Experience
Hands-on security operations, compliance and identity work, from MSP client environments to building security in-house.
<5 minMean time to detect, Crexi
35%Lower mean time to respond, Fuel Cycle
100+SOC 2 Type II controls coordinated
80%Client attack surface reduced
May 2026 – PresentLos Angeles, CA
System Administrator
Crexi
- Led migration and security cutover from an outsourced MSP to in-house operations across CrowdStrike Complete, Avanan, Dropsuite, and NinjaOne, establishing full internal ownership of endpoint, email, and RMM security tooling.
- Own vulnerability triage and the remediation lifecycle for all corporate IT security findings, with a 100% triage and remediation rate and under 5 minute MTTD.
- Audit systems and partner cross-departmentally to close visibility gaps and prevent scope creep, while preparing and evaluating SOC 2 controls ahead of upcoming audits.
- Coordinate threat detection across CrowdStrike Complete, Arctic Wolf MDR, and NinjaOne ticketing, and run Falcon Shield SaaS posture management, catching anomalous OAuth grants and unauthorized third-party app access with automated remediation.
- Author security policies, IR playbooks, and SOPs, and train helpdesk staff on vulnerability triage and remediation workflows to extend security coverage beyond the security team.
July 2025 – May 2026Los Angeles, CA
System Administrator, AI & Security
Fuel Cycle
- Monitored and responded to 30+ daily security incidents using Rapid7, CrowdStrike, and ZScaler (risk-based triage, threat detection, and incident response), reducing MTTR by 35%.
- Primary technical liaison for the SOC 2 Type II audit: coordinated evidence across 100+ controls, worked with external auditors, and validated control effectiveness, achieving certification.
- Executed the SIEM migration from Rapid7 to NGSIEM with zero SOC downtime, validating alert fidelity and keeping 100% security visibility throughout.
- Led the AI governance program: shadow AI detection via ZScaler, Okta SCIM controls, and ISO 42001-aligned policies, blocking unsanctioned AI tool usage before data exposure.
- Designed and implemented a multi-account AWS environment (Prod, Staging, Security, Monitoring) for an internal IT initiative, federating Identity Center with Okta for SSO/SCIM-based access control and managing secrets and encryption with Secrets Manager and KMS, with S3/Glacier for storage and archiving. This established least-privilege access and centralized identity governance across environments.
July 2024 – July 2025Los Angeles, CA
System Administrator
Advanced Networks
- Conducted vulnerability management across 20+ networks, remediating 60+ critical and high vulnerabilities across SonicWall, Cisco Meraki, Unifi, and ESXi, reducing client attack surface by 80% and maintaining 98% patch compliance.
- Investigated and remediated Active Directory authentication attacks, including password spraying across 15+ clients, using Entra ID log analysis, IP geolocation correlation, and conditional access, eliminating unauthorized access attempts within 48 hours.
- Secured email infrastructure for 15+ law firm and enterprise clients using Proofpoint and Zix, tuning detection policies, enforcing SPF/DKIM/DMARC, and coordinating phishing remediation, reducing the successful phishing delivery rate by 25%.
February 2023 – March 2024Santa Monica, CA
IT Technician
Skydance Interactive
- Configured VPN access, whitelisted IP addresses for network and cloud resources, and identified and addressed security vulnerabilities.
- Helped deploy ESXi, creating 5+ VMs and managing server resources, and contributed to server rack installations and upgrades.
- Used Active Directory to create and organize 30 new users, unlock accounts, assign privileges and groups, and enforce group policies.