Amazon Web Services — Corporate Security · Endpoint Platform Team
Jan 2019 – Present · San Luis Obispo, CA
Primary SME for CrowdStrike Falcon operations across a 1.8-million-device corporate fleet. Triage, vendor engagement, module rollouts, incident response, production tooling.
Systems Engineer II L5 · Current
Apr 2024 – Present
Served as Amazon's primary SME during the July 2024 Channel File 291 global outage — the biggest IT incident in industry history. Primary SME for Falcon operations across the 1.8M-device fleet: sensor deployment and policy tuning, exclusions, custom IOA and IOC authoring, Spotlight vulnerability management, agent lifecycle, and cross-platform incident response. Partnered on rolling out five new Falcon modules at scale (F4IT, Firewall, Spotlight, Device Control, Installation Tokens). Shipped the Windows repair script that cut team escalations by 90%, and reduced high-CPU ticket intake by 90%+ through KB articles and runbook documentation that moved routine investigations to self-service.
Systems Engineer I L4
Mar 2020 – Apr 2024
Joined the Endpoint Platform team as a Falcon operator to learn the stack end-to-end. Earned CrowdStrike Certified Falcon Administrator (CCFA) to formalize the platform knowledge, then expanded into sensor deployment, policy tuning, exclusions, and vendor case management. Investigated fleet-impacting EDR regressions across Linux, macOS, and Windows — kernel-level performance issues, sensor conflicts with other security agents, and host-visibility bugs — coordinating fixes directly with CrowdStrike engineering.
IT Support Engineer II
Jan 2019 – Mar 2020
Tier-2 endpoint support for Amazon corporate users. Built the grounding in Amazon's corporate endpoint stack that led straight into the Endpoint Platform team.