Professional Summary
Lead Principal Security Engineer with 30+ years designing, operating, and automating large-scale security and infrastructure platforms. Deep expertise in CrowdStrike Falcon, Tanium, FalconPy, Playwright/CDP automation, Jira/Confluence automation, MCP integrations, prevention policies, tagging, RTR, and approval-gated security workflows. Trusted escalation lead for complex endpoint security, automation, evidence packaging, and repeatable control improvement across enterprise environments.
Professional Experience
Oracle, Inc. (Micros acquired Fry, Inc. 2010; Oracle acquired Micros 2014)
Lead Principal Security Engineer | 2016 - Present
- Led enterprise CrowdStrike Falcon allowlist governance across Oracle operating scopes; standardized master-source intake, approval boundaries, multi-realm access validation, synchronization, cleanup, and audit-ready closeout evidence.
- Built approval-gated Playwright/CDP automation for Falcon allowlist inventory, synchronization, deletion, and cleanup, preserving compare, dry-run, execution, verification, browser-isolation, and operator handback controls while improving inventory throughput nearly 4x through worker-isolated execution.
- Packaged Falcon allowlist workflows as SCM-backed security automation skills with fail-closed authentication preflights, realm-aware guards, deterministic safety tests, access-preservation rules, exact-convergence checks, and evidence handoffs.
- Built and maintained FalconPy automation for host inventory export, tagging, API client management, API scope validation, user-group provisioning, sensor/package support, and large-scale remediation initiatives across all Oracle environments.
- Strengthened Falcon operational governance through prevention, sensor-update, and response policy routing; support-role and NGSIEM access analysis; product-update intelligence tracking; FileVantage replacement planning; endpoint policy implementation; and structured Jira/Confluence evidence workflows.
- Improved Tanium operational reliability and audit readiness through Index CX recovery and exclusion programs, Connect feed validation, outage recovery, endpoint data-store remediation, IDS/FIM evidence packaging, and replacement capability planning.
- Developed MCP integrations for Jira Service Desk and Confluence plus AI-assisted operational reporting workflows, standardizing Dockerized deployment, approval-gated tools, PAT/web-session authentication patterns, deterministic validation, and source-backed handoffs.
- Helped stand up 12 enterprise security environments, including initial Tanium platform deployment and FedRAMP-aligned AWS security architecture, while building repeatable controls and operational runbooks.
- Maintained production runbooks and checksum-backed operational workflows for CrowdStrike Falcon operations, Tanium platform maintenance, prevention policies, CID/user group administration, MFA, RTR, sensor upgrades, patching, and server rebuilds.
Oracle, Inc.
Senior Systems Engineer - Retail Global Industry Units | 2014 - 2016
Delivered senior systems engineering support for retail Global Industry Units, focusing on infrastructure reliability, performance optimization, security integration, and operational stability in high-volume environments.
Oracle, Inc.
Principal Systems Engineer | 2010 - 2014
- Served as principal technical lead for retail systems engineering, delivering architecture, implementation, troubleshooting, and guidance for complex infrastructure projects.
- Provided expert support across Unix/Linux administration, IBM WebSphere, Tomcat, Sybase, networking, and security; partnered with development teams on performance training and root-cause analysis.
Fry, Inc.
Systems Engineering Manager / Senior Systems Engineer | 2005 - 2010
- Established PCI DSS compliance and security requirements for Linux servers and networking infrastructure.
- Led migration from manually built Windows servers to a fully automated Red Hat Linux environment, improving consistency, scalability, and operational efficiency.
- Designed, built, and deployed automated AWS cloud environments for core offerings, enabling faster provisioning and elastic scaling.
- Primary escalation engineer for complex e-commerce troubleshooting across JVM performance, databases, network access, system setup, and multi-vendor content caching.
gedas AG / Volkswagen AG
Senior Network Security Engineer | 2002 - 2005
- Directed networking for US-to-Brazil mainframe migration and replaced dealership satellite communications with Cisco VPN solutions.
- Managed routers and corporate network infrastructure for Volkswagen North America and Western Hemisphere operations.
- Served as F5 Security Engineer and Certified F5 Pre-Sales Engineer for load balancing, application delivery, and security configurations.
- Developed automated IP address database to streamline network management.
Independent Contracting
Partner / Senior Network Engineer | 2000 - 2004
Designed and built custom corporate networks and managed firewall/security configurations for enterprise clients.
CText, Inc.
Systems Engineering Manager / Senior Systems Engineer | 1995 - 2002
- Managed team of 8 engineers supporting editorial/classified systems for newspaper company installations on UNIX platforms (SunOS/AIX).
- Architected and delivered 24x7 high-availability Sybase database solution for The Dallas Morning News using IBM RS/6000 servers, Sybase OpenSwitch, and Replication Server.
- Led porting of core products to Windows NT 4.0, achieving first production installation at the Pittsburgh Post-Gazette.
TekSystems / B.K.O. Enterprises
Partner / Senior Systems Engineer | 1991 - 1997
Architected customer networks and server build automation.