Scoria Software Solutions · March 2025 – Present
Founder & Principal Software Architect
Selected claim: Designed AI-enabled product workflows around explicit trust boundaries, approval paths, and immutable attribution so expert users can review, challenge, and safely act on generated recommendations instead of treating model output as opaque authority.
- Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
- Productized AI-assisted software delivery through the XLM engine and MCP toolkit family, turning natural-language intent into deterministic multi-platform application stacks that let early adopters move from concept to hands-on prototype evaluation in weeks instead of months.
- Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture
Bedrock Information Systems LLC · January 2019 – Present
Principal Architect
Selected claim: Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.
- Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
- Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
- Turned a municipal Microsoft Teams rollout into a five-year product and operations roadmap, translating 26 modernization, security, compliance, training, AI adoption, and legacy phase-out requirements into sequenced delivery priorities with clear ROI milestones.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024
Principal Cybersecurity Architect
Selected claim: Productized SecOps and GRC operating rhythms for a five-person cybersecurity engineering team, turning reactive user reports, Netskope alerts, and staff-chasing into dashboard-driven workflows that reduced disruptions and made audit work manageable through routine checkpoints.
- Redesigned privileged-access workflows around Entra PIM, Just-in-Time access, monitored break-glass governance, M-of-N approvals, and change-management evidence so administrators could complete high-risk work through clear approval paths instead of standing access.
- Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
- Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture
Wells Fargo Bank · July 2022 – July 2023
Senior Cybersecurity Architect
Selected claim: Designed the architecture-review process as an internal product workflow across 128 cloud resource-provider types, turning bespoke security and infrastructure decisions into reusable reference patterns that let application teams choose standardized Azure designs without restarting custom review cycles.
- Redesigned cloud platform review as a standardized approval pattern, increasing throughput from 3-12 application approvals per month to 40-50 completed reviews per week while giving application teams a faster path into Azure architectures without removing expert review gates.
- Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
- Developed SDLC policy-enforcement roadmaps as an expert-user workflow for application teams, moving cloud architecture approval from exception-driven review to standardized control selection and reducing effort from weeks or months to roughly one to two asynchronous hours.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture
Microsoft Corporation · March 2021 – November 2021
Senior Customer Engineer, Global Tech Team
Selected claim: Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
- Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
- Translated high-volume customer-engineering demand into product-group feedback loops, mentoring roughly a dozen engineers and contributing to more than twenty standardized delivery programs while shaping shipped Bookings behavior for expert-user scheduling workflows.
- Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021
Senior Cybersecurity Architect
Selected claim: Translated an eight-domain maturity baseline into a board-adopted three-year roadmap, turning executive, IT, and security priorities into a decision-support product for sequencing funded modernization work and staffing needs.
- Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
- Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
- Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
City National Bank · March 2020 – July 2020
Vice President, Azure Infrastructure
Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
- Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
- Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
- Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture
Molina Healthcare · February 2019 – February 2020
Senior Solutions Architect (Consultant, Infosys)
Selected claim: Designed the Azure migration as a productized control plane for expert technical users, translating a healthcare estate of roughly 16,000 production servers, 630 applications, and more than 2 PB of data into governed landing-zone patterns, migration workflows, and repeatable adoption paths for application owners and platform engineers.
- Reframed a stalled cloud-migration program into an executable delivery model by aligning executives, application owners, platform engineers, project managers, Microsoft, and ServiceNow support around shared migration decisions, owner handoffs, and delivery rituals that restored momentum.
- Sequenced the first major migration around the hardest expert-user workflow: a 450 TB SQL Always On platform with 2.7 TB of daily transactions and 12-15 SDLC environments, proving the migration pattern, control gates, handoffs, and repeatability model before asking application teams to adopt it broadly.
- Authored Terraform-integrated orchestration frameworks as an internal platform product, giving application owners and operations teams familiar workflows while automating landing-zone provisioning, SQL workload maintenance, control checks, and human-monitored cutovers for repeatable healthcare-cloud adoption.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance
Coretek Services · August 2018 – January 2019
Senior Solutions Architect
Selected claim: Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a merger, reducing fragmentation in identity and email operations.
- Productized a 10,000-mailbox Exchange Online migration into controlled runbooks, exception handling, and user-impact workflows, keeping a seven-week cutover below 2% failure while preserving collaboration continuity.
- Turned user attributes, SIDs, passwords, groups, and profile data into explicit migration acceptance criteria, framing access continuity as a product requirement for administrators and business users during consolidation.
- Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Obsidian Availability Solutions · September 2016 – December 2018
Principal Consultant
Selected claim: Co-founded an IT consulting firm and shaped the early service portfolio through Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendor partnerships, expanding the managed-service products available to customer environments.
- Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
- Designed repeatable customer and tenant onboarding flows for managed-service entry, turning sales handoff, implementation strategy, and operating-service readiness into a clearer expert-user workflow.
- Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design
Orion Technology Services · June 2015 – August 2016
Senior Solutions Engineer, Engineering Team Lead
Selected claim: Led a 12-month ITIL managed-services overhaul that redesigned onboarding, SLA discipline, support efficiency, and escalation paths into a repeatable operating model for expert support users and customer-facing service commitments.
- Designed incident, event, standard request, access, and problem-management workflows as reusable service-operation patterns, converting reactive support behavior into clearer expert-user paths for managed-service delivery.
- Modeled ServiceNow and ConnectWise workflows for incident, event, problem, change, and shared service tracking, improving the data foundation for provider and customer teams operating the same service commitments.
- Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into clearer tenant structures for knowledge, governance, and user workflow adoption.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture
Detroit IT / Core 3 Solutions · June 2014 – February 2015
Senior Systems Administrator
Selected claim: Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.5 TB of Windows file services to SharePoint Online, and Skype for Business for internal and external communication.
- Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
- Administered VMware private-cloud VDI and sandbox environments for multiple software-development teams, treating developer workspaces as an internal product surface for experimentation, collaboration, and reliable delivery work.
- Translated recurring Tier 2 and Tier 3 incidents into durable fixes and clearer support paths for service-desk resources and managed-services customers, improving the technical-user support workflow rather than only closing tickets.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology
Detroit Country Day School · June 2013 – June 2014
Senior Systems Analyst, Helpdesk Lead
Selected claim: Redesigned Track-It! ITSM workflows by defining ticket classification, escalation, and prioritization standards, turning recurring helpdesk work into clearer service expectations for a high-touch school user community.
- Productized SCCM-based imaging and systems-management for approximately 2,500 workstations, turning endpoint support into repeatable fleet operations instead of manual one-off remediation.
- Designed and deployed mobile laptop fleets for campuses with limited dedicated technology-center space, expanding classroom access to digital learning by adapting the solution to user and facilities constraints.
- Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture
University of Michigan, Information & Technology Services · June 2011 – September 2012
IT Engineer
Selected claim: Led asset and configuration data workflows for the BMC Remedy to ServiceNow transition, defining import logic and relationship models so technical support users retained reliable service context during ITSM cutover.
- Managed asset-governance workflows for more than 25,000 university endpoints, classroom technologies, and peripherals, giving leadership clearer decision support for assignment, use, location, and disposition across a 100,000-user environment.
- Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, shaping endpoint and asset data into decision-support views for university IT operators and leaders.
- Onboarded critical university departments into a shared-services support model, translating technical-user workflows for high-visibility groups into a more consistent end-user systems administration experience.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design
Battery Giant / Energy Products · January 2007 – December 2010
IT Manager
Selected claim: Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.
- Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
- Built a centralized ecommerce and product-information platform spanning 250,000 products and 3,000,000+ applications, improving expert-user lookup, cross-reference, pricing, and inventory workflows for franchise operations.
- Implemented centralized ledger, inventory-control, and POS workflows across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, shaping internal retail product operations around cleaner transaction integrity, loss prevention, and multi-location use.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership
Detroit Country Day School · June 2005 – August 2006
Systems Analyst
Selected claim: Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.
- Treated the four-campus workstation fleet as an internal product surface, developing imaging and systems-management practices that improved endpoint consistency and reduced manual rebuild friction for classroom users.
- Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
- Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture