Professional Experience

Review Jake’s technology, cybersecurity, AI systems, consulting, and early-career experience in reverse chronological order. Each page is written for screening conversations: scope, operating context, and outcomes first.

Experience Index

# Experience Page
1 Scoria Scoria
2 Bedrock Bedrock
3 LACERA 2023 LACERA-23
4 Wells Fargo Wells-Fargo
5 Microsoft Microsoft
6 LACERA 2021 LACERA-21
7 CNB CNB
8 Molina Molina
9 Coretek Coretek
10 Obsidian Obsidian
11 Orion Orion
12 Detroit IT DetroitIT
13 DCDS 2014 DCDS-14
14 UMich UMich
15 Battery Giant Battery-Giant
16 DCDS 2004 DCDS-04

Experience Record

Role History

Role cards keep the first pass compact while preserving the full public record for detailed review.

Scoria Software Solutions · March 2025 – Present

Founder & Principal Software Architect

Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence,... Abbreviated role summary.

Evidence highlights (19)
  • Built service-principal lifecycle tooling with ephemeral-token preference, check-in/check-out workflows, granular least privilege, and agentic session-ID attribution, reducing non-human identity risk while preserving auditable customer delivery.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.

Additional evidence points: 17

Full role
Scoria Software Solutions · March 2025 – Present

Founder & Principal Software Architect

Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence, producing clearer audit trails, faster incident response (seconds or milliseconds instead of minutes), and a 1–2 order-of-magnitude reduction in attempts to bypass safety controls.

  • Built service-principal lifecycle tooling with ephemeral-token preference, check-in/check-out workflows, granular least privilege, and agentic session-ID attribution, reducing non-human identity risk while preserving auditable customer delivery.
  • Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
  • Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
  • Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
  • Engineered identity-provider-agnostic access tooling that can operate across Entra-native development, CyberArk, HashiCorp, and other privileged-identity planes, keeping customer controls portable instead of binding governance to one vendor interface.
  • Architected Fumaro Sports with Azure Databricks as the analytics backend showcase, using lakehouse-oriented data engineering patterns to support predictive sports intelligence, model-ready feature preparation, context-aware analytics, and governed human-in-the-loop release controls.
  • Designed Fumaro Sports authentication for B2C customer access, SSO, and enterprise tenancy so organizations can run governed, tenant-aware versions of the model and agent experience without collapsing consumer and enterprise identity boundaries.
  • Designing Fumaro Sports around analyst and scout review, feedback capture, telemetry-aware runtime logging, staged private beta evaluation, and human-in-the-loop release controls so sports tools can improve without hiding uncertainty from users.
  • Created the DevOps orchestration engine with built-in AI-development guardrails that reduced technical debt 65–95% of the codebase and compressed feature and patch delivery from weeks or months to days or hours, supporting daily stable releases at one client.
  • Implemented Microsoft Graph and Azure Management API-native control-plane automation for Entra and Microsoft Cloud operations, enabling agentic workflows with stronger audit visibility and finer least-privilege boundaries than default portal-driven administration.
  • Developed a single canonical JSON schema front-end engine that deploys cohesive applications across web, native mobile, desktop, APIs, CLIs, and MCP toolkits, reducing each interface’s codebase 25–30% through shared components and enabling one team to manage all interfaces instead of dedicated teams per platform.
  • Built the vendor- and OS-agnostic infrastructure engine spanning Azure, AWS, private cloud, bare metal, and OpenStack, enabling consistent portable deployments and stronger vendor negotiation leverage that contributed to the observed 65% cloud-cost reduction.
  • Engineered the back-end data engine for live, byte-perfect interconversion and normalization across major relational, document, and file formats, allowing agents to work exclusively in JSON and eliminating the token overhead normally spent on formatting and translation.
  • Designed and implemented a proprietary Rust conversion engine delivering byte-perfect bidirectional Markdown/MDX ↔ DOCX/PDF translation, eliminating branding and styling errors and collapsing white-paper and sales-collateral production from 1–2 weeks to 1–2 days (more than half same-day including human review).
  • Reduced token consumption in LLM-driven document generation by 60–90% across four workflow steps, enabling models to produce publication-ready output with zero post-processing.
  • Marketed and deployed the suite to technology companies, MSPs, and consulting firms, enabling functional hands-on POCs before competitors could pitch, single-source vendor status on multiple public-sector bids, 20–40% lower delivery cost to end customers without eroding margins, and significantly accelerated revenue recognition.
  • Led scalable cloud-solution and software-delivery architecture for client environments, connecting security assessment, DevOps, data, and application patterns so customers could improve operational efficiency without separating modernization from risk control.
  • Conducted cybersecurity architecture and assessment work for client systems handling sensitive data, translating compliance and protection requirements into deployable patterns rather than abstract policy language.
  • Coordinated cross-functional design and delivery across software, cloud, data, infrastructure, and security workstreams, giving clients a single accountable architecture thread from concept through production adoption.
Bedrock Information Systems LLC · January 2019 – Present

Principal Architect

Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices... Abbreviated role summary.

Evidence highlights (16)
  • Designed identity lifecycle and entitlement patterns for Bedrock and customer environments, applying the same governance model to users, service principals, app registrations, and delegated MSP/CSP access so public-sector clients could reduce standing access while preserving auditable operations.
  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.

Additional evidence points: 14

Full role
Bedrock Information Systems LLC · January 2019 – Present

Principal Architect

Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.

  • Designed identity lifecycle and entitlement patterns for Bedrock and customer environments, applying the same governance model to users, service principals, app registrations, and delegated MSP/CSP access so public-sector clients could reduce standing access while preserving auditable operations.
  • Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
  • Standardized SCIM-preferred provisioning and Microsoft Graph / Azure Management API automation as the preferred path for identity and Microsoft Cloud administration, replacing UI-bound workflows with API-native controls that improved least-privilege enforcement and audit visibility.
  • Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
  • Led a Microsoft Teams implementation for a municipal customer that expanded into a five-year city-wide AI adoption roadmap, aligning 26 major IT priorities across modernization, security enhancement, compliance enforcement, user training, AI adoption, and legacy phase-out; prioritized Purview sensitivity labeling and DLP as immediate data-protection work, projected initial ROI within 6–8 months and full ROI by year three, with seven-figure annual savings expected from year four onward.
  • Implemented automated DLP and information-protection controls that detected a public-sector CJIS data exposure within five minutes of availability and applied extreme encryption and protection through Purview, including to copies stored outside Microsoft 365, while preserving NDA-safe disclosure of the incident.
  • Built and deployed a custom microfilm digitization tool that converted more than a century of legacy government records (dating to the 1800s) into OCR/ICR-optimized, PDF/A-compliant digital assets with full metadata in a single 21-hour continuous run—collapsing an estimated 10-year multi-person full-time effort—and reduced pre-digital public records request turnaround from weeks or months to days or hours.
  • Applied structured guardrails and deterministic processes to AI-assisted development, enabling non-developer infrastructure and application engineers to safely expand into development work; accelerated project timelines 50–75%, allowed teams of 2–3 to deliver what previously required teams of 6–12, eliminated engineer overtime (previously 50–60 hours/week), and increased per-engineer revenue and profitability while expanding overall market footprint without added headcount.
  • Governed service-principal and workload-identity access for client-facing and agentic solutions, favoring ephemeral-token patterns, explicit check-in/check-out, granular permissions, and session-level audit trails where customer risk models required non-human identity accountability.
  • Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
  • Designed and operated Azure DevOps and GitHub-based CI/CD pipelines and repository standards that automated deployment and release management for multi-environment application fleets while embedding security and compliance requirements as first-class, non-negotiable constraints alongside functional and budgetary needs.
  • Provided architectural leadership for secure web and application solutions across internal and client environments, expanding Bedrock’s capabilities from family-office technology support into a full managed-service provider model serving public-sector and regulated clients while consistently managing concurrent teams averaging 6–12 people.
  • Extended public-sector security roadmaps beyond compliance checklists by tying Entra governance, delegated privileged access, information protection, and automated audit evidence to practical municipal outcomes: fewer manual controls, clearer accountability, and safer modernization.
  • Developed client IT strategy and governance roadmaps that tied cloud modernization, cybersecurity posture, records workflows, and service management to business outcomes, helping small public-sector teams prioritize work that improved resilience instead of chasing isolated tickets.
  • Managed cross-functional delivery across infrastructure, application, security, records, and operations stakeholders, keeping complex municipal and regulated projects aligned to practical service outcomes rather than vendor-driven implementation checklists.
  • Authored reusable cybersecurity, cloud migration, and modernization guidance for clients and internal teams, turning repeated advisory patterns into durable material for faster planning, clearer executive communication, and more consistent delivery.
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024

Principal Cybersecurity Architect

Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on... Abbreviated role summary.

Evidence highlights (18)
  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Designed Entra-native governance patterns across custom roles, entitlement-style access workflows, lifecycle controls, and ServiceNow-backed approvals so privileged work moved through repeatable evidence paths rather than persistent administrator access.

Additional evidence points: 16

Full role
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024

Principal Cybersecurity Architect

Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.

  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Designed Entra-native governance patterns across custom roles, entitlement-style access workflows, lifecycle controls, and ServiceNow-backed approvals so privileged work moved through repeatable evidence paths rather than persistent administrator access.
  • Designed and implemented Tier 0-equivalent privileged-access controls using resource PIM, Just Enough Administration, PAW/SAW operating patterns, and break-glass governance, then trained infrastructure, service, and administrative users on the new model.
  • Automated Entra and Microsoft Cloud identity operations through Microsoft Graph and Azure Management API control-plane patterns, giving a small security team repeatable leverage for privileged access, lifecycle enforcement, audit evidence, and governed change execution.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
  • Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
  • Paired Pentera (red team) with the Microsoft Defender / Purview suite (blue team) to institutionalize regular red-team / blue-team war-game exercises, producing a two-order-of-magnitude drop in Defender events (from hundreds of thousands to thousands per week across the enterprise) and closing nearly all historical vulnerabilities within one quarter of joint operation.
  • Built DLP alert investigation and remediation workflows that connected Purview, Defender, GRC, and change-management evidence, giving compliance and security stakeholders practical dashboards for policy effectiveness, false-positive reduction, and audit readiness.
  • Integrated security tooling and processes into existing fire-drill and disaster-recovery exercises, creating a unified operational cadence that enabled full business continuity during a real high-privilege account lockdown with zero impact to internal users, external consumers, or public-facing services.
  • Led RFP, demonstration, and proof-of-concept processes for SIEM, SOAR, and SASE platforms while simultaneously advancing the organization’s compliance maturity more than 30 percent across key frameworks through prioritized controls and programmatic governance.
  • Drove ServiceNow-based GRC and change-management integration that increased legitimate change tickets from a handful per month to dozens per week, established a weekly Change Review Board with security as an equal participant, and reduced change delivery cycles from weeks to days or hours with almost no post-change security regressions.
  • Delivered real-time security dashboards and live monitoring that compressed project charter and board-approval cycles from multi-quarter processes to a standard monthly cadence, unlocking faster budget and resource decisions and organization-wide visibility into posture and progress.
  • Established the Information Security Engineering Team as a dedicated function under CISO leadership, creating a durable operating model for security architecture, tool implementation, vulnerability remediation, and consultative support to information systems and application teams.
  • Designed the Secure Productive Enterprise roadmap for greenfield identity, network, Microsoft 365, and Azure foundations, linking endpoint, data-protection, cloud, and access-control modernization into one board-visible security transformation path.
  • Architected the “LACERA Cloud” framework using SDN/SD-WAN concepts across multiple data centers, giving the organization a unified pattern for secure business-service migration, information-security compliance, and availability planning.
  • Overhauled internal service-management and project-portfolio processes so security, IT operations, and end users could move more work through governed channels without slowing remediation or routine service delivery.
  • Developed automation and orchestration patterns that let a small security team manage a large, changing environment, converting headcount constraints into a design requirement for repeatable controls and operational leverage.
Wells Fargo Bank · July 2022 – July 2023

Senior Cybersecurity Architect

Led the Service Enablement Task Force that validated and approved secure architecture and infrastructure blueprints across 128 cloud resource provider types,... Abbreviated role summary.

Evidence highlights (11)
  • Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity and GRC approval gates.
  • Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.

Additional evidence points: 9

Full role
Wells Fargo Bank · July 2022 – July 2023

Senior Cybersecurity Architect

Led the Service Enablement Task Force that validated and approved secure architecture and infrastructure blueprints across 128 cloud resource provider types, creating a library of pre-approved patterns that allowed thousands of downstream business applications to adopt standardized designs and largely eliminated the need for custom infrastructure architecture.

  • Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity and GRC approval gates.
  • Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
  • Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
  • Developed SDLC policy-enforcement roadmaps that shifted the organization from an exception-driven culture to standardized architecture selection; application teams’ effort dropped from dozens of hours spread over weeks or months to roughly one to two hours of asynchronous work, while security and infrastructure teams achieved substantially higher output volume with near-universal consistency of results.
  • Operated as a cross-functional cybersecurity resource influencing groups of 12 to 100+ engineers, GRC specialists, product teams, and cryptography experts; drove the senior-most executive decision to select the cloud provider and compel organization-wide adoption, eliminating longstanding resistance and entire categories of security and compliance risk across tens of thousands of endpoints and approximately 12,000 ATMs globally.
  • Conducted comparative cybersecurity analysis of Azure and Google Cloud Platform services, identifying provider and platform gaps and converting the findings into closure plans that informed the bank’s cloud-security control model.
  • Developed standardized compliance-scoring approaches for cloud services, making architecture and configuration review more consistent, repeatable, reliable, and quantifiable across teams that previously evaluated risk through bespoke review paths.
  • Established repeatable compliance-scoring methods for cloud services and resource-provider gaps, giving cybersecurity, infrastructure, and GRC teams a shared evidence model for closure plans, audit defensibility, and provider selection decisions.
  • Guided infrastructure teams toward ARM Templates and Azure Blueprints for deployment standardization, reducing configuration drift and making security requirements easier to enforce through repeatable infrastructure-as-code patterns.
  • Provided endpoint-encryption subject matter expertise for the BitLocker cloud-management roadmap, extending cloud-governance decisions into endpoint data-protection strategy rather than leaving device encryption as a separate operational silo.
  • Managed vendor integration and technical Q&A with cloud and security SMEs, using vendor evidence to strengthen design guides and preserve cybersecurity approval gates before application architecture review.
Microsoft Corporation · March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers;... Abbreviated role summary.

Evidence highlights (21)
  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.

Additional evidence points: 19

Full role
Microsoft Corporation · March 2021 – November 2021

Senior Customer Engineer, Global Tech Team

Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.

  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
  • Translated legacy enterprise identity findings from the DART remediation work—external identity exposure, forests, tenants, leaked privilege paths, weak MFA posture, and private-cloud dependencies—into a modern control sequence that prioritized privilege closure, external-identity hardening, and phishing-resistant authentication before broader platform cleanup.
  • Sequenced the identity rebuild around priority-zero controls first: external identity hardening, Tier 0 isolation, resource PIM, JEA/constrained administration, PAW/SAW patterns, break-glass governance, and phishing-resistant authentication before broader platform cleanup, reducing the risk that recovery would preserve the same attack path.
  • Averaged one to two critical-situation escalations per week (frequently joining proactively); most notably diagnosed a Windows Server 2016 Storage Spaces Direct (S2D) bug that was causing cascading SQL Always-On, Exchange Online, Remote Desktop Services, DFS, and failover-cluster outages; the resulting global patch resolved long-standing, multi-year issues for six of twelve dedicated customers and every organization running high-availability Windows Server workloads on S2D worldwide.
  • Participated in the critical remediation team for a major global service outage at a hyperscale technology company, helping identify an infrastructure-as-code workflow that triggered the event, providing guidance for the rollback and permanent fix, and contributing to both customer-facing and Microsoft-internal postmortems; the internal postmortem drove backend process changes that improved geo-resiliency protections against rapid global rollouts and influenced standardized geo-resiliency and disaster-recovery planning for Premier and Unified Support customers.
  • Delivered customized Well-Architected Framework engagements for the complex minority of customers whose scale or operating model exceeded the standard program (ten of twelve dedicated accounts), driving nearly nine figures in multi-year Azure commitments (including one customer above eight figures), Azure Reserve Instance purchases, and multiple Unified Support renewals and expansions.
  • Authored and published reusable PowerShell and ARM-template assets to Microsoft’s public GitHub repositories and learn.microsoft.com (cybersecurity, identity, Azure infrastructure, Modern Workplace, and Microsoft 365); these assets were systematically linked from the AskJake.ms technical blog, which reduced repeat customer request volume and freed capacity for higher-value escalation and architecture work.
  • Authored reusable Graph, PowerShell, ARM-template, Microsoft Learn, and field-delivery assets for identity, privileged access, Azure infrastructure, Microsoft 365, and cybersecurity scenarios, converting high-consequence customer lessons into reusable guidance for customer engineers and product groups without exposing protected customer details.
  • Converted repeated Active Directory, Microsoft 365, information-protection, and identity remediation patterns into reusable customer-engineering material, preserving field lessons from high-consequence customer environments without exposing protected customer details.
  • Advised enterprise customers on B2B/B2C and delegated external-access patterns across Entra, federation, partner, and multi-tenant environments, treating external identity as a privileged-access risk surface rather than a convenience feature and translating incident lessons into safer customer and field guidance.
  • Contributed Microsoft Docs articles, internal knowledge, and delivery guidance for Microsoft 365, security, compliance, and information-protection scenarios, turning repeated DLP, labeling, and governance questions into reusable customer and engineer enablement material.
  • Acted as a rare broker between customer escalations and product groups; contributed multiple production features to the Outlook / Exchange Online personal Bookings experience (categories, private booking-link behavior, security and permissions for anonymous links, and Power Platform / inbox-rule integrations), all of which shipped, resulting in standing weekly check-ins requested by the product group.
  • Provided continuity for LACERA after leaving the earlier engagement: as their Microsoft engineer, launched Year 1 of the previously authored three-year roadmap, completed all identity and endpoint cloud-management objectives, stood up greenfield Active Directory and Microsoft 365 environments that closed the prior backdoor-account incident, designed Azure landing zones and SD-WAN foundations, and established the operational momentum that enabled the full multi-year program to finish on schedule years later.
  • Co-founded an elite cross-organizational “Super Pod” that grew from two engineers to nearly one hundred subscribers and more than fifty active participants within three months, overhauling Unified Support intake, triage, and communication processes at a time when backlogs had become unmanageable.
  • Supported Microsoft internal groups including MSIT, LinkedIn, GitHub, and product organizations through identity, cybersecurity, migration, incident, and critical-situation work, bringing customer-facing escalation discipline back into Microsoft’s own operating environment.
  • Developed, maintained, recycled, and distributed managed intellectual property for customer engineers, improving reuse of delivery models, readiness material, and professional-development resources across the global support community.
  • Worked with CSAMs, resource coordinators, Critical Situation Managers, sales, technical pre-sales, support, customer engineering, and cloud solution architecture groups to scope engagements accurately and preserve a unified customer experience across Microsoft touchpoints.
  • Converted red-team, blue-team, laboratory, customer-submission, bug, and vulnerability feedback into product-group signal, helping Microsoft improve security, compliance, identity, and cloud services through evidence gathered from strategic customer environments.
  • Contributed to global communities and managed intellectual-property forums spanning sustainability, GLEAM, identity, Active Directory, and customer engineering, expanding the channels through which field lessons became reusable organizational knowledge.
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021

Senior Cybersecurity Architect

Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap... Abbreviated role summary.

Evidence highlights (11)
  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Treated the hidden account discovery as a Tier 0-equivalent identity-control failure rather than a routine cleanup item, sequencing remediation around directory authority, audit visibility, synchronized cloud privilege, and remote-access hardening so the organization could trust the identity foundation before expanding the security roadmap.

Additional evidence points: 9

Full role
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021

Senior Cybersecurity Architect

Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap spanning eight domains that was formally adopted by the CISO, IT leadership, and the Board; established a NIST CSF baseline at Level 1 with a formal target of Level 3 and secured a funded multi-year program that immediately opened three new security engineering roles.

  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Treated the hidden account discovery as a Tier 0-equivalent identity-control failure rather than a routine cleanup item, sequencing remediation around directory authority, audit visibility, synchronized cloud privilege, and remote-access hardening so the organization could trust the identity foundation before expanding the security roadmap.
  • Transitioned privileged identity administration toward Microsoft Graph-era control-plane patterns during the original LACERA engagement, using API-first inspection and remediation to find high-risk access paths that standard administrative views did not expose.
  • Designed the privileged-access foundation for PAW/SAW, resource PIM, JEA, and break-glass operations, pairing hands-on security implementation with infrastructure-team training so elevated access could be governed without blocking service delivery.
  • Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
  • Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
  • Established the initial identity, access, and visibility foundations that produced the organization’s first clear view of previously unknown shadow IT and high-risk access patterns, and initiated five formal RFP processes for core platforms (including ServiceNow, PMO tooling, and Microsoft security solutions) that locked in the next phase of the maturity program.
  • Led architecture and planning for the Secure Productive Enterprise initiative, defining greenfield landing-zone and core-service direction across Active Directory, networking, Microsoft 365, and Azure so later implementation work had a coherent foundation.
  • Created the strategic roadmap for modernizing identity and endpoint provider/management systems, aligning cloud enablement, business-service migration, and data-protection requirements before individual tool projects were allowed to drive the architecture.
  • Planned data and information-security compliance controls for future business services, ensuring modernization work was evaluated against required security standards instead of only short-term remote-work stabilization.
  • Consulted with information systems and application teams on security states and planned configurations, making the initial security engineering function a service partner rather than a detached compliance reviewer.
City National Bank · March 2020 – July 2020

Vice President, Azure Infrastructure

Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing... Abbreviated role summary.

Evidence highlights (11)
  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized crisis remote-work identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access while facilities closed under emergency mandates.

Additional evidence points: 9

Full role
City National Bank · March 2020 – July 2020

Vice President, Azure Infrastructure

Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.

  • Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
  • Stabilized crisis remote-work identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access while facilities closed under emergency mandates.
  • Kept Active Directory as the coherent source for the emergency remote-access identity path while pairing Ping Federate, Azure AD, Microsoft Authenticator, and RADIUS middleware, reducing the risk that crisis-speed VPN and VDI expansion would fragment authentication or weaken auditability.
  • Drove Azure foundational-infrastructure strategy with enterprise engineering teams, producing roadmap and design guidance for virtual networks, identity, access management, monitoring, and application-team migration planning.
  • Reviewed infrastructure design documents and guided application teams through cloud migration, service refactoring, post-cutover cost control, and secure-access considerations, reducing the risk of one-off designs during a compressed transformation window.
  • Implemented standardized project and service-management practices for cloud migration work, giving technical staff and business units clearer visibility into deliverables, risks, adoption support, and operational readiness.
  • Consulted with security and compliance stakeholders on zero-trust, SIEM/SOAR, endpoint encryption, BitLocker, RBAC, and disaster-recovery considerations, aligning remote-work urgency with regulated banking control expectations.
  • Supported mobile customer front-end and banking-platform architecture discussions, connecting infrastructure resilience and access control to customer-facing digital transformation rather than treating cloud migration as back-end-only work.
  • Created and reviewed infrastructure design documents for application and engineering teams, helping standardize cloud, identity, monitoring, and service-refactoring decisions before workloads moved into Azure.
  • Planned user adoption and transition support for new infrastructure services, reducing the risk that emergency remote-work and cloud changes would succeed technically but fail operationally for staff.
  • Advanced Azure availability monitoring and proactive incident-response patterns, giving infrastructure teams better visibility into resilience during a period when remote access became a business-continuity dependency.
Molina Healthcare · February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

Architected and led the Azure Landing Zone and hybrid-cloud migration program for a healthcare environment of approximately 16,000 production servers (≈40,... Abbreviated role summary.

Evidence highlights (14)
  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.

Additional evidence points: 12

Full role
Molina Healthcare · February 2019 – February 2020

Senior Solutions Architect (Consultant, Infosys)

Architected and led the Azure Landing Zone and hybrid-cloud migration program for a healthcare environment of approximately 16,000 production servers (≈40,000 total environments including non-production), more than 630 business applications, and a data footprint exceeding 2 petabytes; completed migration of roughly one-quarter of the footprint within the year.

  • Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
  • Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.
  • Authored the majority of the Infrastructure-as-Code and orchestration frameworks that provisioned and governed all Landing Zone resources (networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security) as well as the ongoing deployment and maintenance of the critical SQL Always On workload; integrated the frameworks into the organization’s existing Terraform processes so that operational teams experienced zero change to day-to-day maintenance and management, while end-to-end automated cutovers (including a perfectly clean production SQL Always On migration) required only human monitoring.
  • Treated security and compliance as first-class requirements from the outset, embedding HIPAA controls, comprehensive audit trails, and ready integration points for existing SIEM/SOAR tooling; the design received full CISO and security-team approval and satisfied 100 percent of the security organization’s stated requirements.
  • Integrated CyberArk privileged-access governance with Entra ID, Azure RBAC, and landing-zone operating patterns, helping a regulated healthcare migration keep privileged access, least privilege, auditability, and operational execution aligned instead of treating PAM as a separate security checkpoint.
  • Led a combined delivery team of approximately twelve onshore and two dozen offshore Infosys consultants plus a core group of fifteen permanent Molina stakeholders, coordinating Infrastructure-as-Code work with application refactoring (including a significant SQL version upgrade) performed by team developers to make the critical workload cloud-native; the coordinated effort delivered a successful, clean migration of the organization’s most complex and business-critical application while maintaining influence across the full server, data-center, and application footprint.
  • Developed Secure Healthcare Cloud Program patterns from the engagement’s lessons, turning migration, governance, automation, security, and communication practices into reusable material for future healthcare organizations seeking equal-or-better security in public or hybrid cloud.
  • Wrote a proprietary PowerShell module for virtual-machine migration orchestration, reducing repetitive migration work and giving teams a more consistent control plane for lift-and-shift execution.
  • Extended migration orchestration and Infrastructure-as-Code patterns with Azure access-control guardrails, using PowerShell, Terraform-integrated workflows, and human-monitored cutovers to reduce repetitive migration effort while preserving reviewable control over high-impact changes.
  • Standardized service-oriented architecture guidance for network, security, server, compute, database, reporting, IAM, and content-distribution services, helping application teams use common patterns during and after migration.
  • Implemented standardized project and service-management tools, processes, procedures, and communication plans, improving leadership visibility and reducing ambiguity across a large blended delivery organization.
  • Administered Azure tenants, subscriptions, RBAC, and core shared services while approving migration and management plans, connecting architecture governance to operational execution instead of leaving standards unenforced.
  • Governed Azure tenants, subscriptions, RBAC, and privileged-access controls across the migration program, connecting architecture standards to enforceable operating procedures for application, infrastructure, and security teams working inside a HIPAA-aligned environment.
  • Kept IAM, RBAC, audit trails, and SIEM/SOAR integration points inside the landing-zone design instead of treating them as separate security signoffs, helping the CISO and migration teams approve repeatable patterns for a HIPAA-aligned healthcare environment.
Coretek Services · August 2018 – January 2019

Senior Solutions Architect

Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a... Abbreviated role summary.

Evidence highlights (15)
  • Preserved user attributes, SIDs, passwords, groups, and profile data during the multi-forest consolidation, treating identity continuity as a cutover requirement rather than a post-migration repair effort for business users and administrators.
  • Migrated 10,000 on-premises mailboxes from Exchange 2007/2013 to Exchange Online in seven weeks with less than 2% failure and minimal user impact, converting a high-risk mail migration into a controlled execution pattern.

Additional evidence points: 13

Full role
Coretek Services · August 2018 – January 2019

Senior Solutions Architect

Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a merger, reducing fragmentation in identity and email operations.

  • Preserved user attributes, SIDs, passwords, groups, and profile data during the multi-forest consolidation, treating identity continuity as a cutover requirement rather than a post-migration repair effort for business users and administrators.
  • Migrated 10,000 on-premises mailboxes from Exchange 2007/2013 to Exchange Online in seven weeks with less than 2% failure and minimal user impact, converting a high-risk mail migration into a controlled execution pattern.
  • Implemented Conditional Access for device and user compliance, strengthening Microsoft 365 identity security while supporting cloud productivity adoption.
  • Consolidated user and desktop infrastructure after 19 company acquisitions, preserving user attributes and configurations while standardizing Active Directory, print, DNS, DHCP, VPN, and MPLS patterns.
  • Created a Microsoft 365 managed-service program and onboarded a pilot customer with more than 10,000 seats, turning project delivery lessons into a repeatable service offering.
  • Architected a Project Online PMO solution with automated onboarding, offboarding, and access provisioning, improving project governance without adding manual administrative overhead.
  • Designed the Project Online lifecycle model across production and sandbox instances so resource, team-member, project-manager, portfolio-manager, and administrator access could be provisioned and retired through repeatable governance rather than informal project-team requests.
  • Designed custom lifecycle and entitlement patterns across Microsoft 365, Project Online, and merger-consolidation work, translating onboarding, offboarding, license, group, and role-access requirements into repeatable governance controls.
  • Designed a secure, highly available file-sharing and virtual-desktop data solution for collaborative media and digital content, balancing performance-to-cost ratio, availability, patching, backup, and disaster-recovery requirements.
  • Trained administrators and champions to manage cloud systems after production release, reducing post-cutover dependency on project resources and improving operational ownership.
  • Configured secured on-premises SMTP and email relay patterns for applications and devices, preserving business-process continuity while Exchange workloads moved into cloud-managed architectures.
  • Designed alternative migration solutions around network and server limitations, eliminating project delays by treating infrastructure constraints as design inputs instead of blockers.
  • Guided Project Web App roadmap development, project templatization, and PMO process structure, giving customer organizations a repeatable project-management model beyond the initial Project Online deployment.
  • Evaluated internal and client infrastructure and security health, preparing mitigation plans and modernization roadmaps that helped customers sequence cloud, identity, endpoint, and managed-service improvements.
  • Positioned sales and solution-architecture teams to support Dynamics 365 offerings, expanding provider capability and strengthening Microsoft partnership value beyond core infrastructure projects.
Obsidian Availability Solutions · September 2016 – December 2018

Principal Consultant

Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years,... Abbreviated role summary.

Evidence highlights (16)
  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.

Additional evidence points: 14

Full role
Obsidian Availability Solutions · September 2016 – December 2018

Principal Consultant

Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years, expanding the service portfolio available to customer environments.

  • Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
  • Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.
  • Designed early Azure AD lifecycle and entitlement patterns for internal and customer tenants, connecting onboarding, role changes, offboarding, group-based access, and delegated CSP/MSP administration into repeatable managed-service controls.
  • Developed a per-unit managed-services cost model that made contract pricing more accurate, connecting technical delivery scope to financial sustainability instead of relying on broad estimates.
  • Implemented hybrid-cloud, productivity, collaboration, communication, identity, and security systems across customer environments, including Azure subscriptions, virtual networks, Hyper-V, System Center, Exchange, Skype, SharePoint, Teams, and security policies.
  • Implemented hybrid identity and federation foundations across Microsoft cloud customer environments, aligning directory synchronization, access boundaries, and tenant onboarding practices so customers could adopt cloud services without losing operational control of identity risk.
  • Led a 16,000+ user Skype for Business Online and Cloud PBX migration across 67 sites, consolidating more than 100 telecom contracts while delivering end-user training and unified communications support.
  • Implemented an Enterprise PKI hierarchy with an offline root CA, HSM-backed key storage, and certificate issuance for 6,000+ users and devices, strengthening authentication and regulatory-aligned identity controls.
  • Designed certificate templates, enrollment paths, and AD CS administrative RBAC for general, SCCM, and RADIUS use cases, turning certificate-based authentication from a one-time infrastructure build into an operable identity-control service.
  • Designed and implemented privileged-access operating patterns across internal and customer environments, including Tier 0-style separation, PAW/SAW practices, JEA, and resource PIM concepts where organizational maturity supported hands-on enforcement.
  • Led 24/7/365 critical-situation response and executive advisory work, translating availability, security, and business-continuity risks into practical remediation plans for customer and internal environments.
  • Authored, published, and maintained security policies, procedures, designs, and reports for hybrid-cloud, identity, and productivity environments, giving customer and internal teams operational documentation instead of one-time project artifacts.
  • Led a small-business digital-transformation project spanning marketing presence, POS, finance management, CRM, and integrated web solutions, connecting technical modernization to revenue, operations, and customer engagement.
  • Oversaw staff, vendors, strategic partners, external audits, performance reviews, product and service portfolios, scopes of work, and pricing, tying consulting architecture to accountable business operations.
  • Established program-management, communications, service-delivery, and implementation standards so customer engagements could scale without relying on informal founder-level intervention for every decision.
  • Evaluated technical products, services, and strategic partnerships across cloud, security, high-availability, and managed-services domains, keeping the service portfolio current while avoiding unnecessary vendor lock-in.
Orion Technology Services · June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

Served as lead architect and project manager for a 12-month ITIL implementation that overhauled managed-services offerings, improved SLA discipline,... Abbreviated role summary.

Evidence highlights (16)
  • Designed service-operation processes for incident, event, standard request, identity and access, and problem management, converting reactive support patterns into more consistent managed-service delivery.
  • Mapped identity and access work into the same service-operation model as incident, request, problem, and change management, giving managed-service customers a clearer path for provisioning, access issues, and escalation without creating a separate informal IAM queue.

Additional evidence points: 14

Full role
Orion Technology Services · June 2015 – August 2016

Senior Solutions Engineer, Engineering Team Lead

Served as lead architect and project manager for a 12-month ITIL implementation that overhauled managed-services offerings, improved SLA discipline, streamlined onboarding, and increased support-staff efficiency.

  • Designed service-operation processes for incident, event, standard request, identity and access, and problem management, converting reactive support patterns into more consistent managed-service delivery.
  • Mapped identity and access work into the same service-operation model as incident, request, problem, and change management, giving managed-service customers a clearer path for provisioning, access issues, and escalation without creating a separate informal IAM queue.
  • Modeled ServiceNow and ConnectWise integrations for incident, event, problem, and change-management workflows, improving the data foundation for shared managed-services tracking across provider and customer systems.
  • Modeled ServiceNow and ConnectWise workflows for incident, request, change, and identity-access operations, improving cross-system visibility for provider and customer teams managing shared service commitments.
  • Architected Microsoft 365 and SharePoint Online migrations for multiple clients, including a SharePoint environment with more than 150 site collections, helping customers move collaboration content into more governable cloud structures.
  • Designed and deployed Microsoft Project Online PMO solutions for six organizations, automating project structure, visibility, and portfolio discipline for customer delivery teams.
  • Architected Hyper-V and VMware private-cloud environments integrated with Azure ExpressRoute and Azure Backup, giving customers hybrid infrastructure options with clearer disaster-recovery and availability patterns.
  • Designed hosted private-cloud multi-tenancy patterns on VMware-era infrastructure, separating customer environments and access paths in an early control-plane model for managed cloud delivery.
  • Built real-time availability monitoring with rapid on-call escalation and prescriptive analytics, helping the Network Operations Center detect integration and automation failures before they undermined service commitments.
  • Developed technical training and LMS resources for internal and customer teams, improving adoption of new processes and reducing knowledge gaps across audiences with mixed technical depth.
  • Organized engineering for managed services across several dozen Office 365 tenant environments, turning repeated migration and support work into a more consistent cloud-service operating model.
  • Governed delegated administration across several dozen Office 365 tenant environments, turning repeated CSP/MSP support patterns into a more consistent cloud-service operating model with clearer privileged-access boundaries.
  • Built SharePoint team-site collections for client-services teams, operational teams, executive leadership, and sales, integrating collaboration spaces with CRM, PSA, and other systems so organizational knowledge and service workflows were easier to navigate.
  • Completed LogRhythm SIEM training and certification work to support required client projects, expanding the firm’s ability to deliver security monitoring and threat-detection services.
  • Developed service-strategy reporting for finance, demand, service portfolio, and business-relationship management, giving executives clearer visibility into profitability, performance, shortcomings, and customer value.
  • Consulted with client executives, technology leadership, operational management, and end users to define service portfolios and operating processes, improving the fit between managed-service contracts and the outcomes customers actually needed.
Detroit IT / Core 3 Solutions · June 2014 – February 2015

Senior Systems Administrator

Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.... Abbreviated role summary.

Evidence highlights (9)
  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.

Additional evidence points: 7

Full role
Detroit IT / Core 3 Solutions · June 2014 – February 2015

Senior Systems Administrator

Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.5 TB of Windows file services to SharePoint Online, and Skype for Business for internal and external communication.

  • Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
  • Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
  • Provided Tier 2 and Tier 3 escalation for service-desk resources and managed-services customers, translating recurring incidents into more durable fixes and clearer support paths.
  • Implemented availability-management and disaster-recovery practices for customer environments, helping mission-critical systems stay online and aligned with SLA expectations.
  • Coordinated client project plans, milestones, vendors, risks, and deliverables, giving internal leadership and customer stakeholders clearer visibility into active engagements.
  • Managed build-out, quality assurance, and deployment of client project engagements, reducing handoff risk between design, implementation, and managed-services support.
  • Reported project status, milestones, issues, risks, and deliverables to internal leadership, improving visibility into active customer work and enabling earlier escalation of delivery concerns.
  • Conducted security assessments and implemented protective measures for customer environments, connecting infrastructure modernization to breach prevention and risk reduction.
  • Secured Office 365 migration planning for Citrix-hosted customers, preserving identity, access, document integrity, and collaboration controls during the move from hosted Exchange and file services to Microsoft cloud services.
Detroit Country Day School · June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service... Abbreviated role summary.

Evidence highlights (8)
  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.

Additional evidence points: 6

Full role
Detroit Country Day School · June 2013 – June 2014

Senior Systems Analyst, Helpdesk Lead

Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service expectations for faculty, staff, students, parents, alumni, and guests.

  • Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
  • Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
  • Coordinated EUC and classroom-technology vendor escalations, repairs, RMAs, and warranty service, protecting instructional continuity while keeping hardware lifecycle issues visible to leadership.
  • Supported school-issued and sponsored software adoption, including Office 365 and classroom solutions, with account migration assistance, user training, and knowledge resources that reduced adoption friction.
  • Advised academic and administrative stakeholders on technology needs and modernization options, connecting infrastructure and endpoint decisions to educational delivery and operational productivity.
  • Collaborated with academic and administrative departments to identify technology needs, improving the alignment between classroom support, operational productivity, and educational delivery.
  • Managed implementation work for student-information system improvements, strengthening data accessibility for staff and faculty who depended on accurate academic and administrative records.
  • Delivered staff training on new technologies and software, increasing comfort with adopted tools and reducing avoidable support demand after rollout.
University of Michigan, Information & Technology Services · June 2011 – September 2012

IT Engineer

Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover... Abbreviated role summary.

Evidence highlights (9)
  • Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
  • Preserved assignment, location, lifecycle, and use relationships during the ServiceNow transition, creating identity-adjacent operational evidence for who had which institutional assets and how support teams should reason about ownership during service requests.

Additional evidence points: 7

Full role
University of Michigan, Information & Technology Services · June 2011 – September 2012

IT Engineer

Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover preserved the asset and configuration context required for reliable service operations.

  • Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
  • Preserved assignment, location, lifecycle, and use relationships during the ServiceNow transition, creating identity-adjacent operational evidence for who had which institutional assets and how support teams should reason about ownership during service requests.
  • Supported Configuration Management integration with Microsoft System Center and SAP Business Objects-based reporting, turning endpoint and asset data into more useful business intelligence for university IT decisions.
  • Onboarded critical university departments into a shared-services model for end-user systems administration, including Human Resources, Business & Finance, Information & Technology Services, and the Office of the President & Administration.
  • Helped plan touchless user-state migration, Windows and application upgrades, workstation refresh, and support-model updates for 25,000 users across more than 100 university departments and divisions, reducing disruption during enterprise service consolidation.
  • Developed and delivered ITIL training to End User Computing team members after train-the-trainer preparation, improving consistency in incident, request, service transition, and operational practices across the support organization.
  • Maintained campus computing sites and laboratories across workstations, printers, network infrastructure, and physical environments, supporting reliable academic and administrative access at institutional scale.
  • Developed procurement, lifecycle-management, and disposition processes for end-user assets, giving university IT a cleaner chain of custody from purchase through retirement.
  • Provided VIP cybersecurity and technical support for critical university personnel, resolving escalations and deployments where reliability, discretion, and rapid response mattered to institutional leadership.
Battery Giant / Energy Products · January 2007 – December 2010

IT Manager

Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment,... Abbreviated role summary.

Evidence highlights (10)
  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.

Additional evidence points: 8

Full role
Battery Giant / Energy Products · January 2007 – December 2010

IT Manager

Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment, giving branch offices and franchisees a standard operating foundation for growth instead of ad hoc local systems.

  • Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
  • Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
  • Implemented centralized ledger, inventory-control, and POS patterns across QuickBooks, Microsoft Dynamics, and CounterPoint SQL, strengthening financial controls, loss prevention, and fiduciary compliance across a multi-location retail model.
  • Rescued all data and transactions after a vendor-inflicted total system failure, preserving business continuity and financial integrity with no business-operations impact.
  • Rebuilt disaster-recovery and network design practices for mission-critical business systems, achieving 99.99% uptime for two consecutive years after assuming responsibility for availability and recovery systems.
  • Established IT governance, security-awareness training, policy, and procedure standards for franchise technology users, reducing operational risk while giving franchisees clearer support expectations and repeatable compliance practices.
  • Managed IT staff, vendors, contractors, and affiliated service providers, aligning hiring, dismissal, procurement, and operational oversight with the franchise’s growth and support needs.
  • Maintained branch-office technology, local and remote data centers, and replica systems to strengthen availability, business continuity, and franchise support across distributed retail locations.
  • Developed online training, LMS, documentation, and support resources for franchisees and staff, reducing dependence on one-off support interactions while standardizing technology adoption.
  • Advised executives on secure digital transformation, IT governance, and franchise technology strategy, connecting practical systems work to expansion, compliance, and operational risk decisions.
Detroit Country Day School · June 2005 – August 2006

Systems Analyst

Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin... Abbreviated role summary.

Evidence highlights (9)
  • Paired the Kerberos-to-Active Directory consolidation with account and data migration support, training, and getting-started seminars so the new identity model reduced classroom disruption instead of simply changing the authentication backend.
  • Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.

Additional evidence points: 7

Full role
Detroit Country Day School · June 2005 – August 2006

Systems Analyst

Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin assignment into hands-on directory design and build experience.

  • Paired the Kerberos-to-Active Directory consolidation with account and data migration support, training, and getting-started seminars so the new identity model reduced classroom disruption instead of simply changing the authentication backend.
  • Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.
  • Modernized legacy servers and workstations from Windows NT and Windows 98 SE to Windows Server 2003 and Windows XP, reducing operational risk while giving classrooms and administrative teams a more supportable platform.
  • Supported account and data migration into the new Active Directory environment, pairing technical rollout with training, knowledge resources, and getting-started seminars so students and faculty could adopt the change with less disruption.
  • Coordinated repairs, RMAs, warranty work, and vendor escalations for classroom and end-user technology, protecting teaching continuity when hardware or software issues threatened daily operations.
  • Researched and recommended emerging classroom technologies, connecting infrastructure work to the academic experience rather than treating support as a purely back-office function.
  • Led incident, request, and change-management practices for end-user systems during early identity and endpoint modernization, giving users a clearer path for support while the environment shifted from legacy platforms.
  • Developed security-focused service workflows and endpoint protocols for classroom technology, improving prioritization, escalation, and access-control practices in a high-touch academic setting.
  • Managed enterprise imaging, software installation, and workstation refresh activity for students, faculty, management, and directory-infrastructure servers, linking endpoint reliability to day-to-day classroom continuity.