AI & Agentic Systems
Codex, Claude, and Ollama, including AI subagents built for scoped tasks, agent workflows, local and cloud model orchestration, and secure AI enabled operations.
Senior Enterprise Systems Engineer
I build secure, reliable, and scalable enterprise systems at Reddit. My work spans identity, endpoints, SaaS, security, integrations, and AI enabled automation. After 15+ years in technology, I’ve grown from hands on IT support into enterprise systems engineering. I focus on simplifying operations, automating repetitive work, strengthening security controls, and improving the employee technology experience through practical AI enabled workflows.
Expertise matrix
Codex, Claude, and Ollama, including AI subagents built for scoped tasks, agent workflows, local and cloud model orchestration, and secure AI enabled operations.
Identity lifecycle, SSO, MFA, SAML, OAuth, OIDC, and SCIM, with governance and traceable security auditing that supports SOX and other audits with documented results for every approved access request.
Google Workspace, Microsoft 365, Atlassian Cloud, Slack Enterprise Grid, GitHub Enterprise, Zendesk, Asana, 1Password, Oomnitza, Duo, and more, plus custom integrations.
Python, PowerShell, Tines, Okta Workflows, API integrations wrapped into MCP servers, Atlassian Rovo agents, Codex subagents for scoped tasks, repeatable operations, and AI skills with orchestration guides that give AI clear workflows to follow.
Secure device lifecycle across Jamf, Kandji, Microsoft Intune, Cyberhaven, and CrowdStrike, including managed browsers such as Google Chrome, Brave, and Firefox, application deployment across the device fleet, policy creation, controls, and compliance.
Deployed and managed identity providers including Cloudflare, Okta, and Authentik.io, with group access controls, Google Cloud service account provisioning, and infrastructure as code using Terraform through peer reviewed GitHub pull requests and controlled change management. Secure, resilient network deployments with identity provider connections that make office network access easier to manage and secure through RADIUS.
/ experience
A career built across enterprise systems, identity, security, automation, infrastructure, and support.
Enterprise platform engineering, identity architecture, automation, infrastructure modernization, and operational leadership for a workforce of 3,000+ employees.
Led identity, endpoint security, and IT operations supporting 250+ employees.
Owned enterprise identity, productivity, collaboration, and network platforms.
Supported enterprise technology services for 1,000+ employees.
Operated mission-critical production, streaming, and 10Gb network infrastructure supporting globally broadcast TED events.
/ selected impact
Selected work showing how I take complex systems from architecture through production—balancing security, automation, operability, and the people relying on them.
Live self-service activation with structured exception routing
Built a Tines portal that verifies the requester in Okta, finds or provisions the Brivo user and credential, confirms the badge, and activates it. Guarded fallback paths handle delayed provisioning, ambiguous matches, missing identity data, and failed assignments.
Production-enabled, safety-first license recovery
Built a webhook-driven workflow for explicit SaaS Manager release decisions. It validates and deduplicates requests, resolves the exact active Okta identity, checks licensing-group eligibility and protected-user conditions, and verifies the post-change state.
Live self-service triage before support escalation
Created an authenticated portal that correlates the requester in Okta with their signed-in Fleet device, current IP, Meter client, office, and Wi-Fi health. Clean-match requirements and deduplication gates control when a structured support request can be submitted.
Live, location-aware alerting with guided response
Built an end-to-end system that enriches and classifies Meter events, correlates related access point and network-switch symptoms, tracks incident state, and suppresses duplicates before routing targeted Slack alerts to the appropriate local IT team.
Live preventive access reconciliation
Built a scheduled workflow that retrieves Okta group members, resolves each person to a Slack identity by email, aggregates valid matches, and updates the target custom user group through a controlled synchronization path.
/ systems
I do my best work where identity, infrastructure, security, automation, and employee experience overlap — turning ambiguous problems into systems with clear ownership and durable operations.
Identity, access, data protection, and auditability are architectural requirements—not finishing work.
Zero Trust patterns like Cloudflare Access in front of SaaS, Okta as the upstream IdP, and RADIUS 802.1X over shared Wi-Fi secrets.
Automation should remove toil, make outcomes consistent, and leave people with better judgment work.
Production Tines and API workflows that cut manual ops work dramatically while leaving judgment calls and exceptions to people.
Observability, recovery, documentation, and clear escalation paths belong in the initial design.
Network alerting with correlation, runbooks, and local routing; recovery plans that restore capability without bypassing change control.
The strongest control is one people can understand and use without finding a workaround.
Self-service portals for badge, Wi-Fi, and license recovery that verify identity and context before support escalates.
Good integrations reduce fragmentation while preserving ownership, failure visibility, and lifecycle control.
One SSO standard instead of one-off IdP-to-vendor SAML; merge approval stays separate from execution approval and plan-only automation.
Complex engineering decisions become valuable when stakeholders understand the tradeoffs and next steps.
Change envelopes with purpose, targets, rollback, and evidence — plus incident command and runbooks stakeholders can follow.
/ personal lab
My HomeLab is where I explore local AI, self-hosted infrastructure, model orchestration, and the operational details that only become visible when you run the system yourself.
I set out to learn how to design my own AI bot end to end—not just call a cloud API, but own inference, memory, voice, and ops on hardware I control. On an NVIDIA Jetson Orin Nano Super, I run local models through Ollama, chat through Open WebUI, and image generation with ComfyUI on the Jetson GPU in low-VRAM mode. From there, I built agents in Python: Viper, a Discord bot with Ollama chat, ComfyUI images, faster-whisper transcription, and SQLite conversation memory; and EVE, a private local agent with a browser UI, response-review boundaries, sqlite-vec semantic memory and local embeddings, MioTTS speech, and a VRM avatar. I use systemd and Docker to keep the services supervised and recoverable, which is where the real learning stuck—fitting multimodal workloads into about 8 GB of shared memory and shipping something that stays up.
A production-minded home lab built in layers: a UniFi network fabric with separated trust zones, a Server_Core for always-on compute and storage, and a deliberately narrow public edge through Cloudflare Tunnel. ZimaCube runs durable file and service workloads; the Jetson Orin Nano Super owns local AI inference. I design this the same way I design enterprise systems—clear ownership, recoverable services, and intentional exposure.
I’m interested in enterprise system engineering opportunities where I can own architecture through production across identity, AI-enabled automation, SaaS integrations, endpoints, and infrastructure.
user@darksys.dev:~$ Type help to explore.