About Me
Cloud-Security & DevOps Engineer who architects, codes, and defends mission-critical systems. Blends Cisco-grade networking, C++/Python automation, and AWS-first IaC (Terraform / CloudFormation) to ship RMF-compliant, zero-trust platforms—from air-gapped labs to auto-scaling GovCloud fleets.
Education
Community College of the Air Force
A.A.S. — Electronic Systems Technology
Certifications
CISSPCCNA
AWS Cloud PractitionerSecurity+
Network+ITIL Foundations
A+
Professional Experience
BlueHalo — Systems & Network Security Engineer
AFRL, Kirtland AFB · DevOps / Cloud Security focus
- Integrated & ATO-certified two legacy, collateral, and standalone RDT&E networks, migrating terabytes of data into a high-performance virtual data center.
- Hardened Cisco infrastructure (STIGs, 802.1X/RADIUS) and deployed a new switching core, raising throughput and reliability across all enclaves.
- Modernized security stack: deployed ACAS (Security Center + Nessus), Wazuh SIEM, and STIG Manager; performed CentOS 7 → Oracle Linux 8 in-place upgrade and produced gold-image AMIs for rapid redeployment.
- Built a serverless compliance pipeline: Lambda (12 AM/PM) triggers SSM OpenSCAP scans in every AWS account, pushes results to a central S3 bucket, and feeds RMF dashboards.
- Automated patching, inventory, and POA&M evidence with PowerShell, Bash, and Python—scripts also audit a multimillion-dollar cloud enclave and export findings to S3.
- Co-authored the RMF package in eMASS and served as deputy on ATO/ATC submissions and POA&M closure for two Platform IT systems.
150 Comm Sq, ANG — Cyber Defense Operator / Radio Tech
Kirtland AFB
- Designed an air-gapped training network with dual AD domains, EIGRP routing, and SVLANs; delivered Blue-Team curriculum to squadron personnel.
- Deployed Tenable Security Center & Nessus on Rocky Linux; ran RMF-aligned vulnerability workshops.
- Hardened all systems to DISA Stand-Alone STIG; mentored junior admins on secure configuration.
- Led live-fire Blue-Team exercises and RF/LMR troubleshooting, ensuring uninterrupted mission comms.
GRS — Systems / Network Administrator
AFRL, Kirtland AFB
- Administered Windows AD and Cisco switching; planned network upgrades and IP allocations.
- Applied STIGs, imaged/ patched hosts, and scripted automation in PowerShell.
- Served as Facility ISSO, enforcing DIA IA/TEMPEST requirements.
LinQuest — IT Specialist
JNWC, Kirtland AFB
- Built & imaged multi-level systems, maintained ADPE inventory, and resolved help-desk tickets across multiple classification domains.
US Space Force — Satellite Comms Technician
Kirtland AFB
- Operated & tested 6 m antennas and Linux-based mobile ground systems ($40 M).
- Reworked unit maintenance plans and fixed 52 tracking-system issues.
- Authored 87-task checklist for first-of-kind 7.3 m antenna ($16 M).
US Air Force — RF Technician
JB McGuire-Dix-Lakehurst
- Led 5-tech team maintaining 42 Giant-Voice poles and 4 000+ Motorola radios.
- Completed 1 600 PMIs and cleared 300 outages on a $6 M mass-notification system.
- Audited & programmed 4 500 radios worth $14 M across 65 units / 54 000 personnel.
Technical Projects
CatChase — Engine & Game
Hover to flip
CatChase (May 2025 – Present)
- Scratch-built 2D engine (no pre-made framework): RAII Texture/Shader/ResourceManager, batched sprites, layered tile-map renderer, JSON loader, ortho camera, debug passes, 8-direction player, enemy factory, seamless transitions, Nuklear pause menu.
- Python converts PixLab exports → compact JSON & overlays; CMake 23 fetches GLFW/glad/FreeType/Nuklear, builds C++23, zips portable bundle.
TrueTunnel-VPN
Hover to flip
TrueTunnel-VPN (May 2025 – Present)
- Single-binary VPN for Windows with FIPS-mode OpenSSL 3.1, raw-IP tunneling over mutual-auth TLS 1.3.
- Dear ImGui GUI, dual-thread pumps, TCP_NODELAY fast path; pure CMake fetches Wintun/OpenSSL.
AWS-Mirrored Full-Stack Apps
Hover to flip
AWS-Mirrored Apps (Jun 2023 – Present)
- Four Ubuntu apps mirrored to AWS (EC2, ELB, DynamoDB, Lambda, S3, Route 53) via Terraform & GitLab CI/CD.
- Auto-scaling and fail-over keep on-prem and GovCloud stacks perfectly synchronized.