Professional Experience
Review Jake’s technology, cybersecurity, AI systems, consulting, and early-career experience in reverse chronological order. Each page is written for screening conversations: scope, operating context, and outcomes first.
Experience Index
Experience Record
Role History
Role cards keep the first pass compact while preserving the full public record for detailed review.
Scoria Software Solutions · March 2025 – PresentFounder & Principal Software Architect
Designed every tool to operate inside explicit, deterministic guardrails with codified approval and immutable attribution for any divergence,... Abbreviated role summary.
Evidence highlights (19)
- Built service-principal lifecycle tooling with ephemeral-token preference, check-in/check-out workflows, granular least privilege, and agentic session-ID attribution, reducing non-human identity risk while preserving auditable customer delivery.
- Reduced false positives by more than 50% (reaching over 95% in mature deployments) and cut human-intervention escalations from 20–30 per month to roughly one per quarter at one client, freeing security specialists to resume long-shelved SASE work.
Additional evidence points: 17
Bedrock Information Systems LLC · January 2019 – PresentPrincipal Architect
Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices... Abbreviated role summary.
Evidence highlights (16)
- Designed identity lifecycle and entitlement patterns for Bedrock and customer environments, applying the same governance model to users, service principals, app registrations, and delegated MSP/CSP access so public-sector clients could reduce standing access while preserving auditable operations.
- Designed Bedrock's internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
Additional evidence points: 14
Los Angeles County Employees Retirement Association (LACERA) · August 2023 – June 2024Principal Cybersecurity Architect
Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on... Abbreviated role summary.
Evidence highlights (18)
- Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
- Designed Entra-native governance patterns across custom roles, entitlement-style access workflows, lifecycle controls, and ServiceNow-backed approvals so privileged work moved through repeatable evidence paths rather than persistent administrator access.
Additional evidence points: 16
Wells Fargo Bank · July 2022 – July 2023Senior Cybersecurity Architect
Led the Service Enablement Task Force that validated and approved secure architecture and infrastructure blueprints across 128 cloud resource provider types,... Abbreviated role summary.
Evidence highlights (11)
- Led security review of 128 cloud resource provider types as a governed cloud control plane, converting bespoke infrastructure decisions into pre-approved patterns that let application teams adopt Azure services at scale while preserving cybersecurity and GRC approval gates.
- Accelerated security and infrastructure review cycles from an average of 3–12 application approvals per month to 40–50 completed reviews per week, unblocking the bank’s first successful large-scale public-cloud migration program after multiple prior failed attempts and enabling application teams to move into Azure architectures in volume for the first time in years.
Additional evidence points: 9
Microsoft Corporation · March 2021 – November 2021Senior Customer Engineer, Global Tech Team
Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers;... Abbreviated role summary.
Evidence highlights (21)
- Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
- Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
Additional evidence points: 19
Los Angeles County Employees Retirement Association (LACERA) · December 2020 – March 2021Senior Cybersecurity Architect
Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap... Abbreviated role summary.
Evidence highlights (11)
- Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
- Treated the hidden account discovery as a Tier 0-equivalent identity-control failure rather than a routine cleanup item, sequencing remediation around directory authority, audit visibility, synchronized cloud privilege, and remote-access hardening so the organization could trust the identity foundation before expanding the security roadmap.
Additional evidence points: 9
City National Bank · March 2020 – July 2020Vice President, Azure Infrastructure
Led a core infrastructure team of approximately six engineers (expanded to roughly eighteen during the crisis response), serving as the bank’s only pre-existing... Abbreviated role summary.
Evidence highlights (11)
- Executed rapid remote-work enablement that moved all IT staff to remote within one week and emptied the bank’s downtown Los Angeles and New York facilities to align with the governor’s emergency closure mandate; achieved 100% workforce remote transition within 30 days, with only minor adjustments required for branch-based colleagues.
- Stabilized crisis remote-work identity continuity for a national bank by scaling VPN, VDI, Microsoft 365, and Teams access behind Ping Federate, Azure AD, Microsoft Authenticator MFA, and continuous RADIUS validation, preserving secure workforce access while facilities closed under emergency mandates.
Additional evidence points: 9
Molina Healthcare · February 2019 – February 2020Senior Solutions Architect (Consultant, Infosys)
Architected and led the Azure Landing Zone and hybrid-cloud migration program for a healthcare environment of approximately 16,000 production servers (≈40,... Abbreviated role summary.
Evidence highlights (14)
- Reframed a stalled healthcare cloud-migration program into an executable Azure delivery model by unifying executive leadership, application owners, project managers, engineering teams, Microsoft, and ServiceNow support around a common migration plan, reducing program ambiguity and restoring delivery momentum.
- Selected the organization’s single most business-critical application—an SQL Always On cluster protecting 450 TB of data with 2.7 TB of daily transactions and one of the most complex SDLC cycles (up to 12–15 environments)—as the first major workload to move; designed and executed the full migration in four to five months, establishing a fully repeatable pattern that reduced subsequent application migrations from months to days or weeks.
Additional evidence points: 12
Coretek Services · August 2018 – January 2019Senior Solutions Architect
Migrated a 16,000-user base to Exchange Online in a single Azure AD tenant while consolidating 32 Exchange environments across 27 Active Directory forests after a... Abbreviated role summary.
Evidence highlights (15)
- Preserved user attributes, SIDs, passwords, groups, and profile data during the multi-forest consolidation, treating identity continuity as a cutover requirement rather than a post-migration repair effort for business users and administrators.
- Migrated 10,000 on-premises mailboxes from Exchange 2007/2013 to Exchange Online in seven weeks with less than 2% failure and minimal user impact, converting a high-risk mail migration into a controlled execution pattern.
Additional evidence points: 13
Obsidian Availability Solutions · September 2016 – December 2018Principal Consultant
Co-founded an IT consulting firm and established strategic partnerships with Microsoft, ServiceNow, Palo Alto, Dell, HPE, and other vendors within two years,... Abbreviated role summary.
Evidence highlights (16)
- Secured Microsoft Tier 1 / Direct CSP partner status, enabling stronger managed cloud and security offerings while improving the firm’s ability to support customer adoption directly.
- Built rapid customer and tenant onboarding patterns for managed-services lifecycle entry, standardizing implementation strategy so new customers could move from sale to operating service more predictably.
Additional evidence points: 14
Orion Technology Services · June 2015 – August 2016Senior Solutions Engineer, Engineering Team Lead
Served as lead architect and project manager for a 12-month ITIL implementation that overhauled managed-services offerings, improved SLA discipline,... Abbreviated role summary.
Evidence highlights (16)
- Designed service-operation processes for incident, event, standard request, identity and access, and problem management, converting reactive support patterns into more consistent managed-service delivery.
- Mapped identity and access work into the same service-operation model as incident, request, problem, and change management, giving managed-service customers a clearer path for provisioning, access issues, and escalation without creating a separate informal IAM queue.
Additional evidence points: 14
Detroit IT / Core 3 Solutions · June 2014 – February 2015Senior Systems Administrator
Designed and delivered migration of a large hosted Citrix environment to Office 365, including Exchange 2010 to Exchange Online, 2.... Abbreviated role summary.
Evidence highlights (9)
- Planned a comprehensive network overhaul for an engineering firm with six offices across five states, coordinating new ISPs, Cisco UCM voice, network hardware refresh, VPN, MPLS, and disaster-recovery services to reduce infrastructure fragility.
- Administered a VMware-based private cloud hosting VDI and sandbox environments for multiple software-development teams of 20-40 developers, preserving collaboration capacity for complex software work.
Additional evidence points: 7
Detroit Country Day School · June 2013 – June 2014Senior Systems Analyst, Helpdesk Lead
Refreshed Track-It! ITSM usage by defining ticket classification, escalation, and prioritization standards, converting recurring helpdesk work into clearer service... Abbreviated role summary.
Evidence highlights (8)
- Developed Microsoft SCCM-based imaging and systems-management practices for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing repetitive manual support work.
- Designed and deployed mobile laptop fleets for primary and elementary campuses with limited dedicated technology-center space, expanding classroom access to digital learning without forcing facilities changes.
Additional evidence points: 6
University of Michigan, Information & Technology Services · June 2011 – September 2012IT Engineer
Led Asset and Configuration Management work for the BMC Remedy to ServiceNow transition, defining import logic and data relationships so production ITSM cutover... Abbreviated role summary.
Evidence highlights (9)
- Managed asset governance and lifecycle processes for more than 25,000 university workstations, printers, monitors, classroom technologies, and peripherals serving over 100,000 daily users, giving leadership clearer visibility into location, assignment, use, and disposition.
- Preserved assignment, location, lifecycle, and use relationships during the ServiceNow transition, creating identity-adjacent operational evidence for who had which institutional assets and how support teams should reason about ownership during service requests.
Additional evidence points: 7
Battery Giant / Energy Products · January 2007 – December 2010IT Manager
Directed infrastructure, security, networking, identity, remote-server, ERP, and POS operations for a retail franchise technology environment,... Abbreviated role summary.
Evidence highlights (10)
- Designed and deployed standardized franchise technology kits, procurement processes, training resources, and escalation paths that helped expand the franchise platform from 2 stores to 11 in 18 months, with plans established for 30 additional stores in the following year.
- Built a centralized ecommerce and product-information platform covering more than 250,000 products across 3,000,000+ applications, improving lookup, cross-reference, pricing, and inventory workflows for internal users and franchise operations.
Additional evidence points: 8
Detroit Country Day School · June 2005 – August 2006Systems Analyst
Established the school's Active Directory foundation by helping consolidate six separate Kerberos realms into one AD forest, turning an early support/admin... Abbreviated role summary.
Evidence highlights (9)
- Paired the Kerberos-to-Active Directory consolidation with account and data migration support, training, and getting-started seminars so the new identity model reduced classroom disruption instead of simply changing the authentication backend.
- Developed imaging and systems-management practices using Microsoft SMS and Symantec Ghost for approximately 2,500 workstations across four campuses, improving endpoint consistency and reducing manual rebuild effort.
Additional evidence points: 7