# Jake Richard Meyers - Cybersecurity Leadership

## Profile

### Background

Cybersecurity leadership resume focused on security architecture, program ownership, identity and cloud controls, governance, incident response, executive communication, and pragmatic risk reduction in regulated and high-consequence environments.

### Contact Information

- Phone: (626) 988-6620
- Email: resume@askjake.pro
- Website: [https://askjake.pro](https://askjake.pro)
- LinkedIn: [https://www.linkedin.com/in/jakermey](https://www.linkedin.com/in/jakermey)
- GitHub: [https://github.com/jakermey](https://github.com/jakermey)

## Work Experience

### Scoria Software Solutions | March 2025 – Present

> Founder & Principal Software Architect

- Established deterministic AI guardrails with codified approvals, immutable attribution, and explicit divergence controls, giving executive technology and security stakeholders auditable control boundaries for agent-enabled workflows.
- Led fractional cloud, software-delivery, data, application, and security architecture for client environments, tying modernization decisions to security assessment findings and risk-control patterns customers could actually deploy.
- Operationalized red-team/blue-team guardrail testing for deterministic AI tools, using adversarial evaluation and governance review to validate bypass resistance before customer-facing deployment.
- Created AI-assisted delivery guardrails and DevOps orchestration that reduced technical debt across 65-95% of the codebase while preserving controlled release paths for security-sensitive feature and patch delivery.
- Translated cybersecurity architecture, sensitive-data protection, and compliance requirements into deployable client patterns, keeping risk framing close to implementation instead of leaving controls as abstract policy language.
- Reduced security false positives by more than 50% and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing specialists to return to deferred SASE work.
- Built non-human identity controls for agent-enabled delivery, combining ephemeral-token preference, approval workflows, least privilege, and session attribution to reduce service-principal risk without blocking customer work.
- Coordinated software, cloud, data, infrastructure, and security workstreams through one accountable architecture thread, giving clients executive-level continuity from risk framing through production adoption.

### Bedrock Information Systems LLC | January 2019 – Present

> Principal Architect

- Implemented automated Purview DLP and information-protection controls that detected a generalized public-sector CJIS data exposure within five minutes, applied encryption and protection to copies outside Microsoft 365, and kept incident details NDA-safe.
- Established NIST CSF 2.0 Tier 3 (Repeatable) as the security-governance baseline for onboarded municipal systems, replacing awareness-level practices with repeatable controls and single-click audit reporting.
- Designed Microsoft 365 information-protection baselines for regulated public-sector environments, using Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas to support CJIS, PII, CUI, law-enforcement, and public-safety data governance.
- Expanded a municipal Microsoft Teams implementation into a five-year city-wide security and modernization roadmap, aligning 26 priorities across compliance enforcement, Purview sensitivity labeling, DLP, user training, legacy phase-out, and measurable ROI milestones.
- Advanced CJIS compliance for multiple public-sector customers by strengthening security controls while reducing sworn-officer administrative burden by 1–2 hours per day.
- Governed service-principal and workload-identity access for client-facing solutions with ephemeral-token patterns, granular permissions, and session-level audit trails aligned to customer risk models.
- Designed identity lifecycle and entitlement governance for users, service principals, app registrations, and delegated MSP/CSP access, reducing standing access while preserving auditable public-sector operations.
- Developed client governance roadmaps that tied cloud modernization, cybersecurity posture, records workflows, and service management to business outcomes so small public-sector teams could prioritize resilience work over isolated tickets.

### Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

> Principal Cybersecurity Architect

- Led a five-person cybersecurity engineering team under the CISO, turning reactive incident queues and Netskope alert noise into daily operating rhythms that cut user-reported disruptions from dozens per day to a handful per week and moved GRC from staff-chasing to dashboard-driven governance.
- Governed privileged-access risk by eliminating 45 standing administrator accounts through Entra PIM, Just-in-Time access, monitored break-glass controls, M-of-N approvals, and change-management evidence that gave leadership a single auditable control path.
- Contained a phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no business-system impact, validating privileged-access monitoring and lockdown controls under real operating pressure.
- Institutionalized red-team and blue-team exercises across Pentera, Defender, and Purview, driving Defender event volume down by two orders of magnitude and closing nearly all historical vulnerabilities within one quarter of joint operation.
- Delivered board-visible security dashboards and live monitoring that translated posture, progress, and risk into executive operating signals, compressing project-charter and approval cycles from multi-quarter processes to a monthly cadence for faster budget and resource decisions.
- Operationalized continuous red-team validation with Pentera and Defender correlation, converting hundreds of findings into a risk-ranked remediation program that closed Critical and High issues in the first month and drove the residual backlog to roughly 10-12 active findings.
- Established the Information Security Engineering Team as a dedicated CISO-led function, creating the operating model for security architecture, tool implementation, vulnerability remediation, and consultative support to infrastructure and application teams.
- Established security as an equal participant in a weekly Change Review Board, using ServiceNow GRC evidence to raise legitimate change flow from a handful per month to dozens per week while reducing delivery cycles from weeks to days or hours with almost no post-change regressions.

### Wells Fargo Bank | July 2022 – July 2023

> Senior Cybersecurity Architect

- Standardized regulated cloud security review gates that accelerated approvals from 3-12 applications per month to 40-50 completed reviews per week, helping thousands of application teams move into Azure architectures without bypassing security, infrastructure, or GRC requirements.
- Translated cybersecurity, compliance, cryptography, and platform trade-offs into executive and provider decision support, aligning 12 to 100+ engineers and specialists behind a cloud-provider choice that reduced security risk across a bank-scale endpoint and ATM footprint.
- Led the Service Enablement Task Force for regulated cloud security architecture across 128 resource provider types, converting bespoke infrastructure decisions into pre-approved Azure patterns that gave thousands of downstream applications governed adoption paths while preserving cybersecurity and GRC review gates.
- Designed multi-layer HYOK/BYOK and external-key-provider governance that removed third-party cryptographic dependency risk, preserved bank-controlled key operations, and made encryption assurance a decisive cloud-adoption control for regulated architecture review.
- Developed SDLC and security-governance roadmaps that shifted regulated cloud architecture approval from exception-driven review to standardized control selection, reducing application-team effort to roughly one to two asynchronous hours while making review gates more consistent and repeatable.
- Developed standardized compliance scoring for cloud services and resource-provider gaps, giving cybersecurity, infrastructure, and GRC leaders a repeatable evidence model for risk review, closure planning, provider comparison, and governed approval decisions.
- Conducted comparative Azure and Google Cloud security analysis, translating provider gaps into closure plans, compliance scoring inputs, and control-model decisions that balanced platform capability, residual risk, and regulated cloud adoption requirements.
- Guided infrastructure teams toward ARM Templates and Azure Blueprints so cloud security requirements became repeatable deployment standards, reducing configuration drift and making control enforcement more reliable for governed Azure adoption across high-volume application portfolios.

### Microsoft Corporation | March 2021 – November 2021

> Senior Customer Engineer, Global Tech Team

- Led post-DART cybersecurity remediation after a global ransomware response, sequencing a worldwide identity and security overhaul across directory, Microsoft 365, Azure, and private-cloud dependencies while closing leaked-privilege lateral movement and deploying phishing-resistant MFA at enterprise scale.
- Led Microsoft-scale customer engineering for Fortune 500, U.S. government, high-technology, and Microsoft internal customers as a Global Tech Team escalation authority, managing 37 dedicated accounts while resolving identity, cybersecurity, cloud, and product-group issues that had no remaining internal escalation path.
- Led enterprise customer engineering for Microsoft 365 information-protection programs across MIP, Purview, sensitivity labeling, regulated-data discovery, and DLP policy tuning, translating compliance obligations and operational risk into usable security controls.
- Mentored approximately a dozen engineers and contributed to internal training plus standardized customer-delivery programs, turning high-consequence security, identity, and compliance lessons into repeatable field guidance and product-group feedback loops.
- Contributed to customer-facing and Microsoft-internal postmortems for a major global service outage, turning incident evidence into safer rollout controls, geo-resiliency protections, and disaster-recovery guidance for Premier and Unified Support customers.
- Brokered strategic-customer escalation evidence into shipped Microsoft 365 platform behavior, translating anonymous-link security, permissions, workflow, and integration risk into product-group decisions through standing feedback loops.
- Translated red-team, blue-team, laboratory, customer-submission, bug, and vulnerability evidence into product-group signal across security, compliance, identity, and cloud services, helping Microsoft turn strategic-customer findings into safer platform behavior without exposing customer-confidential details.
- Converted DART identity-remediation findings into an executive-ready security control sequence, prioritizing external-identity hardening, privilege closure, and phishing-resistant authentication before broader cloud and platform cleanup.

### Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

> Senior Cybersecurity Architect

- Architected LACERA's first dedicated cybersecurity engineering program and board-adopted three-year security maturity roadmap, converting a NIST CSF Level 1 baseline into a funded Level 3 target state with executive sponsorship and three new security engineering roles.
- Led risk remediation for hidden super-privileged Active Directory and Microsoft 365 Global Administrator access, eliminating unaudited Tier 0 exposure within two weeks while preserving the evidence boundary around suspected destructive associations.
- Sequenced Tier 0-equivalent remediation around directory authority, audit visibility, synchronized cloud privilege, and remote-access hardening so leadership could expand the security roadmap from a trusted identity foundation.
- Governed Entra and Netskope deployment across approximately 550-600 users and endpoints, replacing VPN-only remote-work visibility with identity-aware access, full-tunnel inspection, firewall, web-filtering, and endpoint-security controls.
- Led crisis-period remote-access hardening across identity, VPN, endpoint, firewall, and web-filtering controls, eliminating recurring unexpected downtime and restoring pre-crisis service metrics for the organization served.
- Designed privileged-access governance for PAW/SAW, resource PIM, JEA, and break-glass operations, pairing hands-on implementation with infrastructure-team enablement so elevated access could be controlled without slowing service delivery.
- Converted shadow IT and high-risk access findings into program ownership by initiating five formal RFPs for ServiceNow, PMO tooling, and Microsoft security solutions, tying platform decisions to risk remediation and the next security-maturity phase.
- Led senior security architecture for the Secure Productive Enterprise initiative across Active Directory, networking, Microsoft 365, Azure, landing zones, and core services so implementation teams had a coherent security and cloud-governance foundation.

### City National Bank | March 2020 – July 2020

> Vice President, Azure Infrastructure

- Coordinated with security and compliance stakeholders on zero trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster recovery, keeping emergency remote-work delivery aligned with regulated banking control and audit expectations.
- Preserved Active Directory as the auditable source of authority for emergency remote-access authentication while integrating Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing authentication-fragmentation risk as VPN and VDI expanded at crisis speed.
- Stabilized secure remote-access continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams behind federated identity, MFA, and continuous RADIUS validation, preserving workforce access without relaxing regulated control expectations during emergency facility closures.
- Drove Azure foundational-infrastructure strategy for a regulated bank with identity, access management, virtual networking, monitoring, and migration planning built into the roadmap, giving engineering teams security architecture guidance before workloads moved into cloud execution.
- Reviewed cloud-migration design documents for secure access, service refactoring, post-cutover cost control, and operational risk, reducing one-off security decisions during a compressed regulated-bank transformation window.
- Created and reviewed infrastructure design documents that standardized cloud, identity, monitoring, and service-refactoring decisions before Azure migration, giving application and engineering teams governed security architecture guidance instead of ad hoc workload patterns.
- Advanced Azure availability monitoring and proactive incident-response patterns, improving security-relevant visibility and resilience while remote access became a business-continuity dependency for regulated financial-services operations.
- Implemented standardized project and service-management practices for cloud migration work, giving technical staff and business units clearer visibility into security-relevant deliverables, risks, adoption support, and operational readiness under regulated-bank constraints.

### Molina Healthcare | February 2019 – February 2020

> Senior Solutions Architect (Consultant, Infosys)

- Embedded HIPAA controls, comprehensive audit trails, and SIEM/SOAR integration points into the landing-zone architecture, securing security-team approval by converting regulatory, detection, identity, and privileged-access requirements into architecture decisions migration teams could execute.
- Led security architecture for a HIPAA-aligned Azure Landing Zone and hybrid-cloud migration across roughly 16,000 production servers, 630 applications, and more than 2 PB of healthcare data, keeping identity, privileged access, auditability, zero-trust networking, and cloud-security controls in the program design from the start.
- Authored Terraform-integrated landing-zone and cutover automation for networking, gateways, firewalls, Zero Trust network security, and SQL operations, improving control consistency while keeping high-impact healthcare infrastructure changes reviewable by security, operations, and migration teams.
- Aligned CyberArk privileged-access governance with Entra ID, Azure RBAC, and landing-zone operating patterns so a regulated healthcare migration could coordinate PAM, least privilege, auditability, and operational execution inside one security architecture.
- Governed Azure tenants, subscriptions, Azure RBAC, and privileged-access controls across the migration program, connecting cloud-security architecture standards to enforceable operating procedures for application, infrastructure, and security teams in a HIPAA-aligned environment.
- Chose the organization’s most business-critical SQL Always On workload as the first major migration, using a 450 TB healthcare data platform with 2.7 TB of daily transactions and 12-15 SDLC environments to prove security controls, migration governance, and repeatability decisions before broader cloud adoption.
- Governed Azure tenants, subscriptions, Azure RBAC, and core shared services while approving migration and management plans, connecting cloud-security standards, privileged-access expectations, and access-control decisions to enforceable operating execution.
- Reframed a stalled regulated-healthcare migration into an executable Azure security and delivery model by aligning executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around migration governance, shared risk decisions, and a common execution plan.

### Coretek Services | August 2018 – January 2019

> Senior Solutions Architect

- Consolidated a 16,000-user merger environment into one Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, reducing identity and messaging fragmentation that complicated security governance after the merger.
- Evaluated internal and client cloud, identity, endpoint, security, and managed-service health, converting findings into mitigation plans and modernization roadmaps customers could sequence by risk, readiness, and operational impact.
- Implemented Microsoft 365 Conditional Access controls for device and user compliance, strengthening identity security while keeping cloud productivity adoption viable for users and administrators.
- Architected Project Online onboarding, offboarding, and access provisioning automation, turning PMO role access into a repeatable governance control instead of informal project-team requests.
- Designed a secure, highly available file-sharing and virtual-desktop data solution, balancing collaborative access, patching, backup, disaster recovery, and cost constraints for sensitive media and digital content workflows.
- Configured secured on-premises SMTP and email relay patterns for applications and devices, preserving business-process continuity while Exchange workloads moved into cloud-managed security and messaging architectures.
- Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
- Designed the Project Online lifecycle model across production and sandbox instances, turning resource, team-member, project-manager, portfolio-manager, and administrator access into repeatable provisioning and deprovisioning controls.

### Obsidian Availability Solutions | September 2016 – December 2018

> Principal Consultant

- Implemented Enterprise PKI with offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening authentication controls for regulated customer environments.
- Designed and implemented privileged-access operating patterns across internal and customer environments, using Tier 0-style separation, PAW/SAW practices, JEA, and resource PIM concepts to reduce standing privilege where organizational maturity supported enforcement.
- Designed certificate templates, enrollment paths, and AD CS administrative RBAC for SCCM, RADIUS, and general access use cases, turning certificate authentication into an operable security-control service.
- Designed early Azure AD lifecycle and entitlement patterns for internal and customer tenants, connecting onboarding, role changes, offboarding, group-based access, and delegated CSP/MSP administration into repeatable security controls.
- Implemented hybrid-cloud, identity, collaboration, communication, and security systems across customer environments, aligning Microsoft cloud platforms and security policies into governed operating patterns.
- Implemented hybrid identity and federation foundations across Microsoft cloud customer environments, aligning directory synchronization, access boundaries, and tenant onboarding so customers could adopt cloud services without losing operational control of identity risk.
- Authored and maintained security policies, procedures, designs, and reports for hybrid-cloud, identity, and productivity environments, converting project decisions into reusable governance and operational-control documentation.
- Led 24/7/365 critical-situation response and executive advisory work, translating availability, security, and business-continuity risks into practical remediation plans for customer and internal environments.

### Orion Technology Services | June 2015 – August 2016

> Senior Solutions Engineer, Engineering Team Lead

- Designed incident, event, request, identity-access, and problem-management processes as managed-service control patterns, improving escalation, access operations, and security-service consistency.
- Governed delegated administration across several dozen Office 365 tenant environments, turning CSP/MSP support patterns into a controlled multi-tenant service model with clearer privileged-access boundaries.
- Completed LogRhythm SIEM training and certification work for required client projects, expanding managed-service capability for security monitoring and threat-detection delivery.
- Designed hosted private-cloud multi-tenancy patterns on VMware-era infrastructure, separating customer environments and access paths into a clearer managed-cloud control model.
- Modeled ServiceNow and ConnectWise integrations for incident, event, problem, change, and identity-access workflows, strengthening cross-system tracking for shared managed-service control commitments.
- Organized managed-services engineering across several dozen Office 365 tenant environments, standardizing repeatable tenant support, migration, and access-control patterns for cloud-service operations.
- Led a 12-month ITIL managed-services overhaul that brought onboarding, SLA discipline, access requests, escalation paths, and service commitments into a repeatable control-oriented operating model.
- Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, helping the Network Operations Center detect integration and automation failures before they became service-risk events.

### Detroit IT / Core 3 Solutions | June 2014 – February 2015

> Senior Systems Administrator

- Conducted security assessments and implemented protective measures for customer environments, tying infrastructure modernization to breach prevention, risk reduction, and practical customer control improvement.
- Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365 while preserving identity, document access, and collaboration continuity across customer environments.
- Secured Office 365 migration planning for Citrix-hosted customers, preserving identity, access, document integrity, and collaboration controls during the move from hosted Exchange and file services to Microsoft cloud services.
- Planned a multi-state network overhaul across ISPs, Cisco UCM voice, VPN, MPLS, hardware refresh, and disaster-recovery services, coordinating infrastructure controls that reduced customer operating fragility.
- Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
- Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
- Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
- Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.

### Detroit Country Day School | June 2013 – June 2014

> Senior Systems Analyst, Helpdesk Lead

- Refreshed Track-It! ITSM usage by defining classification, escalation, and prioritization standards, building the service-governance discipline that later security operations and risk escalation depend on.
- Supported Office 365 and classroom-software adoption with account migration assistance, user training, and knowledge resources, reducing identity and collaboration rollout risk for school users.
- Managed implementation work for student-information system improvements, strengthening data accessibility for staff and faculty who depended on accurate academic and administrative records.
- Delivered staff training on new technologies and software, increasing comfort with adopted tools and reducing avoidable support demand after rollout.
- Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
- Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
- Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
- Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.

### University of Michigan, Information & Technology Services | June 2011 – September 2012

> IT Engineer

- Managed asset governance and lifecycle processes for more than 25,000 university endpoints and peripherals, improving leadership visibility into assignment, use, location, and disposition across a 100,000-user environment.
- Provided VIP cybersecurity and technical support for critical university personnel, resolving escalations and deployments where reliability, discretion, rapid response, and institutional trust mattered to leadership.
- Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
- Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
- Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
- Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
- Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.
- Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.

### Battery Giant / Energy Products | January 2007 – December 2010

> IT Manager

- Directed security, identity, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, establishing early ownership of access, infrastructure controls, and operational risk across branch and franchise systems.
- Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational and compliance risk without overstating the early-role scope beyond practical control ownership.
- Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
- Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
- Developed online training, LMS, documentation, and support resources for franchisees and staff, reducing dependence on one-off support interactions while standardizing technology adoption.
- Advised executives on secure digital transformation, IT governance, and franchise technology strategy, connecting practical systems work to expansion, compliance, and operational risk decisions.
- Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
- Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.

### Detroit Country Day School | June 2005 – August 2006

> Systems Analyst

- Helped consolidate six Kerberos realms into one Active Directory forest, creating an early identity-control foundation for a multi-campus school environment while keeping the claim grounded in hands-on directory design rather than formal security leadership.
- Developed security-focused service workflows and endpoint protocols for classroom technology, improving escalation, prioritization, and access-control practices in a high-touch academic environment.
- Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.
- Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
- Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
- Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
- Led incident, request, and change-management practices for end-user systems during early identity and endpoint modernization, giving users a clearer path for support while the environment shifted from legacy platforms.
- Managed enterprise imaging, software installation, and workstation refresh activity for students, faculty, management, and directory-infrastructure servers, linking endpoint reliability to day-to-day classroom continuity.

## Education

### The University of Michigan, Ann Arbor, MI

- College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
- School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

### Detroit Country Day School, Beverly Hills, MI

- High School Diploma | College Preparatory Curriculum

## Skills

**AI Systems, Safety & Applied LLM Engineering**
Deterministic guardrails, immutable attribution, AI-assisted development guardrails, secure LLM deployment patterns, continuous red-team/blue-team exercises, adversarial safety-control testing, prompt-injection and jailbreak evaluation, Azure AI Foundry, Ollama/local models, hybrid multi-model routing, Model- and platform-agnostic XLM (LLM/SLM) orchestration, MCP toolkits, model evaluation frameworks, token optimization

**Cybersecurity Architecture, Detection & Operations**
risk management, Cybersecurity architecture, cloud security architecture, privileged-access overhauls, change-integrated security scanning, GRC / ServiceNow integration, Microsoft Defender, Microsoft Purview, Pentera, XDR and vulnerability management, threat detection, Zero Trust architecture, SIEM, SOAR

**Soft Skills & Cross-Functional Practice**
Executive communication, stakeholder alignment, project and program coordination, technical mentoring, vendor evaluation, RFP demonstration leadership, proof-of-concept facilitation, change adoption, non-technical stakeholder training

**Identity, Access & Cryptography**
Service-principal and workload-identity lifecycle governance, workload identities, managed identities, service principals at scale, RBAC and least-privilege design, secrets-management patterns, Entra ID Governance lifecycle workflows, Microsoft Graph and Azure Management API identity automation, Microsoft Entra ID / Azure AD, Entra ID Governance, CyberArk privileged-access integration governance, Privileged Identity Management (PIM), Entra B2B/B2C, external identity, and CIAM patterns, Tenant access boundaries and multi-tenancy control patterns

**Azure Data, Analytics & AI Platforms**
Azure Databricks, Databricks lakehouse architecture, feature preparation, lakehouse-oriented sports analytics, governed analytics platforms, production readiness, reusable reference architectures, Cloud Adoption Framework, Azure Well-Architected Framework for analytics and AI workloads, data landing zones, workload modernization

**Product Design, Technical UX & Sports Decision Support**
sports decision support, telemetry-informed iteration, schema-driven UI, design systems, component systems, technical-user experience, workflow mapping, executive-ready tradeoff framing, product requirements, product strategy, design-to-production delivery, Stakeholder interviews, cross-functional design reviews, information architecture

**Compliance, Governance & Control Assurance**
CJIS, NIST CSF 2.0, continuous control monitoring, audit automation, HIPAA, PCI, CUI, PII, law-enforcement and public-safety data protection, financial and health data protection, control translation for customer and sector-specific governance models, standards libraries, control evidence and reporting, secure architecture review

**Microsoft Purview, DLP & Information Protection**
Microsoft Purview Data Loss Prevention across Microsoft 365 and endpoints, auto-labeling, data classification, sensitivity labels, retention labels and policies, Teams DLP, sensitive-data discovery and mapping, DLP policy authoring, AD RMS to Azure Information Protection (AIP) to Microsoft Information Protection (MIP) to Purview modernization

_Generated from structured resume artifacts for Cybersecurity Leadership Resume; document version v26.8.20._
