Systems & Platform Engineer · Reference node 001

I dig into messy cross-system problems until the root cause is clear — then I automate the fix.

Endpoint & identity engineering · Kubernetes / GitOps · automation · 20+ years

I've run endpoint, identity, and zero-trust infrastructure for 2,000–10,000-user federal environments — and I build API-first platforms, iOS prototypes, and Kubernetes infrastructure on the side. Washington, DC / remote.

Start here · no wrong answer

What brought you here?

Pick the closest fit. I'll ask one or two quick follow-ups only after you choose — then you send it. Today it opens email; in production this becomes the shared LLM intent-router for every node.

Offers

What I help with

The network's first categories are lessons, services, and local help. This node starts with my real service areas.

Service

Endpoint & employee platforms

macOS, iOS, Windows, Android. Jamf Pro, Intune, MDM baselines, device lifecycle, Tier-4 escalation.

Service

Identity & secure access

Okta, Entra ID, AD, Kerberos, PIV/YubiKey, PKI/CBA, Platform SSO, Zscaler ZTNA, SAML/OAuth.

Lesson

Automation walkthroughs

Python, Bash, PowerShell, ServiceNow & Jamf APIs, Azure Functions, Splunk pipelines, GitHub Actions, Terraform, k8s, ArgoCD.

Service

Incident & migration planning

Runbooks, tiger-team recovery, vendor coordination, audit evidence (FISMA/OIG), phased rollouts.

Exploration

AI-assisted product shaping

Claude/Cursor workflows, API-first prototypes, iOS exploration, dashboards, gentle intake experiences.

Network seed

Hosted profile design

Custom-domain profiles, offers/requests, reputation, public dashboards, portable-identity patterns.

Project dashboard

What I'm building

The Platform

Help wanted

A network of personal sites with shared discovery, reputation, and non-custodial BCH settlement. This page is node #1.

Need: a fintech/crypto attorney; CashScript/BCH escrow reviewers.

First-Catch

Active

An idea-management system — capture, triage, and route ideas to action.

Kubernetes / GitOps lab

Active

Personal clusters on DigitalOcean with Terraform, ArgoCD, and GitHub Actions — where production patterns get pressure-tested.

iOS exploration

Exploring

Native iOS prototypes and API-first experiments — onboarding flows, dashboards, intake.

Requests

What I'm looking for

Proof · why trust this node

Selected experience

2015–Present

Harmonics Consulting — CFPB

Director of Engineering / Sr. Mobility & Systems Engineer. Intune fleet of 2,000+ iPhones, Jamf Pro infrastructure, macOS/iOS Zscaler zero-trust migration, YubiKey rollout, PKI/CBA, Azure→Splunk logging, Tier-4 escalation.

2011–2015

SRA International — OPM & FDIC

Sr. Desktop Engineer. Led a 3-engineer team on a 9,000-node OPM environment; supported FDIC's 10,000-laptop Windows XP→7 migration with SCCM/MDT automation and security baselines.

2004–2011 & self-directed

Solid Systems, Inc. — founder / platform engineer

Ran an IT services business (30+ staff, 2,000+ engagements); later architected and operated a self-hosted email + affiliate-attribution platform — self-hosted mail infra (SPF/DKIM/DMARC), AffiliateWP attribution, multi-vendor API integration, and an eHawk-based fraud/data-quality pipeline. The origin of my Kubernetes and self-hosted-infra practice.

Reputation

Earned, not claimed — and portable

Reputation placeholder

No network ratings yet. Early trust comes from work history, references, and public project artifacts. On the network, reputation accrues only from real, completed work rated by the people on the other side of it.

Portability promise

Your site, your domain, your profile, offers, requests, and reputation — all exportable. A node should be useful because it helps, not because it traps you. Leave anytime, take everything.

Network note: this is one static node. The multi-tenant version moves content into per-profile records, routes by hostname (Cloudflare for SaaS), uses one template across custom domains, and swaps the email action for the shared intent-router API. Brand frontends can change language and styling without splitting accounts, reputation, requests, or settlement.