Lutheran Life Communities
Corporate Director - IT • May 2007 - January 2021
Skills and Abilities
Information Security
• Disaster Recovery Solutions: Expert in initiating and establishing multiple disaster recovery solutions to ensure business continuity.
• Encryption Standards: Skilled in deploying and maintaining encryption standards across multiple organizations, including FIPS 140-2 compliance for data in transit and at rest.
IT Project Management
• IT Virtualization: Led full virtualization of an environment with 95+ physical servers, transitioning from Cisco UCS/VNX to a Scale Computing hyper-converged platform using VMware and Hyper-V.
• Cloud Conversion: Managed cloud conversion of a multi-site phone system and call center, replacing all handsets and analog adapters with new call center software.
• Cloud Conversion: Led migration of on-premise ERP systems to vendor-hosted cloud infrastructure, configuring onsite backups to maintain data redundancy and business continuity.
• Communication systems upgrade: Led a multi-site phone system upgrade — including server hardware, wireless handset replacement, security enhancements, and staff retraining — with zero downtime during cutover.
• Network Planning and Design: Planned, designed, and implemented full IT infrastructure for multiple remodel and greenfield campus projects — most spanning multi-level buildings. Scope included network switching and port planning, wireless (trusted and guest), AP placement, door access control, voice communications, servers, workstations, and redundant power, voice, and ISP connections.
Vendor Management
• MSP Management: Managed MSPs (Managed Service Providers) across multiple environments, including contract negotiation, SLAs, and creation of playbooks and documentation.
• HIPAA Compliance: As HIPAA Security Officer, reviewed Business Associate Agreements to ensure alignment with organizational policy and regulatory requirements.
Team Building and Leadership
• Team Development: Hired, coached, and developed multiple highly functional, cross-trained internal teams.
• Escalation Management: Served as the point of escalation for customers and team members, providing resolution regardless of complexity or timing.
Cybersecurity
• SIEM Implementation: Implemented multiple SIEM systems, building rule sets for reporting, alerting, and remediation across diverse environments.
• Email Security Solutions: Deployed email scanning/filtering solutions and configured DMARC, DKIM, and SPF to prevent phishing and spoofing.
Cloud Migration Projects
• EHR/ERP Migration: Led cloud migration of Electronic Health Record ERP systems, improving accessibility and healthcare regulatory compliance.
• Server Infrastructure: Managed server infrastructure migration to the cloud, optimizing performance, scalability, and cost-efficiency.
Strategic Planning
• Strategic Technology Planning: Led technology planning for a $200M greenfield campus and multiple remodel projects, integrating advanced systems to support growth.
• Market Trend Analysis: Used market trend and technology forecasts to implement one of the first failover DNS solutions before SD-WAN was viable.
Budgeting and Forecasting
• Strategic Financial Planning: Built a three-year plan that increased staffing and service capability while saving approximately $125,000 annually.
• Long-Term IT Roadmaps: Created multiple three- and five-year technology roadmaps addressing virtualization, cloud adoption, and regulatory change.
Network design and support
• Greenfield Campus Network Design: Led complete network design and implementation for a multi-building $200M greenfield campus in Naples, FL.
• Network Segmentation Strategies: Designed segmentation strategies to meet regulatory compliance, maintaining separation between trusted and untrusted networks.
Active Directory
• Active Directory Administration: Managed AD domains — user accounts, groups, and OUs — across on-premise, hybrid, and full cloud environments.
• Group Policy Management: Configured and maintained Group Policies to enforce security settings and manage network resources.
Policy and Procedure (creation and implementation)
• NIST SP 800-171 (CMMC) Guidelines: Established and enforced information security policies aligned with NIST SP 800-171 (CMMC) guidelines.
• HIPAA Compliance: Created and implemented IT security policies aligned with HIPAA regulations and NIST SP 800-53 standards.
Process Change and Improvement
• Onboarding and Offboarding Processes: Built processes ensuring new hires received correct access and departing employees were promptly deprovisioned.
• Technology Request Form (TRF): Introduced a standardized TRF process for staff to request resources, new tech, and access changes.
Risk Assessment and Mitigation
• Comprehensive Risk Assessments: Conducted internal risk assessments for HIPAA, CMMC, and PCI, managing third-party assessors to build mitigation plans.
• Incident Response Leadership: Led technical remediation for security incidents, serving as primary liaison to the DoD and Department of the Navy.
Security & Compliance Frameworks
- • NIST 800-171
- • NIST 800-53
- • PCI-DSS
- • HIPAA
- • CMMC / DFARS 252.204-7012
- • NIST / ISO frameworks (general)
- • CIS Controls
- • Multiple GRC Frameworks
Firewalls & Network Security
- • Fortinet Firewalls
- • Cisco (Switches / Firewalls / Wi-Fi / UCS)
- • Ubiquiti (Firewalls / Switching / Wi-Fi)
- • Meraki (Switching / Wi-Fi)
- • SonicWALL
- • WatchGuard
- • SD-WAN / VPN: Site-to-Site / P2P, IPSEC, SSL
- • VLANs / Network Segmentation
Mobile & Endpoint Management
- • Microsoft Intune
- • Microsoft MDM
- • BitLocker
- • SmartDeploy
- • Apple / iOS
- • Android
- • ManageEngine MDM
SIEM / SOC / Monitoring
- • ManageEngine SIEM (deployed & administered)
- • Splunk (dashboard / user level)
- • MSSP SOC integration
- • OpUtils
- • ADManager Plus
- • ADAudit Plus
- • AD360
Collaboration & Productivity Applications
- • Microsoft Teams
- • Microsoft Office Suite (Word, Excel, PowerPoint, etc.)
- • SharePoint
- • Egnyte
- • Adobe PDF
- • PDF X-Change
- • Foxit PDF
Cloud & Virtualization
- • Microsoft Azure
- • VMware
- • Hyper-V
- • vSphere
- • Scale Computing HCI
- • Cisco UCS
Identity & Access Management
- • Active Directory
- • Entra ID
- • Duo / Duo FedRAMP
- • Microsoft Authenticator
- • SSL Certificates
- • SSO
IT Service Management & Operations Tools
- • ConnectWise
- • Pulseway
- • Quest KACE
- • Spiceworks
- • ITIL Service Management
Storage & Infrastructure
- • HP
- • Dell
- • VNX
- • QNAP
- • Synology
Endpoint Detection & Response (EDR) / Endpoint Security
- • SentinelOne
- • Microsoft Defender for Office 365 and Endpoint
- • Trend Micro
- • Symantec
- • MalwareBytes EDR/MDR
Email Security
- • Proofpoint
- • Barracuda (Mail and Archive)
- • Check Point
- • DMARC / DKIM / SPF
- • MS Exchange
Backup & Disaster Recovery
- • Veeam
- • Acronis
- • Barracuda
- • Disaster Recovery & Business Continuity Planning
Vulnerability Management
- • Qualys
- • Tenable
- • Risk Register tools
- • Tabletop Exercise Facilitation
VOIP / Telecom Platforms
- • Avaya
- • Call Tower
- • RingCentral
Risk & Compliance Monitoring
- • BitSight
- • Internal Audit & Remediation Tools
- • Incident Response Planning
Physical & Access Control
- • Johnson Controls C·CURE
- • Verkada
- • Various Door Access Control Systems
Password Management
- • Dashlane
- • Keeper
- • Bitwarden