I design secure cloud solutions and hybrid infrastructure.
Certified Azure Solutions Architect with a Secret clearance, building secure, survivable systems for federal agencies and global enterprises, from stretched on-prem clusters to compliant delivery pipelines.
- Clearance
- Secret
- Focus
- Secure cloud / hybrid
- Certs
- 5× Azure
- Base
- Texas
Problem → architecture → outcome.
Complete Azure Landing Zone (CAF Hub & Spoke)
A full Cloud Adoption Framework Azure Landing Zone in Terraform and Azure Verified Modules, covering the management-group hierarchy, an enforced policy baseline, dual-region hub-and-spoke with Azure Firewall Premium, four platform subscriptions, and corp/online landing zones, all shipped through OIDC GitHub Actions with policy-as-code PR gates.
Read case studyAzure Virtual Desktop Landing Zone (Terraform + AVM)
A reference-grade AVD application landing zone built entirely from Azure Verified Modules in Terraform and shipped through OIDC GitHub Actions with no stored secrets. It is CAF-aligned, Entra ID-joined, private-only, and mapped against every Microsoft AVD design area.
Read case studySecure CI/CD for Federal Workloads
Built and hardened CI/CD pipelines for multiple federal agencies, from application delivery to a multi-environment Azure data platform, folding code analysis and supply-chain scanning into the path to production, administering the GitHub organization (80+ repositories across ~10 applications), and holding the line on NIST and FedRAMP controls.
Read case studyGovernance & Secure Landing Zones
Operationalized the security pillar of the Well-Architected Framework into repeatable landing-zone guardrails, turning one-off security reviews into automated, baseline-enforced governance across Azure deployments.
Read case studyTwo-Site Stretched Azure Local Cluster
Designed and built a two-site stretched Azure Local (Azure Stack HCI) reference environment with storage-replica site-to-site replication and Azure Arc management, demonstrating edge infrastructure that survives the loss of a full site.
Read case studyDepth across the stack.
Architecture & Hybrid
- Landing zones & governance
- Azure Local / Stack HCI
- Disaster recovery & BCDR
- Network & identity design
DevSecOps & IaC
- GitHub Actions / Azure DevOps
- Terraform · Bicep · ARM
- SonarQube / GH Advanced Security
- Docker / Kubernetes security
Security & Observability
- Sentinel · Defender · Purview
- Entra ID & RBAC
- Azure Monitor · Log Analytics · KQL
- NIST · FedRAMP alignment