Every engagement is led by someone who has built, broken, and recovered the systems we work on. No layered overhead, no offshore handoffs -- just the people doing the work.
20+ years across enterprise networks, OT/ICS, multi-cloud, and security engineering. Lead architect on FortiGate fleets, Catalyst 9K upgrades, NetBox SoT pipelines, and NERC CIP automation.
Multi-account AWS, Terragrunt stacks across regions, Transit Gateway design, and serverless platforms. Past lead on financial-services landing zones and Secrets Manager migrations.
Utility-scale OT segmentation, VXLAN-over-IPsec for Ovation DCS, substation FortiSwitch fleets, and NERC CIP-005 evidence pipelines. Years of hands-on substation comm work.
SIEM detection engineering (Splunk, Wazuh), Tenable + Cisco Secure Endpoint operations, Duo MFA rollouts, and TLS hardening programs. Built the 289-IP TLS audit framework we still use today.
Ansible install-mode workflows for Cisco IOS-XE, GitLab CI pipelines, Python network automation (paramiko, SWIS, NetBox). Wrote the Cat9K 9-gotcha install-mode playbook our network team relies on.
NERC CIP, NIST, and CIS programs delivered as evidence pipelines, not spreadsheets. Specializes in turning audit findings into reusable controls coded against the actual systems.
Senior delivery, written work product, and direct access to the engineer doing the work.