AD & M365 Onboarding Automation
WPF-based PowerShell GUI automating AD and Microsoft 365 user onboarding — account creation, license assignment, and manager mapping.
Senior Network & Systems Administrator | Cloud, Security & Automation
Senior Network & Systems Administrator with 20+ years of experience managing, securing, and maintaining enterprise infrastructure. Skilled in hybrid AD/Entra ID, Intune/Autopilot, Meraki/UniFi/pfSense, virtualization, and cloud security. Known for automation, troubleshooting, and securing critical systems.
Enterprise achievements and homelab builds.
WPF-based PowerShell GUI automating AD and Microsoft 365 user onboarding — account creation, license assignment, and manager mapping.
Enterprise migration from SCCM to Intune with Autopilot provisioning, Entra ID modernization, and zero-touch deployment.
End-to-end RMM and helpdesk implementation — PSA, patch management, endpoint management, Auvik network monitoring, ScreenConnect, and BrightGauge dashboards.
End-to-end ownership of a hybrid enterprise environment — pfSense, UniFi, Hyper-V, Ubuntu servers, Microsoft 365, Exchange Online, Entra ID, Intune, VLANs, VPN, and DNS/DHCP across the full stack.
Self-hosted Network Operations Center dashboard with real-time visibility into Proxmox VMs, Docker containers, UPS status, backup coverage, security posture, and certificate expiry. Multi-user auth, TOTP 2FA, FastAPI + React.
Wazuh SIEM custom detection rules and CrowdSec bouncer configs across a multi-host homelab, with OpenCanary honeypot integration.
Self-hosted homelab observability — Prometheus + Grafana + node_exporter + cAdvisor across multiple Docker hosts, with alerting via n8n polling the Prometheus API into Telegram (no Alertmanager required).
Zone-based rules, IoT isolation, DNS control, and hardened routing.
Self-hosted RAG pipeline for an AI homelab agent — semantic search over an Obsidian vault with automated secrets/IP redaction before embedding, Qdrant + Ollama (nomic-embed-text) + gitleaks.
Hardened, read-only MCP gateway exposing Portainer, GitHub, Filesystem, Proxmox, PBS, and Vault RAG visibility to an AI agent — loopback-only, SSH-tunneled, zero client-side credentials.
Automated VM/container recovery, backup-failure alerting, and SIEM event routing to Telegram.
Personal knowledge base built on Obsidian, structured as long-term memory for a self-hosted AI agent — RAG-indexed, auto-logged, secrets-redacted before embedding.
Windows Server, Azure, Entra ID, Intune, Autopilot, Active Directory / Group Policy, Windows 365 Cloud PCs, Apple Business Manager, Exchange Online, SharePoint, Teams, VMware, Hyper-V, Proxmox, pfSense, UniFi, Linux
Routing, Switching, VPN, VLANs, DNS/DHCP, Meraki, MFA, Conditional Access, Intune Compliance & Configuration Policies, LAPS, BitLocker, IDS/IPS, Firewall/WAF Management, Network Segmentation, Wireless, Zero Trust (Cloudflare Access/Tunnel), DNS Filtering, Wazuh, CrowdSec, LimaCharlie, Cloudflare
Sophos, Proofpoint, ConnectWise RMM, ConnectWise Manage, Auvik, ScreenConnect, Cisco Umbrella, CrowdStrike, Mimecast, Veeam, ManageEngine, PowerShell, Power Automate, Microsoft Graph API, Git, Docker, KnowBe4, Portainer, GitHub
AI Agents, MCP, RAG, n8n, Telegram Alerting, Grafana, Prometheus, Automated Alerting, Self-Healing Workflows