Summary
Senior Endpoint Management Engineer with 25+ years of experience designing, deploying, and optimizing enterprise infrastructure across Windows, Linux, and UNIX environments. Specialized in BigFix (HCL) endpoint management, Microsoft Intune, Windows Autopilot, software packaging, large-scale automation, patch compliance, and system migrations across environments exceeding 120,000 endpoints. Proven ability to reduce risk, improve compliance, and automate complex operational workflows.
Core Expertise
- BigFix (Lifecycle, Compliance, Inventory, WebUI, Web Reports)
- Microsoft Intune & Windows Autopilot
- Endpoint Management (Windows, Linux, AIX, macOS)
- Patch Management & Compliance Automation
- Relevance Language & ActionScript Development
- PowerShell & Automation Engineering
- Software Packaging & Deployment
- Operating System Deployment (OSD), MDT, Zero-Touch Provisioning
- Active Directory & Domain Migrations
- REST API Integration & Reporting
- MECM / SCCM Infrastructure
- High Availability Systems & Clustering
Professional Experience
Charles Schwab (Consultant)
- Led end-of-life software remediation using BigFix Inventory, Qualys, and REST APIs, improving security posture.
- Executed 500+ application removals while managing dependencies and minimizing business impact.
- Developed and delivered internal training on BigFix capabilities and automation strategies.
Meridian Medical Technologies
- Led enterprise domain migration of 2,000+ endpoints, ensuring seamless transition and license compliance.
- Built 180+ BigFix software packages to support migration and operational needs.
- Automated patching using BigFix WebUI and Lifecycle policies, improving compliance and reducing manual effort.
- Designed migration strategy that saved over $200K in penalties and operational costs.
- Partnered with HCL to optimize BigFix architecture, including database, relays, and client settings.
- Engineered MECM infrastructure supporting 10K+ endpoints for deployment, patching, and compliance.
- Reduced deployment effort by 80% through PowerShell automation and task sequencing.
- Managed endpoint devices using Microsoft Intune, including policy deployment, compliance enforcement, and device lifecycle management.
- Configured device compliance policies, configuration profiles, and security baselines aligned with organizational standards.
- Administered application deployment for Win32, MSI, and Microsoft Store apps using assignment groups and targeted deployment strategies.
- Monitored device health, compliance status, and remediation through Endpoint Manager reporting.
- Implemented and supported Windows Autopilot for zero-touch device provisioning.
- Registered devices through hardware hash import, OEM integration, and Azure AD enrollment workflows.
- Designed and deployed Autopilot profiles including User-Driven, Self-Deploying, and Hybrid Azure AD Join scenarios.
- Streamlined onboarding processes, reducing manual provisioning time and improving end-user experience.
- Packaged and deployed applications using the Intune Win32 packaging tool and MSI-based installers.
- Created detection rules, requirement rules, and dependency chains for reliable software deployment.
- Troubleshot application deployment failures using Intune Management Extension logs and Event Viewer.
- Maintained version control and update lifecycle management for enterprise applications.
Champion Solutions Group
- Packaged and deployed thousands of applications across Windows, Linux, and macOS environments.
- Led enterprise BigFix implementation replacing legacy tools across multi-OS environments.
- Developed custom Fixlets, baselines, and compliance content for enterprise clients.
- Supported Windows 10 migration strategy using BigFix automation and lifecycle tools.
- Designed and implemented Operating System Deployment (OSD) solutions leveraging zero-touch provisioning, MDT, and HCL BigFix to deliver seamless, automated deployments across multiple Windows operating systems.
- Streamlined build and deployment processes, reducing manual intervention and improving consistency across enterprise endpoints.
- Integrated zero-touch strategies with modern provisioning tools such as Windows Autopilot and Microsoft Intune to support hybrid and cloud-managed environments.
- Developed and maintained standardized OS images, task sequences, and driver management for diverse hardware models.
- Automated post-deployment configuration, including application installs, security baselines, and domain/Azure AD join processes.
- Troubleshot and optimized OSD workflows, improving deployment success rates and reducing build times.
Client: The Children’s Place (via CSG)
- Managed BigFix deployments across retail POS infrastructure including registers, scanners, and pin pads.
- Built PKI certificate monitoring and renewal automation from CSR generation through deployment.
- Developed API-based automation to track hardware warranties across OEM platforms.
- Implemented phased rollout strategies to minimize operational disruption nationwide.
IBM
- Designed and implemented BigFix solutions for patching, reporting, and endpoint management.
- Built custom reporting frameworks leveraging BigFix Web Reports and Excel integrations.
- Delivered enterprise Windows 10 upgrade solutions including bare-metal and in-place upgrades.
- Developed custom compliance and security scanning solutions for audit readiness.
Computer Sciences Corporation (CSC)
- Designed and managed BigFix environments for multiple enterprise clients.
- Built custom Fixlets, reporting, and compliance dashboards across Windows and UNIX systems.
- Implemented lifecycle management processes including patching, software distribution, and reporting.
- Developed automation for software deployment including Java, Adobe, and Microsoft Office.
- Designed relay architectures and optimized content distribution strategies.
Earlier Experience
- The Zenith – Senior Systems Analyst / BigFix Administrator
- Citigroup – Information Systems Manager
- U.S. Navy – Information Systems Manager
Technical Skills
- Endpoint Management: BigFix (11.x, 10.x, 9.x), SCCM/MECM, Tivoli Endpoint Manager, Microsoft Intune, Windows Autopilot
- Operating Systems: Windows Server (2003–2016+), Windows 10/11, RHEL, AIX, Solaris, HP-UX
- Automation & Scripting: PowerShell, Shell Scripting, PERL, PHP
- Deployment & Packaging: OSD, MDT, Intune Win32 Packaging, MSI Packaging, Task Sequences
- Infrastructure & Tools: Active Directory, Azure AD / Entra ID, WSUS, SQL, REST APIs, IIS, SharePoint
- Networking & Storage: TCP/IP, Cisco Networking, SAN/NAS (EMC, NetApp)
- Security: PKI, Certificate Management (CA/RA), Compliance & Audit Frameworks, Security Baselines
Education & Credentials
- Master’s: Information Systems Management, University of Phoenix
- Bachelor’s: Information Systems, Strayer University
- Certification: IBM BigFix Administrator (2018)
- Security Clearance: Active Public Trust (2021)
Projects
- Post-Quantum Cryptography API: Developed an API supporting NIST PQC standards for quantum-ready encryption and digital signature workflows.
- ML-KEM (Kyber): Key exchange
- ML-DSA (Dilithium): Digital signatures
- SLH-DSA (SPHINCS+): Long-term integrity