Summary

Technical foundations and security leader with 20 years of experience building the platform, infrastructure, and security systems that engineering organizations depend on, with a throughline of identity, access, secrets, and compliance across healthcare and other regulated environments. Repeatedly brought into early-stage, scaling, and under-structured organizations to turn fragmented or prototype systems into coherent, durable, and secure foundations. That experience underpins a broader focus on data protection, privacy, and governance, connecting technical controls to organizational trust.

Professional Experience

Trener / T-Robotics
Head of Technical Foundations
San Jose, CA (Hybrid) • August 2025 – Present
  • Serve as principal technical authority across engineering, mentoring and unblocking the full product team beyond direct reports
  • Built and now lead the Technical Foundations function, owning seven charters: Cloud Foundations, Developer Platform, Security, SRE, Observability, Delivery Engineering, and Corporate IT
  • Built, in Go, the build and provisioning toolchain for the company's customer-deployed Jetson Orin edge appliance:
    tforge: the administrative interface that produces its custom ARM64 root filesystem and overlay via Docker containerization and embedded modules.
    tspark: the integrator-facing tool that provisions units and applies post-deploy configuration
  • Designed and built the device enrollment and fleet-management path, registering appliances with the production control plane and bringing them under centralized management with assigned identity, location, service stack, remote-support integration (BetterDesk), and Tailscale auto-join
  • Defined the appliance lifecycle architecture: immutable rootfs build pipelines, A/B update flows, and SSD/eMMC deployment paths
  • Created the internal platform monorepo and operating model as the source of truth for infrastructure-as-code, GitOps, operational standards, security practices, and developer tooling
  • Designed and implemented GCP core infrastructure using OpenTofu/Terraform, Atmos, Helm, ArgoCD, and private GKE across staging and production
  • Architected a private Tailscale/WireGuard overlay WAN connecting GCP workloads, offices, developer systems, and field-deployed robot infrastructure without exposing public control-plane access
  • Built observability and reliability foundations with Prometheus, Grafana, Loki, Alertmanager/Karma, service monitors, dashboards, alert rules, ArgoCD drift detection, restore drills, and runbooks
  • Established secrets and security architecture with Infisical, External Secrets, IAM guardrails, network policies, private clusters, CI/CD secret sync, and repo security standards
Latent Health
Principal SRE / Security Engineer
San Francisco, CA (Hybrid) • June 2024 – March 2025
  • Took a health-tech platform from prototype to production, rebuilding infrastructure, security, and delivery foundations inherited at proof-of-concept stage
  • Re-architected the platform from a single EKS cluster partitioned by namespace into multiple purpose-separated clusters with ArgoCD GitOps delivery and DNS-backed environment isolation across dev, test, staging, and prod
  • Led SOC 2 Type II certification end to end via Vanta, spanning infrastructure controls, secrets handling, audit logging, incident response, and deployment practices
  • Hardened AWS infrastructure with Terraform, isolating prod and dev at the account and environment level, with tightened IAM, audit logging, and deployment guardrails
  • Deployed the observability and incident stack (Prometheus Operator, Grafana, Alertmanager, Karma) with PagerDuty-integrated response workflows
  • Built secure Python tooling for secrets encryption/decryption and Infisical-backed workflows across CI/CD and runtime
F5 Networks
Principal SRE
San Jose, CA (Hybrid) • June 2022 – November 2023
  • Spearheaded Kubernetes-based PaaS implementation for large-scale national service provider
  • Integrated CRDs and enhanced functionality for secure FedRAMP-targeted platforms
  • Led platform security scanning (OSCAP) to align with NIS 1 & 2 standards
  • Authored internal documentation for cross-team onboarding and vendor access
  • Provided on-call support for 150+ microservices across multiple Kubernetes platforms
  • Acted as U.S. team lead within global SRE organization and mentored new hires
Domino Data Lab
Staff Software Engineer
San Francisco, CA (Hybrid) • April 2021 – May 2022
  • Co-led development of internal X2Go-based remote dev environments on AWS EKS
  • Automated deployments and configuration via Terraform, Ansible, Helm
  • Mentored engineers on infrastructure troubleshooting and automation best practices
  • Drove reliability and performance improvements for internal dev-prod workflows
Apple (via Infosys)
Principal DevOps Engineer
San Jose, CA (Remote) • April 2020 – March 2021
  • Migrated 30+ applications from on-prem to AWS (EKS, Docker, Concourse)
  • Created and maintained Jenkins and Concourse pipelines with YAML-based job configs
  • Standardized CI/CD practices to reduce onboarding time for new teams
  • Built custom Bash and Docker automation for application delivery
  • Collaborated closely with app teams to embed DevOps practices into dev lifecycles
Ditto Technologies
Principal DevOps Engineer
Oakland, CA (Hybrid) • July 2018 – January 2020
  • Owned the AWS infrastructure practice, introducing Terraform for infrastructure management and state tracking
  • Overhauled network design to emphasize private networking for security
  • Designed and maintained AMI imaging process to simplify environment provisioning
  • Built Jenkins pipelines for Dockerized Python applications
  • Advised engineers on automation, monitoring, and deployment best practices
Apixio
DevOps Architect
San Mateo, CA (Hybrid) • September 2016 – July 2018
  • Led the automation architecture, rebuilding the framework on Ansible with custom deployment state tracking
  • Created internal self-service tooling with Python and Bash
  • Deployed and maintained Vault, Consul, and Packer-based infrastructure
  • Supported multiple VPCs and application teams with shared secure platform design
  • Reduced CI/CD build times by 60% through pipeline refactoring and caching

Earlier Experience (2005–2016)

Roles held:

DevOps Lead, Systems Engineer, DevOps Architect, Infrastructure Manager

Companies:

TwinPrime, Twelvefold, Quantifind, Sequent Software, Transpera, CipherTrust, VeriCenter

Key Achievements:
  • Architected and migrated legacy stacks to AWS and hybrid-cloud platforms
  • Built early CI/CD and monitoring stacks using Jenkins, Nagios, and custom tooling
  • Automated bare-metal and virtual infrastructure using PXE, Kickstart, and config management
  • Led network redesigns and monitoring deployments across data centers and cloud providers

Consulting

CT-Unlimited LLC
Founder & Principal Platform Architect
Remote • 2024 – 2026
Client engagement: Anshin Health
  • Sole technical lead and architect for a healthcare client's on-prem and cloud platform, owning cloud infrastructure, networking, identity, CI/CD, and operations
  • Designed and led a staged, in-place migration from Proxmox to a self-hosted OpenStack + Ceph private cloud across the client's HPE ML350 fleet, replacing a static virtualization model with AWS-style, API-driven, Terraform-native private-cloud infrastructure on their own hardware
  • Redesigned the network from a prosumer Cisco RV340 and ad-hoc Netgear switching to a centrally managed multi-tier TP-Link Omada buildout, with 1/2.5/10GbE throughput tiering and segmented storage, systems, management, and edge planes plus out-of-band console access
  • Built and deployed the self-hosted GitLab platform on AlmaLinux as the SCM and CI/CD backbone, then migrated the production Next.js/Prisma application from AWS Amplify onto it via a Proxmox LXC runner, eliminating its dependency on Amplify
  • Architected the identity and secure-access layer, implementing WireGuard with split-horizon DNS and FreeIPA-backed LDAP and domain identity, and designing subsequent Authentik SSO and NetBird managed-overlay architectures
  • Deployed k3s workloads (ERPNext, ingress-nginx) with Ansible-driven certificate automation and Uptime Kuma monitoring with alerting

Education

B.S. in Cybersecurity

Southern New Hampshire University, Expected 2028
4.0 GPA, President's List, Honor Roll (2025–2026)

Core Competencies

Cloud & Platform

AWS, GCP, Kubernetes, EKS, GKE, OpenStack, Ceph

Infrastructure & Delivery

OpenTofu/Terraform, Atmos, Ansible, Helm, ArgoCD, GitHub Actions, GitLab CI

Observability & Reliability

Prometheus, Grafana, Loki, Alertmanager, Karma, PagerDuty

Security, Identity & Access

Infisical, External Secrets, Vault, FreeIPA, IAM, Tailscale/WireGuard, NetBird

Systems & Product Infrastructure

Linux, ARM64, NVIDIA Jetson, containerized build systems, edge provisioning

Languages

Go, Python, Bash

Governance & Compliance

SOC 2 (Type II), HIPAA, HITRUST, FedRAMP-aligned environments