Senior Software Developer & DevOps Engineer
20+ years in software engineering, DevOps, and infrastructure automation.
Professional Summary
Senior Software Developer and DevOps Engineer with 20+ years building
and securing enterprise software and Linux infrastructure for NIH, DOE,
and NNSA. Hands-on expertise in Python, PHP, Ruby, Puppet, Terraform/OpenTofu,
GitLab CI/CD, HashiCorp Vault, VMware vSphere, and REST API development.
Builds full-stack applications, repeatable infrastructure automation,
secrets-management systems, and security tooling in FISMA-regulated
and FIPS environments. Brings 14+ years of fully remote delivery across
federal and commercial teams.
Core Competencies
Software Engineering & API Development
PHP, Python, Ruby, Bash, Perl, CakePHP 5, Symfony, MVC, REST APIs, SQL,
HTML, CSS, JavaScript, Composer, PHPUnit, PHPStan, PSR Standards, JSON, YAML
Infrastructure-as-Code & Automation
Puppet (20+ Custom Modules), Terraform/OpenTofu, HashiCorp Packer,
VMware vSphere, HCL, EPP Templates, GitOps, R10K, Infrastructure-as-Code (IaC),
Configuration Management, Kickstart, cloud-init
CI/CD & Platform Delivery
GitLab CI/CD, GitLab Runner, Docker, Podman, Terraform Module Registry,
Documentation-as-Code, MediaWiki Automation, Package and Release Automation
Secrets, Security & Compliance Engineering
HashiCorp Vault, Vault Raft Clustering, AppRole Authentication, Vault KV,
SSH Certificate Authorities, Zero-Trust IAM, PAM Access Controls, FISMA,
CIS Benchmarks, FIPS Compliance, SELinux, TLS/PKI, Vulnerability Management,
Endpoint Security Agent Orchestration
Linux, Observability & Security Analytics
Red Hat Enterprise Linux (RHEL 9/10), Ubuntu, Alpine Linux, Nginx,
Apache HTTP Server, PHP-FPM, MySQL, PostgreSQL, SQLite, Splunk,
Splunk Add-on Builder, Opsview, NetBox, Infoblox WAPI, Jira, ServiceNow
Professional Experience
Senior Software Developer & DevOps Engineer (Contractor)
NIH (National Institutes of Health) - OD/OCIO/ISAO | Rockville, MD
10/2017 - Present
Contracting Companies: Triumph Enterprises (2017-2021), IBM (2021-Present)
Fully Remote
Lead developer and infrastructure automation and site reliability engineer for
NIH's Information Security and Assurance Office. Designs and delivers production
software systems, GitOps CI/CD frameworks, secrets management infrastructure,
and enterprise security tooling across a large-scale, multi-OS hybrid-cloud server fleet.
-
Secrets Management Infrastructure:
Engineered an automated HashiCorp Vault lifecycle pipeline using custom Puppet modules
and Bash orchestration for server initialization, dynamic multi-key unsealing,
and AppRole client enrollment; eliminated manual initialization and unsealing steps
while securing key-shares with strict access controls and environment variable fallbacks.
-
Zero-Trust Identity & Access Management:
Designed and deployed a Zero-Trust IAM module to automate enterprise PAM login policies
and multi-OS sudo sanitization; integrated HashiCorp Vault APIs to orchestrate authentication,
Vault-signed SSH Certificate Authorities, and dynamic public key distribution, removing
reliance on static user passwords across managed hosts.
-
Enterprise Infrastructure Automation:
Authored and maintained 20+ custom Puppet modules managing the security-agent and
configuration lifecycle across hundreds of multi-OS servers (RHEL, Ubuntu, Windows)
- covering Microsoft Defender for Endpoint, Tenable Nessus, FireEye, IBM BigFix, Opsview,
and GitLab CI/CD runners through consistent, code-managed configuration.
-
VM Image Automation:
Engineered a unified suite of FIPS-compliant virtual machine base image templates
(RHEL 9, Ubuntu 24.04, RHEL 10) using HashiCorp Packer and VMware vSphere;
integrated live Vault API lookups for credential-less builds and implemented noexec
bypass provisioning, standardizing automated OS image delivery across enterprise
environments.
-
Infrastructure-as-Code (IaC) Provisioning:
Built a multi-phase VMware VM provisioning framework using Terraform and custom
Bash orchestrators; automated VM cloning, dynamic block storage partitioning, RHSM
subscription licensing, Puppet agent bootstrap, and Vault SSH CA enrollment,
removing static deployment credentials from the provisioning workflow.
-
GitOps CI/CD Framework & Documentation-as-Code:
Architected an enterprise GitLab CI/CD component library and Documentation-as-Code
(DaC) pipeline; automated Terraform module packaging and developed a programmatic
Markdown-to-wikitext conversion engine (pandoc + JSON) to publish structured
project documentation directly to the NIH Knowledge Base, reducing manual
documentation publishing.
-
Cryptographic Certificate Automation:
Engineered a cross-platform Certificate Authority (CA) deployment module and
automated TLS certificate synchronization engine; added runtime cryptographic
fingerprint auditing (openssl SHA1) before system trust-store enrollment to protect
RHEL, Debian/Ubuntu, and Windows Server environments from certificate injection.
-
Splunk Application Development:
Engineered custom Splunk applications in Python for threat intelligence ingestion,
automated network threat blocking, dynamic CIDR-to-organization lookup tables, and
environmental monitoring log ingestion - each with full GitLab CI/CD pipelines,
unit tests, Bandit security scanning, and Splunk AppInspect validation.
-
Infrastructure Inventory & Asset Management:
Maintained comprehensive infrastructure asset documentation and datacenter rack
inventory using Netbox and Racktables to support capacity planning, change
management, and audit readiness across the hybrid-cloud server fleet.
Senior Software Developer & Cybersecurity Analyst (Contractor)
NIH (National Institutes of Health) - OD/ORS/ITB | Rockville, MD
03/2012 - 10/2017
Contracting Companies: OnPoint Consulting (2012-2013), SAIC (2013), Leidos (2013-2017)
Fully Remote
Engineered multiple secure web-based tracking portals and custom processing systems to support
NIH security, compliance, and counterintelligence operations.
-
FISMA Compliance Portal Suite:
Developed and maintained multiple custom PHP portals for the Counterintelligence,
Security Officer, and SA&A teams - tracking FISMA system hierarchies, hardware
sanitization workflows, Active Directory exemptions, and removable media custody
chains with executive-level reporting dashboards.
-
Secure File Processing Libraries:
Authored custom CakePHP libraries to extract, sanitize, and process complex
structured data from raw Excel, PDF, and RTF source formats - enabling automated
data ingestion from multi-source agency reporting tools.
-
Multi-Portal Architecture:
Designed shared plugin and library architecture allowing management and updates of
multiple independent portals at a macro level, reducing code duplication and
accelerating feature delivery across the portal suite.
-
Executive Reporting:
Architected real-time reporting dashboards providing agency leadership with
continuous visibility into security posture, asset custody, and compliance status.
Cybersecurity Analyst & Software Developer (Contractor)
Department of Energy (DOE) | Germantown, MD
02/2009 - 03/2012
Contracting Companies: Energy Enterprise Solutions (2009-2011), OnPoint Consulting (2011-2012)
Fully Remote
Built custom security analytics platforms and network threat correlation systems for
DOE's Cyber Security Team - entirely via telework.
-
Threat Analytics Platform:
Developed web applications enabling analysts to dynamically search, analyze, and
correlate large volumes of enterprise network traffic against known and emerging
threat vectors - improving threat detection speed and analyst efficiency.
-
Parallel Processing Network:
Engineered a budget-conscious parallel processing cluster to handle high-throughput
network traffic analysis across an enterprise-scale network - dramatically
increasing processing capacity without significant capital investment.
-
Secure API Integration:
Authored secure REST APIs to enable authenticated, standardized data sharing between
isolated security platforms - establishing a common integration layer across the DOE
security toolchain.
Web Master (Contractor)
National Nuclear Security Administration (NNSA) - Nevada Site Office | Las Vegas, NV
07/2008 - 02/2009
Contracting Company: Energy Enterprise Solutions
-
Managed and updated the primary NNSA external-facing public portal under direction
of the Director of Public Relations.
-
Initiated a comprehensive portal modernization effort to bring design and
usability in line with current web standards.
Intermediate Security Analyst (Contractor)
Department of Energy (DOE) | Germantown, MD
10/2007 - 07/2008
Contracting Company: Energy Enterprise Solutions
-
Monitored intrusion detection and prevention systems; blocked malicious hosts and
reported suspicious activity.
-
Analyzed existing security workflows and engineered custom web applications to
automate manual monitoring steps - transitioning the role from reactive incident
response to proactive threat hunting operations.
Technical Director
ImageWorks Studio | Chantilly, VA
03/2003 - 10/2007
-
Designed, developed, and secured LAMP-based web applications and MySQL databases
for 50+ commercial clients.
-
Administered high-availability Linux production servers hosting critical web,
email, and application services.
Web Master & Systems Administrator
IP Group | Herndon, VA
02/2001 - 03/2003
-
Co-developed a custom enterprise e-commerce platform using PHP, Perl, MySQL, and
Apache (LAMP); designed and maintained multiple client websites and office systems.
Education
Northern Virginia Community College
Focus in Computer Science and Information Systems
2000-2001
Twentynine Palms High School
General Studies
1995-1999