Sr. Cybersecurity Engineer
C. H. Robinson WorldwidePRIVATEEden Prairie, MN · Oct 2021 – Present
Scope: Senior-level IC on a dedicated Cybersecurity Engineering team inside a Fortune 500 multi-national enterprise (~12,000 employees). Security initiatives aligned to NIST CSF 2.0 and CIS Controls v8. Security consulting for peer technology and engineering teams.
PKI / Certificate Lifecycle Management (2023 – Present)
- Led a 3-year enterprise PKI modernization, including a rebuild of the offline root CA as a Windows Server 2022 VM on two redundant, network-isolated Hyper-V hosts kept in a data-center safe. The rebuild replaced a racked 2U server, cut root-CA hardware and licensing cost ~50% (~$8K → ~$4K, one-time), and improved the operational CRL publication process and procedures.
- Reduced certificate-expiry outages, previously 2–4 per year from late deployments and untracked expirations, through Venafi discovery and automated renewal across ~1,500 certificates.
- Recovered ~600 engineering hours per year by implementing Venafi certificate automation on F5 load balancers.
- Deployed 2 new internal ADCS issuing CAs for redundancy, and unified public and private certificate lifecycle by integrating GlobalSign (public CA) alongside ADCS via Venafi.
- Extends certificate lifecycle automation into Azure Key Vault for cloud-native workloads (in progress).
- Used Claude (Sonnet and Opus), with ChatGPT, to produce the offline root CA rebuild's runbooks, configurations, test scripts, procedures, and technical documentation.
- Engaged directly with PKI engineering leads at Microsoft and Venafi to resolve architecture gaps; led enterprise-wide technical briefings on CA/Browser Forum Ballot SC-081, which cuts public TLS certificate validity to 200 days from March 2026 and 47 days by 2029.
Network Segmentation & Traffic Legitimization (2026 – Present)
- One of five engineers on the company's first enterprise network micro-segmentation program, a multi-year Zero Trust initiative covering ~10,000 user endpoints in 37 countries.
- Traffic legitimization (whitelist-build) sub-project: reviews firewall logs for network flows of interest and breaks them into manageable sets to rationalize the corporate firewall rule base; thousands of rules under analysis. Uses GitHub Copilot with MCP tooling to correlate those flows and Palo Alto firewall rule sets with Microsoft Defender workstation logs, generating a technical narrative for each set.
AI Operationalization (2025 – Present)
- Trains the Cybersecurity Engineering team, as its AI superuser, to use AI tooling in engineering and operations; builds project- and task-based GitHub Copilot workflows, prompt libraries, and environment configurations.
Security Awareness & Phishing Simulation (2022 – Present)
- Drove enterprise phish-prone percentage (PPP) from 8–10% down to 2–5%, a sustained year-over-year reduction across all ~12,000 employees, by owning the full KnowBe4 security awareness and phishing simulation program, including monthly simulations with automated closed-loop remediation for anyone who fails.
- Runs at-least-quarterly phishing tests of every population group (targeted campaigns and training tracks for privileged and high-risk users), designs and runs the annual Cybersecurity Awareness Month campaign, and administers Corporate Compliance Month security training.
Enterprise SSO (2022, completed)
- Delivered enterprise SSO on Microsoft Entra ID, onboarding 50 applications and sites to centralized identity management.
Third Party Risk Management (TPRM) (2022, completed)
- Stood up the third-party vendor risk management process; transitioned ownership to a dedicated department once the program was operational.
SOC Analyst
C. H. Robinson WorldwidePRIVATEEden Prairie, MN · Jun 2019 – Oct 2021
Scope: Build and operationalize the company's first Security Operations Center. Develop SIEM/SOAR functionality, build-out investigative workflows, and further develop detection capabilities.
- Co-engineered the company's first SOC and SIEM/SOAR (LogRhythm), with log sources including server event logs, firewalls, Cisco ISE, VPN, Okta, Azure, and internal security systems. Built alert rules, behavioral detections, incident management workflows, and operational playbooks while simultaneously operating the live environment.
- Built behavioral detection models by baselining user behavior, network traffic, and system-resource patterns, then engineering alert rules on deviations; integrated threat-intelligence feeds for real-time situational alerting.
- Automated alert adjudication, incident creation, and tiered escalation/notification with PowerShell.
- Authored the full library of operational, scenario-based, and incident-based playbooks; documented all SOC workflows and processes from scratch (greenfield: no prior documentation existed).
- Handled business email compromise (BEC) incidents and wrote the SOC's BEC response runbook.
- Helped staff and scale the SOC to a global follow-the-sun model; interviewed ~24 analyst candidates over 18 months to build out the international team.
- Aligned SOC operations to NIST CSF 1.1 and CIS Controls v7.1 (v8 from May 2021); collaborated cross-functionally with corporate and technology departments to develop policy, standards, and escalation workflows.
Information Security Analyst
Minnesota State LotteryPRIVATERoseville, MN · 2018 – 2019
Scope: Sole practitioner securing the agency's information systems.
- Developed and enforced information security strategies, policies, and technical standards in a high-governance, heavily regulated environment.
- Conducted technical security reviews of business and information systems; ensured security posture met state and industry regulatory requirements.
- Ensured the agency's LogRhythm SIEM was configured to meet security policy requirements; used it occasionally for operational issues.
Network Security Engineer
University of Minnesota, Office of Information TechnologyPRIVATEMinneapolis, MN · 2017 – 2018
Scope: Primary technical SME for a $14M enterprise firewall and UTM modernization (Cisco ASA to Fortinet) spanning ~70,000 endpoints across all five campuses, as part of an $80M network infrastructure overhaul and the system's first core-network rebuild in 25 years.
- Designed logical firewall and UTM policy architecture, configurations, and rule-sets. Led data-center firewall equipment deployment, and collaborated with multiple technology teams and vendors to debug platform performance issues and resolve hardware/software defects.
IT Infrastructure Manager
Boynton Health, University of MinnesotaPRIVATEMinneapolis, MN · 2010 – 2017
Scope: Managed IT Service Desk and Infrastructure groups (9–12 FTE) supporting ~600 endpoints and ~85 servers in an academic healthcare environment.
- Remediated 19 essential IT audit findings from an institutional internal audit within 18 months.
- Led the full physical relocation of the enterprise IT data center and systems, managing risk, continuity, and coordination across multiple stakeholder groups.
- Contributed to ISO 27002 committee work in support of the institution's ISO 27001 program.
- Collaborated with Boynton Health administrators on HIPAA Security and Privacy Rule compliance for every system that handled patient information.
- Hired, mentored, and managed performance and career development across both teams.
Earlier Career: Sr. Systems Engineer
Mystic Lake Casino HotelPRIVATEPrior Lake, MN · 2002 – 2010
Built foundational IT operations and systems-management expertise in a 24/7/365 high-availability environment (~3,500 employees, ~5,000 endpoints, 7,500–30,000 daily guests, 350-room hotel). Implemented and administered PCI DSS controls for several credit-card systems and their integrations, supporting the underlying technology for dozens of card-accepting businesses on the property, from the hotel and restaurants to the gift shops and golf course.
Technologies: Oracle · MS SQL · UNIX · Micros (Hospitality POS) · Property Management System (PMS) · Electronic Payment / Card Processing · Document Imaging · Windows Server · Virtualization · Patch Management
Career origins (1998–2002): Entered enterprise technology at a national call-center (Sr. Support Specialist: Tier-2 support, staff training, and QC) and full-service brokerage house (Technical Support: online trading-system QA and desktop support; designed and managed a multi-platform Windows/Linux/Mac test lab).