direct model delivery.
- Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021
Senior Cybersecurity Architect
Selected claim: Architected a board-adopted security maturity roadmap across eight domains, establishing governance, control evidence, identity, endpoint-visibility, and secure-delivery foundations that later AI and automation programs would need before trusted rollout.
- Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
- Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
- Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
City National Bank · March 2020 – July 2020
Vice President, Azure Infrastructure
Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
- Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
- Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
- Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Molina Healthcare · February 2019 – February 2020
Senior Solutions Architect (Consultant, Infosys)
Selected claim: Architected a HIPAA-aligned Azure Landing Zone and hybrid-cloud migration model for roughly 16,000 production servers, 630 applications, and more than 2 PB of data, establishing the governed cloud, data, API, and automation substrate required before regulated AI systems can be trusted.
- Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
- Sequenced the first major cloud workload around a 450 TB SQL Always On cluster with 2.7 TB of daily transactions and 12-15 SDLC environments, turning the highest-risk data platform into a repeatable migration pattern for governed analytics, automation, and future AI-adjacent workloads.
- Authored Terraform-integrated Infrastructure-as-Code and orchestration frameworks for landing-zone resources, security guardrails, and SQL workload operations, creating deterministic platform controls and human-monitored cutovers that regulated data and AI systems need before higher-level automation is introduced.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Coretek Services · August 2018 – January 2019
Senior Solutions Architect
Selected claim: Consolidated a 16,000-user merger environment into a single Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, establishing the identity and messaging control-plane substrate needed for governed cloud and future AI-enabled service adoption.
- Converted a high-risk 10,000-mailbox Exchange Online migration into a controlled execution pattern with less than 2% failure, demonstrating the production-readiness discipline needed before AI-adjacent services depend on cloud collaboration data and identity continuity.
- Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
- Consolidated user and desktop infrastructure after 19 company acquisitions, preserving user attributes and configurations while standardizing Active Directory, print, DNS, DHCP, VPN, and MPLS patterns.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Obsidian Availability Solutions · September 2016 – December 2018
Principal Consultant
Selected claim: Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.
- Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
- Built repeatable customer and tenant onboarding patterns for managed-services lifecycle entry, establishing the multitenant operating substrate and access-boundary discipline that secure agent and automation platforms later depend on.
- Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Orion Technology Services · June 2015 – August 2016
Senior Solutions Engineer, Engineering Team Lead
Selected claim: Led a 12-month ITIL managed-services overhaul that turned onboarding, SLA discipline, support efficiency, and service commitments into the kind of repeatable operating model needed for governed AI-adjacent platform services.
- Designed incident, event, request, identity-access, and problem-management processes as reusable service-control patterns, establishing an operating substrate for governed automation and AI-adjacent platform workflows.
- Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the cross-system service-data foundation that governed automation and AI-adjacent support agents would need.
- Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into governable tenant structures that support knowledge, retrieval, and access-control patterns for AI-adjacent systems.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Detroit IT / Core 3 Solutions · June 2014 – February 2015
Senior Systems Administrator
Selected claim: Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365, creating cloud collaboration, document, and identity substrate for later governed automation and agent-assisted knowledge workflows.
- Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
- Administered VMware private-cloud VDI and sandbox environments for multiple software-development teams, supporting the isolated experimentation and platform reliability patterns later needed by complex AI and agent systems.
- Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Detroit Country Day School · June 2013 – June 2014
Senior Systems Analyst, Helpdesk Lead
Selected claim: Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.
- Developed SCCM-based imaging and systems-management practices for approximately 2,500 workstations, turning endpoint support into repeatable platform operations instead of manual one-off remediation.
- Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
- Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
University of Michigan, Information & Technology Services · June 2011 – September 2012
IT Engineer
Selected claim: Led asset and configuration data work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships that preserved operational context for reliable service workflows and later agent-ready ITSM reasoning.
- Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
- Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, converting endpoint and asset data into governed business intelligence for university IT decisions.
- Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Battery Giant / Energy Products · January 2007 – December 2010
IT Manager
Selected claim: Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.
- Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
- Built a centralized product-information platform spanning 250,000 products and 3,000,000+ applications, creating governed lookup, cross-reference, pricing, and inventory data substrate for later decision-support and agent-style workflows.
- Implemented centralized ledger, inventory-control, and POS data patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, grounding multi-location retail decisions in cleaner operational and financial data.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Detroit Country Day School · June 2005 – August 2006
Systems Analyst
Selected claim: Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
- Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, building early endpoint consistency and automation substrate for reliable platform operations.
- Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
- Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture