# Jake Richard Meyers - AI Systems and Agent Architecture

## Profile

### Background

AI systems and agent architecture resume focused on deterministic guardrails, model-agnostic orchestration, governed automation, data and API foundations, security controls, and practical operating models for AI-enabled delivery.

### Contact Information

- Phone: (626) 988-6620
- Email: resume@askjake.pro
- Website: [https://askjake.pro](https://askjake.pro)
- LinkedIn: [https://www.linkedin.com/in/jakermey](https://www.linkedin.com/in/jakermey)
- GitHub: [https://github.com/jakermey](https://github.com/jakermey)

## Work Experience

### Scoria Software Solutions | March 2025 – Present

> Founder & Principal Software Architect

- Architected deterministic agent guardrails with codified approval paths, immutable attribution, and explicit divergence controls, giving AI-enabled tools auditable safety boundaries instead of relying on prompt intent alone.
- Built the XLM engine and MCP toolkit family as a model-agnostic agent architecture that converts a single prompt into deterministic multi-platform application stacks, compressing early-adopter POC cycles from months to weeks.
- Designed model- and platform-agnostic routing across Azure AI Foundry, Ollama, local models, consumer apps, and enterprise platforms, improving portability while one customer reduced Azure spend 65% and cut latency from 3–5 seconds to 10–150 ms.
- Developed a canonical JSON-schema application engine for web, native, desktop, API, CLI, and MCP surfaces, giving agentic workflows one structured contract boundary and shared component vocabulary across generated interfaces.
- Architected Fumaro Sports on Azure Databricks lakehouse patterns for model-ready feature preparation, predictive analytics, and governed human-in-the-loop release controls, translating sports intelligence into a reusable AI data-platform pattern.
- Reduced token consumption 60–90% across four LLM-driven document-generation workflow steps, giving agentic content pipelines a lower-runtime path to publication-ready output without post-processing.
- Designed Fumaro Sports evaluation loops around analyst review, scout feedback, telemetry-aware runtime logging, staged beta validation, and human-in-the-loop release governance so model output can improve without concealing uncertainty from users.
- Created a DevOps orchestration engine with AI-development guardrails that reduced technical debt across 65–95% of the codebase and compressed feature and patch delivery from weeks or months to days or hours.

### Bedrock Information Systems LLC | January 2019 – Present

> Principal Architect

- Operationalized deterministic guardrails for AI-assisted development so infrastructure and application engineers could use agentic tooling within controlled delivery patterns, accelerating timelines 50–75% while preserving team capacity, auditability, and release discipline.
- Governed non-human identity access for client-facing agentic solutions with ephemeral-token patterns, explicit check-in/check-out, granular permissions, and session-level audit trails so tool execution stayed accountable to customer risk models.
- Built a government records digitization workflow that converted century-scale microfilm into OCR/ICR-optimized, PDF/A-compliant assets with full metadata, creating a searchable data substrate for future analytics and AI-assisted public-records workflows without overstating autonomous system deployment.
- Established NIST CSF 2.0 Tier 3 (Repeatable) as a governance substrate for municipal AI adoption, turning control evidence, compliance workflows, and audit reporting into repeatable architecture guardrails before introducing higher-risk automation.
- Designed Azure DevOps and GitHub repository, CI/CD, and release standards that made security, compliance, budget constraints, and deterministic review gates first-class controls for AI-assisted and conventional delivery across multi-environment application fleets.
- Designed Microsoft 365 information-protection and classification guardrails for public-sector AI readiness, using Purview sensitivity labels, DLP patterns, retention controls, and regulated-data schemas to keep CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, and public-safety data governed before automation.
- Expanded a municipal Microsoft Teams implementation into a five-year city-wide AI adoption and modernization roadmap, sequencing 26 priorities across security, compliance, user training, data protection, legacy phase-out, and ROI milestones so AI work rested on governed collaboration and information-protection foundations.
- Developed public-sector AI readiness and governance roadmaps that connected cloud modernization, cybersecurity posture, records workflows, service management, and business outcomes so small teams could prioritize governed automation opportunities over isolated tickets.

### Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

> Principal Cybersecurity Architect

- Automated Entra and Microsoft Cloud identity operations through Microsoft Graph and Azure Management API control-plane patterns, proving the API, audit, and lifecycle-governance foundations needed for safe agentic administration without persistent privilege.
- Connected Purview, Defender, GRC, and change-management evidence into DLP investigation workflows, giving stakeholders audit-ready classification, policy-effectiveness, false-positive, and remediation signals needed before governed automation or agent-assisted security workflows can be trusted.
- Developed automation and orchestration patterns around repeatable controls, audit evidence, governed change execution, and headcount constraints, defining deterministic operating inputs that a future security automation or agent architecture could safely inherit.
- Converted privileged administration into deterministic Entra PIM, Just-in-Time access, M-of-N approval, break-glass monitoring, and change-evidence flows, creating the auditable access substrate future security automation or agent workflows would need before acting on high-risk systems.
- Tuned Purview DLP, sensitivity-labeling, retention, and compliance controls for regulated data categories, creating deterministic data-classification and access-governance foundations that support safe AI and agent platform adoption without exposing sensitive information.
- Validated the privileged-access and monitoring substrate during a real high-value phishing compromise, proving that governed identity controls, telemetry, and lockdown workflows could contain risk with zero data extraction, lateral movement, or business impact before any higher-risk automation depended on them.
- Designed a Secure Productive Enterprise roadmap across identity, Microsoft 365, Azure foundations, endpoint controls, data protection, and access modernization, defining the secure platform architecture future AI and agent capabilities would need to inherit.
- Converted ServiceNow GRC and change-management data into a governed delivery loop for privileged-access and security changes, giving future automation and agent workflows explicit approval paths, evidence capture, regression controls, and deterministic go/no-go inputs.

### Wells Fargo Bank | July 2022 – July 2023

> Senior Cybersecurity Architect

- Developed standardized compliance scoring for cloud services and resource-provider gaps, giving security, infrastructure, and GRC teams a quantifiable evidence model for governed AI/data workload readiness, agent-tool review, closure planning, and audit-defensible platform decisions.
- Led governed architecture review across 128 cloud resource provider types, turning bespoke infrastructure decisions into reusable control-plane patterns for regulated cloud platforms, including future policy-bound AI, agent, and data workload foundations that still require cybersecurity and GRC gates.
- Developed SDLC policy-enforcement roadmaps that replaced exception-driven cloud architecture review with standardized control selection, creating a repeatable guardrail operating model for governed AI, agent-tool, and data-platform delivery without implying direct AI deployment.
- Conducted comparative Azure and Google Cloud security analysis, translating provider gaps into closure plans and control-model decisions that establish governed multi-cloud foundations for data, AI-platform, and agent-tool evaluation.
- Guided infrastructure teams toward ARM Templates and Azure Blueprints so security requirements could be encoded as repeatable cloud landing patterns, reducing drift and creating governed foundations suitable for future AI, agent-service, and data workloads.
- Managed vendor integration and security-SME Q&A, converting provider evidence into design-guide controls and repeatable approval gates for governed cloud services, including the same evidence discipline required for AI, agent-tool, and data-platform review.
- Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
- Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.

### Microsoft Corporation | March 2021 – November 2021

> Senior Customer Engineer, Global Tech Team

- Converted red-team, blue-team, lab, customer-submission, bug, and vulnerability evidence into product-group signal for security, compliance, identity, and cloud services, a public-safe pattern for AI safety work that separates adversarial testing evidence from model-specific or customer-confidential details.
- Delivered custom Azure Well-Architected engagements for complex enterprise customers whose scale exceeded standard guidance, translating cloud, data, resilience, governance, and platform-engineering constraints into reference architecture decisions that supported major multi-year Azure commitments.
- Brokered customer escalation evidence into shipped Microsoft 365 platform behavior, translating workflow, permissions, anonymous-link security, and integration constraints into product-group feedback loops relevant to governed agent/tool architecture.
- Advised enterprise Microsoft 365 customers on governed information-protection and DLP control patterns across Purview, sensitivity labeling, regulated-data discovery, and policy tuning, grounding agent and AI governance claims in deterministic data-access, classification, and compliance controls rather than model-specific promises.
- Supported MSIT, LinkedIn, GitHub, and Microsoft product organizations through distributed identity, cybersecurity, migration, incident, and critical-situation work, applying enterprise escalation discipline to internal platform reliability patterns relevant to agentic systems.
- Converted repeated customer-engineering demand into reusable delivery programs, engineer mentoring, and product-group feedback loops, an AI-substrate pattern for turning field evidence into governed platform behavior without claiming direct model delivery.
- Helped remediate a hyperscale service outage by tracing an infrastructure-as-code workflow to the failure path, guiding rollback and permanent-fix planning, and turning postmortem evidence into safer geo-resiliency and rollout controls that map directly to deterministic agent/tool governance patterns.
- Published reusable PowerShell, ARM-template, GitHub, Microsoft Learn, and field-delivery assets that converted repeated Azure infrastructure, Microsoft 365, identity, and cybersecurity escalation patterns into governed tooling and reference guidance for customer engineers and product groups.

### Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

> Senior Cybersecurity Architect

- Applied Microsoft Graph-era control-plane patterns to privileged identity administration, using API-first inspection and remediation to expose high-risk access paths that UI-only governance would miss in automation-driven environments.
- Architected a board-adopted security maturity roadmap across eight domains, establishing governance, control evidence, identity, endpoint-visibility, and secure-delivery foundations that later AI and automation programs would need before trusted rollout.
- Designed privileged-access guardrails for PAW/SAW, resource PIM, JEA, and break-glass operations, creating control patterns for elevated automation paths while preserving service delivery and operator accountability.
- Created a modernization roadmap that aligned identity, endpoint management, cloud enablement, business-service migration, and data-protection requirements before platform tooling could shape the control architecture for automation-ready services.
- Planned data and information-security compliance controls for future business services, grounding modernization decisions in classification, protection, and control-evidence requirements before higher-trust automation or AI-adjacent workflows could be considered safe.
- Planned identity, endpoint, and information-security compliance controls for future business services, aligning access governance, data protection, and required security standards before implementation choices narrowed the architecture.
- Consulted with information systems and application teams on security states and planned configurations, making access, compliance, and secure configuration decisions part of delivery rather than detached review.
- Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.

### City National Bank | March 2020 – July 2020

> Vice President, Azure Infrastructure

- Consulted security and compliance stakeholders on zero trust, SIEM/SOAR, endpoint encryption, RBAC, and disaster recovery, preserving the control-plane guardrails that governed AI-enabled and agentic systems require before sensitive workflows can be automated safely.
- Reviewed cloud-migration design documents for service refactoring, post-cutover cost control, and secure-access considerations, translating architecture review into reusable guardrails for regulated platform delivery rather than one-off workload exceptions.
- Drove Azure foundational-infrastructure strategy across virtual networks, identity, access management, monitoring, and application migration planning, establishing cloud substrate patterns that later AI and agent systems depend on for secure platform execution.
- Created and reviewed infrastructure design documents that standardized cloud, identity, monitoring, and service-refactoring decisions before Azure migration, turning application-team guidance into reusable platform architecture substrate.
- Advanced Azure availability monitoring and proactive incident-response patterns, strengthening the observability and resilience substrate needed before regulated digital workflows can safely depend on automated or agent-assisted platform operations.
- Implemented standardized project and service-management practices for cloud migration work, making deliverables, risks, adoption support, and operational readiness visible enough for governed platform delivery under regulated-bank constraints.
- Planned user adoption and transition support for new infrastructure services, reducing the risk that cloud platform changes would pass technical validation but fail operationally for the staff expected to use governed tooling.
- Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.

### Molina Healthcare | February 2019 – February 2020

> Senior Solutions Architect (Consultant, Infosys)

- Authored Terraform-integrated Infrastructure-as-Code and orchestration frameworks for landing-zone resources, security guardrails, and SQL workload operations, creating deterministic platform controls and human-monitored cutovers that regulated data and AI systems need before higher-level automation is introduced.
- Embedded HIPAA controls, audit trails, and SIEM/SOAR integration points into the landing-zone architecture, creating the deterministic governance, compliance evidence, and security-review gates required for regulated data platforms and AI-adjacent systems.
- Architected a HIPAA-aligned Azure Landing Zone and hybrid-cloud migration model for roughly 16,000 production servers, 630 applications, and more than 2 PB of data, establishing the governed cloud, data, API, and automation substrate required before regulated AI systems can be trusted.
- Sequenced the first major cloud workload around a 450 TB SQL Always On cluster with 2.7 TB of daily transactions and 12-15 SDLC environments, turning the highest-risk data platform into a repeatable migration pattern for governed analytics, automation, and future AI-adjacent workloads.
- Developed reusable secure-healthcare-cloud patterns from migration, governance, automation, auditability, security, and communication lessons, packaging the operating foundations regulated data and AI-adjacent programs need before system-specific implementation work begins.
- Extended migration orchestration and Infrastructure-as-Code patterns with Azure access-control guardrails, using PowerShell, Terraform-integrated workflows, and human-monitored cutovers to create a repeatable, reviewable control plane for regulated data-platform modernization and AI-adjacent automation.
- Wrote a proprietary PowerShell migration-orchestration module that reduced repetitive lift-and-shift work and gave teams a consistent control plane for repeatable workload movement, a prerequisite operating pattern for governed data and AI-adjacent platform modernization.
- Standardized service-oriented architecture guidance across network, security, compute, database, reporting, IAM, and content-distribution services, giving application teams reusable service boundaries and control patterns for governed API, data, automation, and agent-platform adoption.

### Coretek Services | August 2018 – January 2019

> Senior Solutions Architect

- Designed lifecycle and entitlement patterns across Microsoft 365, Project Online, and merger-consolidation work, translating onboarding, offboarding, license, group, and role-access requirements into reusable governance controls for automation-heavy platforms.
- Designed Project Online production and sandbox lifecycle controls for resource, team-member, project-manager, portfolio-manager, and administrator access, establishing a role-governed workflow model applicable to agentic system boundaries.
- Architected Project Online onboarding, offboarding, and access provisioning automation, turning PMO role access into a repeatable governance pattern relevant to policy-bound agent and workflow systems.
- Consolidated a 16,000-user merger environment into a single Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, establishing the identity and messaging control-plane substrate needed for governed cloud and future AI-enabled service adoption.
- Evaluated cloud, identity, endpoint, security, and managed-service health, converting architecture findings into modernization roadmaps that sequence platform improvements before higher-risk AI or automation adoption.
- Guided Project Web App roadmap development, templatization, and PMO process structure, turning project operations into a repeatable workflow model that aligns with governed agent and automation architecture patterns.
- Turned Microsoft 365 project delivery lessons into a repeatable managed-service program for a 10,000-plus-seat pilot customer, creating an operating pattern for governed cloud adoption that can support later AI-enabled workplace services.
- Converted a high-risk 10,000-mailbox Exchange Online migration into a controlled execution pattern with less than 2% failure, demonstrating the production-readiness discipline needed before AI-adjacent services depend on cloud collaboration data and identity continuity.

### Obsidian Availability Solutions | September 2016 – December 2018

> Principal Consultant

- Implemented hybrid-cloud, identity, collaboration, communication, and security platforms across customer environments, creating the governed infrastructure substrate that future automation, data, and AI-adjacent systems require.
- Implemented Enterprise PKI with offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, providing cryptographic trust fabric for secure identity, device, service, and automation control planes.
- Designed early Azure AD lifecycle and entitlement patterns for internal and customer tenants, connecting onboarding, role changes, offboarding, group-based access, and delegated CSP/MSP administration into a repeatable identity control plane for managed automation.
- Designed and implemented privileged-access operating patterns across internal and customer environments, using Tier 0-style separation, PAW/SAW practices, JEA, and resource PIM concepts to reduce standing privilege in automation-capable control planes.
- Authored and maintained security policies, procedures, designs, and reports for hybrid-cloud, identity, and productivity environments, creating reusable governance artifacts for secure platform operations and AI-adjacent control maturity.
- Implemented hybrid identity and federation foundations across Microsoft cloud customer environments, aligning directory synchronization, access boundaries, and tenant onboarding practices into a governed trust layer for automation-ready cloud adoption.
- Built repeatable customer and tenant onboarding patterns for managed-services lifecycle entry, establishing the multitenant operating substrate and access-boundary discipline that secure agent and automation platforms later depend on.
- Evaluated technical products, services, and strategic partnerships across cloud, security, high-availability, and managed-services domains, building architecture judgment for vendor-agnostic platform choices that AI and agent systems still require.

### Orion Technology Services | June 2015 – August 2016

> Senior Solutions Engineer, Engineering Team Lead

- Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, creating observability and failure-detection patterns that support dependable automation and AI-adjacent service operations.
- Governed delegated administration across several dozen Office 365 tenant environments, turning CSP/MSP support patterns into a controlled multi-tenant service model relevant to secure AI-adjacent agent operations.
- Designed hosted private-cloud multi-tenancy patterns on VMware-era infrastructure, separating customer environments and access paths in an early control-plane model for managed cloud and AI-adjacent platform delivery.
- Organized managed-services engineering across several dozen Office 365 tenant environments, turning repeated migration and support work into a multi-tenant cloud-service operating model relevant to governed AI and agent platforms.
- Designed incident, event, request, identity-access, and problem-management processes as reusable service-control patterns, establishing an operating substrate for governed automation and AI-adjacent platform workflows.
- Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, establishing hybrid infrastructure and resilience patterns that later AI-adjacent platform services depend on.
- Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the cross-system service-data foundation that governed automation and AI-adjacent support agents would need.
- Led a 12-month ITIL managed-services overhaul that turned onboarding, SLA discipline, support efficiency, and service commitments into the kind of repeatable operating model needed for governed AI-adjacent platform services.

### Detroit IT / Core 3 Solutions | June 2014 – February 2015

> Senior Systems Administrator

- Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365, creating cloud collaboration, document, and identity substrate for later governed automation and agent-assisted knowledge workflows.
- Administered VMware private-cloud VDI and sandbox environments for multiple software-development teams, supporting the isolated experimentation and platform reliability patterns later needed by complex AI and agent systems.
- Implemented availability-management and disaster-recovery practices for customer environments, strengthening the reliability substrate that governed automation and agent-supported service workflows depend on.
- Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
- Conducted security assessments and implemented protective measures for customer environments, connecting infrastructure modernization to breach prevention and risk reduction.
- Secured Office 365 migration planning for Citrix-hosted customers, preserving identity, access, document integrity, and collaboration controls during the move from hosted Exchange and file services to Microsoft cloud services.
- Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
- Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.

### Detroit Country Day School | June 2013 – June 2014

> Senior Systems Analyst, Helpdesk Lead

- Developed SCCM-based imaging and systems-management practices for approximately 2,500 workstations, turning endpoint support into repeatable platform operations instead of manual one-off remediation.
- Managed student-information system improvements that strengthened data accessibility for staff and faculty, reinforcing the governed records substrate needed for later analytics and agent-assisted administrative workflows.
- Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
- Delivered staff training on new technologies and software, increasing comfort with adopted tools and reducing avoidable support demand after rollout.
- Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.
- Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
- Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
- Supported school-issued and sponsored software adoption, including Office 365 and classroom solutions, with account migration assistance, user training, and knowledge resources that reduced adoption friction.

### University of Michigan, Information & Technology Services | June 2011 – September 2012

> IT Engineer

- Led asset and configuration data work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships that preserved operational context for reliable service workflows and later agent-ready ITSM reasoning.
- Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, converting endpoint and asset data into governed business intelligence for university IT decisions.
- Developed and delivered ITIL training that standardized incident, request, service-transition, and operational practices, building the governed service substrate needed before automation can safely reshape support workflows.
- Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
- Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
- Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
- Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
- Developed procurement, lifecycle-management, and disposition processes for end-user assets, giving university IT a cleaner chain of custody from purchase through retirement.

### Battery Giant / Energy Products | January 2007 – December 2010

> IT Manager

- Built a centralized product-information platform spanning 250,000 products and 3,000,000+ applications, creating governed lookup, cross-reference, pricing, and inventory data substrate for later decision-support and agent-style workflows.
- Implemented centralized ledger, inventory-control, and POS data patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, grounding multi-location retail decisions in cleaner operational and financial data.
- Rebuilt disaster-recovery and network design practices for mission-critical systems, proving the availability and recovery substrate that dependable AI-enabled business workflows require before higher-level automation can be trusted.
- Developed LMS, documentation, and support resources that turned franchise technology rollout knowledge into reusable adoption substrate, an early pattern for scaling complex systems through governed human enablement.
- Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.
- Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
- Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
- Maintained branch-office technology, local and remote data centers, and replica systems to strengthen availability, business continuity, and franchise support across distributed retail locations.

### Detroit Country Day School | June 2005 – August 2006

> Systems Analyst

- Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, building early endpoint consistency and automation substrate for reliable platform operations.
- Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
- Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
- Developed security-focused service workflows and endpoint protocols for classroom technology, improving prioritization, escalation, and access-control practices in a high-touch academic setting.
- Managed enterprise imaging, software installation, and workstation refresh activity for students, faculty, management, and directory-infrastructure servers, linking endpoint reliability to day-to-day classroom continuity.
- Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
- Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
- Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.

## Education

### The University of Michigan, Ann Arbor, MI

- College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
- School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

### Detroit Country Day School, Beverly Hills, MI

- High School Diploma | College Preparatory Curriculum

## Skills

**AI Systems, Safety & Applied LLM Engineering**
Deterministic guardrails, immutable attribution, AI-assisted development guardrails, secure LLM deployment patterns, Model- and platform-agnostic XLM (LLM/SLM) orchestration, MCP toolkits, Azure AI Foundry, Ollama/local models, hybrid multi-model routing, token optimization, model evaluation frameworks, continuous red-team/blue-team exercises, adversarial safety-control testing, prompt-injection and jailbreak evaluation

**Cybersecurity Architecture, Detection & Operations**
risk management, Cybersecurity architecture, cloud security architecture, change-integrated security scanning, REST and GraphQL API security, Microsoft Purview, Microsoft Defender, Zero Trust architecture, GRC / ServiceNow integration, Pentera, XDR and vulnerability management, threat detection, SIEM, SOAR

**Product Design, Technical UX & Sports Decision Support**
schema-driven UI, design systems, component systems, technical-user experience, sports decision support, telemetry-informed iteration, baseball analytics, baseball operations software, workflow mapping, executive-ready tradeoff framing, product requirements, product strategy, design-to-production delivery, Stakeholder interviews

**Azure Data, Analytics & AI Platforms**
Azure Databricks, Databricks lakehouse architecture, feature preparation, lakehouse-oriented sports analytics, Data engineering, production readiness, governed analytics platforms, reusable reference architectures, Cloud Adoption Framework, Azure Well-Architected Framework for analytics and AI workloads, data landing zones, workload modernization

**Soft Skills & Cross-Functional Practice**
Executive communication, stakeholder alignment, project and program coordination, technical mentoring, vendor evaluation, RFP demonstration leadership, proof-of-concept facilitation, change adoption, non-technical stakeholder training

**Identity, Access & Cryptography**
Service-principal and workload-identity lifecycle governance, workload identities, managed identities, service principals at scale, RBAC and least-privilege design, secrets-management patterns, Entra ID Governance lifecycle workflows, Microsoft Graph and Azure Management API identity automation, Microsoft Entra ID / Azure AD, Entra ID Governance, Entra B2B/B2C, external identity, and CIAM patterns, Tenant access boundaries and multi-tenancy control patterns, customer identity and access management (CIAM), Entra ID B2C

**Compliance, Governance & Control Assurance**
NIST CSF 2.0, continuous control monitoring, audit automation, CJIS, HIPAA, PCI, CUI, PII, law-enforcement and public-safety data protection, financial and health data protection, control translation for customer and sector-specific governance models, standards libraries, control evidence and reporting, secure architecture review

**Infrastructure as Code, DevOps & Supply Chain**
Azure DevOps, GitHub, CI/CD pipelines, repository governance, Policy as Code, Infrastructure as Code, ARM Templates, Terraform, PowerShell, full lifecycle automation across heterogeneous targets, private-cloud, configuration management patterns

_Generated from structured resume artifacts for AI Systems and Agent Architecture Resume; document version v26.8.20._
