Project Experience

CircleCI Deployment Pipeline Security

March 2024

  • Satisfied SEC/FINRA regulatory and audit requirements before set deadlines by scoping and delivering a months-long project to upgrade the security of 50+ deployment pipelines and 20+ artifact registries.
  • Guaranteed two-person approval of all code in production by implementing a new deployment process that utilized GitHub rulesets, CircleCI context restrictions, automatic rotation and revocation of 40+ unique environment-specific API keys, and mandatory image promotion from lower environments.

Custom Alerting Kubernetes Operator

July 2023

  • Led and participated in a working group of 3 engineers developing a Kubernetes operator in Go using Operator Framework to deploy custom resource definitions to route alerts from applications.
  • Enabled developer ownership of alerting for 50+ microservices by allowing them to control and define alert routing to PagerDuty inside of Helm charts using familiar workflows and Kubernetes manifests.

Ansible Git Repo Standardization

March 2023

Developed Ansible roles, playbooks, and necessary infrastructure to create and manage standardized GitHub repositories and their configurations. Created a pipeline that posts dry-run output to PR comments to allow for easy review of changes and verification of functionality. Wrote a custom inventory script using Python to interact with the GitHub API to gather repository info dynamically. This system allows engineers and developers to rapidly create repositories in a secure manner using our standards without requiring potentially dangerous permissions for end users.

GitOps Helm Deployment Redesign

August 2022

  • Enabled the rapid deployment of internal services while ensuring a high degree of trust that the deployed changes will succeed in production by authoring a CircleCI orb to manage the packaging and release of Helm charts to Kubernetes via Flux.
  • Allowed for automated testing of PRs in lower environments and control over production promotions by migrating legacy branch-per-environment git workflows to a trunk-based model. Provided real-time feedback and verification of deployments to developers by implementing pipeline workflows to query the Kubernetes API for status and run integration tests in the cluster.

Terraform Bootstrapping

March 2022

  • Enabled rapid (under 30 min) customer onboarding by defining a project and managing a team of 2 engineers developing a fully automated process to generate Terraform scaffolding and GCP projects.
  • Met security requirements and avoided secret exposure risk by integrating with GitHub Actions to automatically provision IAM Service Accounts utilizing Workload Identity Federation.

Managed Kubernetes Product Development

August 2021

  • Developed a new product for bare-metal k8s clusters based on customer requirements for high-performance networking by utilizing direct BGP peering to top-of-rack switches ensuring scalability to 3+ racks of servers.
  • Enabled rapid deployment of new build-outs and existing customer upgrades through Ansible playbooks that automated the deployment of k8s worker nodes and networking configuration.

Managed Customer Workload Migrations

Various 2017-2021

  • Served as technical lead on 5 large customer migrations to hosted managed service offerings and ensured that workloads comprising 100+ services were migrated with minimal downtime and customer impact.
  • Frequently went on-site and worked directly with customers both as a pre-sales discovery technical resource and to plan and execute migrations with customer engineers to ensure project success.

Internal Containerized Hosting Stack

November 2020

  • Enabled internal migration to containerized application development by planning and building a new internal hosting platform on Docker Swarm.
  • Developed Ansible playbooks to automate deployment of new virtual servers (Docker, Logstash, MySQL, HAProxy) and CI/CD process for deploying new app code to dedicated hosting environments.

Staff Cross-training

May 2020

  • Designed and implemented a training program to prevent single sources of knowledge and siloing of information within the team.
  • Worked with subject matter experts to foster a culture of cross-training and knowledge sharing among team members.

Ansible Network Configuration Automation

Feb 2020

  • Decreased the total time to prepare and execute network changes by working with network engineers to develop an automated process via Ansible for configuring customer network interfaces and security filters.
  • Assisting with creating Jinja templates for JunOS network device configuration and trained network engineers on playbook usage for simultaneous deployment to dozens of network devices.

Ansible Monitoring Platform Automation

Sep 2019

  • Decreased time to customer delivery for managed monitoring service from days to hours and laid the foundation for customer self-service automation by developing custom Ansible modules using Python.
  • Wrote logic to interface with a vendor’s proprietary REST API and configure SaaS-based monitoring of hundreds of internal servers and deploy managed single-tenant monitoring for dozens of customers.
  • Verified logic to guarantee idempotence for Ansible playbook runs and ensured success by training customer support staff on module usage and responding to feature requests.

Backend Management Network Refactor

Feb 2018

  • Resolved engineer access issues by scoping and executing on a management network refactoring project for 200+ devices including firewall policies, L3VPN routing in 5 datacenters, and secure credentials storage.
  • Managed risks to nearly a dozen in-progress projects and orders by utilizing custom scripting, monitoring, and testing to migrate 200+ legacy systems to new standards with less than 1 hour of total downtime.

Helpdesk PowerShell Automation

Feb 2017

  • Enabled automatic routing and triage of work tickets and decreased the time to resolution for service desk requests by authoring a suite of PowerShell script modules to interface with a proprietary ticketing system REST API to allow greater automation.
  • Fostered utilization by mentoring internal service department employees on shell script creation utilizing these modules to implement streamlined business processes.

Citrix/Wyse Migration

Jun 2016

  • Supported the upgrade and/or replacement of 60+ Wyse terminals running user applications by deploying a new Wyse Device Manager server and a new pool of Terminal Services servers with automatic provisioning.
  • Migrated 2 XenApp 6/6.5 farms comprising 30+ VMs hosting 20+ applications to a new XenApp 7.6 farm.

SAN Migration

Jun 2013

  • Evaluated vendor offerings for a new SAN and successfully migrated virtual infrastructure consisting of over 30 virtual machines to the new storage with minimal downtime, increasing redundancy and reliability.

T1 PRI to VoIP PBX Migration

Feb 2013

  • Migrated 60 user phone system to a new VoIP PBX and transferred existing telephone service from a T1 PRI to VoIP.
  • Designed and implemented network for VoIP traffic, including QoS.

Office Network Redesign & Migration

Mar 2012

  • Increased network security and prevent unauthorized access by migrating over 100 devices from a flat network to 802.1Q VLANs for network segmentation and logical separation.
  • Implemented 802.1x certificate-based authentication and the necessary public key infrastructure for endpoints to auto-provision credentials

vCenter Implementation and P2V of existing servers

Nov 2011

  • Achieved a significant reduction in physical server footprint by implementing vCenter with shared iSCSI storage and high availability for critical workloads.
  • Migrated several critical services to new infrastructure, including MSSQL, Active Directory, and Exchange.