Scoria Software Solutions · March 2025 – Present
Founder & Principal Software Architect
Selected claim: Established deterministic AI guardrails with codified approvals, immutable attribution, and explicit divergence controls, giving executive technology and security stakeholders auditable control boundaries for agent-enabled workflows.
- Reduced security false positives by more than 50% and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing specialists to return to deferred SASE work.
- Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
- Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Bedrock Information Systems LLC · January 2019 – Present
Principal Architect
Selected claim: Established NIST CSF 2.0 Tier 3 (Repeatable) as the security-governance baseline for onboarded municipal systems, replacing awareness-level practices with repeatable controls and single-click audit reporting.
- Designed Microsoft 365 information-protection baselines for regulated public-sector environments, using Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas to support CJIS, PII, CUI, law-enforcement, and public-safety data governance.
- Advanced CJIS compliance for multiple public-sector customers by strengthening security controls while reducing sworn-officer administrative burden by 1–2 hours per day.
- Expanded a municipal Microsoft Teams implementation into a five-year city-wide security and modernization roadmap, aligning 26 priorities across compliance enforcement, Purview sensitivity labeling, DLP, user training, legacy phase-out, and measurable ROI milestones.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024
Principal Cybersecurity Architect
Selected claim: Led a five-person cybersecurity engineering team under the CISO, turning reactive incident queues and Netskope alert noise into daily operating rhythms that cut user-reported disruptions from dozens per day to a handful per week and moved GRC from staff-chasing to dashboard-driven governance.
- Governed privileged-access risk by eliminating 45 standing administrator accounts through Entra PIM, Just-in-Time access, monitored break-glass controls, M-of-N approvals, and change-management evidence that gave leadership a single auditable control path.
- Owned information-protection outcomes across Purview DLP, sensitivity labels, retention, compliance workflows, and Defender operations, reducing unmanaged sensitive-data exposure across regulated data categories while giving security and compliance leaders usable control evidence.
- Contained a phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no business-system impact, validating privileged-access monitoring and lockdown controls under real operating pressure.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Wells Fargo Bank · July 2022 – July 2023
Senior Cybersecurity Architect
Selected claim: Led the Service Enablement Task Force for regulated cloud security architecture across 128 resource provider types, converting bespoke infrastructure decisions into pre-approved Azure patterns that gave thousands of downstream applications governed adoption paths while preserving cybersecurity and GRC review gates.
- Standardized regulated cloud security review gates that accelerated approvals from 3-12 applications per month to 40-50 completed reviews per week, helping thousands of application teams move into Azure architectures without bypassing security, infrastructure, or GRC requirements.
- Designed multi-layer HYOK/BYOK and external-key-provider governance that removed third-party cryptographic dependency risk, preserved bank-controlled key operations, and made encryption assurance a decisive cloud-adoption control for regulated architecture review.
- Developed SDLC and security-governance roadmaps that shifted regulated cloud architecture approval from exception-driven review to standardized control selection, reducing application-team effort to roughly one to two asynchronous hours while making review gates more consistent and repeatable.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Microsoft Corporation · March 2021 – November 2021
Senior Customer Engineer, Global Tech Team
Selected claim: Led Microsoft-scale customer engineering for Fortune 500, U.S. government, high-technology, and Microsoft internal customers as a Global Tech Team escalation authority, managing 37 dedicated accounts while resolving identity, cybersecurity, cloud, and product-group issues that had no remaining internal escalation path.
- Led enterprise customer engineering for Microsoft 365 information-protection programs across MIP, Purview, sensitivity labeling, regulated-data discovery, and DLP policy tuning, translating compliance obligations and operational risk into usable security controls.
- Mentored approximately a dozen engineers and contributed to internal training plus standardized customer-delivery programs, turning high-consequence security, identity, and compliance lessons into repeatable field guidance and product-group feedback loops.
- Led post-DART cybersecurity remediation after a global ransomware response, sequencing a worldwide identity and security overhaul across directory, Microsoft 365, Azure, and private-cloud dependencies while closing leaked-privilege lateral movement and deploying phishing-resistant MFA at enterprise scale.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021
Senior Cybersecurity Architect
Selected claim: Architected LACERA's first dedicated cybersecurity engineering program and board-adopted three-year security maturity roadmap, converting a NIST CSF Level 1 baseline into a funded Level 3 target state with executive sponsorship and three new security engineering roles.
- Led risk remediation for hidden super-privileged Active Directory and Microsoft 365 Global Administrator access, eliminating unaudited Tier 0 exposure within two weeks while preserving the evidence boundary around suspected destructive associations.
- Governed Entra and Netskope deployment across approximately 550-600 users and endpoints, replacing VPN-only remote-work visibility with identity-aware access, full-tunnel inspection, firewall, web-filtering, and endpoint-security controls.
- Led crisis-period remote-access hardening across identity, VPN, endpoint, firewall, and web-filtering controls, eliminating recurring unexpected downtime and restoring pre-crisis service metrics for the organization served.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
City National Bank · March 2020 – July 2020
Vice President, Azure Infrastructure
Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
- Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
- Stabilized secure remote-access continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams behind federated identity, MFA, and continuous RADIUS validation, preserving workforce access without relaxing regulated control expectations during emergency facility closures.
- Preserved Active Directory as the auditable source of authority for emergency remote-access authentication while integrating Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing authentication-fragmentation risk as VPN and VDI expanded at crisis speed.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Molina Healthcare · February 2019 – February 2020
Senior Solutions Architect (Consultant, Infosys)
Selected claim: Led security architecture for a HIPAA-aligned Azure Landing Zone and hybrid-cloud migration across roughly 16,000 production servers, 630 applications, and more than 2 PB of healthcare data, keeping identity, privileged access, auditability, zero-trust networking, and cloud-security controls in the program design from the start.
- Reframed a stalled regulated-healthcare migration into an executable Azure security and delivery model by aligning executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around migration governance, shared risk decisions, and a common execution plan.
- Chose the organization’s most business-critical SQL Always On workload as the first major migration, using a 450 TB healthcare data platform with 2.7 TB of daily transactions and 12-15 SDLC environments to prove security controls, migration governance, and repeatability decisions before broader cloud adoption.
- Authored Terraform-integrated landing-zone and cutover automation for networking, gateways, firewalls, Zero Trust network security, and SQL operations, improving control consistency while keeping high-impact healthcare infrastructure changes reviewable by security, operations, and migration teams.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Coretek Services · August 2018 – January 2019
Senior Solutions Architect
Selected claim: Consolidated a 16,000-user merger environment into one Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, reducing identity and messaging fragmentation that complicated security governance after the merger.
- Migrated 10,000 on-premises mailboxes from Exchange 2007/2013 to Exchange Online in seven weeks with less than 2% failure and minimal user impact, converting a high-risk mail migration into a controlled execution pattern.
- Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
- Implemented Microsoft 365 Conditional Access controls for device and user compliance, strengthening identity security while keeping cloud productivity adoption viable for users and administrators.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Obsidian Availability Solutions · September 2016 – December 2018
Principal Consultant
Selected claim: Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.
- Secured Microsoft Tier 1 / Direct CSP partner status, expanding managed cloud and security offerings while giving customer environments a stronger direct-adoption path for governed Microsoft services.
- Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.
- Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Orion Technology Services · June 2015 – August 2016
Senior Solutions Engineer, Engineering Team Lead
Selected claim: Led a 12-month ITIL managed-services overhaul that brought onboarding, SLA discipline, access requests, escalation paths, and service commitments into a repeatable control-oriented operating model.
- Designed incident, event, request, identity-access, and problem-management processes as managed-service control patterns, improving escalation, access operations, and security-service consistency.
- Modeled ServiceNow and ConnectWise integrations for incident, event, problem, change, and identity-access workflows, strengthening cross-system tracking for shared managed-service control commitments.
- Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into more governable tenant and access-control structures.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Detroit IT / Core 3 Solutions · June 2014 – February 2015
Senior Systems Administrator
Selected claim: Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365 while preserving identity, document access, and collaboration continuity across customer environments.
- Planned a multi-state network overhaul across ISPs, Cisco UCM voice, VPN, MPLS, hardware refresh, and disaster-recovery services, coordinating infrastructure controls that reduced customer operating fragility.
- Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
- Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Detroit Country Day School · June 2013 – June 2014
Senior Systems Analyst, Helpdesk Lead
Selected claim: Refreshed Track-It! ITSM usage by defining classification, escalation, and prioritization standards, building the service-governance discipline that later security operations and risk escalation depend on.
- Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
- Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
- Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
University of Michigan, Information & Technology Services · June 2011 – September 2012
IT Engineer
Selected claim: Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.
- Managed asset governance and lifecycle processes for more than 25,000 university endpoints and peripherals, improving leadership visibility into assignment, use, location, and disposition across a 100,000-user environment.
- Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
- Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Battery Giant / Energy Products · January 2007 – December 2010
IT Manager
Selected claim: Directed security, identity, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, establishing early ownership of access, infrastructure controls, and operational risk across branch and franchise systems.
- Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
- Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
- Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Detroit Country Day School · June 2005 – August 2006
Systems Analyst
Selected claim: Helped consolidate six Kerberos realms into one Active Directory forest, creating an early identity-control foundation for a multi-campus school environment while keeping the claim grounded in hands-on directory design rather than formal security leadership.
- Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.
- Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
- Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture