Securing identities, endpoints, and infrastructure at scale.
4+ years hardening enterprise environments across Identity & Access Management, SIEM/EDR operations, and endpoint security — with a hands-on focus on offensive-minded, defense-first thinking. Currently applying that same discipline to AI-driven automation at Dealership Accelerator.
Profile
IT Security and Infrastructure professional with 4+ years of experience spanning Identity & Access Management (IAM), endpoint security, SIEM/EDR operations, and enterprise systems administration.
Proven record securing and supporting 5,000+ users and 815+ endpoints across 120 retail locations — implementing SailPoint IdentityNow IAM, Azure Entra ID SSO/MFA/Conditional Access, and CrowdStrike Falcon EDR, while managing SIEM operations through a transition from Arctic Wolf to Rapid7.
Led the migration of 120 retail locations from legacy on-premises hardware servers to a Hyper-V-based Remote Desktop Server Collection (RDSC), mitigating end-of-life security risk while improving system performance by 70%. Hands-on across MECM/SCCM, JAMF Pro, SOTI, SharePoint/Teams/Power Platform, and DSPM-driven data governance, with additional experience building AI automation and CRM integrations using LLM-based conversational agents.
Skilled at translating complex technical and security initiatives into clear documentation, measurable KPIs, and cross-functional collaboration with HR, Security, and Network teams.
Professional Experience
- Architected end-to-end AI automation workflows integrating CRM platforms (CDK Global, Cox Automotive, Tekion) with GoHighLevel and Twilio A2P SMS/voice, increasing qualified-lead response rates for dealership clients.
- Built and deployed 10+ automated workflows in GoHighLevel — lead routing, follow-up sequencing, CRM syncing — cutting manual outreach time by 60% and accelerating lead response speed by 45%.
- Extended automation beyond native platform capabilities with custom multi-step n8n pipelines connecting CRM, inventory, and communication systems.
- Maintained 12+ RESTful API integrations processing 10,000+ records/month; onboarded and maintained 245 active client accounts at 99.7% data accuracy, supporting ~$840K in monthly recurring revenue.
- Delivered measurable ROI on deployed AI solutions by gathering client requirements and iterating on prompt engineering and model configuration with LLM-based conversational agents.
- Strengthened enterprise identity security for 5,000+ users by implementing SailPoint IdentityNow-driven IAM and configuring Azure Entra ID SSO, cutting unauthorized-access risk.
- Enforced a Zero Trust access model — MFA and Conditional Access across all corporate and retail accounts, with automated provisioning/deprovisioning through SailPoint.
- Designed Organizational Units in Azure AD to align permissions with role-based access requirements across a hybrid on-prem AD / Azure Admin Center environment.
- Streamlined user lifecycle management across a hybrid identity environment spanning on-premises Active Directory and the Azure Admin Center.
- Managed SIEM operations through a strategic transition from Arctic Wolf to Rapid7, expanding continuous monitoring coverage and improving incident triage speed.
- Deployed and administered CrowdStrike Falcon EDR across 815+ endpoints, maintaining a 98% security patch compliance rate via MECM/SCCM.
- Reduced unclassified sensitive-data exposure by 70% across 50,000+ data assets through DSPM-driven classification, retention, and access-governance with Varonis and Cyera, aligned to Purview litigation hold policy.
- Reduced endpoint-related incidents by 28% and sustained 99%+ uptime across 815+ Windows/macOS endpoints spanning 120 retail locations via MECM/SCCM, JAMF Pro, and SOTI Cloud.
- Led a Jamf-to-Intune coexistence initiative, linking Jamf Smart Groups to Entra Conditional Access for real-time compliance evaluation and automated remediation.
- Administered SharePoint Online and Microsoft Teams for 5,000+ users — provisioning sites/libraries with metadata and versioning, managing channel access and Teams-SharePoint permissions alignment.
- Architected a Hyper-V-based Remote Desktop Server Collection (RDSC) to replace legacy on-premises infrastructure, improving system performance by 70% and retiring end-of-life server risk across 120 locations.
- Maintained zero data-loss incidents and 100% audit-trail compliance over two years managing Veeam Backup & Replication and Cisco Meraki monitoring.
- Co-built a SailPoint / Power Automate HRIS automation application with HR, Security, and Network stakeholders, increasing HR team productivity by 50%.
- Resolved 500+ ServiceNow tickets/month within SLA; authored runbooks and knowledge articles that cut onboarding time for new IT staff by 25%.
- Reduced AI error rates by 30% and cut QA testing time by 40% running structured regression testing across 8 model-review cycles.
- Resolved 85%+ of Tier 1 support tickets at first contact (50+ tickets/month), maintaining a 20+ article knowledge base.
- Sustained 99%+ uptime across 815+ endpoints, monitoring performance via MECM and flagging 30+ issues/month before store-level impact.
- Reduced end-user downtime by an estimated 20% by diagnosing and resolving hardware/software issues across 50+ endpoints.
- Maintained data integrity across 600+ Active Directory object changes supporting the company's cloud migration to a Hyper-V RDSC environment.
- Delivered high-volume customer service (20–40 daily interactions); ranked in the top 10% of sales associates company-wide (Q4 2023).
- Designed weekly/monthly KPI dashboards, enabling teams to identify performance gaps and improve operational efficiency by 15%.
Education
Technical Skills
Organized the way a SOC would tier its own toolset — identity outward to automation.
Identity & Access Security
SIEM / EDR & Data Security
Endpoint & Infrastructure
Microsoft 365 & Collaboration
AI & Automation
ITSM & Analytics
Business, Analytics & Communication
Certifications
Actively maintained across identity, data security, and AI security disciplines.
Projects
Enterprise-scale infrastructure work, offensive-security lab practice, and self-built automation. Click a category to filter, or a card to expand.
End-to-end environment design, cutover sequencing across 120 sites, and post-migration validation — coordinated to avoid store-level downtime during business hours.
Eliminated end-of-life security risk on unsupported 2008 R2 hosts and improved system performance by 70%.
Hardware/software compatibility validation, pilot rings, then staged rollout across remaining endpoints with rollback checkpoints at each ring.
Brought the full device fleet current on Windows 11 24H2 ahead of Windows 10 end-of-support, with no unplanned downtime.
Captured and dissected live traffic in Wireshark to study protocol behavior and spot anomalies, while using Nmap to map hosts, open services, and likely attack surface on lab networks.
Keeps offensive-security instincts sharp and directly informs how I harden the environments I'm responsible for defending.
Paired CyberStrike's agent framework with a locally-hosted, open-weight model served through LM Studio, keeping every prompt and finding on local hardware instead of a cloud API.
Ran scoped, authorized checks against sites I own and maintain for family — the kind of gaps this class of tooling typically surfaces: outdated software versions, missing security headers, weak TLS configuration, and overly permissive admin access.
Remediated the confirmed issues directly on the affected sites — patching, header hardening, and access-control tightening.
CyberStrike is an open-source project (AGPL-3.0) — used and configured for this assessment, not self-authored.
Runs automatically every morning, scraping fresh listings and filtering out anything that doesn't match my actual background — IAM, SIEM/EDR, endpoint security, and related roles — instead of surfacing generic results.
Built, scheduled, and hosted end-to-end on my own infrastructure — the same automation instinct I bring to client and employer workflows, applied to my own job search.