Securing global fleets, end to end.
I build, secure, and scale enterprise endpoint platforms, currently a global fleet of more than 150,000 devices across macOS, Windows, iOS, and Android. I work at the implementation layer: hardening baselines shipped as version-controlled configuration, device posture wired into Entra ID conditional access as a trust gate, and automation that replaces manual device operations.
Across thirteen years I have built, secured, and scaled enterprise endpoint platforms. Today I lead endpoint platform engineering for a global fleet of over 150,000 devices, with ownership across Microsoft Intune, Jamf Pro, Entra ID conditional access, device compliance, host hardening, vulnerability remediation, automation, and incident response.
I lead a team of eleven engineers across Apple and enterprise mobility services, setting technical direction while staying hands-on in the code and the consoles, close enough to write the policy, harden the host, and lead the room when something breaks at scale. I bring people along rather than dictating to them, and I would rather grow an engineer than escalate past one.
I am known for turning complex endpoint, identity, and Zero Trust requirements into practical platform standards that reduce risk, improve compliance visibility, and keep the user experience clean.
Security, Risk, Infrastructure, and business teams trust me to own difficult endpoint problems from strategy through execution. I size controls to real risk, prove outcomes rather than effort, and measure what I ship.
I treat AI as part of the toolchain, not a novelty. Claude, Copilot, and ChatGPT are a daily part of how my team generates and refactors scripts, reviews code, triages logs, and keeps documentation current, and I set the norms for how AI-generated code gets reviewed before it merges.
Technical lead for enterprise endpoint platforms serving a global fleet of more than 150,000 devices. Lead a team of eleven engineers across Apple and enterprise mobility services, owning engineering direction across device management, identity integration, conditional access, hardening, automation, and escalation while staying hands-on in the code and the consoles.
Built and governed global endpoint and mobility platforms across multiple GE business units.
Led global escalation operations for enterprise mobility and secure communication platforms serving financial and government clients.
A live platform that helps contractors navigate building permits across Fort Lauderdale, Miami, and Tampa. It centers on local depth and rejection prevention, turning jurisdiction specific rules into clear, actionable guidance.
I designed and built the whole thing: data schema, application logic, payments, email automation, and analytics, shipping it end to end as a solo founder.
This site. A single page, hand built, no framework, with a serif display face, dark mode, and a grid texture. Hosted on a static deploy.
PowerShell and Bash automation built against the Microsoft Graph and Jamf Pro APIs for provisioning, hardening, inventory reconciliation, and compliance reporting, version controlled and released through Azure DevOps as configuration as code.
Whether it is a staff level endpoint security role, a hard platform problem, or a conversation about what I am building, I would be glad to hear from you.