Structured special resume

Entertainment and Live Venue Technology Resume

Profile-specific evidence selected from role-local JSON artifacts, using linked variants and dedupe keys so one underlying claim can be reviewed through this resume lens without duplicating the source record.

Resume at a glance

Roles
16 public role records selected for this profile.
Evidence
208 profile-selected evidence points, deduped by claim family.
Source
Adjacent JSON artifacts beside the role MDX files drive this page.

Selected Evidence

Profile-matched work history

Each panel uses the variant selected for this profile first, with supporting bullets from the same structured role artifact.

Scoria Software Solutions · March 2025 – Present

Founder & Principal Software Architect

Selected claim: Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence, producing clearer audit trails, faster incident response (seconds or milliseconds instead of minutes), and a 1–2 order-of-magnitude reduction in attempts to bypass safety controls.

  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Built a model- and platform-agnostic XLM/MCP delivery engine that converts natural-language intent into deterministic multi-surface application stacks, a transferable pattern for live-event platforms that need web, API, CLI, and tool workflows to move together under production guardrails.
  • Designed model- and platform-agnostic runtime options across Azure AI Foundry, Ollama, local models, consumer apps, and enterprise platforms, preserving low-latency and cost-aware deployment paths that transfer to live-event systems where local fallback and fast response matter.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture

Bedrock Information Systems LLC · January 2019 – Present

Principal Architect

Selected claim: Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.

  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Led a municipal Microsoft Teams collaboration rollout into a five-year modernization roadmap across 26 priorities, a transferable operating model for entertainment technology groups coordinating collaboration, security, compliance, training, adoption, and legacy phase-out without claiming entertainment-employer delivery.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024

Principal Cybersecurity Architect

Selected claim: Converted reactive security queues, user-reported disruptions, and alert noise into daily operating rhythms and dashboard-driven governance, a transferable live-venue technology pattern for keeping service continuity visible under operational pressure.

  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Extended regulated content-security controls by tuning Purview DLP, sensitivity labels, retention policies, and Defender-aligned compliance workflows, a transferable pattern for protecting sensitive entertainment, venue, or audience data without claiming direct production credit.
  • Contained a high-pressure privileged-account compromise with zero data extraction, zero lateral movement, and no business-system impact, a transferable incident-response and service-continuity pattern for live operations where downtime is visible immediately.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture

Wells Fargo Bank · July 2022 – July 2023

Senior Cybersecurity Architect

Selected claim: Led governed cloud-architecture review across 128 resource-provider types, turning bespoke infrastructure choices into reusable patterns transferable to studio and venue enterprises that need trusted cloud foundations without weakening security or GRC approval gates.

  • Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
  • Designed multi-layer HYOK cryptography and external key-provider governance as transferable content-security discipline for studio and venue cloud systems that must protect sensitive data while preserving auditable key control.
  • Developed SDLC policy-enforcement roadmaps that shifted the organization from an exception-driven culture to standardized architecture selection; application teams’ effort dropped from dozens of hours spread over weeks or months to roughly one to two hours of asynchronous work, while security and infrastructure teams achieved substantially higher output volume with near-universal consistency of results.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture

Microsoft Corporation · March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

Selected claim: Operated at Microsoft customer-engineering scale across Fortune 500, public-sector, high-technology, and internal customers, managing 37 dedicated accounts while resolving cloud, data, identity, reliability, and product-group escalations whose operational pressure transfers to live-venue technology environments without implying venue-specific delivery.

  • Advised enterprise Microsoft 365 customers on Purview, sensitivity labeling, regulated-data discovery, and DLP policy tuning, framing content-protection controls that transfer to entertainment enterprises managing sensitive creative, operational, and partner-access data.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021

Senior Cybersecurity Architect

Selected claim: Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap spanning eight domains that was formally adopted by the CISO, IT leadership, and the Board; established a NIST CSF baseline at Level 1 with a formal target of Level 3 and secured a funded multi-year program that immediately opened three new security engineering roles.

  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
  • Stabilized workforce remote access under crisis conditions, sequencing identity, VPN, endpoint, firewall, and web-filtering controls to eliminate recurring unexpected downtime, a transferable live-venue service-continuity pattern for time-bound operations and production-adjacent support workflows.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

City National Bank · March 2020 – July 2020

Vice President, Azure Infrastructure

Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.

  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized secure remote-access continuity by scaling VPN, VDI, Microsoft 365, and Teams behind federated identity, MFA, and continuous RADIUS validation, a transferable live-venue operations pattern for preserving staff access without relaxing control expectations during facility disruption.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture

Molina Healthcare · February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

Selected claim: Architected a governed Azure landing-zone and hybrid-cloud migration model for roughly 16,000 production servers, 630 applications, and more than 2 PB of regulated data, a transferable studio and live-venue platform pattern for secure workload migration and executive-ready operating foundations.

  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Sequenced the first major migration around the most business-critical SQL Always On workload, protecting 450 TB of data with 2.7 TB of daily transactions and 12-15 SDLC environments to prove a resilient platform pattern transferable to live-venue and production-systems operations.
  • Authored the majority of the Infrastructure-as-Code and orchestration frameworks that provisioned and governed all Landing Zone resources (networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security) as well as the ongoing deployment and maintenance of the critical SQL Always On workload; integrated the frameworks into the organization’s existing Terraform processes so that operational teams experienced zero change to day-to-day maintenance and management, while end-to-end automated cutovers (including a perfectly clean production SQL Always On migration) required only human monitoring.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance

Coretek Services · August 2018 – January 2019

Senior Solutions Architect

Selected claim: Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a merger, reducing fragmentation in identity and email operations.

  • Migrated 10,000 on-premises mailboxes to Exchange Online in seven weeks with less than 2% failure, a transferable cutover pattern for creative and live-venue teams that need collaboration access to continue while platform foundations change.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during consolidation, a transferable access-continuity pattern for creative teams that need shared workspaces and collaboration history to survive platform migration.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Obsidian Availability Solutions · September 2016 – December 2018

Principal Consultant

Selected claim: Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.

  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design

Orion Technology Services · June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

Selected claim: Led a 12-month ITIL managed-services overhaul that strengthened onboarding, SLA discipline, support efficiency, and escalation paths, transferable to live-venue technology operations where production-adjacent services need predictable run-state control.

  • Designed incident, event, standard request, access, and problem-management processes as managed-service operating patterns, transferable to venue technology teams that need calm escalation and continuity during live operations.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the service-data foundation transferable to venue technology operations, production-systems tracking, and continuity control.
  • Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into governable tenant structures transferable to venue operations, production knowledge, and content-security workflows.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Detroit IT / Core 3 Solutions · June 2014 – February 2015

Senior Systems Administrator

Selected claim: Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.5 TB of Windows file services to SharePoint Online, and Skype for Business for internal and external communication.

  • Planned a multi-state network overhaul across ISPs, Cisco UCM voice, VPN, MPLS, hardware refresh, and disaster-recovery services, showing transferable continuity planning for distributed venue technology operations with network and voice dependencies.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into durable fixes and clearer support paths for technical users in service-continuity-sensitive environments.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

Detroit Country Day School · June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

Selected claim: Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, creating clearer service expectations for a high-touch user community that included faculty, staff, students, parents, alumni, and guests.

  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets across campuses with limited dedicated technology-center space, showing transferable device-fleet planning for venue-like environments where users need technology without facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting user-facing continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture

University of Michigan, Information & Technology Services · June 2011 – September 2012

IT Engineer

Selected claim: Built a University of Michigan School of Music, Theatre, and Dance production background across 18 theatre productions from 2011-2015, spanning lighting design, sound design, stage management, assistant master electrician work, light-board operation, sound-board operation, live sound, and music-production training.

  • Led asset and configuration data work for the BMC Remedy to ServiceNow transition, preserving operational context that live-venue and production technology teams also need for reliable equipment support, ownership, and service continuity.
  • Managed asset governance and lifecycle processes for more than 25,000 endpoints, classroom technologies, and peripherals, showing transferable asset-readiness discipline for venue and production technology environments.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, turning endpoint and asset data into operational visibility relevant to venue technology readiness, equipment support, and service decisions.
Operations/service deliveryTraining/knowledge managementEntertainment ProductionEntertainment Live Venue TechnologyEntertainment ProductionAvailability Resilience

Battery Giant / Energy Products · January 2007 – December 2010

IT Manager

Selected claim: Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.

  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
  • Implemented centralized ledger, inventory-control, and POS data patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, giving transferable evidence for venue-like commerce systems where transaction integrity, loss prevention, and multi-location operations matter.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership

Detroit Country Day School · June 2005 – August 2006

Systems Analyst

Selected claim: Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.

  • Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, showing transferable endpoint-readiness discipline for venue-like environments with shared devices, rotating users, and time-sensitive service demand.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture