IT Security Administrator

Securing identities, endpoints, and infrastructure at scale.

4+ years hardening enterprise environments across Identity & Access Management, SIEM/EDR operations, and endpoint security — with a hands-on focus on offensive-minded, defense-first thinking. Currently applying that same discipline to AI-driven automation at Dealership Accelerator.

5,000+
Users Secured
815+
Endpoints Managed
120
Retail Locations
mkhan@secops — zsh
01 — Summary

Profile

IT Security and Infrastructure professional with 4+ years of experience spanning Identity & Access Management (IAM), endpoint security, SIEM/EDR operations, and enterprise systems administration.

Proven record securing and supporting 5,000+ users and 815+ endpoints across 120 retail locations — implementing SailPoint IdentityNow IAM, Azure Entra ID SSO/MFA/Conditional Access, and CrowdStrike Falcon EDR, while managing SIEM operations through a transition from Arctic Wolf to Rapid7.

Led the migration of 120 retail locations from legacy on-premises hardware servers to a Hyper-V-based Remote Desktop Server Collection (RDSC), mitigating end-of-life security risk while improving system performance by 70%. Hands-on across MECM/SCCM, JAMF Pro, SOTI, SharePoint/Teams/Power Platform, and DSPM-driven data governance, with additional experience building AI automation and CRM integrations using LLM-based conversational agents.

Skilled at translating complex technical and security initiatives into clear documentation, measurable KPIs, and cross-functional collaboration with HR, Security, and Network teams.

Languages
EnglishNative
UrduNative
GermanFull Professional
ArabicProfessional Working
SpanishLimited Working
LocationSkokie, IL
02 — Experience

Professional Experience

AI Implementation Engineer
JAN 2026 — PRESENT
Dealership Accelerator · Remote
  • Architected end-to-end AI automation workflows integrating CRM platforms (CDK Global, Cox Automotive, Tekion) with GoHighLevel and Twilio A2P SMS/voice, increasing qualified-lead response rates for dealership clients.
  • Built and deployed 10+ automated workflows in GoHighLevel — lead routing, follow-up sequencing, CRM syncing — cutting manual outreach time by 60% and accelerating lead response speed by 45%.
  • Extended automation beyond native platform capabilities with custom multi-step n8n pipelines connecting CRM, inventory, and communication systems.
  • Maintained 12+ RESTful API integrations processing 10,000+ records/month; onboarded and maintained 245 active client accounts at 99.7% data accuracy, supporting ~$840K in monthly recurring revenue.
  • Delivered measurable ROI on deployed AI solutions by gathering client requirements and iterating on prompt engineering and model configuration with LLM-based conversational agents.
IT Security Administrator
JAN 2024 — JAN 2026
American Signature Inc. · Remote
  • Strengthened enterprise identity security for 5,000+ users by implementing SailPoint IdentityNow-driven IAM and configuring Azure Entra ID SSO, cutting unauthorized-access risk.
  • Enforced a Zero Trust access model — MFA and Conditional Access across all corporate and retail accounts, with automated provisioning/deprovisioning through SailPoint.
  • Designed Organizational Units in Azure AD to align permissions with role-based access requirements across a hybrid on-prem AD / Azure Admin Center environment.
  • Streamlined user lifecycle management across a hybrid identity environment spanning on-premises Active Directory and the Azure Admin Center.
  • Managed SIEM operations through a strategic transition from Arctic Wolf to Rapid7, expanding continuous monitoring coverage and improving incident triage speed.
  • Deployed and administered CrowdStrike Falcon EDR across 815+ endpoints, maintaining a 98% security patch compliance rate via MECM/SCCM.
  • Reduced unclassified sensitive-data exposure by 70% across 50,000+ data assets through DSPM-driven classification, retention, and access-governance with Varonis and Cyera, aligned to Purview litigation hold policy.
Infrastructure Specialist & Systems Administrator
AUG 2022 — JAN 2024
American Signature Inc. · Remote
  • Reduced endpoint-related incidents by 28% and sustained 99%+ uptime across 815+ Windows/macOS endpoints spanning 120 retail locations via MECM/SCCM, JAMF Pro, and SOTI Cloud.
  • Led a Jamf-to-Intune coexistence initiative, linking Jamf Smart Groups to Entra Conditional Access for real-time compliance evaluation and automated remediation.
  • Administered SharePoint Online and Microsoft Teams for 5,000+ users — provisioning sites/libraries with metadata and versioning, managing channel access and Teams-SharePoint permissions alignment.
  • Architected a Hyper-V-based Remote Desktop Server Collection (RDSC) to replace legacy on-premises infrastructure, improving system performance by 70% and retiring end-of-life server risk across 120 locations.
  • Maintained zero data-loss incidents and 100% audit-trail compliance over two years managing Veeam Backup & Replication and Cisco Meraki monitoring.
  • Co-built a SailPoint / Power Automate HRIS automation application with HR, Security, and Network stakeholders, increasing HR team productivity by 50%.
  • Resolved 500+ ServiceNow tickets/month within SLA; authored runbooks and knowledge articles that cut onboarding time for new IT staff by 25%.
AI Support Agent
JAN 2022 — JAN 2024
CyCobra AI · Remote (Part-time)
  • Reduced AI error rates by 30% and cut QA testing time by 40% running structured regression testing across 8 model-review cycles.
  • Resolved 85%+ of Tier 1 support tickets at first contact (50+ tickets/month), maintaining a 20+ article knowledge base.
Information Technology Intern
MAY 2022 — AUG 2022
American Signature Inc. · Remote
  • Sustained 99%+ uptime across 815+ endpoints, monitoring performance via MECM and flagging 30+ issues/month before store-level impact.
  • Reduced end-user downtime by an estimated 20% by diagnosing and resolving hardware/software issues across 50+ endpoints.
  • Maintained data integrity across 600+ Active Directory object changes supporting the company's cloud migration to a Hyper-V RDSC environment.
— Additional Experience —
Shift Team Lead / Sales Specialist
MAR 2017 — AUG 2024
Best Buy · United States
  • Delivered high-volume customer service (20–40 daily interactions); ranked in the top 10% of sales associates company-wide (Q4 2023).
  • Designed weekly/monthly KPI dashboards, enabling teams to identify performance gaps and improve operational efficiency by 15%.
Customer ServiceSales ConsultingRetail OperationsPOS SystemsTeam Leadership
03 — Education

Education

Bachelor of Science — Management Information Systems & Finance
DePaul University, Driehaus College of Business
Minor in Accounting · Aug 2022 — Jun 2024
Relevant Coursework
SaaS SystemsBusiness Analytics Database Systems Analysis & DesignApplied Networks & Security Financial Statement AnalysisWeb Computing Microsoft Access
Additional Credentials
Bloomberg Market ConceptsBloomberg
Alternative InvestmentsCAIA Association
Driver's LicenseValid IL, Clear Bkgd Check
04 — Capabilities

Technical Skills

Organized the way a SOC would tier its own toolset — identity outward to automation.

01

Identity & Access Security

SailPoint IdentityNowAzure AD / Entra ID Conditional AccessMFA / SSO Zero TrustRBAC On-Prem ADLDAPGlobal Admin
02

SIEM / EDR & Data Security

CrowdStrike FalconRapid7 Arctic WolfDSPM (Varonis, Cyera, Securiti AI) Threat & Vulnerability MgmtPurview Litigation Hold ISO 27001GRC
03

Endpoint & Infrastructure

MECM / SCCMMicrosoft Intune JAMF ProSOTI Cloud Cisco MerakiHyper-V / RDSC VMwareWindows Autopilot BitLocker / FileVaultPowerShell Patch ManagementAzure SQL
04

Microsoft 365 & Collaboration

SharePoint OnlineTeams Administration Power AutomatePower Apps Copilot StudioM365 Global Admin
05

AI & Automation

Prompt EngineeringLLM Integration Conversational AICRM Automation GoHighLevelTwilio A2P n8nREST API IntegrationWeb Scraping / Actors
06

ITSM & Analytics

ServiceNowJIRA ITILIncident / Change Mgmt Veeam Backup & ReplicationPower BI KPI DashboardsMicroStrategy Reporting System Administration
07

Business, Analytics & Communication

Financial Statement AnalysisRisk Management Data AnalysisBusiness Planning Business DevelopmentAccount Management Strategic CommunicationsMicrosoft Office Suite
05 — Credentials

Certifications

Actively maintained across identity, data security, and AI security disciplines.

PrivacyOps
Securiti AI
Issued Jul 2026 · ID 144EFABC1-144E0DFD8
↗ Verify credential
Claude Platform 101
Anthropic
Issued Jul 2026
↗ Verify credential
Claude Code 101
Anthropic
Issued Jul 2026
↗ Verify credential
Introduction to the Threat Landscape 3.0
Fortinet
Issued Jul 2026
SOC Essentials: Introduction to Threat Hunting
Splunk
Issued Jul 2026
Introduction to Enterprise Security
Splunk
Issued Jul 2026
Certified AI Trust Practitioner
Cyera
Issued Jul 2026 · ID 11757
Certified DSPM Fundamentals
Cyera
Issued Jun 2026 · ID 11585
Certified AI Security Fundamentals
Cyera
Issued Jun 2026 · ID 11625
Certified DSPM Architect
Cyera
Issued Jun 2026 · ID 11597
DSPM Fundamentals
Securiti AI
Issued Jun 2026 · ID 150EB4BD4-150F97E98
↗ Verify credential
AI Fluency for Builders
Anthropic
Issued Jun 2026
↗ Verify credential
Claude 101
Anthropic
Issued Jun 2026
↗ Verify credential
Microsoft Azure AI Essentials Professional Certificate
Microsoft & LinkedIn Learning
Issued Jun 2026
↗ Verify credential
SaaS Workflows
SailPoint
Credential
Discover Non-Employee Risk Management
SailPoint
Credential
Identity Now Introduction
SailPoint
Credential
Bloomberg Market Concepts (BMC)
Bloomberg
Credential
Fundamentals of Alternative Investments
CAIA Association
Credential
06 — Applied Work

Projects

Enterprise-scale infrastructure work, offensive-security lab practice, and self-built automation. Click a category to filter, or a card to expand.

PROJECT / 01
Server 2008 R2 → 2022 RDSC Migration
Planned and executed the full retirement of legacy Windows Server 2008 R2 infrastructure across 120 retail locations, replacing it with a modern Hyper-V-based Remote Desktop Server Collection running Server 2022.
Hyper-VWindows Server 2022RDSC
Scope

End-to-end environment design, cutover sequencing across 120 sites, and post-migration validation — coordinated to avoid store-level downtime during business hours.

Outcome

Eliminated end-of-life security risk on unsupported 2008 R2 hosts and improved system performance by 70%.

→ Eliminated end-of-life risk, +70% performance
PROJECT / 02
SCCM-Driven Windows 11 24H2 Fleet Upgrade
Led the full-fleet transition from Windows 10 to Windows 11 24H2 using MECM/SCCM task sequences and phased deployment rings across the entire endpoint estate.
MECM / SCCMWindows 11 24H2Deployment Rings
Scope

Hardware/software compatibility validation, pilot rings, then staged rollout across remaining endpoints with rollback checkpoints at each ring.

Outcome

Brought the full device fleet current on Windows 11 24H2 ahead of Windows 10 end-of-support, with no unplanned downtime.

→ Full-fleet OS currency, zero disruption rollout
PROJECT / 03
Network Traffic Analysis & Pentesting Lab
Self-directed home lab for hands-on offensive-security practice — packet-level traffic analysis with Wireshark and host/service/vulnerability discovery with Nmap.
WiresharkNmapNetwork Recon
Focus

Captured and dissected live traffic in Wireshark to study protocol behavior and spot anomalies, while using Nmap to map hosts, open services, and likely attack surface on lab networks.

Why it matters

Keeps offensive-security instincts sharp and directly informs how I harden the environments I'm responsible for defending.

→ Ongoing hands-on offensive-security practice
PROJECT / 04
Authorized Assessment with CyberStrike + Local LLM
Configured CyberStrike, an open-source AI-driven offensive-security agent, to run entirely offline against a locally-hosted open-weight model in LM Studio — then used it to run authorized assessments against personal, family-owned websites.
CyberStrike (OSS)LM StudioLocal LLM InferenceAuthorized Testing
CyberStrike terminal session showing agent capabilities
Setup

Paired CyberStrike's agent framework with a locally-hosted, open-weight model served through LM Studio, keeping every prompt and finding on local hardware instead of a cloud API.

Scope

Ran scoped, authorized checks against sites I own and maintain for family — the kind of gaps this class of tooling typically surfaces: outdated software versions, missing security headers, weak TLS configuration, and overly permissive admin access.

Outcome

Remediated the confirmed issues directly on the affected sites — patching, header hardening, and access-control tightening.

Tool

CyberStrike is an open-source project (AGPL-3.0) — used and configured for this assessment, not self-authored.

→ Ran fully offline, closed real gaps on live sites
PROJECT / 05
Automated Job Intelligence Pipeline
Built a scheduled web-scraping system using automated Actors to surface new job postings each morning, filtered specifically against the skills and titles on my own resume — hosted on my personal domain.
Apify ActorsScheduled AutomationCustom DomainResume Matching
Job pipeline dashboard showing lane-sorted, filtered live listings
How it runs

Runs automatically every morning, scraping fresh listings and filtering out anything that doesn't match my actual background — IAM, SIEM/EDR, endpoint security, and related roles — instead of surfacing generic results.

Why it matters

Built, scheduled, and hosted end-to-end on my own infrastructure — the same automation instinct I bring to client and employer workflows, applied to my own job search.

→ Runs daily, unattended, on my own domain