Principal Software Engineer
August 2019 — PresentOracle Cloud Infrastructure — Seattle, WA
- Own identity and authorization infrastructure for isolated, sovereign, and dedicated cloud environments, spanning the internal authorization platform, just-in-time access service, and identity provider federation.
- Led design and delivery of the identity and permissions capabilities required for fully automated region bring-up, so new regions bootstrap policy provisioning and directory synchronization with no manual intervention.
- Broke a cyclic dependency between the internal authorization platform and a legacy corporate identity provider, clearing the path to a modern provider with phishing-resistant hardware login in place of one-time passwords; led identification and migration of affected users without loss of access.
- Authored the infrastructure-as-code provider for the authorization service, letting partner teams declare access resources directly instead of filing requests; cut resource-creation time ~50% for our largest partner team and extended the provider with owner groups and membership separation as adoption grew.
- Led automation of credential rotation for a security hardening initiative — bootstrapped the rotator service, added service-principal support across internal and customer-facing environments, and integrated an SSH certificate authority, bringing each rotation to under 5 minutes with minimal manual involvement.
- Built security-key programming and lifecycle tooling for Windows, Oracle Linux, and secure-facility environments, including certificate provisioning for multi-factor workstation login, letting regional teams program and distribute keys for 1,000+ users locally instead of shipping from a single site.
- Cut entities under periodic access review from ~5,000 to ~200 by switching the reviewed entity from resources and groups to users carrying an eligibility attribute, reducing reviewer load without losing coverage.
- Added batching to the directory update pipeline, splitting a bulk change across ~40k accounts into batches of 500 so it landed incrementally instead of blocking on a single long-running thread; refactored a single-purpose directory syncer into a generic multi-domain sync job.
- Led design and delivery of an isolated administrative environment giving internal support engineers scoped, audited access to dedicated cloud distributions, integrating console, plugin, and partner applications, and drove it through architecture and security review boards; bootstrapped the resulting environments and automated their resource creation to remove most manual touch points.
- Delivered disaster recovery and multi-region administrative login with downstream partner teams, keeping dedicated regions reachable during a regional failure; added per-region timeout controls and dynamic adjustment for regions with degraded networks.
- Stood up a Windows Active Directory proof of concept end to end — network, jump hosts, gateway, directory, and group-policy login — then designed the pre-production and production architecture as a reusable deployment blueprint for future customers and regions.
- Mentor engineers through onboarding and their first designs; run brown-bag sessions and author the runbooks for the processes I own; act as technical point of contact for partner teams and program managers.