Career

Resume

10+ years architecting, securing, and automating enterprise macOS and Windows fleets with Jamf Pro and Microsoft Intune. See selected projects and field notes.

Download CV (PDF)
Experience

Work History

Aug 2025 — Present

Endpoint Administrator

Monster Energy Company — Corona, CA (Hybrid)

Architect the full macOS and iOS device lifecycle in Jamf Pro — PreStage enrollment, DEP/ABM, configuration profiles, Smart Groups, extension attributes, patch policies, and software deployment for 1,000+ Apple devices across hybrid corporate and manufacturing environments. Design and maintain Microsoft Intune Autopilot/OOBE deployment profiles, compliance policies, Win32/MSIX app packaging, Windows update rings, and app protection policies (MAM) for managed and unmanaged devices.

Architect and enforce Conditional Access in Entra ID — device-compliance requirements, MFA enforcement, app-based access controls, sign-in risk policies, and named-location restrictions. Develop PowerShell and Python automation against the Microsoft Graph API for device compliance reporting, user/group provisioning, bulk policy assignment, and offboarding — cutting manual provisioning time by roughly 40%. Build inventory and compliance dashboards tracking 1,000+ assets, patch status, and audit readiness, run automated secure-offboarding workflows (device wipe, Jamf/Intune unenrollment, Entra ID and Okta access revocation), and act as Tier 3 escalation for complex MDM, Conditional Access, and identity incidents.

2021 — Aug 2025

System Administrator

Lendistry (FinTech) — Irvine / Tustin, CA (Hybrid) · Promoted through multiple IT roles

Progressed through multiple IT roles to own enterprise endpoint engineering and security for 1,000+ macOS, Windows, iOS, and ChromeOS devices in a regulated FinTech environment. Owned full macOS/iOS fleet management in Jamf Pro, Jamf Protect, and Jamf Connect — zero-touch DEP enrollment, configuration profiles, patch automation, macOS threat prevention and behavioral analytics, and identity-integrated login with Entra ID / Okta.

Deployed 1,000+ Windows and macOS devices via Intune Autopilot/OOBE; designed compliance policies, Conditional Access rules, and app protection policies (MAM) for a hybrid Jamf + Intune environment aligned to SOC 2 requirements. Built PowerShell automation on the Microsoft Graph API for bulk device-compliance exports, automated access reviews, onboarding/offboarding, license assignment, and audit reporting. Administered Microsoft 365, Exchange Online, SharePoint, OneDrive, Entra ID, Okta, and Active Directory (IAM, RBAC, licensing, SOC 2 operations), managed Google Chrome Enterprise across both platforms, and mentored 5+ Service Desk technicians while authoring SOPs and onboarding guides.

2006 — 2021

Earlier IT career — system administration & desktop engineering

Various organizations

Progressive IT experience before specializing in endpoint management: system administration for 500+ Windows workstations, Active Directory and Group Policy, Windows Server domain services, virtualization and storage infrastructure, and multi-organization desktop support. This foundation is why endpoint problems rarely surprise me — I've usually seen the underlying cause somewhere before.

Education

Academic Background

2012 — 2015

Bachelor of Science, Information Technology

University of Applied Science and Technology · GPA 15.25/20

2008 — 2010

Associate of Science, Information Technology

Islamic Azad University

Expertise

Core Competencies

Jamf Pro / Protect / Connect

PreStage EnrollmentDEP / ABMSmart Groups & Extension AttributesConfiguration ProfilesPatch PoliciesApp InstallersJamf ProtectJamf ConnectJamf School

Microsoft Intune

Autopilot / OOBECompliance PoliciesWin32 / MSIX PackagingWindows Update RingsProactive RemediationsSCCM Co-managementEndpoint Analytics

Conditional Access & App Protection

Device-compliance CA policiesSign-in Risk PoliciesApp-based CAMFA & Named LocationsApp Protection Policies (MAM)Selective Wipe / DLP

Microsoft Graph API & Automation

PowerShell + Graph APIPythonBash / ShellBulk policy assignmentCompliance reportingOnboarding / OffboardingJamf Pro API

Identity, Compliance & Security

Entra ID / Azure ADOktaActive DirectorySAML / SSO & RBACPrivileged Identity ManagementSOC 2 audit readinessCIS BenchmarksFileVault & BitLocker key management

macOS & Windows Engineering

PLIST & MDM profilesPPPC payloadsSystem ExtensionsmacOS update governanceWindows 10 / 11 hardeningWUfB / WSUSGPO-to-Intune migrationWindows Hello for Business

Chrome Enterprise & M365

Chrome Enterprise policyChromeOS managementExtension controlCertificate deploymentExchange OnlineSharePoint / OneDrive / Teams
Credentials

Certifications

40+ active industry certifications — the credentials most relevant to endpoint and identity roles, all verifiable on Credly.

Jamf

Jamf Certified Associate — Pro, Protect & School

Plus Jamf Command Line Innovator and Jamf Certified Endpoint Security Associate

Google

Professional Chrome Enterprise Administrator

Plus Professional ChromeOS Administrator and Google Admin Console

EC-Council

Certified Security Analyst — Practical (ECSA)

Plus Certified Cybersecurity Technician (CCT)

CompTIA / Microsoft

CompTIA A+ ce · MCSA / MCSE: Server Infrastructure

Windows Server, Active Directory & Group Policy

Fortinet

Fortinet Certified Associate — Cybersecurity

Plus FortiGate 7.6 Operator (NSE 3)

Proofpoint

Certified AI Data Security & Ransomware Specialist

Plus Certified Security Awareness Specialist

Security Blue Team · Qualys

Blue Team Junior Analyst · VMDR

Vulnerability management, threat hunting, network analysis, digital forensics

ISC2

ISC2 Candidate — CISSP track

Working toward the CISSP

40+ industry certifications

Jamf, Google, Microsoft, CompTIA, EC-Council, Fortinet, Proofpoint, and more — verified on Credly.

View Badges on Credly
Giving Back

Volunteer & Community

Jul 2025 — Present

CyberPatriot Technical Mentor

Air Force Association (AFA) — coaching middle and high school teams in the National Youth Cyber Defense Competition.

Aug 2023 — Present

OWASP Global Education Committee

Contributing to global application-security education through the OWASP Foundation.

Languages

Languages

English (Full Professional) · Azerbaijani (Native) · Persian (Native) · Turkish (Native / Bilingual)

More context

Read the full background, browse projects and field notes, or get in touch.

Contact Me