Production guardrails for AI agents
I define permissions, approval gates, rollback paths, and evaluation standards so AI agents remain controlled in production.
I set direction for cloud architecture, platform engineering, and secure AI systems.
I am a working manager. I lead a six-person DevSecOps team and still build the Azure platform and secure AI workflows our developers use.
I own Azure security across a HIPAA and SOC 2 regulated estate spanning 25 subscriptions and more than 20 applications and services.
I define permissions, approval gates, rollback paths, and evaluation standards so AI agents remain controlled in production.
I own FinOps for a $2M+ annual Azure estate. Rightsizing, automated scaling, reservations, log-volume controls, and model selection cut annual costs by $650K to $900K, or 32% to 46%.
I reduced critical scanner findings by 95% year over year with policy-as-code and automated compliance checks.
I completed three consecutive SOC 2 Type II examinations with no exceptions.
I led a full datacenter exit and migrated 500+ single-tenant workloads. I then redesigned the platform for multi-tenant delivery, supporting growth from 500 to 1500+ clients without a matching increase in infrastructure.
I built multi-agent workflows in Claude Code for pull-request review, coding-standard enforcement, and infrastructure generation. MCP servers connect the agents to internal tools, while PostgreSQL and pgvector provide operational memory. Local and self-hosted models keep PHI inside the environment.
I own the security posture for a HIPAA and SOC 2 regulated Azure estate, from identity and Zero Trust to risk governance and incident response.
I lead secure AI engineering with scoped permissions, human approval gates, model evaluation, and in-boundary models for regulated data.
I own the internal developer platform used by 200+ developers, including self-service environments, delivery pipelines, and operating standards.
I lead and mentor six engineers who work across cloud, automation, and security. Each engineer has clear ownership, and the team shares accountability.
Cloud programs move faster when ownership is clear and teams know what they are responsible for in production.
I define the business and security outcome first, then choose the architecture and controls that reduce that risk.
I judge a design by whether teams can run it in production. Automation and clear standards make that possible; ownership keeps it working.
I give teams clear guardrails and enough context to make sound decisions on their own.
Zero Trust strategy, security posture, and governance across an enterprise environment.
Earned April 8, 2023
Azure solution design for identity, networking, data, and infrastructure.
Earned May 8, 2021
Delivery pipelines, infrastructure as code, and operational practices for repeatable, auditable releases.
Earned May 10, 2021
Azure identity, platform protection, security operations, and data security.
Earned March 4, 2023
Day-to-day administration of Azure identity, governance, storage, compute, and networking.
Earned June 5, 2019
Microsoft Certified Solutions Expert.
Earned July 18, 2018
Microsoft Certified Solutions Associate.
Earned August 27, 2017
Earned August 22, 2017