Experience

Hands-on security operations, compliance and identity work, from MSP client environments to building security in-house.

Download resume (PDF)

<5 minMean time to detect, Crexi
35%Lower mean time to respond, Fuel Cycle
100+SOC 2 Type II controls coordinated
80%Client attack surface reduced
May 2026 – PresentLos Angeles, CA

System Administrator

Crexi

  • Led migration and security cutover from an outsourced MSP to in-house operations across CrowdStrike Complete, Avanan, Dropsuite, and NinjaOne, establishing full internal ownership of endpoint, email, and RMM security tooling.
  • Own vulnerability triage and the remediation lifecycle for all corporate IT security findings, with a 100% triage and remediation rate and under 5 minute MTTD.
  • Audit systems and partner cross-departmentally to close visibility gaps and prevent scope creep, while preparing and evaluating SOC 2 controls ahead of upcoming audits.
  • Coordinate threat detection across CrowdStrike Complete, Arctic Wolf MDR, and NinjaOne ticketing, and run Falcon Shield SaaS posture management, catching anomalous OAuth grants and unauthorized third-party app access with automated remediation.
  • Author security policies, IR playbooks, and SOPs, and train helpdesk staff on vulnerability triage and remediation workflows to extend security coverage beyond the security team.
July 2025 – May 2026Los Angeles, CA

System Administrator, AI & Security

Fuel Cycle

  • Monitored and responded to 30+ daily security incidents using Rapid7, CrowdStrike, and ZScaler (risk-based triage, threat detection, and incident response), reducing MTTR by 35%.
  • Primary technical liaison for the SOC 2 Type II audit: coordinated evidence across 100+ controls, worked with external auditors, and validated control effectiveness, achieving certification.
  • Executed the SIEM migration from Rapid7 to NGSIEM with zero SOC downtime, validating alert fidelity and keeping 100% security visibility throughout.
  • Led the AI governance program: shadow AI detection via ZScaler, Okta SCIM controls, and ISO 42001-aligned policies, blocking unsanctioned AI tool usage before data exposure.
  • Designed and implemented a multi-account AWS environment (Prod, Staging, Security, Monitoring) for an internal IT initiative, federating Identity Center with Okta for SSO/SCIM-based access control and managing secrets and encryption with Secrets Manager and KMS, with S3/Glacier for storage and archiving. This established least-privilege access and centralized identity governance across environments.
July 2024 – July 2025Los Angeles, CA

System Administrator

Advanced Networks

  • Conducted vulnerability management across 20+ networks, remediating 60+ critical and high vulnerabilities across SonicWall, Cisco Meraki, Unifi, and ESXi, reducing client attack surface by 80% and maintaining 98% patch compliance.
  • Investigated and remediated Active Directory authentication attacks, including password spraying across 15+ clients, using Entra ID log analysis, IP geolocation correlation, and conditional access, eliminating unauthorized access attempts within 48 hours.
  • Secured email infrastructure for 15+ law firm and enterprise clients using Proofpoint and Zix, tuning detection policies, enforcing SPF/DKIM/DMARC, and coordinating phishing remediation, reducing the successful phishing delivery rate by 25%.
February 2023 – March 2024Santa Monica, CA

IT Technician

Skydance Interactive

  • Configured VPN access, whitelisted IP addresses for network and cloud resources, and identified and addressed security vulnerabilities.
  • Helped deploy ESXi, creating 5+ VMs and managing server resources, and contributed to server rack installations and upgrades.
  • Used Active Directory to create and organize 30 new users, unlock accounts, assign privileges and groups, and enforce group policies.