Projects

Technical case studies with architecture details and outcomes.

Extension Attribute: Inventorying VS Code Extensions Per User

Complete

A Jamf Pro extension attribute that enumerates every installed VS Code extension and version for the logged-in user — the verification half of an IDE extension policy, and a supply-chain inventory nothing else was collecting.

Jamf Pro Extension Attributes Visual Studio Code Bash Software Inventory

Extension Attribute: Surfacing Why People Took Admin

Complete

A Jamf Pro extension attribute that reads the Jamf Connect elevation log and reports the last five justifications into inventory — turning a local log file into a searchable, fleet-wide audit trail.

Jamf Pro Extension Attributes Jamf Connect zsh Auditing

Extension Attribute: Which Accounts Can Actually Unlock the Disk

Complete

A Jamf Pro extension attribute that enumerates every secure-token-enabled user on a Mac — the state FileVault depends on, that nothing in standard inventory reports.

Jamf Pro Extension Attributes FileVault Secure Token Bash XSLT

Config Profile: Time-Boxed Admin Rights with Mandatory Justification

Complete

A Jamf Connect Temporary User Permissions profile that grants admin for 15 minutes, expires it automatically, and refuses to elevate anyone until they type a reason.

Jamf Connect Configuration Profiles macOS Least Privilege

Config Profile: Blocking AI Coding Assistants in VS Code

Complete

A managed-preferences profile that enforces an extension allowlist in Visual Studio Code — permitting extensions broadly while denying the AI assistants that would send source code to unapproved vendors, and switching telemetry off.

Configuration Profiles Visual Studio Code macOS AI Governance Data Loss Prevention

Jamf Compliance Bridge

Complete

Automation service that syncs Jamf Pro smart group membership into Okta and Microsoft Entra ID groups, so Conditional Access and authentication policies gate on live device compliance.

Python Jamf Pro API Okta Microsoft Entra ID OAuth2

Jamf Fleet Toolkit

Complete

Read-only Python automation for Jamf Pro fleet operations — compliance reporting, stale device detection, smart group auditing, and policy drift detection built on the OAuth2 API.

Python Jamf Pro API OAuth2 CSV Reporting

AI Tool Governance Program

In Progress

Own the AI tool approval program at Ontinue — sanctioning GitHub Copilot and Claude Code for engineering use while restricting unapproved AI tools on managed Macs to limit company data leaving the environment.

Sanitized for public disclosure

macOS Jamf Pro Configuration Profiles Data Governance

Platform SSO Rollout and Enrollment Remediation

Complete

Rolled out Platform SSO across a 300+ device Mac fleet at Ontinue using staged pilot rings, then built and open-sourced a remediation script that detects and recovers devices where enrollment silently never completed.

Sanitized for public disclosure

Platform SSO Jamf Pro Microsoft Entra ID macOS Shell Scripting

Jamf Toolkit

In Progress

Production-tested bash scripts, Extension Attributes, and configuration profiles for Jamf Pro, drawn from managing macOS fleets from 300 to 2,800+ endpoints.

Bash Jamf Pro macOS swiftDialog Configuration Profiles

Extension Attribute: Turning App Auto-Patch Receipts Into Patch Evidence

Complete

A Jamf Pro extension attribute that reads every App Auto-Patch receipt on a Mac and reports each title's version, timestamp and exit code into inventory — split into successes and failures, so a silently failing patch is visible.

Jamf Pro Extension Attributes App Auto-Patch zsh Compliance

Jira and Confluence Governance

In Progress

Rebuilt Jira and Confluence administration across multiple departments at Ontinue — custom fields, screen schemes, and content lifecycle automation — cutting administrative workload by 35%.

Sanitized for public disclosure

Jira Confluence Atlassian Administration Workflow Automation

Cyber Essentials Patch Compliance

Complete

Built the macOS patching and update-enforcement program behind Ontinue's UK Cyber Essentials posture, meeting the 14-day remediation window for OS and third-party application updates across the Mac fleet.

Sanitized for public disclosure

Jamf Pro macOS App Auto-Patch swiftDialog Cyber Essentials

Jamf Onboarding Automation

Complete

Automated macOS onboarding at Ontinue with department-based paths, Jamf Setup Manager, and AutoPKG, cutting compliance time from 2+ hours to a self-service process across 300+ devices.

Sanitized for public disclosure

Jamf Pro macOS AutoPKG Shell Scripting

macOS Enrollment Experience and Self Service Branding

Complete

Rebuilt what a new Ontinue Mac looks like out of the box — branded Setup Manager enrollment, a company-branded Self Service portal, an acceptable-use login banner, and cleaned-up device reporting.

Sanitized for public disclosure

Jamf Pro Jamf Setup Manager macOS Configuration Profiles

VPN Brute-Force Incident — Early Detection and Response

Complete

Identified a credential-stuffing attack against the corporate VPN that locked out 15+ users, and was among the first to escalate it to the Security Operations Center, contributing to mitigation and the formal post-mortem.

Sanitized for public disclosure

Incident Response Okta VPN Identity Security

Google Workspace and Zoom to Microsoft 365 Migration

Complete

Led the company-wide move off Google Workspace and Zoom onto Microsoft 365 and Teams across US and Canadian offices, including room licensing and conference room hardware — up to and including the most complex room in the company.

Sanitized for public disclosure

Microsoft 365 Microsoft Teams Google Workspace Zoom AV Systems

MDM Compliance Improvement

Complete

Built compliance verification and remediation scripts across 2,800+ endpoints at Infoblox, raising MDM compliance from 82% to 98%.

Sanitized for public disclosure

Jamf Pro Intune macOS Shell Scripting

GCC High Federal Tenant Administration

Complete

Built and administered the separate GCC High environment for Infoblox federal operations — custom Windows imaging for 60+ federal users, Jamf Connect and Intune in dedicated federal tenants, and zero audit findings across two consecutive review cycles.

Sanitized for public disclosure

Microsoft GCC High Intune Jamf Connect Windows Imaging DoD Compliance

Config Profile: FileVault, Key Escrow, and Firewall as One Baseline

Complete

The encryption baseline profile from a 2,800-endpoint fleet — enforces FileVault, escrows the recovery key to Jamf Pro, enables the built-in firewall, and locks down the login window in a single payload set.

Sanitized for public disclosure

Configuration Profiles FileVault macOS Jamf Pro Compliance

IT Asset Lifecycle and Secure Disposal

Complete

Ran the full hardware lifecycle across US and Canadian offices — procurement and refresh through DoD-standard data destruction and certified recycling — including remote-locking 86 missing or inactive devices to close an inventory gap.

Sanitized for public disclosure

Jamf Pro API ITAM BitRaser Asset Management

Okta Identity and Access Administration

Complete

Served as lead Okta subject-matter expert for a global IT organization — SSO and MFA configuration, app onboarding, and the full user lifecycle from provisioning through role change to offboarding across a 2,800+ endpoint environment.

Sanitized for public disclosure

Okta SSO MFA SAML Identity Lifecycle