Structured special resume

Enterprise and Cloud Architecture Resume

Profile-specific evidence selected from role-local JSON artifacts, using linked variants and dedupe keys so one underlying claim can be reviewed through this resume lens without duplicating the source record.

Resume at a glance

Roles
16 public role records selected for this profile.
Evidence
219 profile-selected evidence points, deduped by claim family.
Source
Adjacent JSON artifacts beside the role MDX files drive this page.

Selected Evidence

Profile-matched work history

Each panel uses the variant selected for this profile first, with supporting bullets from the same structured role artifact.

Scoria Software Solutions · March 2025 – Present

Founder & Principal Software Architect

Selected claim: Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence, producing clearer audit trails, faster incident response (seconds or milliseconds instead of minutes), and a 1–2 order-of-magnitude reduction in attempts to bypass safety controls.

  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Architected the XLM engine and MCP toolkit family as a model- and platform-agnostic application architecture, converting natural-language intent into deterministic cloud, web, API, CLI, and MCP delivery patterns that shortened early-adopter POC cycles from months to weeks.
  • Designed model- and platform-agnostic cloud architecture across Azure AI Foundry, Ollama, local models, consumer apps, and enterprise platforms, improving workload portability while one customer cut Azure spend 65% and reduced application latency from 3-5 seconds to 10-150 ms.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture

Bedrock Information Systems LLC · January 2019 – Present

Principal Architect

Selected claim: Established NIST CSF 2.0 Tier 3 (Repeatable) as a platform-governance baseline for onboarded municipal systems, turning scattered control practices into repeatable architecture evidence and single-click audit reporting.

  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Expanded a municipal Microsoft Teams implementation into a five-year city-wide AI adoption and modernization roadmap, sequencing 26 priorities across security, compliance, user training, data protection, legacy phase-out, and ROI milestones so AI work rested on governed collaboration and information-protection foundations.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024

Principal Cybersecurity Architect

Selected claim: Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.

  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture

Wells Fargo Bank · July 2022 – July 2023

Senior Cybersecurity Architect

Selected claim: Led the Service Enablement Task Force for enterprise cloud architecture across 128 resource provider types, converting custom infrastructure decisions into reusable Azure blueprints and pre-approved service patterns that let bank application teams adopt standardized designs at migration scale.

  • Accelerated enterprise cloud architecture approvals from 3-12 applications per month to 40-50 completed reviews per week, unblocking the bank's first successful large-scale public-cloud migration program through standardized Azure infrastructure solution patterns.
  • Designed HYOK and external-key-provider architecture as the enterprise cloud adoption unblocker, removing third-party cryptographic dependencies and giving the bank a 100% bank-controlled key-management model for regulated public-cloud migration.
  • Developed enterprise cloud governance roadmaps that moved application teams from exception-driven architecture review to standardized blueprint selection, reducing review effort from weeks or months to roughly one to two asynchronous hours while preserving platform approval gates.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture

Microsoft Corporation · March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

Selected claim: Led Microsoft-scale customer engineering across Fortune 500, public-sector, high-technology, and internal Microsoft environments, managing 37 dedicated accounts while serving as the final architecture escalation path for global cloud, data, identity, reliability, and product-group issues.

  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Led post-DART enterprise architecture remediation after a global ransomware response, sequencing recovery across Active Directory forests, Microsoft 365 tenants, Azure, Azure Stack, and private-cloud dependencies while closing privilege-risk paths without losing platform modernization momentum.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021

Senior Cybersecurity Architect

Selected claim: Architected a board-adopted three-year enterprise technology and security roadmap across eight domains, converting a NIST CSF Level 1 baseline into a funded Level 3 target state that sequenced cloud foundations, platform modernization, staffing, and risk reduction for executive decision-makers.

  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Modernized the remote-work platform across approximately 550-600 users and endpoints, replacing VPN-only visibility with Entra, Netskope, full-tunnel inspection, firewall, web-filtering, and endpoint controls that gave cloud and infrastructure teams an operable visibility foundation for distributed service delivery.
  • Stabilized enterprise remote access during the COVID crisis by sequencing VPN, identity, endpoint, firewall, and web-filtering work, eliminating recurring unexpected downtime and restoring service metrics while preserving the longer-term cloud enablement and platform modernization path.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

City National Bank · March 2020 – July 2020

Vice President, Azure Infrastructure

Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.

  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Scaled VPN, VDI, Microsoft 365, and Teams access as enterprise continuity infrastructure for a national bank, preserving workforce availability during emergency facility closures while federated identity, MFA, and RADIUS validation remained supporting control-plane requirements.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture

Molina Healthcare · February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

Selected claim: Architected the Azure Landing Zone and hybrid-cloud migration program for a regulated healthcare estate of roughly 16,000 production servers, 40,000 total environments, 630 applications, and more than 2 PB of data, giving application and infrastructure teams a governed enterprise-cloud foundation for platform modernization at production scale.

  • Reframed a stalled healthcare cloud-migration program into an executable enterprise architecture by aligning executives, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around shared platform decisions, restoring delivery momentum for LOB modernization.
  • Sequenced the first major migration around the highest-value LOB workload: a 450 TB SQL Always On platform with 2.7 TB of daily transactions and 12-15 SDLC environments, proving the workload-migration architecture, cost model, risk posture, and repeatable pattern before broader enterprise-cloud adoption.
  • Authored Terraform-integrated Infrastructure-as-Code and orchestration frameworks for landing-zone resources including networking, Virtual WAN, storage, gateways, firewalls, SQL Always On operations, and automated cutovers, preserving familiar operations workflows while standardizing enterprise platform governance and repeatable migration execution.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance

Coretek Services · August 2018 – January 2019

Senior Solutions Architect

Selected claim: Architected a 16,000-user Exchange Online and Azure AD tenant consolidation across 32 Exchange environments and 27 Active Directory forests after a merger, reducing platform fragmentation for administrators and business users.

  • Migrated 10,000 on-premises Exchange mailboxes to Exchange Online in seven weeks with less than 2% failure, converting legacy collaboration migration risk into a controlled cloud-platform execution pattern.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Obsidian Availability Solutions · September 2016 – December 2018

Principal Consultant

Selected claim: Co-founded an IT consulting firm and built Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendor partnerships into a managed-cloud service portfolio for customer tenant, infrastructure, collaboration, and security environments.

  • Secured Microsoft Tier 1 / Direct CSP partner status, strengthening the firm's managed cloud architecture model for direct customer tenant onboarding, Microsoft service adoption, and CSP-backed delivery.
  • Built repeatable customer and tenant onboarding patterns for managed cloud lifecycle entry, turning sales handoff, implementation scope, delegated access, and Microsoft tenant readiness into a predictable operating model.
  • Developed a per-unit managed-services cost model that connected cloud tenant, infrastructure, collaboration, and platform delivery scope to more accurate contract pricing and financially sustainable customer operations.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design

Orion Technology Services · June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

Selected claim: Led a 12-month ITIL managed-services architecture overhaul that turned onboarding, SLA discipline, support efficiency, and escalation paths into a repeatable operating model for enterprise cloud and infrastructure services.

  • Designed incident, event, standard request, access, and problem-management processes as reusable service-operation architecture, converting reactive support patterns into more predictable managed cloud delivery and escalation control.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the shared service-data foundation for managed cloud and infrastructure operations.
  • Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a 150-plus-site-collection environment, moving collaboration workloads into more governable tenant structures for enterprise cloud operations.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Detroit IT / Core 3 Solutions · June 2014 – February 2015

Senior Systems Administrator

Selected claim: Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365, including Exchange Online, SharePoint Online, and Skype for Business collaboration services.

  • Planned a multi-state network overhaul for six offices across five states, coordinating ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving reliable collaboration and experimentation capacity.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

Detroit Country Day School · June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

Selected claim: Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, turning recurring helpdesk work into clearer service operations for a multi-campus school environment.

  • Developed SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, turning endpoint support into repeatable platform operations instead of manual remediation.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding digital-learning access through a fit-for-facilities endpoint platform.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture

University of Michigan, Information & Technology Services · June 2011 – September 2012

IT Engineer

Selected claim: Built a University of Michigan School of Music, Theatre, and Dance production background across 18 theatre productions from 2011-2015, spanning lighting design, sound design, stage management, assistant master electrician work, light-board operation, sound-board operation, live sound, and music-production training.

  • Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved service operations context.
  • Managed asset governance and lifecycle processes for more than 25,000 university endpoints, classroom technologies, and peripherals, giving leadership clearer visibility across a 100,000-user environment.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, turning endpoint and asset data into governed decision support for university IT operations.
Operations/service deliveryTraining/knowledge managementEntertainment ProductionEntertainment Live Venue TechnologyEntertainment ProductionAvailability Resilience

Battery Giant / Energy Products · January 2007 – December 2010

IT Manager

Selected claim: Directed infrastructure, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, giving branch offices and franchisees a standard platform foundation for growth instead of ad hoc local systems.

  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths, helping the retail platform expand from 2 stores to 11 in 18 months with a repeatable branch rollout model.
  • Built a centralized ecommerce and product-information platform spanning 250,000 products and 3,000,000+ applications, giving franchise operations a shared platform for lookup, pricing, inventory, and cross-reference workflows.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, standardizing multi-location retail operations around shared financial and inventory platforms.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership

Detroit Country Day School · June 2005 – August 2006

Systems Analyst

Selected claim: Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.

  • Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency through a repeatable device-platform model.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while moving classrooms and administrative teams onto a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture