Owned infrastructure, identity, security and endpoint strategy across corporate, retail, cultivation and manufacturing sites in six states: 50+ locations and a $650K annual technology CapEx budget. As the organization's most senior technical resource, originated the technology direction for infrastructure, identity, cloud and data.
Led enterprise AI end to end: business case, vendor comparison, security review and rollout to corporate users, then drove adoption personally through recurring office hours and company-wide webinars.
Owned AI after launch, monitoring usage analytics and managing consumption, licensing and feature governance as adoption grew from a team deployment into an enterprise platform.
Wrote custom AI connectors linking identity, support and data systems, plus an agent that surfaced answers from the SOP library and prompted users to close its gaps.
Led security improvements moving identity from no MFA at all to least privilege, Entra Privileged Identity Management and phishing-resistant MFA for every IT admin, ahead of Microsoft's own mandate.
Served as senior information security champion: deployed Microsoft Defender, migrated SIEM from FortiSIEM to Microsoft Sentinel and rolled out Conditional Access organization-wide.
Owned physical security across surveillance, access control and intrusion across a multi-state footprint.
Built Log Analytics workspaces extending logging depth for Entra ID, Sentinel and Defender.
Migrated endpoint management from an outsourced Kaseya VSA platform to Microsoft Intune, standing the new platform up in parallel and cutting over patch management once it proved out.
Deployed Windows Autopilot with coordinated OEM integrations to automate laptop provisioning and automated desktop and server patching fleet-wide through Microsoft Intune and Autopatch.
Wrote PowerShell remediation and deployment scripts packaged through Intune for application delivery, troubleshooting, log collection and registry configuration.
Automated high-volume new-hire onboarding end to end: Entra accounts created automatically from HR data, zero-touch computer provisioning through Intune and Autopilot.
Brought the full physical server estate under Azure Arc with established security baselines and standardized new workloads in Azure with point-to-point connectivity across the footprint.
Directed the migration of 15 firewalls in nine months with a team that had no prior firewall migration experience; managed Cisco Meraki networks across all sites.
Contracted Avanade for managed M365 backup and disaster recovery, adding a second layer of resilience alongside the endpoint estate.
Standardized and operated networks across 55 locations in six states with segmented POS/debit, data, guest and security traffic.
Provided network, wireless, Internet, voice, design input and incident response behind building-management and cultivation systems at five facilities, including GrowLink, BACnet controls, sensors, fertigation and plant monitoring.
Replaced vendor-deployed SFF desktops running critical facility apps with six Dell Hyper-V servers in 2025, consolidating two to three workloads per host with backup, DR and Azure Arc management.
Led new-store technology builds from LOI/license through completion: long-lead circuits, vendors, procurement, MDF/network, POS, back-office, kiosks and physical security. Pushed a repeatable NSO process and Microsoft Planner/Project tracking.
Personally performed most acquisition infrastructure due diligence, classifying findings as Day 1, this year or next year. Led integration including six acquisitions across two states in 60 days.
Built and mentored a 5-person infrastructure and field-operations team: two engineers grew from no infrastructure background into building Azure and network architecture within two years.
Owned annual IT opex/capex budget planning, capital builds and hardware spend; managed vendor relationships across CDW, Axis, Wachter, CTS and Thrive.
Stayed hands on in L2 support and operations. Adapted Zendesk around infrastructure, project, field-service and procurement work, and routed PRTG/Meraki monitoring through Zenduty for on-call alerts.