Summary
Technical foundations and security leader with 20 years of experience building the platform, infrastructure, and security systems that engineering organizations depend on, with a throughline of identity, access, secrets, and compliance across healthcare and other regulated environments. Repeatedly brought into early-stage, scaling, and under-structured organizations to turn fragmented or prototype systems into coherent, durable, and secure foundations. That experience underpins a broader focus on data protection, privacy, and governance, connecting technical controls to organizational trust.
Professional Experience
- Serve as principal technical authority across engineering, mentoring and unblocking the full product team beyond direct reports
- Built and now lead the Technical Foundations function, owning seven charters: Cloud Foundations, Developer Platform, Security, SRE, Observability, Delivery Engineering, and Corporate IT
-
Built, in Go, the build and provisioning toolchain for the
company's customer-deployed Jetson Orin edge appliance:
tforge: the administrative interface that produces its custom ARM64 root filesystem and overlay via Docker containerization and embedded modules.
tspark: the integrator-facing tool that provisions units and applies post-deploy configuration - Designed and built the device enrollment and fleet-management path, registering appliances with the production control plane and bringing them under centralized management with assigned identity, location, service stack, remote-support integration (BetterDesk), and Tailscale auto-join
- Defined the appliance lifecycle architecture: immutable rootfs build pipelines, A/B update flows, and SSD/eMMC deployment paths
- Created the internal platform monorepo and operating model as the source of truth for infrastructure-as-code, GitOps, operational standards, security practices, and developer tooling
- Designed and implemented GCP core infrastructure using OpenTofu/Terraform, Atmos, Helm, ArgoCD, and private GKE across staging and production
- Architected a private Tailscale/WireGuard overlay WAN connecting GCP workloads, offices, developer systems, and field-deployed robot infrastructure without exposing public control-plane access
- Built observability and reliability foundations with Prometheus, Grafana, Loki, Alertmanager/Karma, service monitors, dashboards, alert rules, ArgoCD drift detection, restore drills, and runbooks
- Established secrets and security architecture with Infisical, External Secrets, IAM guardrails, network policies, private clusters, CI/CD secret sync, and repo security standards
- Took a health-tech platform from prototype to production, rebuilding infrastructure, security, and delivery foundations inherited at proof-of-concept stage
- Re-architected the platform from a single EKS cluster partitioned by namespace into multiple purpose-separated clusters with ArgoCD GitOps delivery and DNS-backed environment isolation across dev, test, staging, and prod
- Led SOC 2 Type II certification end to end via Vanta, spanning infrastructure controls, secrets handling, audit logging, incident response, and deployment practices
- Hardened AWS infrastructure with Terraform, isolating prod and dev at the account and environment level, with tightened IAM, audit logging, and deployment guardrails
- Deployed the observability and incident stack (Prometheus Operator, Grafana, Alertmanager, Karma) with PagerDuty-integrated response workflows
- Built secure Python tooling for secrets encryption/decryption and Infisical-backed workflows across CI/CD and runtime
- Spearheaded Kubernetes-based PaaS implementation for large-scale national service provider
- Integrated CRDs and enhanced functionality for secure FedRAMP-targeted platforms
- Led platform security scanning (OSCAP) to align with NIS 1 & 2 standards
- Authored internal documentation for cross-team onboarding and vendor access
- Provided on-call support for 150+ microservices across multiple Kubernetes platforms
- Acted as U.S. team lead within global SRE organization and mentored new hires
- Co-led development of internal X2Go-based remote dev environments on AWS EKS
- Automated deployments and configuration via Terraform, Ansible, Helm
- Mentored engineers on infrastructure troubleshooting and automation best practices
- Drove reliability and performance improvements for internal dev-prod workflows
- Migrated 30+ applications from on-prem to AWS (EKS, Docker, Concourse)
- Created and maintained Jenkins and Concourse pipelines with YAML-based job configs
- Standardized CI/CD practices to reduce onboarding time for new teams
- Built custom Bash and Docker automation for application delivery
- Collaborated closely with app teams to embed DevOps practices into dev lifecycles
- Owned the AWS infrastructure practice, introducing Terraform for infrastructure management and state tracking
- Overhauled network design to emphasize private networking for security
- Designed and maintained AMI imaging process to simplify environment provisioning
- Built Jenkins pipelines for Dockerized Python applications
- Advised engineers on automation, monitoring, and deployment best practices
- Led the automation architecture, rebuilding the framework on Ansible with custom deployment state tracking
- Created internal self-service tooling with Python and Bash
- Deployed and maintained Vault, Consul, and Packer-based infrastructure
- Supported multiple VPCs and application teams with shared secure platform design
- Reduced CI/CD build times by 60% through pipeline refactoring and caching
Earlier Experience (2005–2016)
DevOps Lead, Systems Engineer, DevOps Architect, Infrastructure Manager
TwinPrime, Twelvefold, Quantifind, Sequent Software, Transpera, CipherTrust, VeriCenter
- Architected and migrated legacy stacks to AWS and hybrid-cloud platforms
- Built early CI/CD and monitoring stacks using Jenkins, Nagios, and custom tooling
- Automated bare-metal and virtual infrastructure using PXE, Kickstart, and config management
- Led network redesigns and monitoring deployments across data centers and cloud providers
Consulting
- Sole technical lead and architect for a healthcare client's on-prem and cloud platform, owning cloud infrastructure, networking, identity, CI/CD, and operations
- Designed and led a staged, in-place migration from Proxmox to a self-hosted OpenStack + Ceph private cloud across the client's HPE ML350 fleet, replacing a static virtualization model with AWS-style, API-driven, Terraform-native private-cloud infrastructure on their own hardware
- Redesigned the network from a prosumer Cisco RV340 and ad-hoc Netgear switching to a centrally managed multi-tier TP-Link Omada buildout, with 1/2.5/10GbE throughput tiering and segmented storage, systems, management, and edge planes plus out-of-band console access
- Built and deployed the self-hosted GitLab platform on AlmaLinux as the SCM and CI/CD backbone, then migrated the production Next.js/Prisma application from AWS Amplify onto it via a Proxmox LXC runner, eliminating its dependency on Amplify
- Architected the identity and secure-access layer, implementing WireGuard with split-horizon DNS and FreeIPA-backed LDAP and domain identity, and designing subsequent Authentik SSO and NetBird managed-overlay architectures
- Deployed k3s workloads (ERPNext, ingress-nginx) with Ansible-driven certificate automation and Uptime Kuma monitoring with alerting
Education
B.S. in Cybersecurity
4.0 GPA, President's List, Honor Roll (2025–2026)