Structured special resume

Identity Management Resume

Profile-specific evidence selected from role-local JSON artifacts, using linked variants and dedupe keys so one underlying claim can be reviewed through this resume lens without duplicating the source record.

Resume at a glance

Roles
16 public role records selected for this profile.
Evidence
225 profile-selected evidence points, deduped by claim family.
Source
Adjacent JSON artifacts beside the role MDX files drive this page.

Selected Evidence

Profile-matched work history

Each panel uses the variant selected for this profile first, with supporting bullets from the same structured role artifact.

Scoria Software Solutions · March 2025 – Present

Founder & Principal Software Architect

Selected claim: Designed deterministic AI and automation guardrails for agentic and non-human workflows, using codified approvals, immutable attribution, and explicit divergence controls to strengthen audit trails and reduce attempts to bypass safety controls by 1–2 orders of magnitude.

  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
  • Kept AI-enabled tooling model- and platform-agnostic across consumer, enterprise, Azure AI Foundry, Ollama, and local-model runtimes, preserving portable control boundaries so governance did not depend on one identity or cloud provider interface.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture

Bedrock Information Systems LLC · January 2019 – Present

Principal Architect

Selected claim: Established NIST CSF 2.0 Tier 3 (Repeatable) as the baseline for onboarded systems, turning governance, compliance, and audit evidence into a repeatable control model with single-click reporting for municipal IT environments.

  • Designed Microsoft 365 information-protection controls with Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas for public-sector and regulated client data, including CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, and public-safety records.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Expanded a municipal Microsoft Teams implementation into a five-year city-wide modernization and AI roadmap, prioritizing Purview sensitivity labeling and DLP as immediate data-protection controls across 26 IT priorities.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024

Principal Cybersecurity Architect

Selected claim: Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.

  • Eliminated 45 standing privileged accounts by implementing Entra PIM and Just-in-Time access, leaving only one monitored break-glass account while enforcing M-of-N approvals, change-management evidence, and a single privileged-access audit trail.
  • Extended identity-aware information protection by tuning Microsoft Purview DLP policies, sensitivity labels, retention controls, and compliance workflows with Defender operations for regulated data categories.
  • Contained a phishing compromise of a high-value executive identity with zero data extraction, zero lateral movement, and no business impact, validating the Entra privileged-access, monitoring, and lockdown controls built for high-risk accounts.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture

Wells Fargo Bank · July 2022 – July 2023

Senior Cybersecurity Architect

Selected claim: Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity, policy, and GRC review gates.

  • Accelerated regulated cloud-security approvals from 3-12 applications per month to 40-50 reviews per week, replacing bespoke access-to-cloud review paths with standardized control gates that let application teams adopt Azure architectures at banking scale.
  • Designed Hold-Your-Own-Key (HYOK) cryptography and external key-provider controls as a bank-owned cryptographic access boundary, eliminating third-party key dependencies while preserving auditable cloud adoption under securities-regulation and FISA scrutiny.
  • Developed SDLC policy-enforcement roadmaps that moved cloud access and architecture approval from exception handling to standardized control selection, cutting application-team review effort from weeks or months to roughly one to two asynchronous hours while preserving review gates.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture

Microsoft Corporation · March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

Selected claim: Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.

  • Guided enterprise Microsoft 365 customers through Zero Trust-aligned information-protection controls across AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, connecting sensitivity labeling, regulated-data discovery, DLP policy tuning, and compliance operations to identity-aware governance outcomes.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Led post-DART identity recovery for a global ransomware response, rebuilding Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack identity dependencies, and private-cloud access paths while closing leaked-privilege lateral movement and deploying FIDO plus Microsoft Authenticator MFA across the global user base.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021

Senior Cybersecurity Architect

Selected claim: Established LACERA’s first dedicated security engineering function and three-year roadmap, grounding identity, access, governance, endpoint visibility, and security maturity work in a board-adopted NIST CSF plan that funded the next security engineering roles.

  • Remediated a Tier 0 identity-control failure by eliminating hidden super-privileged Active Directory accounts with built-in administrator, domain, enterprise, schema, and synchronized Microsoft 365 Global Administrator rights within two weeks of discovery.
  • Designed and deployed Entra and Netskope controls across approximately 550–600 users and endpoints, replacing legacy VPN-only visibility with identity-aware remote access, full-tunnel traffic inspection, firewall, web filtering, and endpoint security coverage.
  • Hardened workforce remote access during the COVID crisis, sequencing identity, VPN, endpoint, firewall, and web-filtering controls to eliminate recurring unexpected downtime and restore pre-crisis service metrics.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

City National Bank · March 2020 – July 2020

Vice President, Azure Infrastructure

Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.

  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access through Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
  • Preserved Active Directory as the source of authority for emergency remote-access authentication while integrating Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, keeping VPN and VDI scale-up auditable under crisis conditions.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture

Molina Healthcare · February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

Selected claim: Led Azure Landing Zone and hybrid-cloud migration architecture for a HIPAA-aligned healthcare estate of roughly 16,000 production servers, 630 applications, and more than 2 PB of data, keeping identity, privileged access, auditability, and cloud-security controls inside the migration model from the start.

  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.
  • Authored Terraform-integrated landing-zone automation for networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security, giving operations teams repeatable Azure guardrails while preserving reviewable control over privileged, high-impact infrastructure changes.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance

Coretek Services · August 2018 – January 2019

Senior Solutions Architect

Selected claim: Consolidated a 16,000-user merger environment into a single Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, reducing identity and email fragmentation for administrators and business users.

  • Migrated 10,000 on-premises mailboxes to Exchange Online in seven weeks with less than 2% failure, preserving user access continuity while legacy Exchange workloads moved into Microsoft 365.
  • Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
  • Implemented Microsoft 365 Conditional Access controls for device and user compliance, strengthening Azure AD identity security while preserving cloud productivity adoption.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Obsidian Availability Solutions · September 2016 – December 2018

Principal Consultant

Selected claim: Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.

  • Secured Microsoft Tier 1 / Direct CSP partner status, strengthening the firm's ability to support governed Microsoft tenant adoption and customer-facing identity operations directly.
  • Built tenant onboarding patterns for managed-services entry, giving customer environments clearer access boundaries and a more predictable path from sale through identity-aware operating service.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design

Orion Technology Services · June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

Selected claim: Led a 12-month ITIL managed-services overhaul that brought identity and access requests, customer onboarding, SLA discipline, and escalation paths into a repeatable service-operation model.

  • Designed managed-service identity and access processes alongside incident, standard request, event, and problem management, giving customers clearer provisioning, access-issue, escalation, and operational-control paths.
  • Modeled ServiceNow and ConnectWise workflows for incident, request, change, and identity-access operations, improving cross-system visibility for provider and customer teams managing shared access and service commitments.
  • Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a 150-plus-site-collection SharePoint environment, moving collaboration content into more governable tenant and access-control structures.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Detroit IT / Core 3 Solutions · June 2014 – February 2015

Senior Systems Administrator

Selected claim: Designed and delivered migration from hosted Exchange and Windows file services into Office 365, preserving user identity, document access, and collaboration continuity across Exchange Online, SharePoint Online, and Skype for Business.

  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

Detroit Country Day School · June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

Selected claim: Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.

  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture

University of Michigan, Information & Technology Services · June 2011 – September 2012

IT Engineer

Selected claim: Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.

  • Managed asset governance and lifecycle processes for more than 25,000 university endpoints and peripherals, giving leadership clearer visibility into assignment, use, location, and disposition across a 100,000-user environment.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design

Battery Giant / Energy Products · January 2007 – December 2010

IT Manager

Selected claim: Directed security, identity, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, giving branch offices and franchisees a more consistent access and infrastructure operating model.

  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing access and compliance risk while giving franchisees clearer support expectations.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership

Detroit Country Day School · June 2005 – August 2006

Systems Analyst

Selected claim: Established the school's Active Directory foundation by helping consolidate six Kerberos realms into one AD forest, giving students, faculty, and administrators a simpler authentication model and stronger directory operating base.

  • Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency so account and directory changes landed on a more predictable workstation fleet.
  • Modernized legacy Windows NT servers and Windows 98 SE workstations onto Windows Server 2003 and Windows XP, giving the new Active Directory environment a more supportable server and desktop base for daily account access.
  • Supported account and data migration into the new Active Directory environment, pairing identity rollout with training and knowledge resources so classroom users could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture