Systems Administrator
@ Aalis Management Consulting · Alexandria, VA (Remote) · 50+ users, 30+ endpoints, CUI · two-person technical team with the CTOBuilt the automation layer the company runs on: PowerShell, Microsoft Graph, and Power Automate systems for onboarding/offboarding and license lifecycle, security alert routing, compliance document generation, invoicing, and recurring status reporting. Estimated 1,200+ staff-hours returned annually.
Raised Microsoft Secure Score from 54.5% to 83.6% across 30+ endpoints through configuration remediation, Conditional Access and MFA enforcement, least-privilege access controls, and endpoint hardening.
Investigate phishing and security events in the Defender XDR incident queue using KQL Advanced Hunting, email header and message-trace forensics, and Entra ID sign-in logs; remediate affected mailboxes and identities and escalate to leadership.
Ran the investigation of a data-handling incident involving improper access to sensitive records — preserved audit-log evidence, reconstructed the timeline, scoped exposure, and delivered written findings to executives.
Primary author of the SSP and POA&M, producing roughly 70% of the compliance program under NIST SP 800-171 and DFARS 252.204-7012; co-led the self-assessment behind a 110/110 SPRS score and current CMMC Level 2 preparation.
Wrote and maintain 12+ policies, runbooks, and SOPs covering incident response, access control, onboarding/offboarding, audit readiness, and the company's AI acceptable-use policy — authored as the de facto owner of AI adoption. Brief executives directly on posture, risk, and remediation.