Robert D. Lish

Systems AdministratorSalt Lake City metro, Utah

I am the primary IT contact for a ~200-employee e-commerce company — identity, endpoints, network and security are mine end to end, along with the internal tools that run on top of them. Outside of that I run Drecht, a Proxmox lab where I build AI agent infrastructure against local inference: about seventy MCP tools, a self-hosted model server, and a daily agent that checks the whole estate before I wake up.

Ten years across managed services, 24/7 life-safety monitoring, CJIS-regulated public sector, and e-commerce.

years in IT
10+
devices administered
~225
MCP tools in production
~70
automated daily checks
13

Professional

Enterprise infrastructure

Primary IT contact at Olive & Cocoa, a 200-employee luxury gifting and e-commerce company — a ~225-device hybrid Windows/Mac fleet, with director-level support and a separate development team owning application code.

  • Windows Hello for Business rollout

    Passwordless authentication across the fleet on Cloud Kerberos Trust.

    Root-caused a class of enrollment failures traced to protected-account attribute conflicts that blocked a subset of users, then drove the rollout to completion.

    • Entra ID
    • Cloud Kerberos Trust
    • Conditional Access
  • Global Secure Access deployment

    Replaced legacy remote access with Microsoft Private Access.

    Included constrained delegation on connector infrastructure and service principal name registration to reach backend databases.

    • Global Secure Access
    • Kerberos
    • Entra ID
  • Wazuh SIEM

    Built the security monitoring pipeline from nothing.

    Network appliance syslog ingestion, custom decoders and correlation rules, and chat-based alert routing — plus a recurring vulnerability triage process with documented risk assessment and remediation tracking.

    • Wazuh
    • syslog / CEF
    • FortiGate
  • Equipment checkout system

    A Django application for issuing and returning employee equipment kits.

    Entra ID single sign-on with group-resolved authorisation, hardware label printing with an audit trail, and signature capture that stores the exact terms text and a content fingerprint alongside each signature — so what was agreed to can never be silently rewritten by editing a template. A separate operator role lets non-IT staff issue equipment without administrative access to the database.

    • Django
    • PostgreSQL
    • Docker
    • Entra ID
    • Microsoft Graph
    • GitLab CI
  • Employee self-service desktop tool

    A Windows app that lets staff fix common IT problems without a ticket or an admin password.

    Privilege separation across a process boundary: the desktop client runs as a standard user and delegates elevated work to a LocalSystem service, so nobody is prompted for credentials they do not have. Requests are attributed to the calling account rather than trusted from the payload. Packaged for org-wide Intune deployment, with the launch path designed around a Defender ASR rule blocking unsigned executables.

    • C#
    • .NET 8
    • WPF
    • Windows Services
    • Intune
    • Defender ASR
  • Intune detection & remediation scripting

    Enforced a weekly reboot cadence across 100+ endpoints.

    Versioned state tracking, an uptime threshold rather than a blunt schedule, and permission hardening so users cannot tamper with the state file.

    • Intune
    • PowerShell
    • Microsoft Graph
  • Storefront failure diagnosis

    Resolved a customer-facing product configuration failure nobody could reproduce.

    HAR-based analysis isolated an interaction between API rate limiting, an active A/B test, and an internal DNS conflict — three systems that were each individually healthy.

    • HAR analysis
    • DNS
    • REST APIs
  • Identity, endpoint & network estate

    The day job underneath the projects.

    Autopilot provisioning, hybrid Entra join troubleshooting across directory sync scoping, high-availability FortiGate perimeter with multi-ISP failover, UniFi switching and wireless, RDS/RemoteApp with broker HA, and Hyper-V migrations including legacy dynamic disk recovery.

    • Intune
    • Autopilot
    • FortiGate
    • UniFi
    • Hyper-V
    • RDS

Drecht

Homelab & applied AI

A self-designed lab built to production patterns: Proxmox VE on 256 GB of RAM, VLAN-segmented storage, media and infrastructure traffic, and external exposure through health-checked Cloudflare tunnels with token authentication.

  • Hermes Agent

    A custom orchestration agent with roughly 70 registered MCP tools.

    Local inference is the default provider, with a hosted frontier model as fallback — so routine work costs nothing and only hard problems reach the paid path. Includes a coding-task delegation tool that hands implementation to an autonomous coding agent, and a deploy tool targeting multiple repositories.

    • Model Context Protocol
    • Python
    • Node.js
  • D-Forge

    Local LLM inference node — a quantized 26B mixture-of-experts model on CPU.

    Running llama-server with a 32k context window. The lab’s discrete GPU was retired, so throughput came from tuning thread count, context and batching rather than hardware.

    • llama.cpp
    • quantization
    • systemd
  • Planner Agent

    A scheduled daily agent running 13 checks across the entire estate.

    Infrastructure, services, security, storage, network, revenue, snapshot integrity and inference health — each result routed to a purpose-specific chat channel so the signal is not buried in one firehose.

    • Python
    • cron / systemd timers
    • webhooks
  • Mission Control

    A Next.js operations dashboard for the lab.

    Its own repository with a key-based deployment pipeline, alongside a cost tracking service that reconciles monthly lab operating expense against side-project revenue.

    • Next.js
    • REST APIs
  • D-Trader

    Retired 2026

    An ML trading bot, and the evaluation that retired it.

    A PyTorch signal model for crypto and stocks, retrained weekly. Before trusting its validation scores with money, I rebuilt the evaluation to match live trading: weekly walk-forward retrains, fees and slippage, random-entry baselines and a sealed holdout. That surfaced a look-ahead leak and a shuffled validation split — on the following week the model did worse than always predicting “hold”, and crypto lost 0.48% a trade after fees. Six replacement strategies with pass marks set in advance failed too, so it stays retired.

    crypto accuracy, shuffled validation vs. following week0.580.36

    • Python
    • PyTorch
    • walk-forward testing
    • brokerage API
  • Self-hosted services & operating practice

    The unglamorous half that makes the rest trustworthy.

    Home Assistant migrated from an appliance-style VM to multi-container Docker on the NAS, splitting core, Z-Wave and Matter into independently upgradable services. Least-privilege read-only tokens on every external integration, a full-credential rotation procedure exercised end to end, and snapshot and backup verification built into the daily check suite.

    • Docker
    • Proxmox
    • Cloudflare Tunnel
    • NAS

Background

Where I've worked

Environments with real consequences for downtime — dispatch centres, alarm monitoring, regulated public sector, and revenue-carrying storefronts.

  1. Systems Administrator

    Mar 2025 – Present

    Olive & CocoaSalt Lake City, UT

    Primary IT contact for a 200-employee e-commerce company, administering a ~225-device hybrid Windows/Mac fleet end to end.

  2. Systems Administrator

    Dec 2023 – Mar 2025

    Platform Accounting GroupHolladay, UT

    Multi-office accounting firm. Led SonicWall-to-FortiGate migrations across several offices including corporate HQ.

  3. Systems Administrator

    Feb 2022 – Oct 2023

    First Response Inc.Beaverton, OR

    24/7 alarm-receiving and camera-monitoring infrastructure for a life-safety central station. Cut system downtime 25%.

  4. Systems Administrator

    Mar 2021 – Feb 2022

    Convergence NetworksPortland, OR

    Led a three-person service desk at an MSP, supporting dozens of SMB client environments.

  5. Systems Administrator

    Mar 2019 – May 2020

    Tooele CountyTooele, UT

    Desktop and server support across county departments, including CJIS-regulated Sheriff's Office and Emergency Dispatch environments.

  6. Systems Administrator → IT Manager

    Feb 2015 – Mar 2019

    Peak Alarm CompanySalt Lake City, UT

    Promoted to IT Manager. Maintained high-availability infrastructure supporting 12,000+ emergency dispatch panels.

Certifications

  • CompTIA A+
  • CompTIA Network+
  • CompTIA Security+
  • Microsoft 365 Certified: Endpoint Administrator Associate
  • WGU AI Skills Fundamentals

Toolkit

What I work with

Identity & Cloud

  • Microsoft 365
  • Entra ID
  • Conditional Access
  • Windows Hello for Business
  • Global Secure Access
  • Exchange Online
  • Hybrid Active Directory
  • Directory synchronization

Servers & Virtualization

  • Windows Server 2016–2025
  • Active Directory
  • Group Policy
  • DNS / DHCP
  • RDS / RemoteApp
  • SQL Server
  • Hyper-V
  • Proxmox VE
  • Docker / LXC

Endpoints

  • Intune
  • Autopilot
  • Apple Business Manager
  • Windows 10/11
  • macOS / iOS
  • Imaging & deployment

Networking & Firewalls

  • FortiGate (HA clusters)
  • SonicWall
  • UniFi wired & wireless
  • VLAN segmentation
  • Site-to-site & SSL VPN
  • Cloudflare Tunnel
  • ZTNA

Security & Monitoring

  • Microsoft Defender
  • Wazuh SIEM
  • Zabbix
  • Grafana
  • Vulnerability triage
  • Syslog & CEF pipelines
  • CJIS-regulated environments

Automation & Development

  • PowerShell
  • Microsoft Graph API
  • Python
  • Django
  • C# / .NET 8
  • Node.js
  • GitLab CI
  • systemd
  • REST APIs
  • Model Context Protocol
  • Local LLM deployment

ITSM & Telephony

  • ConnectWise ASIO (RMM/PSA)
  • Jira Service Management
  • Snipe-IT
  • Microsoft Teams Phone
  • 3CX
  • Asterisk / SIP

Physical Systems

  • Milestone XProtect
  • UniFi Access
  • Life-safety monitoring