# Jake Richard Meyers - Identity Management

## Profile

### Background

Identity and access security architect focused on identity infrastructure, privileged-access reduction, information protection, cloud governance, non-human identity, and audit-ready control patterns across Microsoft, finance, healthcare, public-sector, product, and regulated enterprise environments.

### Contact Information

- Phone: (626) 988-6620
- Email: resume@askjake.pro
- Website: [https://askjake.pro](https://askjake.pro)
- LinkedIn: [https://www.linkedin.com/in/jakermey](https://www.linkedin.com/in/jakermey)
- GitHub: [https://github.com/jakermey](https://github.com/jakermey)

## Work Experience

### Scoria Software Solutions | March 2025 – Present

> Founder & Principal Software Architect

- Built service-principal lifecycle tooling with ephemeral-token preference, check-in/check-out approval workflows, granular least privilege, and agentic session-ID attribution, reducing non-human identity risk while preserving auditable customer delivery.
- Implemented Microsoft Graph and Azure Management API-native control-plane automation for Entra and Microsoft Cloud operations, enabling agentic workflows with stronger audit visibility and finer least-privilege boundaries than default portal-driven administration.
- Designed deterministic AI and automation guardrails for agentic and non-human workflows, using codified approvals, immutable attribution, and explicit divergence controls to strengthen audit trails and reduce attempts to bypass safety controls by 1–2 orders of magnitude.
- Engineered identity-provider-agnostic access tooling that can operate across Entra-native development, CyberArk, HashiCorp, and other privileged-identity planes, keeping customer controls portable instead of binding governance to one vendor interface.
- Kept AI-enabled tooling model- and platform-agnostic across consumer, enterprise, Azure AI Foundry, Ollama, and local-model runtimes, preserving portable control boundaries so governance did not depend on one identity or cloud provider interface.
- Translated cybersecurity, compliance, and sensitive-data protection requirements into deployable architecture patterns for client systems, keeping governance evidence connected to practical security controls.
- Designed Fumaro Sports authentication for B2C customer access, SSO, and enterprise tenancy so organizations can run governed, tenant-aware versions of the model and agent experience without collapsing consumer and enterprise identity boundaries.
- Operationalized red-team/blue-team review for deterministic AI tools, testing bypass resistance and governance approval paths before customer-facing deployment of agent-enabled workflows.

### Bedrock Information Systems LLC | January 2019 – Present

> Principal Architect

- Governed service-principal, app-registration, and workload-identity access for client-facing and agentic solutions, favoring ephemeral-token patterns, explicit check-in/check-out, granular permissions, and session-level audit trails where customer risk models required non-human identity accountability.
- Designed an Intune device-compliance and Conditional Access gate for municipal Microsoft 365 access, using policy-controlled device state as the authorization decision instead of user training alone so unmanaged endpoints could not become the path around CJIS and data-protection requirements.
- Implemented automated Purview DLP and information-protection controls that detected a public-sector CJIS exposure within five minutes and applied encryption and protection to copies stored outside Microsoft 365.
- Standardized SCIM-preferred provisioning and Microsoft Graph / Azure Management API automation as the preferred path for identity and Microsoft Cloud administration, replacing UI-bound workflows with API-native, policy-controlled operations that improved least-privilege enforcement and audit visibility.
- Designed identity lifecycle and entitlement patterns for Bedrock and customer environments, applying one governance model across users, service principals, app registrations, and delegated MSP/CSP access so public-sector clients could govern authorization, delegation, auditability, and retirement without normalizing standing access.
- Designed Microsoft 365 information-protection controls with Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas for public-sector and regulated client data, including CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, and public-safety records.
- Established NIST CSF 2.0 Tier 3 (Repeatable) as the baseline for onboarded systems, turning governance, compliance, and audit evidence into a repeatable control model with single-click reporting for municipal IT environments.
- Extended public-sector security roadmaps beyond compliance checklists by tying Entra governance, delegated MSP/CSP privileged access, information protection, and automated audit evidence to practical municipal outcomes: fewer manual controls, clearer accountability, and safer modernization.

### Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

> Principal Cybersecurity Architect

- Eliminated 45 standing privileged accounts by implementing Entra PIM and Just-in-Time access, leaving only one monitored break-glass account while enforcing M-of-N approvals, change-management evidence, and a single privileged-access audit trail.
- Contained a phishing compromise of a high-value executive identity with zero data extraction, zero lateral movement, and no business impact, validating the Entra privileged-access, monitoring, and lockdown controls built for high-risk accounts.
- Designed Entra-native governance across custom roles, entitlement-style access workflows, lifecycle controls, and ServiceNow-backed approvals so privileged work moved through repeatable evidence paths instead of persistent administrator access.
- Designed and implemented Tier 0-equivalent privileged-access controls using resource PIM, Just Enough Administration, PAW/SAW operating patterns, and break-glass governance, then trained infrastructure, service, and administrative users to operate without standing privilege.
- Connected privileged-access changes to ServiceNow GRC evidence, change tickets, and a weekly Change Review Board, giving identity and security work an auditable approval path while reducing delivery cycles from weeks to days or hours with almost no post-change regressions.
- Automated Entra and Microsoft Cloud identity operations through Microsoft Graph and Azure Management API control-plane patterns, giving a small security team repeatable leverage for privileged access, lifecycle enforcement, audit evidence, and governed change execution without persistent privilege.
- Built Purview DLP investigation workflows that connected Defender, GRC, and change-management evidence so security and compliance teams could govern sensitive-data access, policy effectiveness, false positives, and audit readiness from practical dashboards.
- Extended identity-aware information protection by tuning Microsoft Purview DLP policies, sensitivity labels, retention controls, and compliance workflows with Defender operations for regulated data categories.

### Wells Fargo Bank | July 2022 – July 2023

> Senior Cybersecurity Architect

- Developed standardized compliance scoring for cloud services and resource-provider gaps, giving cybersecurity, infrastructure, and GRC teams a shared evidence model for regulated cloud approvals, audit defensibility, and consistent control review.
- Accelerated regulated cloud-security approvals from 3-12 applications per month to 40-50 reviews per week, replacing bespoke access-to-cloud review paths with standardized control gates that let application teams adopt Azure architectures at banking scale.
- Developed SDLC policy-enforcement roadmaps that moved cloud access and architecture approval from exception handling to standardized control selection, cutting application-team review effort from weeks or months to roughly one to two asynchronous hours while preserving review gates.
- Designed Hold-Your-Own-Key (HYOK) cryptography and external key-provider controls as a bank-owned cryptographic access boundary, eliminating third-party key dependencies while preserving auditable cloud adoption under securities-regulation and FISA scrutiny.
- Influenced 12 to 100+ engineers, GRC specialists, product teams, and cryptography experts to align cloud-provider selection and adoption with bank-wide security and compliance controls across tens of thousands of endpoints and approximately 12,000 ATMs.
- Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity, policy, and GRC review gates.
- Conducted comparative Azure and Google Cloud cybersecurity analysis, translating provider gaps into closure plans that shaped the bank's cloud-security control model, policy enforcement expectations, and governed application adoption decisions.
- Guided infrastructure teams toward ARM Templates and Azure Blueprints so cloud security requirements could be encoded as repeatable deployment patterns, reducing configuration drift and strengthening policy-enforced access to approved Azure service designs.

### Microsoft Corporation | March 2021 – November 2021

> Senior Customer Engineer, Global Tech Team

- Led post-DART identity recovery for a global ransomware response, rebuilding Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack identity dependencies, and private-cloud access paths while closing leaked-privilege lateral movement and deploying FIDO plus Microsoft Authenticator MFA across the global user base.
- Sequenced the identity rebuild around priority-zero controls first: external identity hardening, Tier 0 isolation, resource PIM, JEA/constrained administration, PAW/SAW patterns, break-glass governance, and phishing-resistant authentication before broader platform cleanup, reducing the risk that recovery would preserve the same attack path.
- Authored reusable Graph, PowerShell, ARM-template, Microsoft Learn, and field-delivery assets for identity, privileged access, Azure infrastructure, Microsoft 365, and cybersecurity scenarios, converting high-consequence customer lessons into public-safe guidance for customer engineers and product groups.
- Translated legacy enterprise identity findings from DART remediation work into a modern control sequence that prioritized external-identity hardening, privilege closure, and phishing-resistant authentication before broader platform cleanup.
- Launched the first year of LACERA's three-year identity and endpoint modernization roadmap as their Microsoft engineer, standing up greenfield Active Directory and Microsoft 365 environments that closed a prior backdoor-account incident and gave the multi-year program durable operational momentum.
- Guided enterprise Microsoft 365 customers through Zero Trust-aligned information-protection controls across AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, connecting sensitivity labeling, regulated-data discovery, DLP policy tuning, and compliance operations to identity-aware governance outcomes.
- Authored reusable Graph, PowerShell, ARM-template, Microsoft Learn, and field-delivery assets for identity, privileged access, Azure infrastructure, Microsoft 365, and cybersecurity scenarios, converting high-consequence customer lessons into reusable guidance for customer engineers and product groups without exposing protected customer details.
- Translated red-team, blue-team, lab, customer-submission, bug, and vulnerability evidence into product-group signal for identity, compliance, security, and cloud services, helping Microsoft convert strategic-customer findings into safer platform behavior.

### Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

> Senior Cybersecurity Architect

- Remediated a Tier 0 identity-control failure by eliminating hidden super-privileged Active Directory accounts with built-in administrator, domain, enterprise, schema, and synchronized Microsoft 365 Global Administrator rights within two weeks of discovery.
- Treated the hidden account discovery as a Tier 0-equivalent identity-control failure, sequencing remediation around directory authority, audit visibility, synchronized cloud privilege, and remote-access hardening before expanding the security roadmap.
- Designed and deployed Entra and Netskope controls across approximately 550–600 users and endpoints, replacing legacy VPN-only visibility with identity-aware remote access, full-tunnel traffic inspection, firewall, web filtering, and endpoint security coverage.
- Established LACERA’s first dedicated security engineering function and three-year roadmap, grounding identity, access, governance, endpoint visibility, and security maturity work in a board-adopted NIST CSF plan that funded the next security engineering roles.
- Established identity, access, and visibility foundations that exposed previously unknown shadow IT and high-risk access patterns, then initiated five formal platform RFPs to turn the findings into funded modernization work.
- Created the roadmap for modernizing identity and endpoint provider systems, aligning cloud enablement, business-service migration, and data-protection requirements before tool projects could dictate access architecture.
- Designed the privileged-access foundation for PAW/SAW, resource PIM, JEA, and break-glass operations, pairing hands-on security implementation with infrastructure-team training so elevated access could be governed without blocking service delivery.
- Hardened workforce remote access during the COVID crisis, sequencing identity, VPN, endpoint, firewall, and web-filtering controls to eliminate recurring unexpected downtime and restore pre-crisis service metrics.

### City National Bank | March 2020 – July 2020

> Vice President, Azure Infrastructure

- Preserved Active Directory as the source of authority for emergency remote-access authentication while integrating Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, keeping VPN and VDI scale-up auditable under crisis conditions.
- Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access through Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
- Aligned emergency remote-work identity and endpoint-control decisions with regulated banking expectations by consulting security and compliance stakeholders on zero trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster recovery.
- Drove Azure infrastructure strategy that treated identity and access management as landing-zone design inputs, giving enterprise engineering and application teams roadmap guidance for secure migration planning, virtual networks, monitoring, and access control.
- Reviewed cloud-migration design documents for secure-access, service-refactoring, and post-cutover risk considerations, reducing one-off identity and infrastructure decisions during a compressed regulated-bank transformation window.
- Implemented standardized project and service-management practices for cloud migration work, giving technical staff and business units clearer visibility into deliverables, risks, adoption support, and operational readiness.
- Created and reviewed infrastructure design documents for application and engineering teams, helping standardize cloud, identity, monitoring, and service-refactoring decisions before workloads moved into Azure.
- Planned user adoption and transition support for new infrastructure services, reducing the risk that emergency remote-work and cloud changes would succeed technically but fail operationally for staff.

### Molina Healthcare | February 2019 – February 2020

> Senior Solutions Architect (Consultant, Infosys)

- Embedded HIPAA controls, comprehensive audit trails, and SIEM/SOAR integration points into the landing-zone design, earning security-team approval by making identity, privileged-access activity, and compliance evidence reviewable from the architecture layer rather than a late-stage checkpoint.
- Authored Terraform-integrated landing-zone automation for networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security, giving operations teams repeatable Azure guardrails while preserving reviewable control over privileged, high-impact infrastructure changes.
- Aligned CyberArk privileged-access governance with Entra ID, Azure RBAC, and landing-zone operating patterns, helping a regulated healthcare migration keep privileged access, least privilege, auditability, and operational execution coordinated across existing PAM and cloud-control boundaries.
- Led Azure Landing Zone and hybrid-cloud migration architecture for a HIPAA-aligned healthcare estate of roughly 16,000 production servers, 630 applications, and more than 2 PB of data, keeping identity, privileged access, auditability, and cloud-security controls inside the migration model from the start.
- Administered Azure tenants, subscriptions, Azure RBAC, and core shared services while approving migration and management plans, connecting least-privilege standards, identity governance, and landing-zone access decisions to operational execution.
- Governed Azure tenants, subscriptions, Azure RBAC, and privileged-access controls across the migration program, connecting landing-zone identity standards to enforceable operating procedures for application, infrastructure, and security teams working inside a HIPAA-aligned environment.
- Translated the engagement into Secure Healthcare Cloud Program patterns that packaged migration, identity governance, privileged-access alignment, automation, auditability, and security communication practices for future regulated healthcare cloud programs.
- Extended migration orchestration and Infrastructure-as-Code patterns with Azure RBAC and access-control guardrails, using PowerShell, Terraform-integrated workflows, and human-monitored cutovers to reduce repetitive migration effort while preserving reviewable control over high-impact changes.

### Coretek Services | August 2018 – January 2019

> Senior Solutions Architect

- Consolidated a 16,000-user merger environment into a single Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, reducing identity and email fragmentation for administrators and business users.
- Preserved user attributes, SIDs, passwords, groups, and profile data during multi-forest consolidation, treating identity continuity as a cutover requirement for business users and administrators.
- Implemented Microsoft 365 Conditional Access controls for device and user compliance, strengthening Azure AD identity security while preserving cloud productivity adoption.
- Designed the Project Online lifecycle model across production and sandbox instances, turning resource, team-member, project-manager, portfolio-manager, and administrator access into repeatable provisioning and deprovisioning controls.
- Migrated 10,000 on-premises mailboxes to Exchange Online in seven weeks with less than 2% failure, preserving user access continuity while legacy Exchange workloads moved into Microsoft 365.
- Architected Project Online onboarding, offboarding, and access provisioning patterns that made role access repeatable and auditable without expanding manual administration.
- Consolidated identity-adjacent desktop services after 19 acquisitions, preserving user attributes and configurations while standardizing Active Directory, VPN, DNS, DHCP, print, and network access patterns.
- Designed custom identity lifecycle and entitlement patterns across Microsoft 365, Project Online, and merger-consolidation work, translating onboarding, offboarding, license, group, and role-access requirements into repeatable governance controls.

### Obsidian Availability Solutions | September 2016 – December 2018

> Principal Consultant

- Implemented Enterprise PKI with an offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening certificate-based authentication and regulatory-aligned identity controls.
- Designed certificate templates, enrollment paths, and AD CS administrative RBAC for general, SCCM, and RADIUS use cases, turning certificate-based authentication from a one-time infrastructure build into an operable identity-control service.
- Designed early Azure AD lifecycle and entitlement patterns for internal and customer tenants, connecting onboarding, role changes, offboarding, group-based access, and delegated CSP/MSP administration into repeatable access-continuity controls.
- Designed and implemented least-privilege operating patterns across internal and customer environments, including Tier 0-style separation, PAW/SAW practices, JEA, and resource PIM concepts where organizational maturity supported hands-on enforcement.
- Implemented hybrid identity and federation foundations across Microsoft cloud customer environments, aligning directory synchronization, access boundaries, and tenant onboarding practices so customers could adopt cloud services without losing operational control of identity risk.
- Authored and maintained security policies, procedures, designs, and reports for hybrid-cloud, identity, and productivity environments, giving teams reusable governance documentation instead of one-time project artifacts.
- Implemented Microsoft cloud identity and security foundations across customer environments, aligning Azure subscriptions, productivity platforms, collaboration systems, and security policies into identity-aware managed-service operating patterns.
- Built tenant onboarding patterns for managed-services entry, giving customer environments clearer access boundaries and a more predictable path from sale through identity-aware operating service.

### Orion Technology Services | June 2015 – August 2016

> Senior Solutions Engineer, Engineering Team Lead

- Designed managed-service identity and access processes alongside incident, standard request, event, and problem management, giving customers clearer provisioning, access-issue, escalation, and operational-control paths.
- Governed delegated administration across several dozen Office 365 tenant environments, turning repeated CSP/MSP support patterns into a more consistent cloud-service operating model with clearer tenant and privileged-access boundaries.
- Organized managed-services engineering across several dozen Office 365 tenant environments, standardizing repeatable tenant support, migration, and delegated-administration patterns for a clearer cloud-service operating model.
- Modeled ServiceNow and ConnectWise workflows for incident, request, change, and identity-access operations, improving cross-system visibility for provider and customer teams managing shared access and service commitments.
- Designed hosted private-cloud multi-tenancy patterns on VMware-era infrastructure, separating customer environments and access paths into a repeatable control-plane model for managed cloud delivery.
- Led a 12-month ITIL managed-services overhaul that brought identity and access requests, customer onboarding, SLA discipline, and escalation paths into a repeatable service-operation model.
- Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a 150-plus-site-collection SharePoint environment, moving collaboration content into more governable tenant and access-control structures.
- Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, visibility, and portfolio discipline for customer delivery teams.

### Detroit IT / Core 3 Solutions | June 2014 – February 2015

> Senior Systems Administrator

- Designed and delivered migration from hosted Exchange and Windows file services into Office 365, preserving user identity, document access, and collaboration continuity across Exchange Online, SharePoint Online, and Skype for Business.
- Secured Office 365 migration planning for Citrix-hosted customers, preserving identity, access, document integrity, and collaboration controls as users moved from hosted Exchange and file services to Microsoft cloud services.
- Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
- Conducted security assessments and implemented protective measures for customer environments, connecting infrastructure modernization to breach prevention and risk reduction.
- Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
- Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
- Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.
- Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.

### Detroit Country Day School | June 2013 – June 2014

> Senior Systems Analyst, Helpdesk Lead

- Supported Office 365 and classroom-software adoption with account migration assistance, user training, and knowledge resources, reducing account and collaboration adoption friction for school users.
- Managed implementation work for student-information system improvements, strengthening data accessibility for staff and faculty who depended on accurate academic and administrative records.
- Delivered staff training on new technologies and software, increasing comfort with adopted tools and reducing avoidable support demand after rollout.
- Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.
- Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
- Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
- Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
- Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.

### University of Michigan, Information & Technology Services | June 2011 – September 2012

> IT Engineer

- Managed asset governance and lifecycle processes for more than 25,000 university endpoints and peripherals, giving leadership clearer visibility into assignment, use, location, and disposition across a 100,000-user environment.
- Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
- Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
- Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
- Provided VIP cybersecurity and technical support for critical university personnel, resolving escalations and deployments where reliability, discretion, and rapid response mattered to institutional leadership.
- Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.
- Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
- Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.

### Battery Giant / Energy Products | January 2007 – December 2010

> IT Manager

- Directed security, identity, networking, remote-server, ERP, and POS operations for a distributed retail franchise environment, giving branch offices and franchisees a more consistent access and infrastructure operating model.
- Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing access and compliance risk while giving franchisees clearer support expectations.
- Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
- Advised executives on secure digital transformation, IT governance, and franchise technology strategy, connecting practical systems work to expansion, compliance, and operational risk decisions.
- Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
- Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
- Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
- Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after assuming responsibility for availability and recovery systems.

### Detroit Country Day School | June 2005 – August 2006

> Systems Analyst

- Established the school's Active Directory foundation by helping consolidate six Kerberos realms into one AD forest, giving students, faculty, and administrators a simpler authentication model and stronger directory operating base.
- Managed imaging, software installation, and workstation refresh activity for students, faculty, management, and directory-infrastructure servers, supporting reliable account access across classroom and administrative endpoints.
- Supported account and data migration into the new Active Directory environment, pairing identity rollout with training and knowledge resources so classroom users could adopt the change with less disruption.
- Developed security-focused service workflows and endpoint protocols for classroom technology, improving escalation and access-control practices in a high-touch academic identity environment.
- Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency so account and directory changes landed on a more predictable workstation fleet.
- Led incident, request, and change-management practices for end-user systems during identity and endpoint modernization, giving students and faculty a clearer support path while account access and workstation platforms changed.
- Modernized legacy Windows NT servers and Windows 98 SE workstations onto Windows Server 2003 and Windows XP, giving the new Active Directory environment a more supportable server and desktop base for daily account access.
- Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.

## Education

### The University of Michigan, Ann Arbor, MI

- College of Literature, Science, and the Arts (LSA) | Biochemistry, Economics, and Data Science
- School of Music, Theatre, and Dance (SMTD) | Design & Production, Stage Management, Lighting Design & Electrics, Sound Engineering, and Music Production

### Detroit Country Day School, Beverly Hills, MI

- High School Diploma | College Preparatory Curriculum

## Skills

**Identity, Access & Cryptography**
Service-principal and workload-identity lifecycle governance, workload identities, managed identities, service principals at scale, RBAC and least-privilege design, secrets-management patterns, Entra ID Governance lifecycle workflows, Microsoft Graph and Azure Management API identity automation, Microsoft Entra ID / Azure AD, Entra ID Governance, CyberArk privileged-access integration governance, Privileged Identity Management (PIM), Entra B2B/B2C, external identity, and CIAM patterns, Tenant access boundaries and multi-tenancy control patterns

**AI Systems, Safety & Applied LLM Engineering**
Deterministic guardrails, immutable attribution, AI-assisted development guardrails, secure LLM deployment patterns, Azure AI Foundry, Ollama/local models, hybrid multi-model routing, Model- and platform-agnostic XLM (LLM/SLM) orchestration, MCP toolkits, continuous red-team/blue-team exercises, adversarial safety-control testing, prompt-injection and jailbreak evaluation, model evaluation frameworks, token optimization

**Cybersecurity Architecture, Detection & Operations**
risk management, privileged-access overhauls, Cybersecurity architecture, cloud security architecture, change-integrated security scanning, GRC / ServiceNow integration, REST and GraphQL API security, Microsoft Purview, Microsoft Defender, Zero Trust architecture, XDR and vulnerability management, Pentera, threat detection, SIEM

**Product Design, Technical UX & Sports Decision Support**
schema-driven UI, design systems, component systems, technical-user experience, sports decision support, telemetry-informed iteration, workflow mapping, executive-ready tradeoff framing, product requirements, product strategy, design-to-production delivery, Stakeholder interviews, cross-functional design reviews, information architecture

**Soft Skills & Cross-Functional Practice**
Executive communication, stakeholder alignment, project and program coordination, technical mentoring, vendor evaluation, RFP demonstration leadership, proof-of-concept facilitation, change adoption, non-technical stakeholder training

**Azure Data, Analytics & AI Platforms**
Azure Databricks, Databricks lakehouse architecture, feature preparation, lakehouse-oriented sports analytics, governed analytics platforms, production readiness, reusable reference architectures, Cloud Adoption Framework, Azure Well-Architected Framework for analytics and AI workloads, data landing zones, workload modernization

**Microsoft 365 & Modern Workplace**
Conditional Access for Microsoft 365, Microsoft Purview compliance administration, endpoint and identity cloud-management foundations, Exchange Online, Microsoft 365 migration and adoption planning, collaboration governance, SharePoint Online

**Compliance, Governance & Control Assurance**
CJIS, law-enforcement and public-safety data protection, HIPAA, PCI, CUI, PII, financial and health data protection, NIST CSF 2.0, continuous control monitoring, audit automation, control translation for customer and sector-specific governance models, standards libraries, control evidence and reporting, GRC / ServiceNow integration

_Generated from structured resume artifacts for Identity Management Resume; document version v26.8.20._
