Senior Customer Engineer, Global Tech Team

Microsoft Corporation | March 2021 – November 2021

Role Summary

Elite escalation and architecture role serving Fortune 500, public-sector, Microsoft internal, and high-technology customers. The most relevant examples are global incident remediation, identity overhaul after ransomware containment, root-cause work on critical infrastructure defects, Well-Architected commitments, public reusable engineering assets, and product-group influence.

  • Operated as a Senior Customer Engineer on the elite Global Tech Team supporting Fortune 500, U.S. government, Microsoft internal, and high-technology customers; managed 37 dedicated accounts (12 persistent for the full tenure) while serving as a broader escalation resource and the final technical authority for Microsoft IT and product-group escalations—resolving issues that had no remaining internal escalation path.
  • Helped customers design, implement, and administer information-protection and DLP capabilities spanning AD RMS, Azure Information Protection, Microsoft Information Protection, and Microsoft Purview, including sensitivity labeling, regulated-data discovery, policy tuning, and compliance operations across Microsoft 365 environments.
  • Mentored approximately a dozen engineers and contributed to more than six internal training programs and over twenty standardized customer delivery programs; the volume and variety of customer demand directly led to requesting and shaping production features that later shipped in Exchange Online Bookings.
  • Served as a primary post-incident remediation resource for Microsoft’s Detection and Response Team (DART); after DART contained a global ransomware attack against a Fortune 500 transportation company, led the subsequent worldwide identity-management overhaul spanning Active Directory forests, Microsoft 365 tenants, Azure and Azure Stack deployments, and private-cloud regions across tens of thousands of endpoints and users, permanently closing the privilege-escalation and leaked-privilege lateral-movement vectors that enabled the original attack and rapidly deploying FIDO-token plus Microsoft Authenticator multi-factor authentication to the entire global user base.
  • Translated legacy enterprise identity findings from the DART remediation work—external identity exposure, forests, tenants, leaked privilege paths, weak MFA posture, and private-cloud dependencies—into a modern control sequence that prioritized privilege closure, external-identity hardening, and phishing-resistant authentication before broader platform cleanup.
  • Sequenced the identity rebuild around priority-zero controls first: external identity hardening, Tier 0 isolation, resource PIM, JEA/constrained administration, PAW/SAW patterns, break-glass governance, and phishing-resistant authentication before broader platform cleanup, reducing the risk that recovery would preserve the same attack path.
  • Averaged one to two critical-situation escalations per week (frequently joining proactively); most notably diagnosed a Windows Server 2016 Storage Spaces Direct (S2D) bug that was causing cascading SQL Always-On, Exchange Online, Remote Desktop Services, DFS, and failover-cluster outages; the resulting global patch resolved long-standing, multi-year issues for six of twelve dedicated customers and every organization running high-availability Windows Server workloads on S2D worldwide.
  • Participated in the critical remediation team for a major global service outage at a hyperscale technology company, helping identify an infrastructure-as-code workflow that triggered the event, providing guidance for the rollback and permanent fix, and contributing to both customer-facing and Microsoft-internal postmortems; the internal postmortem drove backend process changes that improved geo-resiliency protections against rapid global rollouts and influenced standardized geo-resiliency and disaster-recovery planning for Premier and Unified Support customers.
  • Delivered customized Well-Architected Framework engagements for the complex minority of customers whose scale or operating model exceeded the standard program (ten of twelve dedicated accounts), driving nearly nine figures in multi-year Azure commitments (including one customer above eight figures), Azure Reserve Instance purchases, and multiple Unified Support renewals and expansions.
  • Authored and published reusable PowerShell and ARM-template assets to Microsoft’s public GitHub repositories and learn.microsoft.com (cybersecurity, identity, Azure infrastructure, Modern Workplace, and Microsoft 365); these assets were systematically linked from the AskJake.ms technical blog, which reduced repeat customer request volume and freed capacity for higher-value escalation and architecture work.
  • Authored reusable Graph, PowerShell, ARM-template, Microsoft Learn, and field-delivery assets for identity, privileged access, Azure infrastructure, Microsoft 365, and cybersecurity scenarios, converting high-consequence customer lessons into reusable guidance for customer engineers and product groups without exposing protected customer details.
  • Converted repeated Active Directory, Microsoft 365, information-protection, and identity remediation patterns into reusable customer-engineering material, preserving field lessons from high-consequence customer environments without exposing protected customer details.
  • Advised enterprise customers on B2B/B2C and delegated external-access patterns across Entra, federation, partner, and multi-tenant environments, treating external identity as a privileged-access risk surface rather than a convenience feature and translating incident lessons into safer customer and field guidance.
  • Contributed Microsoft Docs articles, internal knowledge, and delivery guidance for Microsoft 365, security, compliance, and information-protection scenarios, turning repeated DLP, labeling, and governance questions into reusable customer and engineer enablement material.
  • Acted as a rare broker between customer escalations and product groups; contributed multiple production features to the Outlook / Exchange Online personal Bookings experience (categories, private booking-link behavior, security and permissions for anonymous links, and Power Platform / inbox-rule integrations), all of which shipped, resulting in standing weekly check-ins requested by the product group.
  • Provided continuity for LACERA after leaving the earlier engagement: as their Microsoft engineer, launched Year 1 of the previously authored three-year roadmap, completed all identity and endpoint cloud-management objectives, stood up greenfield Active Directory and Microsoft 365 environments that closed the prior backdoor-account incident, designed Azure landing zones and SD-WAN foundations, and established the operational momentum that enabled the full multi-year program to finish on schedule years later.
  • Co-founded an elite cross-organizational “Super Pod” that grew from two engineers to nearly one hundred subscribers and more than fifty active participants within three months, overhauling Unified Support intake, triage, and communication processes at a time when backlogs had become unmanageable.
  • Supported Microsoft internal groups including MSIT, LinkedIn, GitHub, and product organizations through identity, cybersecurity, migration, incident, and critical-situation work, bringing customer-facing escalation discipline back into Microsoft’s own operating environment.
  • Developed, maintained, recycled, and distributed managed intellectual property for customer engineers, improving reuse of delivery models, readiness material, and professional-development resources across the global support community.
  • Worked with CSAMs, resource coordinators, Critical Situation Managers, sales, technical pre-sales, support, customer engineering, and cloud solution architecture groups to scope engagements accurately and preserve a unified customer experience across Microsoft touchpoints.
  • Converted red-team, blue-team, laboratory, customer-submission, bug, and vulnerability feedback into product-group signal, helping Microsoft improve security, compliance, identity, and cloud services through evidence gathered from strategic customer environments.
  • Contributed to global communities and managed intellectual-property forums spanning sustainability, GLEAM, identity, Active Directory, and customer engineering, expanding the channels through which field lessons became reusable organizational knowledge.