About

I’m a Senior IT Architect and Information Security Professional with more than 25 years of hands-on enterprise experience. My career has centered on bridging operational IT and defensive security — designing and operating SIEM/SOAR/XDR/EDR platforms, Elastic Stack security environments, large-scale endpoint automation, and ITIL-aligned service management systems.

I’ve delivered architecture and engineering work for multi-national clients across healthcare, finance, and technology, authored extensive technical and compliance documentation (including a 225+ page Engineering Manual and ITAR Compliance Manuals), and led high-impact operational initiatives such as a 300+ device deployment completed single-handedly in two months.

In parallel with operational roles, I conduct independent security research. My published analysis of CVE-2025-59145 (CamoLeak) — a CVSS 9.6 prompt injection vulnerability in GitHub Copilot affecting 100M+ developers — reflects an ongoing commitment to understanding and improving the security of the systems we all depend on.

I’m the founder and CTO of Cynipol Systems, an enterprise operations platform that integrates ITSM, Security (SIEM/SOAR), HR, Projects, Events, Financials, and Student Information Services. Cynipol is both my MS IT Capstone project at Southern New Hampshire University and an actively evolving commercial platform.

Originally from the Boston area, I now live in Maricopa, Arizona. Outside of work I enjoy time with family, genealogy research, reading, film, and learning about space, science, and astrophysics.

Core Competencies

Technical

  • SIEM / SOAR / XDR / EDR Architecture
  • Elastic Stack (Elasticsearch, Logstash, Kibana)
  • IAM & Operational Incident Management
  • Vulnerability Research & CVE Analysis
  • Endpoint Automation (MECM/SCCM, PXE, MDT)
  • PowerShell & BASH Automation
  • Windows Server & Linux Administration
  • Active Directory, Group Policy & IAM
  • AWS, Microsoft 365, Google Workspace

Professional

  • ITSM Architecture & ITIL Processes
  • Technical Writing (SOPs, KBAs, Manuals)
  • Compliance (HIPAA, ITAR, HCRA, PCI DSS)
  • Level 3 Escalation Leadership
  • Team Mentoring & Training
  • Vendor & SLA Management
  • Security Policy & Governance