Scoria Software Solutions · March 2025 – PresentFounder & Principal Software Architect
Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence, producing clearer audit trails, faster incident response (seconds or milliseconds instead of minutes), and a 1–2 order-of-magnitude reduction in attempts to bypass safety controls.
Inline bullet summary
- Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
- Built the XLM engine and MCP toolkit family that turns a single prompt into a complete, deterministic, multi-platform application stack while remaining fully model- and platform-agnostic, enabling early adopters to collapse POC cycles from months to weeks, double win rates, and increase inbound leads tenfold.
- Made the suite model- and platform-agnostic so the same tools run interchangeably across consumer apps, enterprise platforms, Azure AI Foundry, Ollama, and local models; one customer cut Azure spend 65% while dropping application latency from 3–5 seconds to 10–150 ms.
Bedrock Information Systems LLC · January 2019 – PresentPrincipal Architect
Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.
Inline bullet summary
- Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
- Led a Microsoft Teams implementation for a municipal customer that expanded into a five-year city-wide AI adoption roadmap, aligning 26 major IT priorities across modernization, security enhancement, compliance enforcement, user training, AI adoption, and legacy phase-out; projected initial ROI within 6–8 months and full ROI by year three, with seven-figure annual savings expected from year four onward.
- Built and deployed a custom microfilm digitization tool that converted more than a century of legacy government records (dating to the 1800s) into OCR/ICR-optimized, PDF/A-compliant digital assets with full metadata in a single 21-hour continuous run—collapsing an estimated 10-year multi-person full-time effort—and reduced pre-digital public records request turnaround from weeks or months to days or hours.
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024Principal Cybersecurity Architect
Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
Inline bullet summary
- Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
- Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
- Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
Wells Fargo Bank · July 2022 – July 2023Senior Cybersecurity Architect
Led the Service Enablement Task Force that validated and approved secure architecture and infrastructure blueprints across 128 cloud resource provider types, creating a library of pre-approved patterns that allowed thousands of downstream business applications to adopt standardized designs and largely eliminated the need for custom infrastructure architecture.
Inline bullet summary
- Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
- Designed and implemented multi-layered Hold-Your-Own-Key (HYOK) cryptography with external key providers that eliminated all third-party cryptographic dependencies and delivered 100% bank-controlled operations with zero exceptions; this removed an entire class of key-management risk, strengthened audit posture under high securities-regulation and FISA scrutiny, and served as a decisive requirement that finally unblocked enterprise cloud adoption.
- Developed SDLC policy-enforcement roadmaps that shifted the organization from an exception-driven culture to standardized architecture selection; application teams’ effort dropped from dozens of hours spread over weeks or months to roughly one to two hours of asynchronous work, while security and infrastructure teams achieved substantially higher output volume with near-universal consistency of results.
Microsoft Corporation · March 2021 – November 2021Senior Customer Engineer, Global Tech Team
Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
Inline bullet summary
- Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
- Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
- Averaged one to two critical-situation escalations per week (frequently joining proactively); most notably diagnosed a Windows Server 2016 Storage Spaces Direct (S2D) bug that was causing cascading SQL Always-On, Exchange Online, Remote Desktop Services, DFS, and failover-cluster outages; the resulting global patch resolved long-standing, multi-year issues for six of twelve dedicated customers and every organization running high-availability Windows Server workloads on S2D worldwide.
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021Senior Cybersecurity Architect
Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap spanning eight domains that was formally adopted by the CISO, IT leadership, and the Board; established a NIST CSF baseline at Level 1 with a formal target of Level 3 and secured a funded multi-year program that immediately opened three new security engineering roles.
Inline bullet summary
- Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
- Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
- Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
City National Bank · March 2020 – July 2020Vice President, Azure Infrastructure
Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing remote-access capability and the first group transitioned to full remote work in March 2020.
Inline bullet summary
- Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
- Designed and scaled corporate VPN, Microsoft Teams / Microsoft 365 collaboration, and VDI infrastructure to support the full national workforce, while implementing updated multi-factor authentication (Ping Federate + Azure AD + Microsoft Authenticator with continuous RADIUS) and Azure availability monitoring—foundational capabilities preserved for subsequent enterprise adoption.
Molina Healthcare · February 2019 – February 2020Senior Solutions Architect (Consultant, Infosys)
Architected and led the Azure Landing Zone and hybrid-cloud migration program for a healthcare environment of approximately 16,000 production servers (≈40,000 total environments including non-production), more than 630 business applications, and a data footprint exceeding 2 petabytes; completed migration of roughly one-quarter of the footprint within the year.
Inline bullet summary
- Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.
- Authored the majority of the Infrastructure-as-Code and orchestration frameworks that provisioned and governed all Landing Zone resources (networking, Virtual WAN, storage, gateways, firewalls, and Zero Trust network security) as well as the ongoing deployment and maintenance of the critical SQL Always On workload; integrated the frameworks into the organization’s existing Terraform processes so that operational teams experienced zero change to day-to-day maintenance and management, while end-to-end automated cutovers (including a perfectly clean production SQL Always On migration) required only human monitoring.
- Treated security and compliance as first-class requirements from the outset, embedding HIPAA controls, comprehensive audit trails, and ready integration points for existing SIEM/SOAR tooling; the design received full CISO and security-team approval and satisfied 100 percent of the security organization’s stated requirements.
Coretek Services · August 2018 – January 2019Senior Solutions Architect
Delivered senior solution architecture support across Microsoft-centered infrastructure, cloud, and managed-service environments, bridging hands-on systems engineering with later regulated cloud migration and security architecture work.
Obsidian Availability Solutions · September 2016 – December 2018Principal Consultant
Provided principal-level consulting across infrastructure availability, modernization, and customer technical leadership, strengthening the continuity between engineering lead roles and later enterprise architecture engagements.
Orion Technology Services · June 2015 – August 2016Senior Solutions Engineer, Engineering Team Lead
Led senior solution-engineering work and team-level technical execution across customer infrastructure environments, building the delivery and escalation habits that later carried into principal architecture roles.
Detroit IT / Core 3 Solutions · June 2014 – February 2015Senior Systems Administrator
Supported and administered customer infrastructure environments in a managed-services setting, combining hands-on systems operations, escalation response, and durable client-facing technical support.
Detroit Country Day School · June 2013 – June 2014Senior Systems Analyst, Helpdesk Lead
Led helpdesk and systems-analysis work for an education environment, balancing responsive support, endpoint operations, and practical infrastructure upkeep for faculty, staff, and students.
University of Michigan, Information & Technology Services · June 2011 – September 2012Systems Analyst
Supported systems-analysis and information-technology service work in a large university environment, developing early habits around documentation, service reliability, and cross-functional technical support.
Battery Giant / Energy Products · January 2007 – December 2010Information Technology Specialist
Provided hands-on information-technology support for business operations, combining systems troubleshooting, user support, and practical infrastructure upkeep during the early phase of the technology career path.
Detroit Country Day School · June 2005 – August 2006Systems Analyst
Supported education-sector systems and user needs in an early technical role, establishing practical foundations in support, operations, and reliable service delivery.