Principal Architect
Bedrock Information Systems LLC | January 2019 – Present
Role Summary
Principal architecture and delivery leadership across municipal, regulated, and managed-service environments. This role is the clearest evidence for contract, project, and advisory work: security maturity, CJIS and NIST alignment, AI adoption planning, records modernization, MDM migration, DevOps standards, and practical delivery with small teams under public-sector constraints.
- Established NIST CSF 2.0 Tier 3 (Repeatable) as the new baseline for onboarded systems across all core functions, replacing prior Tier 1 awareness-level practices and enabling automated, single-click audit reporting that reduced typical municipal IT audit effort from 40–120 staff hours to under 30 minutes.
- Designed identity lifecycle and entitlement patterns for Bedrock and customer environments, applying the same governance model to users, service principals, app registrations, and delegated MSP/CSP access so public-sector clients could reduce standing access while preserving auditable operations.
- Designed Bedrock’s internal and client-facing Microsoft 365 information-protection baseline, including Purview sensitivity labels, DLP policy patterns, retention controls, and classification schemas that support client data subject to CJIS, HIPAA, PCI, CUI, PII, financial, health, law-enforcement, public-safety, and other regulated-data requirements.
- Standardized SCIM-preferred provisioning and Microsoft Graph / Azure Management API automation as the preferred path for identity and Microsoft Cloud administration, replacing UI-bound workflows with API-native controls that improved least-privilege enforcement and audit visibility.
- Delivered measurable advances in CJIS compliance for multiple public-sector customers, strengthening security controls while reducing administrative burden on sworn officers by 1–2 hours per day and allowing more time for street-level public safety work.
- Led a Microsoft Teams implementation for a municipal customer that expanded into a five-year city-wide AI adoption roadmap, aligning 26 major IT priorities across modernization, security enhancement, compliance enforcement, user training, AI adoption, and legacy phase-out; prioritized Purview sensitivity labeling and DLP as immediate data-protection work, projected initial ROI within 6–8 months and full ROI by year three, with seven-figure annual savings expected from year four onward.
- Implemented automated DLP and information-protection controls that detected a public-sector CJIS data exposure within five minutes of availability and applied extreme encryption and protection through Purview, including to copies stored outside Microsoft 365, while preserving NDA-safe disclosure of the incident.
- Built and deployed a custom microfilm digitization tool that converted more than a century of legacy government records (dating to the 1800s) into OCR/ICR-optimized, PDF/A-compliant digital assets with full metadata in a single 21-hour continuous run—collapsing an estimated 10-year multi-person full-time effort—and reduced pre-digital public records request turnaround from weeks or months to days or hours.
- Applied structured guardrails and deterministic processes to AI-assisted development, enabling non-developer infrastructure and application engineers to safely expand into development work; accelerated project timelines 50–75%, allowed teams of 2–3 to deliver what previously required teams of 6–12, eliminated engineer overtime (previously 50–60 hours/week), and increased per-engineer revenue and profitability while expanding overall market footprint without added headcount.
- Governed service-principal and workload-identity access for client-facing and agentic solutions, favoring ephemeral-token patterns, explicit check-in/check-out, granular permissions, and session-level audit trails where customer risk models required non-human identity accountability.
- Directed a large-scale public-sector MDM migration completed in 45 days with one part-time engineer (versus a prior 6–9 month estimate requiring five engineers), achieving 100% success, zero data loss or service interruption, and only five support requests from a 2,300-user organization after a 15-minute training session.
- Designed and operated Azure DevOps and GitHub-based CI/CD pipelines and repository standards that automated deployment and release management for multi-environment application fleets while embedding security and compliance requirements as first-class, non-negotiable constraints alongside functional and budgetary needs.
- Provided architectural leadership for secure web and application solutions across internal and client environments, expanding Bedrock’s capabilities from family-office technology support into a full managed-service provider model serving public-sector and regulated clients while consistently managing concurrent teams averaging 6–12 people.
- Extended public-sector security roadmaps beyond compliance checklists by tying Entra governance, delegated privileged access, information protection, and automated audit evidence to practical municipal outcomes: fewer manual controls, clearer accountability, and safer modernization.
- Developed client IT strategy and governance roadmaps that tied cloud modernization, cybersecurity posture, records workflows, and service management to business outcomes, helping small public-sector teams prioritize work that improved resilience instead of chasing isolated tickets.
- Managed cross-functional delivery across infrastructure, application, security, records, and operations stakeholders, keeping complex municipal and regulated projects aligned to practical service outcomes rather than vendor-driven implementation checklists.
- Authored reusable cybersecurity, cloud migration, and modernization guidance for clients and internal teams, turning repeated advisory patterns into durable material for faster planning, clearer executive communication, and more consistent delivery.