Projects
Technical case studies with architecture details and outcomes.
Extension Attribute: Inventorying VS Code Extensions Per User
CompleteA Jamf Pro extension attribute that enumerates every installed VS Code extension and version for the logged-in user — the verification half of an IDE extension policy, and a supply-chain inventory nothing else was collecting.
Extension Attribute: Surfacing Why People Took Admin
CompleteA Jamf Pro extension attribute that reads the Jamf Connect elevation log and reports the last five justifications into inventory — turning a local log file into a searchable, fleet-wide audit trail.
Extension Attribute: Which Accounts Can Actually Unlock the Disk
CompleteA Jamf Pro extension attribute that enumerates every secure-token-enabled user on a Mac — the state FileVault depends on, that nothing in standard inventory reports.
Config Profile: Time-Boxed Admin Rights with Mandatory Justification
CompleteA Jamf Connect Temporary User Permissions profile that grants admin for 15 minutes, expires it automatically, and refuses to elevate anyone until they type a reason.
Config Profile: Blocking AI Coding Assistants in VS Code
CompleteA managed-preferences profile that enforces an extension allowlist in Visual Studio Code — permitting extensions broadly while denying the AI assistants that would send source code to unapproved vendors, and switching telemetry off.
Jamf Compliance Bridge
CompleteAutomation service that syncs Jamf Pro smart group membership into Okta and Microsoft Entra ID groups, so Conditional Access and authentication policies gate on live device compliance.
Jamf Fleet Toolkit
CompleteRead-only Python automation for Jamf Pro fleet operations — compliance reporting, stale device detection, smart group auditing, and policy drift detection built on the OAuth2 API.
AI Tool Governance Program
In ProgressOwn the AI tool approval program at Ontinue — sanctioning GitHub Copilot and Claude Code for engineering use while restricting unapproved AI tools on managed Macs to limit company data leaving the environment.
Sanitized for public disclosure
Platform SSO Rollout and Enrollment Remediation
CompleteRolled out Platform SSO across a 300+ device Mac fleet at Ontinue using staged pilot rings, then built and open-sourced a remediation script that detects and recovers devices where enrollment silently never completed.
Sanitized for public disclosure
Jamf Toolkit
In ProgressProduction-tested bash scripts, Extension Attributes, and configuration profiles for Jamf Pro, drawn from managing macOS fleets from 300 to 2,800+ endpoints.
Extension Attribute: Turning App Auto-Patch Receipts Into Patch Evidence
CompleteA Jamf Pro extension attribute that reads every App Auto-Patch receipt on a Mac and reports each title's version, timestamp and exit code into inventory — split into successes and failures, so a silently failing patch is visible.
Jira and Confluence Governance
In ProgressRebuilt Jira and Confluence administration across multiple departments at Ontinue — custom fields, screen schemes, and content lifecycle automation — cutting administrative workload by 35%.
Sanitized for public disclosure
Cyber Essentials Patch Compliance
CompleteBuilt the macOS patching and update-enforcement program behind Ontinue's UK Cyber Essentials posture, meeting the 14-day remediation window for OS and third-party application updates across the Mac fleet.
Sanitized for public disclosure
Jamf Onboarding Automation
CompleteAutomated macOS onboarding at Ontinue with department-based paths, Jamf Setup Manager, and AutoPKG, cutting compliance time from 2+ hours to a self-service process across 300+ devices.
Sanitized for public disclosure
macOS Enrollment Experience and Self Service Branding
CompleteRebuilt what a new Ontinue Mac looks like out of the box — branded Setup Manager enrollment, a company-branded Self Service portal, an acceptable-use login banner, and cleaned-up device reporting.
Sanitized for public disclosure
VPN Brute-Force Incident — Early Detection and Response
CompleteIdentified a credential-stuffing attack against the corporate VPN that locked out 15+ users, and was among the first to escalate it to the Security Operations Center, contributing to mitigation and the formal post-mortem.
Sanitized for public disclosure
Google Workspace and Zoom to Microsoft 365 Migration
CompleteLed the company-wide move off Google Workspace and Zoom onto Microsoft 365 and Teams across US and Canadian offices, including room licensing and conference room hardware — up to and including the most complex room in the company.
Sanitized for public disclosure
MDM Compliance Improvement
CompleteBuilt compliance verification and remediation scripts across 2,800+ endpoints at Infoblox, raising MDM compliance from 82% to 98%.
Sanitized for public disclosure
GCC High Federal Tenant Administration
CompleteBuilt and administered the separate GCC High environment for Infoblox federal operations — custom Windows imaging for 60+ federal users, Jamf Connect and Intune in dedicated federal tenants, and zero audit findings across two consecutive review cycles.
Sanitized for public disclosure
Config Profile: FileVault, Key Escrow, and Firewall as One Baseline
CompleteThe encryption baseline profile from a 2,800-endpoint fleet — enforces FileVault, escrows the recovery key to Jamf Pro, enables the built-in firewall, and locks down the login window in a single payload set.
Sanitized for public disclosure
IT Asset Lifecycle and Secure Disposal
CompleteRan the full hardware lifecycle across US and Canadian offices — procurement and refresh through DoD-standard data destruction and certified recycling — including remote-locking 86 missing or inactive devices to close an inventory gap.
Sanitized for public disclosure
Okta Identity and Access Administration
CompleteServed as lead Okta subject-matter expert for a global IT organization — SSO and MFA configuration, app onboarding, and the full user lifecycle from provisioning through role change to offboarding across a 2,800+ endpoint environment.
Sanitized for public disclosure