Principal Cybersecurity Architect

Los Angeles County Employees Retirement Association (LACERA) | August 2023 – June 2024

Role Summary

Senior-most technical authority for a dedicated cybersecurity engineering team reporting under the CISO. The public evidence centers on privileged-access elimination, continuous red-team / blue-team operations, phishing containment, compliance automation, change-management integration, and visible risk reduction in a regulated public retirement environment.

  • Led a five-person dedicated cybersecurity engineering team as the senior-most technical authority under the CISO, shifting the team from reactive whack-a-mole on user reports and Netskope alerts to consistent daily workflows focused on fundamentals and holistic remediation; user-submitted incidents and business disruptions fell from dozens per day to a handful per week, while GRC moved from constant chasing of IT staff to dashboard-driven work, reducing audit compliance effort from a dedicated full-time auditor to a monthly inter-team checkpoint with largely automated report generation.
  • Implemented Entra Privileged Identity Management with Just-in-Time access, eliminating 45 standing privileged accounts and all persistent admin access except a monitored break-glass account, while unifying a single audit trail and introducing M-of-N controls integrated with change management.
  • Designed Entra-native governance patterns across custom roles, entitlement-style access workflows, lifecycle controls, and ServiceNow-backed approvals so privileged work moved through repeatable evidence paths rather than persistent administrator access.
  • Designed and implemented Tier 0-equivalent privileged-access controls using resource PIM, Just Enough Administration, PAW/SAW operating patterns, and break-glass governance, then trained infrastructure, service, and administrative users on the new model.
  • Automated Entra and Microsoft Cloud identity operations through Microsoft Graph and Azure Management API control-plane patterns, giving a small security team repeatable leverage for privileged access, lifecycle enforcement, audit evidence, and governed change execution.
  • Configured and tuned Microsoft Purview DLP policies, sensitivity-labeling controls, retention policies, and compliance workflows alongside Defender operations, extending protection across regulated data categories and reducing previously unknown or unprotected sensitive-data exposure.
  • Stopped a successful phishing compromise of a high-value, high-privilege executive account with zero data extraction, zero lateral movement, and no impact to business systems, validating the effectiveness of the new privileged access and monitoring controls.
  • Deployed Pentera as a continuous red-team capability that initially surfaced hundreds of findings (thousands when correlated with Defender), consolidated after MITRE-aligned triage to approximately 360 actionable items; Critical and High severity issues (roughly 10–15 percent of the total) were closed within the first month’s change cycles, and the residual backlog was driven down to an average of 10–12 active findings, with zero-day exposures typically detected within 1–24 hours of CVE assignment and more than 80 percent remediated inside a single change cycle.
  • Paired Pentera (red team) with the Microsoft Defender / Purview suite (blue team) to institutionalize regular red-team / blue-team war-game exercises, producing a two-order-of-magnitude drop in Defender events (from hundreds of thousands to thousands per week across the enterprise) and closing nearly all historical vulnerabilities within one quarter of joint operation.
  • Built DLP alert investigation and remediation workflows that connected Purview, Defender, GRC, and change-management evidence, giving compliance and security stakeholders practical dashboards for policy effectiveness, false-positive reduction, and audit readiness.
  • Integrated security tooling and processes into existing fire-drill and disaster-recovery exercises, creating a unified operational cadence that enabled full business continuity during a real high-privilege account lockdown with zero impact to internal users, external consumers, or public-facing services.
  • Led RFP, demonstration, and proof-of-concept processes for SIEM, SOAR, and SASE platforms while simultaneously advancing the organization’s compliance maturity more than 30 percent across key frameworks through prioritized controls and programmatic governance.
  • Drove ServiceNow-based GRC and change-management integration that increased legitimate change tickets from a handful per month to dozens per week, established a weekly Change Review Board with security as an equal participant, and reduced change delivery cycles from weeks to days or hours with almost no post-change security regressions.
  • Delivered real-time security dashboards and live monitoring that compressed project charter and board-approval cycles from multi-quarter processes to a standard monthly cadence, unlocking faster budget and resource decisions and organization-wide visibility into posture and progress.
  • Established the Information Security Engineering Team as a dedicated function under CISO leadership, creating a durable operating model for security architecture, tool implementation, vulnerability remediation, and consultative support to information systems and application teams.
  • Designed the Secure Productive Enterprise roadmap for greenfield identity, network, Microsoft 365, and Azure foundations, linking endpoint, data-protection, cloud, and access-control modernization into one board-visible security transformation path.
  • Architected the “LACERA Cloud” framework using SDN/SD-WAN concepts across multiple data centers, giving the organization a unified pattern for secure business-service migration, information-security compliance, and availability planning.
  • Overhauled internal service-management and project-portfolio processes so security, IT operations, and end users could move more work through governed channels without slowing remediation or routine service delivery.
  • Developed automation and orchestration patterns that let a small security team manage a large, changing environment, converting headcount constraints into a design requirement for repeatable controls and operational leverage.