Senior Cybersecurity Architect

Los Angeles County Employees Retirement Association (LACERA) | December 2020 – March 2021

Role Summary

Initial cybersecurity architecture engagement that established the organization’s first dedicated security engineering foundation. This record is useful for evaluating roadmap formation, privileged-account discovery and remediation, remote-work stabilization, endpoint visibility, identity hardening, and board-supported multi-year security modernization.

  • Served as the organization’s first dedicated cybersecurity engineer and primary architect of a comprehensive three-year technology and security maturity roadmap spanning eight domains that was formally adopted by the CISO, IT leadership, and the Board; established a NIST CSF baseline at Level 1 with a formal target of Level 3 and secured a funded multi-year program that immediately opened three new security engineering roles.
  • Discovered and fully remediated hidden super-privileged Active Directory backdoor accounts that held the highest possible rights—built-in administrator, domain, enterprise, and schema administrator in Active Directory, plus synchronized Global Administrator access in Microsoft 365. These accounts were invisible in standard tools, completely excluded from audit trails and authentication records, and carried suspected logic-bomb associations; they were eliminated within two weeks of discovery.
  • Treated the hidden account discovery as a Tier 0-equivalent identity-control failure rather than a routine cleanup item, sequencing remediation around directory authority, audit visibility, synchronized cloud privilege, and remote-access hardening so the organization could trust the identity foundation before expanding the security roadmap.
  • Transitioned privileged identity administration toward Microsoft Graph-era control-plane patterns during the original LACERA engagement, using API-first inspection and remediation to find high-risk access paths that standard administrative views did not expose.
  • Designed the privileged-access foundation for PAW/SAW, resource PIM, JEA, and break-glass operations, pairing hands-on security implementation with infrastructure-team training so elevated access could be governed without blocking service delivery.
  • Designed and deployed Entra and Netskope across the entire organizational footprint of approximately 550–600 users and endpoints, converting the environment from zero visibility on remote endpoints (beyond legacy VPN tunnel traffic) to full visibility, full-tunnel VPN, firewall, web filtering, and endpoint security controls.
  • Stabilized and hardened remote access for the entire workforce during the COVID crisis, eliminating frequent unexpected downtime (previously one to two hours of partial or full impact several times per week) so that only scheduled maintenance remained; zero unexpected incidents occurred in the first quarter after implementation, restoring pre-crisis customer service metrics for the populations the organization served.
  • Established the initial identity, access, and visibility foundations that produced the organization’s first clear view of previously unknown shadow IT and high-risk access patterns, and initiated five formal RFP processes for core platforms (including ServiceNow, PMO tooling, and Microsoft security solutions) that locked in the next phase of the maturity program.
  • Led architecture and planning for the Secure Productive Enterprise initiative, defining greenfield landing-zone and core-service direction across Active Directory, networking, Microsoft 365, and Azure so later implementation work had a coherent foundation.
  • Created the strategic roadmap for modernizing identity and endpoint provider/management systems, aligning cloud enablement, business-service migration, and data-protection requirements before individual tool projects were allowed to drive the architecture.
  • Planned data and information-security compliance controls for future business services, ensuring modernization work was evaluated against required security standards instead of only short-term remote-work stabilization.
  • Consulted with information systems and application teams on security states and planned configurations, making the initial security engineering function a service partner rather than a detached compliance reviewer.