Professional
Enterprise infrastructure
Primary IT contact at Olive & Cocoa, a 200-employee luxury gifting and e-commerce company — a ~225-device hybrid Windows/Mac fleet, with director-level support and a separate development team owning application code.
Windows Hello for Business rollout
Passwordless authentication across the fleet on Cloud Kerberos Trust.
Root-caused a class of enrollment failures traced to protected-account attribute conflicts that blocked a subset of users, then drove the rollout to completion.
- Entra ID
- Cloud Kerberos Trust
- Conditional Access
Global Secure Access deployment
Replaced legacy remote access with Microsoft Private Access.
Included constrained delegation on connector infrastructure and service principal name registration to reach backend databases.
- Global Secure Access
- Kerberos
- Entra ID
Wazuh SIEM
Built the security monitoring pipeline from nothing.
Network appliance syslog ingestion, custom decoders and correlation rules, and chat-based alert routing — plus a recurring vulnerability triage process with documented risk assessment and remediation tracking.
- Wazuh
- syslog / CEF
- FortiGate
Equipment checkout system
A Django application for issuing and returning employee equipment kits.
Entra ID single sign-on with group-resolved authorisation, hardware label printing with an audit trail, and signature capture that stores the exact terms text and a content fingerprint alongside each signature — so what was agreed to can never be silently rewritten by editing a template. A separate operator role lets non-IT staff issue equipment without administrative access to the database.
- Django
- PostgreSQL
- Docker
- Entra ID
- Microsoft Graph
- GitLab CI
Employee self-service desktop tool
A Windows app that lets staff fix common IT problems without a ticket or an admin password.
Privilege separation across a process boundary: the desktop client runs as a standard user and delegates elevated work to a LocalSystem service, so nobody is prompted for credentials they do not have. Requests are attributed to the calling account rather than trusted from the payload. Packaged for org-wide Intune deployment, with the launch path designed around a Defender ASR rule blocking unsigned executables.
- C#
- .NET 8
- WPF
- Windows Services
- Intune
- Defender ASR
Intune detection & remediation scripting
Enforced a weekly reboot cadence across 100+ endpoints.
Versioned state tracking, an uptime threshold rather than a blunt schedule, and permission hardening so users cannot tamper with the state file.
- Intune
- PowerShell
- Microsoft Graph
Storefront failure diagnosis
Resolved a customer-facing product configuration failure nobody could reproduce.
HAR-based analysis isolated an interaction between API rate limiting, an active A/B test, and an internal DNS conflict — three systems that were each individually healthy.
- HAR analysis
- DNS
- REST APIs
Identity, endpoint & network estate
The day job underneath the projects.
Autopilot provisioning, hybrid Entra join troubleshooting across directory sync scoping, high-availability FortiGate perimeter with multi-ISP failover, UniFi switching and wireless, RDS/RemoteApp with broker HA, and Hyper-V migrations including legacy dynamic disk recovery.
- Intune
- Autopilot
- FortiGate
- UniFi
- Hyper-V
- RDS
Drecht
Homelab & applied AI
A self-designed lab built to production patterns: Proxmox VE on 256 GB of RAM, VLAN-segmented storage, media and infrastructure traffic, and external exposure through health-checked Cloudflare tunnels with token authentication.
Hermes Agent
A custom orchestration agent with roughly 70 registered MCP tools.
Local inference is the default provider, with a hosted frontier model as fallback — so routine work costs nothing and only hard problems reach the paid path. Includes a coding-task delegation tool that hands implementation to an autonomous coding agent, and a deploy tool targeting multiple repositories.
- Model Context Protocol
- Python
- Node.js
D-Forge
Local LLM inference node — a quantized 26B mixture-of-experts model on CPU.
Running llama-server with a 32k context window. The lab’s discrete GPU was retired, so throughput came from tuning thread count, context and batching rather than hardware.
- llama.cpp
- quantization
- systemd
Planner Agent
A scheduled daily agent running 13 checks across the entire estate.
Infrastructure, services, security, storage, network, revenue, snapshot integrity and inference health — each result routed to a purpose-specific chat channel so the signal is not buried in one firehose.
- Python
- cron / systemd timers
- webhooks
Mission Control
A Next.js operations dashboard for the lab.
Its own repository with a key-based deployment pipeline, alongside a cost tracking service that reconciles monthly lab operating expense against side-project revenue.
- Next.js
- REST APIs
D-Trader
Retired 2026An ML trading bot, and the evaluation that retired it.
A PyTorch signal model for crypto and stocks, retrained weekly. Before trusting its validation scores with money, I rebuilt the evaluation to match live trading: weekly walk-forward retrains, fees and slippage, random-entry baselines and a sealed holdout. That surfaced a look-ahead leak and a shuffled validation split — on the following week the model did worse than always predicting “hold”, and crypto lost 0.48% a trade after fees. Six replacement strategies with pass marks set in advance failed too, so it stays retired.
crypto accuracy, shuffled validation vs. following week0.580.36
- Python
- PyTorch
- walk-forward testing
- brokerage API
Self-hosted services & operating practice
The unglamorous half that makes the rest trustworthy.
Home Assistant migrated from an appliance-style VM to multi-container Docker on the NAS, splitting core, Z-Wave and Matter into independently upgradable services. Least-privilege read-only tokens on every external integration, a full-credential rotation procedure exercised end to end, and snapshot and backup verification built into the daily check suite.
- Docker
- Proxmox
- Cloudflare Tunnel
- NAS
Background
Where I've worked
Environments with real consequences for downtime — dispatch centres, alarm monitoring, regulated public sector, and revenue-carrying storefronts.
Systems Administrator
Mar 2025 – PresentOlive & CocoaSalt Lake City, UT
Primary IT contact for a 200-employee e-commerce company, administering a ~225-device hybrid Windows/Mac fleet end to end.
Systems Administrator
Dec 2023 – Mar 2025Platform Accounting GroupHolladay, UT
Multi-office accounting firm. Led SonicWall-to-FortiGate migrations across several offices including corporate HQ.
Systems Administrator
Feb 2022 – Oct 2023First Response Inc.Beaverton, OR
24/7 alarm-receiving and camera-monitoring infrastructure for a life-safety central station. Cut system downtime 25%.
Systems Administrator
Mar 2021 – Feb 2022Convergence NetworksPortland, OR
Led a three-person service desk at an MSP, supporting dozens of SMB client environments.
Systems Administrator
Mar 2019 – May 2020Tooele CountyTooele, UT
Desktop and server support across county departments, including CJIS-regulated Sheriff's Office and Emergency Dispatch environments.
Systems Administrator → IT Manager
Feb 2015 – Mar 2019Peak Alarm CompanySalt Lake City, UT
Promoted to IT Manager. Maintained high-availability infrastructure supporting 12,000+ emergency dispatch panels.
Certifications
- CompTIA A+
- CompTIA Network+
- CompTIA Security+
- Microsoft 365 Certified: Endpoint Administrator Associate
- WGU AI Skills Fundamentals
Toolkit
What I work with
Identity & Cloud
- Microsoft 365
- Entra ID
- Conditional Access
- Windows Hello for Business
- Global Secure Access
- Exchange Online
- Hybrid Active Directory
- Directory synchronization
Servers & Virtualization
- Windows Server 2016–2025
- Active Directory
- Group Policy
- DNS / DHCP
- RDS / RemoteApp
- SQL Server
- Hyper-V
- Proxmox VE
- Docker / LXC
Endpoints
- Intune
- Autopilot
- Apple Business Manager
- Windows 10/11
- macOS / iOS
- Imaging & deployment
Networking & Firewalls
- FortiGate (HA clusters)
- SonicWall
- UniFi wired & wireless
- VLAN segmentation
- Site-to-site & SSL VPN
- Cloudflare Tunnel
- ZTNA
Security & Monitoring
- Microsoft Defender
- Wazuh SIEM
- Zabbix
- Grafana
- Vulnerability triage
- Syslog & CEF pipelines
- CJIS-regulated environments
Automation & Development
- PowerShell
- Microsoft Graph API
- Python
- Django
- C# / .NET 8
- Node.js
- GitLab CI
- systemd
- REST APIs
- Model Context Protocol
- Local LLM deployment
ITSM & Telephony
- ConnectWise ASIO (RMM/PSA)
- Jira Service Management
- Snipe-IT
- Microsoft Teams Phone
- 3CX
- Asterisk / SIP
Physical Systems
- Milestone XProtect
- UniFi Access
- Life-safety monitoring