I build and harden enterprise infrastructure โ OS configurations, network infrastructure, domain trust, compliance, and the automation that ties them together.
Active Directory, RBAC, MFA, SSO, least privilege enforcement, account lifecycle management across domain and local environments
STIG/CIS benchmark remediation, NIST RMF, FIPS 140-2/140-3, SCAP/ACAS scanning, BitLocker, SIEM integration
PowerShell, Bash, Python โ infrastructure-as-code, configuration management, CI/CD pipeline tooling, schema validation
Redhat Enterprise Linux, Kickstart provisioning, SELinux, FIPS, FAPolicy, USBGuard, Encryption, Realm Management
Hyper-V, VMware ESXi/Workstation, VM lifecycle management, virtual networking, cluster design
RADIUS/NPS AAA, 802.1X, Cisco/Ruckus/Dell switch management, Cisco EWC wireless, VLAN segmentation