Microsoft 365 Business Premium Migration
Architected a cloud-only M365 Business Premium tenant — identity, device and security policy across Entra ID, Intune and Defender XDR for a 130-user, four-office organization.
I’m a results-driven IT professional with a B.Sc. in Computer Science from Trent University and over six years across IT infrastructure, system administration, cybersecurity and identity management, spanning Canada and Sri Lanka. I keep enterprise environments scalable, secure and user-focused, managing complex systems, running deep root-cause analysis, and pairing technical depth with the leadership to move teams forward and hold the line on compliance.
I work fluently across modern IT ecosystems like Microsoft 365, Windows Server, VMware, ServiceNow and Active Directory, but the job is as much people as platforms. I’ve trained and mentored junior technicians, streamlined workflows and built cross-team collaboration, with a style that’s analytical yet empathetic. Grounded in both data-driven analysis and hands-on engineering, I gravitate to work where innovation and resilience matter, strengthening IT governance and cybersecurity practices and aligning technology to strategy so the systems I design stay secure, efficient and future-ready.
Underneath all of it, I see the world through a scientific lens, meeting problems with reason and curiosity and treating each one as a puzzle worth solving. I try to be the best version of myself not by chasing perfection but by embracing growth, learning, unlearning and relearning, letting curiosity fuel progress and resilience steady me through uncertainty. Every challenge teaches me something, and every success reinforces my belief that persistence, discipline and vision turn possibility into reality.
Served as sole IT authority for a 130-user, four-office organization. Led the Microsoft 365 Business Premium migration and built identity, device and security policy across Entra ID, Intune and Defender XDR. First responder for cybersecurity incidents; built the phishing-triage automation and formal cyber incident response procedure, and drove risk-assessed vendor evaluations for executive leadership.
Ran daily IT for 850+ users at a 24/7 airline contact centre. Managed 450+ Windows desktops and 500+ home thin clients via WYSE Management Suite and Citrix, plus Endpoint Central for patching, deployment, asset tracking and AD reporting. Escalation point for Genesys Cloud, networking and security incidents; led onboarding/offboarding, root-cause analysis and infrastructure upgrades.
Assessed and improved IT infrastructure across 16 corporate branches in the US and Canada, including a 350-user site. Built inventory management, floor-mapping and network-topology documentation to streamline ticket handling and first-level support.
Installed, configured and maintained telecom equipment across residential, commercial and outdoor sites. Diagnosed connectivity issues, performed preventive maintenance and delivered on-site customer support.
Delivered Level 1 and Level 2 global IT support in a 24/7 operation, coordinating with HP, Microsoft and Dell vendor teams to expedite service recovery. Documented troubleshooting methodologies for the IT knowledge base and led software and hardware deployment initiatives.
Architected a cloud-only M365 Business Premium tenant — identity, device and security policy across Entra ID, Intune and Defender XDR for a 130-user, four-office organization.
Designed and staged Conditional Access policies to move the org toward a true zero-trust posture, then cut over from security defaults in a single controlled maintenance window.
Rolled out Defender for Endpoint, Office 365 and Identity with attack-surface-reduction rules and Secure Score hardening across the estate.
Evaluated and deployed Firebox perimeter security across sites, with VPN provisioning and network segmentation, plus root-cause work to stabilize connectivity.
Built an agent in Copilot Studio that analyzes reported messages and accelerates first-pass assessment, cutting the manual load of routine email-threat review.
Transitioned IT services from the YPQ site to global locations — migrating agents to Azure Europe, planning data-center shutdowns, and coordinating the hardware-retirement strategy.
Complete overhaul of local Active Directory across sites to simplify operations and retire legacy Group Policy objects.
Zero-trust-aligned two-factor authentication for LHG applications using Microsoft Authenticator and Reiner SCT.
Moved Azure DaaS Citrix from RSA to Microsoft Authenticator — lowering licensing cost and consolidating to single-device authentication.
Stood up a PCI-compliant pen-test environment — three VMware machines inside the CDE VLAN with reserved IPs — as a recurring quarterly setup.
Structured cabling standards and full device mapping in Visio and NetBrain, with VLAN/IP documentation — improving uptime and cutting troubleshooting time ~30%.
Defined and validated firewall rules ahead of a bulk cut-over, and advised on implementation issues and the pack file for the YPQ site.
Migrated 400+ Dell OptiPlex thin clients with PXE and automated provisioning and standardized imaging — cutting voice issues from ~30% to ~7%.
Phased rollout replacing Dell 5040 and 5470 AIO units to improve security, cut energy use, and streamline centralized management in a VDI environment.
Built a Lucidchart visualization mapping servers across 16 branches, capturing switch configuration files and data-center information in one reference.
Migrated from Cisco to Ubiquiti switches, installed a patch panel, and deployed a server rack — improving network performance and physical organization.
Built and embedded the AI assistant powering this portfolio, using the Anthropic Claude API behind a Cloudflare Worker proxy, with streaming responses and voice output. It answers recruiter questions about my experience in real time — you're looking at it.