Structured special resume

Sports and MLB Technology Resume

Profile-specific evidence selected from role-local JSON artifacts, using linked variants and dedupe keys so one underlying claim can be reviewed through this resume lens without duplicating the source record.

Resume at a glance

Roles
16 public role records selected for this profile.
Evidence
201 profile-selected evidence points, deduped by claim family.
Source
Adjacent JSON artifacts beside the role MDX files drive this page.

Selected Evidence

Profile-matched work history

Each panel uses the variant selected for this profile first, with supporting bullets from the same structured role artifact.

Scoria Software Solutions · March 2025 – Present

Founder & Principal Software Architect

Selected claim: Designed AI-enabled product workflows around explicit trust boundaries, approval paths, and immutable attribution so expert users can review, challenge, and safely act on generated recommendations instead of treating model output as opaque authority.

  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Productized AI-assisted software delivery through the XLM engine and MCP toolkit family, turning natural-language intent into deterministic multi-platform application stacks that let early adopters move from concept to hands-on prototype evaluation in weeks instead of months.
  • Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
CybersecurityGovernance/complianceOperations/service deliveryCybersecurity LeadershipIdentity ManagementAi Systems Agent Architecture

Bedrock Information Systems LLC · January 2019 – Present

Principal Architect

Selected claim: Established a repeatable NIST CSF 2.0 control baseline with single-click audit reporting, offering transferable club-technology relevance for governed analytics, operational trust, and decision-support tooling that must show where data, controls, and decisions came from.

  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Translated a Microsoft Teams rollout into a five-year modernization and AI adoption roadmap across 26 priorities, a transferable club-technology planning pattern where collaboration, analytics substrate, security, user adoption, and ROI milestones must move together.
Governance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb TechnologyEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024

Principal Cybersecurity Architect

Selected claim: Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.

  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
CybersecurityGovernance/complianceCybersecurity LeadershipEntertainment Live Venue TechnologyProduct Engineering DesignCybersecurity Architecture

Wells Fargo Bank · July 2022 – July 2023

Senior Cybersecurity Architect

Selected claim: Led governed cloud-architecture review across 128 resource-provider types, turning bespoke infrastructure choices into reusable deployment patterns transferable to sports analytics platforms that need trusted cloud standards without custom architecture review for every workload.

  • Accelerated regulated architecture review from 3-12 approvals per month to 40-50 completed reviews per week, demonstrating a transferable high-volume approval model for sports technology platforms that need faster cloud adoption without weakening governance.
  • Designed multi-layer HYOK cryptography and external key-provider governance, showing transferable encryption and key-control discipline for club-scale cloud systems that must protect sensitive operational and analytics data.
  • Developed SDLC policy-enforcement roadmaps that shifted cloud architecture approval from exception-driven review to standardized selection, a transferable governance pattern for sports analytics platforms that need repeatable controls and low-friction team adoption.
CybersecurityCloud/infrastructureOperations/service deliveryTraining/knowledge managementIdentity ManagementAi Systems Agent Architecture

Microsoft Corporation · March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

Selected claim: Operated at Microsoft customer-engineering scale across Fortune 500, public-sector, high-technology, and internal customers, managing 37 dedicated accounts while resolving cloud, data, security, reliability, and product-group escalations whose complexity transfers to club-scale technology decision support.

  • Advised enterprise customers on governed Microsoft 365 information-protection patterns across Purview, regulated-data discovery, sensitivity labeling, and DLP policy tuning, transferable to club-scale analytics platforms where decision support depends on trusted data boundaries and explainable access controls.
  • Converted repeated Microsoft customer-engineering demand into reusable delivery programs, engineer mentoring, and product-group feedback loops, a transferable pattern for turning field evidence into trusted platform guidance for sports decision systems without claiming sports customer delivery.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
CybersecurityCloud/infrastructureProduct designOperations/service deliveryCybersecurity LeadershipEnterprise Cloud Architecture

Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021

Senior Cybersecurity Architect

Selected claim: Architected a board-adopted three-year technology and security maturity roadmap across eight domains, a transferable executive-planning pattern for club technology leaders who need governed platforms, trusted operating signals, and funded modernization capacity before analytics tools can scale.

  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Deployed identity-aware access, full-tunnel inspection, web filtering, firewall, and endpoint controls across approximately 550-600 users and endpoints, transferable to club-scale platform environments where analytics workflows depend on secure remote access and trusted endpoint visibility.
  • Stabilized workforce remote access under crisis conditions, sequencing identity, VPN, endpoint, firewall, and web-filtering controls to eliminate recurring unexpected downtime, a transferable service-operations pattern for time-bound club technology and analytics workflows.
CybersecurityGovernance/complianceIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

City National Bank · March 2020 – July 2020

Vice President, Azure Infrastructure

Selected claim: Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.

  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized COVID emergency identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access and auditability while facilities closed.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
Identity/accessCloud/infrastructureCanonicalTraining/knowledge managementOperations/service deliveryEnterprise Cloud Architecture

Molina Healthcare · February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

Selected claim: Architected a governed Azure landing-zone and hybrid-cloud migration model for roughly 16,000 production servers, 630 applications, and more than 2 PB of regulated data, a transferable club-scale platform pattern for trusted analytics, workload migration, and executive decision support.

  • Reframed a stalled cloud-migration program into an executable delivery model by aligning executives, application owners, platform engineers, project managers, Microsoft, and ServiceNow support around shared migration decisions, owner handoffs, and delivery rituals that restored momentum.
  • Sequenced the first major migration around the most business-critical SQL Always On workload, protecting 450 TB of data with 2.7 TB of daily transactions and 12-15 SDLC environments, proving a repeatable governed data-platform pattern transferable to club analytics, model trust, and time-sensitive decision support.
  • Authored Terraform-integrated Infrastructure-as-Code and orchestration frameworks for landing-zone resources, security guardrails, and SQL workload operations, creating repeatable club-scale platform controls where analytics, infrastructure, and high-impact cutovers need reliable execution with human review.
Identity/accessPrivileged AccessCybersecurityCloud/infrastructureData/AIGovernance/compliance

Coretek Services · August 2018 – January 2019

Senior Solutions Architect

Selected claim: Consolidated a 16,000-user merger environment into one Azure AD tenant across 32 Exchange environments and 27 Active Directory forests, a transferable pattern for club-scale technology groups that need governed identity, collaboration data, and platform access after organizational change.

  • Converted a high-risk 10,000-mailbox Exchange Online migration into a controlled seven-week execution pattern with less than 2% failure, transferable to club technology operations where collaboration, analytics, and business workflows cannot pause for platform change.
  • Turned user attributes, SIDs, passwords, groups, and profile data into explicit migration acceptance criteria, framing access continuity as a product requirement for administrators and business users during consolidation.
  • Implemented Microsoft 365 Conditional Access controls for device and user compliance, a transferable security pattern for club-scale platforms where analysts, staff, and business users need trusted access without slowing productivity adoption.
Identity/accessCloud/infrastructureOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Obsidian Availability Solutions · September 2016 – December 2018

Principal Consultant

Selected claim: Co-founded an IT consulting firm and shaped the early service portfolio through Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendor partnerships, expanding the managed-service products available to customer environments.

  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Built repeatable customer and tenant onboarding patterns for managed-services lifecycle entry, a transferable club-scale operating pattern for moving analytics, collaboration, and venue-adjacent support services from intake to reliable operations.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
Operations/service deliveryEnterprise Cloud ArchitectureProduct Engineering DesignEnterprise ArchitectureCloud InfrastructureTechnical Product Design

Orion Technology Services · June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

Selected claim: Led a 12-month ITIL managed-services overhaul that strengthened onboarding, SLA discipline, support efficiency, and escalation paths, transferable to club-scale technology operations where analytics and venue services need predictable run-state control.

  • Designed incident, event, standard request, access, and problem-management workflows as reusable service-operation patterns, converting reactive support behavior into clearer expert-user paths for managed-service delivery.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change workflows, improving the service-data foundation transferable to club-scale analytics support, systems tracking, and venue operations control.
  • Architected Microsoft 365 and SharePoint Online migrations, including a 150-plus-site-collection environment, moving collaboration content into governable tenant structures transferable to club-scale knowledge, analytics, and decision-support workflows.
Identity/accessGovernance/complianceOperations/service deliveryEnterprise Cloud ArchitectureIdentity ManagementAi Systems Agent Architecture

Detroit IT / Core 3 Solutions · June 2014 – February 2015

Senior Systems Administrator

Selected claim: Designed and delivered migration from hosted Citrix, Exchange, and Windows file services into Office 365, preserving document access and collaboration continuity for users who depended on shared information systems.

  • Planned a multi-state network overhaul across ISPs, Cisco UCM voice, VPN, MPLS, hardware refresh, and disaster-recovery services, showing transferable continuity planning for distributed club or venue technology operations.
  • Administered VMware private-cloud VDI and sandbox environments for multiple software-development teams, treating developer workspaces as an internal product surface for experimentation, collaboration, and reliable delivery work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into durable fixes and clearer support paths for technical users.
Identity/accessCloud/infrastructureIdentity ManagementAi Systems Agent ArchitectureCybersecurity LeadershipSports Mlb Technology

Detroit Country Day School · June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

Selected claim: Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, creating clearer service expectations for a high-touch user community that included faculty, staff, students, parents, alumni, and guests.

  • Developed SCCM-based imaging and systems-management practices for approximately 2,500 workstations, showing transferable endpoint-platform discipline for club-scale environments with shared workstations, devices, and support demand.
  • Designed and deployed mobile laptop fleets across campuses with limited dedicated technology-center space, showing transferable device-fleet planning for venue-like environments where users need technology without facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting user-facing continuity while keeping hardware lifecycle issues visible to leadership.
Operations/service deliveryCybersecurity LeadershipSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering DesignEnterprise Cloud Architecture

University of Michigan, Information & Technology Services · June 2011 – September 2012

IT Engineer

Selected claim: Led asset and configuration data work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so service teams retained the operational context needed for reliable support workflows.

  • Managed asset governance and lifecycle processes for more than 25,000 endpoints and peripherals serving over 100,000 daily users, giving leadership clearer visibility into assignment, use, location, and disposition at institutional scale.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects reporting, converting endpoint and asset data into governed business intelligence for operational technology decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, showing transferable support-model migration for high-visibility operational groups.
Data/AIOperations/service deliveryAi Systems Agent ArchitectureSports Mlb TechnologyEntertainment Live Venue TechnologyProduct Engineering Design

Battery Giant / Energy Products · January 2007 – December 2010

IT Manager

Selected claim: Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.

  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized product-information platform spanning 250,000 products and 3,000,000+ applications, creating transferable evidence for governed lookup, cross-reference, pricing, and inventory data that club-scale operations could depend on for decision support.
  • Implemented centralized ledger, inventory-control, and POS data patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, showing transferable governed-operations data discipline for multi-location club or venue technology environments.
Identity/accessCybersecurityCloud/infrastructureOperations/service deliveryIdentity ManagementCybersecurity Leadership

Detroit Country Day School · June 2005 – August 2006

Systems Analyst

Selected claim: Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.

  • Developed imaging and systems-management practices for approximately 2,500 workstations across four campuses, showing transferable endpoint administration discipline for club-scale technology environments with many shared devices and users.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
Identity/accessData/AIIdentity ManagementCybersecurity LeadershipIdentity AccessCybersecurity Architecture