Accomplishments

Career highlights and milestones.
Showing 17 of 17
  • Feb 2026
    Microsoft Teams Phone Rollout Across Global Operations
    Deployed Microsoft Teams Phone across U.S., offshore, and nearshore operations, replacing legacy telephony with auto attendants, call queues, and centralized inbound communication visibility.
    Microsoft 365 Internal Tools

    Led the full rollout of Microsoft Teams Phone for Sales, Recruiting and Staffing, and front-desk teams across U.S., offshore, and nearshore offices, modernizing inbound communication infrastructure:

    • Replaced legacy telephony with Microsoft Teams Phone across 3 countries
    • Configured auto attendants and call queues for routing and responsiveness
    • Enabled centralized visibility into inbound communication volume and patterns
    • Coordinated rollout across distributed teams with minimal operational disruption

    Result: improved call routing efficiency, responsiveness, and leadership visibility into inbound communication while eliminating legacy telephony overhead and reducing per-seat communication costs.

  • Jan 2026
    Cloud-Based Printing with Microsoft Universal Print
    Designed and deployed Microsoft Universal Print as the company's first cloud-managed printing solution, eliminating manual driver installs and integrating printer access directly into the Intune device lifecycle.
    Microsoft Intune Azure

    Designed and deployed an end-to-end cloud printing architecture to eliminate manual print driver installs that had persisted as a hands-on dependency even after Intune streamlined the rest of device provisioning:

    • Implemented Microsoft Universal Print as the company’s first cloud-managed printing platform
    • Built secure hybrid connectivity using an Azure-hosted Windows Server VM running the Universal Print connector, linked to Ohio HQ via site-to-site IPsec VPN
    • Registered and published the HQ printer through Universal Print with proper access controls
    • Deployed the printer automatically to all Intune-managed laptops via Intune Printer Provisioning policies, eliminating manual driver installs entirely
    • Authored full operational documentation for both IT administrators and end users

    Result: printing is now fully integrated into the Intune device lifecycle. New and reprovisioned laptops receive the corporate printer automatically, with no onsite configuration or IT involvement required.

  • Jan 2026
    Encrypted Email & Do Not Forward Protection
    Enabled Microsoft Purview Message Encryption and Do Not Forward protections tenant-wide, repairing the underlying Exchange Online IRM to Azure RMS binding to bring encryption workflows fully online.
    Microsoft 365 Security Governance

    Enabled Microsoft Purview Message Encryption and Information Rights Management tenant-wide, giving Finance, HR, and the broader organization a controlled way to send sensitive communications:

    • Diagnosed tenant-level failures preventing encryption workflows from running
    • Repaired the Exchange Online IRM to Azure RMS binding so the licensor certificate, templates, and service endpoints loaded correctly
    • Ran and validated IRM self-tests and end-to-end encryption workflows
    • Coordinated with Microsoft Support to finalize activation after tenant remediation

    Result: encrypted email and Do Not Forward protections are live for all users, giving Finance and HR a controlled, auditable way to protect sensitive communications from unauthorized sharing.

  • Sep 2025
    Centralized Email Signature Automation with CodeTwo
    Deployed CodeTwo as the company-wide signature automation platform, standardizing branding across Outlook desktop, web, and mobile, driven off Entra attributes at roughly $1 per user per month.
    Microsoft 365 Automation

    Deployed CodeTwo as the company-wide email signature automation platform, standardizing branding and centralizing signature management across every Outlook surface:

    • Enabled consistent signatures across Outlook desktop, web, mobile, and external clients
    • Configured Combo Mode for client-side previews plus server-side fallback (no duplicates, guaranteed delivery)
    • Integrated with Entra ID so name, title, department, and contact data populate automatically
    • Documented end-user and admin workflows to support long-term maintenance

    Result: consistent, professional, centrally managed branding, with the ability to push org-wide signature, legal, or marketing updates instantly, at a fraction of the cost of traditional branding tools.

  • Aug 2025
    Enterprise Endpoint Management with Microsoft Intune
    Stood up Intune as the company's centralized endpoint platform, bringing every Windows device under a scalable, policy-driven lifecycle with automated provisioning and enforced security baselines.
    Microsoft Intune Security

    Designed and deployed Microsoft Intune as the company’s centralized endpoint management platform, bringing every Windows device under a scalable, policy-driven lifecycle:

    • Built tenant configuration, enrollment, and automated provisioning to eliminate manual rebuilds
    • Enforced security baselines: BitLocker, firewall, AV, LAPS, update compliance, location services
    • Automated M365 app delivery, OneDrive auto sign-in with storage redirection, and Company Portal for approved software
    • Authored enrollment and reprovisioning runbooks and trained IT staff on ongoing administration

    Result: a scalable, repeatable device lifecycle with consistent security enforcement, corporate credential sign-in, and no reliance on third-party reinstalls.

  • Jul 2025
    Legacy Security Tool Remediation & Account Lockout Resolution
    Investigated and resolved a pattern of unexpected account disablements, tracing the behavior to an undecommissioned legacy ITDR tool and fully retiring it from the tenant.
    Security IAM

    Investigated a pattern of unexpected account disablements that didn’t match the modernized Conditional Access policies, and led the remediation end-to-end:

    • Traced disablement events through Entra sign-in logs and tenant audit history
    • Identified a legacy MSP-installed security tool as the source of the account manipulations
    • Worked with the MSP to confirm the tool had been superseded during their transition to a newer ITDR platform
    • Removed the integration and coordinated the full retirement of the legacy tooling

    Result: a clean identity governance surface under Conditional Access, with only approved platforms managing account enforcement.

  • Jul 2025
    Secure Remote Access for Distributed Engineering Teams
    Deployed Tailscale and IPsec tunnels between Azure and HQ to protect internal systems and enable compliant, zero-trust access for engineers across three countries.
    Networking Azure Security

    Replaced ad hoc remote access with a structured, secure architecture:

    • Deployed Tailscale for zero-trust network access across distributed engineering and IT teams
    • Established IPsec tunnels between Azure infrastructure and HQ to protect development systems
    • Enabled compliant access for remote and offshore teams without exposing internal systems to the public internet

    Result: internal systems are protected behind authenticated, encrypted access paths, with no more open firewall rules or VPN exceptions.

  • Jun 2025
    Dynamic Department Distribution Lists & Communication Automation
    Automated department and all-company distribution lists using Entra dynamic groups, giving HR and leadership always-accurate, zero-maintenance messaging at any scale.
    Microsoft Entra Automation

    Automated department and all-company messaging on top of standardized Entra attributes, giving HR and leadership always-accurate distribution without any manual list upkeep:

    • Built dynamic security groups driven by department and employment status
    • Established department distribution lists that update automatically on hire, transfer, and departure
    • Implemented an accurate all-company distribution group for org-wide communications
    • Enabled HR and leadership to send and schedule announcements with no manual recipient work

    Result: always-up-to-date distribution lists, zero manual list maintenance, and scalable communication as the organization grows.

  • Jun 2025
    Self-Service IT & Internal Knowledge Enablement
    Launched a centralized internal knowledge platform and shifted key IT workflows toward structured self-service, reducing support fatigue and building a scalable foundation for IT operations.
    Internal Tools Azure

    Established an organization-wide self-service and documentation enablement program to reduce person-dependent IT support and scale operations without adding headcount:

    • Launched a centralized internal knowledge hub for IT processes, onboarding guides, and operational procedures
    • Documented critical repeatable workflows — device provisioning, Universal Print, Intune enrollment, automated signatures — to shift resolution away from ad-hoc support
    • Trained additional administrators to ensure operational continuity and reduce single-point-of-failure risk
    • Built on portable markdown so content stays migration-friendly and isn’t locked in proprietary tooling

    Result: a scalable IT support model with faster onboarding execution, reduced ticket volume for routine requests, and a documented foundation that grows with the organization.

    View full project →

  • Jun 2025
    Microsoft 365 Sprawl Cleanup & Collaboration Governance
    Consolidated hundreds of Teams and SharePoint sites and introduced Group-creation guardrails, restoring a coherent collaboration structure and preventing future tenant sprawl.
    Microsoft 365 Governance

    Led a Microsoft 365 cleanup and governance initiative to consolidate collaboration workspaces and establish lifecycle standards across Teams and SharePoint:

    • Audited and consolidated active departmental workspaces, retiring unused and duplicate sites
    • Restricted Microsoft 365 Group creation via PowerShell to an approved admin security group
    • Established baseline governance standards for group and site lifecycle
    • Laid the groundwork for sustainable collaboration management going forward

    Result: a clearer collaboration structure, tighter permission hygiene, and safeguards in place to prevent future sprawl.

  • May 2025
    Entra ID Attribute Standardization & Identity Data Backfill
    Standardized Entra ID attributes (department, manager, hire date, employee type, etc.) across every account, unlocking dynamic groups, org charts, automated signatures, and identity-driven automation.
    Microsoft Entra IAM Governance

    Drove a company-wide initiative to standardize Entra ID user attributes (department, manager, hire date, employee type, etc.) across the tenant, building the identity foundation needed for downstream automation:

    • Defined the attribute set required for automation, reporting, and governance
    • Partnered with leadership on a structured data collection process using standardized templates
    • Standardized attributes across nearly all active accounts, including external partner users operating in the tenant
    • Established expectations for maintaining accurate identity data going forward

    Result: a complete, automation-ready directory that directly enabled dynamic distribution lists, automated security groups, org charts (including exports for banking requirements), CodeTwo signature automation and more.

  • May 2025
    Functional Shared Mailboxes & Departmental Email Governance
    Established a standardized functional mailbox model for HR, Finance, and other departments, moving departmental email into properly governed Microsoft 365 shared mailboxes with delegated access.
    Microsoft 365 Governance

    Established a standardized functional mailbox model for departmental email, moving shared workflows into properly governed Microsoft 365 shared mailboxes with delegated access:

    • Migrated departmental access into properly managed shared mailboxes with delegated permissions instead of shared credentials
    • Built out structured Finance inboxes for AP, AR, taxes, and expenses
    • Stood up dedicated mailboxes for HR, Recruiting, Marketing, PMO, and general info routing
    • Reduced license consumption on non-user accounts while improving auditability

    Result: a secure, cost-effective, role-based approach to departmental email, with clear ownership, proper access governance, and clean offboarding.

  • Apr 2025
    Enterprise Password Management with Bitwarden
    Deployed Bitwarden as the enterprise password management platform, establishing SSO-integrated vaults for secure credential storage, cleaner offboarding, and stronger governance on non-SSO systems.
    Security IAM

    Deployed Bitwarden as the enterprise password management platform, building on prior successful experience introducing it at a previous employer, to give teams secure, governed credential storage beyond what SSO can cover:

    • Rolled out to Advanced Analytics as the primary delivery team, with staged expansion across other departments
    • Secured with Entra ID SSO so vault access follows the employee lifecycle
    • Established administrative recovery controls to preserve continuity on non-SSO external systems
    • Enabled stronger password hygiene and integrated MFA that reduces reliance on personal devices

    Result: secure vault-based credential storage, cleaner offboarding for non-SSO apps, and a scalable foundation for broader rollout across Finance, HR, and the rest of the org.

  • Apr 2025
    Org-Wide MFA Enforcement & Self-Service Password Reset
    Enforced MFA across all users and enabled Self-Service Password Reset, establishing baseline identity security against phishing and credential attacks while reducing IT support burden for routine access issues.
    Security IAM Microsoft Entra

    Implemented organization-wide MFA enforcement and self-service recovery tools to address the absence of identity security guardrails and reduce reliance on limited IT staff for routine access issues:

    • Enforced Multi-Factor Authentication across all user accounts to eliminate password-only access and reduce account takeover risk
    • Established Conditional Access policies and baseline authentication controls aligned with modern security standards
    • Converted shared licensed functional mailboxes (e.g., HR@, Finance@) to properly secured accounts, eliminating high-value soft targets
    • Enabled Self-Service Password Reset so employees can securely recover credentials without IT intervention

    Result: significantly stronger protection against phishing and credential-based attacks, with centralized identity security enforcement and reduced IT dependency for routine access recovery.

  • Mar 2025
    Shadow Application SSO, SCIM & JIT Identity Consolidation
    Identified Strategic Systems shadow applications across departments and divisions and integrated them into Entra ID via SSO, SCIM, and JIT provisioning to centralize IAM and automate access lifecycle across tool stack.
    IAM Microsoft Entra Security Governance

    Drove a cross-departmental initiative to bring Strategic Systems shadow applications under centralized identity governance, replacing disconnected, manually-managed access with Entra-driven SSO, SCIM, and Just-in-Time (JIT) provisioning:

    • Inventoried and assessed shadow applications in active use across multiple departments and divisions
    • Integrated applications into Entra ID with SSO to tie access directly to the employee identity lifecycle
    • Implemented SCIM provisioning where supported to automate account creation, attribute sync, and deprovisioning
    • Enabled JIT provisioning for applications without SCIM support, ensuring access is granted on-demand and revoked automatically
    • Standardized onboarding, offboarding, and role-change flows so access grants and revocations happen consistently across the full tool stack

    Result: a centralized, Entra-governed access model across Strategic Systems tooling that eliminates orphaned accounts, reduces manual offboarding risk, and ensures employees have the right access at every stage of their lifecycle.

  • Apr 2021
    HIPAA-Compliant ETL Pipelines Powering 90% of Audit Reporting
    Built and automated Informatica ETL pipelines that became the backbone of reporting and compliance operations at a PBM, while implementing PHI/PII encryption to meet HIPAA, CMS, and financial standards.
    Data Engineering Governance

    At Navitus Health Solutions, inherited a largely manual reporting environment and rebuilt it on a reliable, automated foundation:

    • Designed and automated Informatica ETL pipelines that powered 90% of reporting and audit readiness
    • Implemented PHI/PII encryption in collaboration with the security team to meet HIPAA, CMS, and financial compliance requirements
    • Developed API-driven pipelines to load CMS exports directly into the enterprise warehouse
    • Improved SQL and ETL workflow performance, reducing processing times and improving reliability

    Result: audit teams went from manual data pulls to automated, compliance-ready reporting pipelines.