About

I’m an Endpoint Administrator based in Irvine, California, with 10+ years of experience architecting, securing, and automating enterprise macOS and Windows device fleets at scale. My specialty is the two platforms that run modern U.S. enterprises — Jamf Pro (with Jamf Protect and Jamf Connect) for the Apple ecosystem and Microsoft Intune for Windows and mobile — joined by Conditional Access and Microsoft Graph API automation. I’ve done this for organizations where getting endpoint management wrong has real consequences: regulated finance, manufacturing, and the SOC 2 audits that come with them.

What I actually do

I own the full device lifecycle end to end — from the moment hardware is ordered to secure offboarding. In practice that means zero-touch enrollment through Apple Business Manager (DEP and VPP) and Windows Autopilot, configuration profiles and compliance policies aligned to CIS benchmarks and SOC 2, app packaging across PKG, DMG, Win32 and MSIX, app protection policies (MAM) with data-loss prevention and selective wipe, OS update and patch governance with real service levels, and Conditional Access in Entra ID — device compliance, MFA, app-based controls, sign-in risk, and named locations — so a non-compliant Mac is governed by exactly the same rules as a non-compliant PC.

A large part of the job is automation against the Microsoft Graph API: PowerShell and Python that turns device compliance reporting, bulk policy assignment, access reviews, and onboarding/offboarding from manual toil into a scheduled job. Combined with Jamf Pro API scripting, that’s how one administrator keeps a 1,000+ device fleet consistent and audit-ready.

How I work

Automate everything repeatable, and document everything else. If a task has to happen on more than a handful of devices, it becomes a script, an Intune remediation, or a Jamf policy — never a manual checklist that rots the moment the person who wrote it leaves.

A concrete example: I inherited a fleet where macOS patching was “send an email and hope.” Compliance sat around 60% and nobody could say which machines were behind or why. I replaced it with a written patch standard (minor updates in 14 days, critical security patches in 7), Smart Groups that continuously identified drift, managed deferrals with a firm deadline enforced through Apple’s declarative device management, and a Graph-API-driven dashboard that reported against the standard rather than raw version numbers. Within two release cycles the fleet was self-maintaining and audit-ready, and the “where are we on patching” meeting stopped happening. That pattern — a written standard, automation that targets drift, humane enforcement, reporting in the language of the framework — is how I approach almost everything.

Where I’ve done it

I’ve built my career in environments where endpoint management genuinely matters. A regulated U.S. FinTech, where every compliance policy and Conditional Access rule had to satisfy SOC 2 auditors as well as users, and where I progressed through multiple IT roles to own enterprise endpoint engineering and security while the fleet grew past a thousand devices across macOS, Windows, iOS, and ChromeOS. A global consumer brand running hybrid corporate offices and manufacturing floors, where the same estate has to work for a designer and a plant technician. And before that, a decade supporting and engineering desktop environments for organizations of 500+ workstations — Active Directory, Group Policy, Windows Server, virtualization. That range is why endpoint problems rarely surprise me; I’ve usually seen the underlying cause somewhere before.

Certifications

I back the hands-on experience with 40+ industry certifications, all verifiable on Credly. The ones most relevant to endpoint and identity work:

I keep them current because this field doesn’t stand still — Apple’s declarative device management, Intune’s settings catalog, Platform SSO, and Conditional Access all move every quarter.

Beyond the day job

I mentor a CyberPatriot team through the Air Force Association (AFA), coaching middle and high school students through the National Youth Cyber Defense Competition — hardening systems, reading logs, and thinking like a defender. I also serve on the OWASP Global Education Committee, contributing to application-security education through the OWASP Foundation.

As a U.S. citizen eligible to obtain a security clearance, I work with organizations across finance, manufacturing, defense, and government. I speak English (full professional), and Azerbaijani, Persian, and Turkish natively.

Writing

I publish field notes on Jamf Pro, Microsoft Intune, Conditional Access, and enterprise deployment in Articles — practical, vendor-neutral write-ups from work on real fleets in regulated environments, not lab setups. If you run one platform and are weighing the other, or you run both and want them to behave like one governed estate, that’s most of what I write about.

What I’m looking for

I’m open to endpoint and system administration roles and consulting engagements — particularly where an organization runs both Apple and Windows at scale, has compliance obligations, and wants the estate automated and audit-ready rather than firefought. The fastest way to reach me is the contact form, or connect on LinkedIn. My resume and selected projects have the detail.