A technology expert with over 25 years of experience in macOS fleet management. Successfully managed and secured a large macOS fleet of 180,000 devices. Proficient in provisioning, configuration management, software deployment, security, and monitoring across diverse Mac and UNIX environments.
Experience
2024 — Now
New York, New York, United States
2006 — 2024
2006 — 2024
New York City Metropolitan Area
Tech Lead, founding member, and key contributor to the Mac Operations team, successfully managed a global fleet of over 180,000 macOS endpoints. Led the team to effectively manage a 100x increase in endpoints. Spearheaded the deployment of 15 major OS releases (OS X 10.5 to macOS 14) and all minor releases and security updates, ensuring swift uptake and minimal user disruption. Implemented automation and optimization techniques, enabling significant growth in the macOS fleet while maintaining a small team size.
• Spearheaded the initial rollout and ongoing maintenance of Puppet (from versions 0.24 to 7.2).
• Designed and deployed Puppet in a standalone mode, eliminating the need for dozens of configuration servers, resulting in reduced infrastructure costs and improved operational efficiency.
• Implemented fully automated configuration management releases, freeing up team time for higher-value initiatives.
• Partnered with Apple engineers to diagnose and report complex Mac fleet management issues at scale, leveraging expertise in troubleshooting and problem-solving. This collaboration led to the development of improved fleet management tools and processes for Apple.
• Evolved and implemented Mac configuration policies from using MCX within LDAP, to local profiles with a custom Puppet provider, and finally to a custom in-house MDM solution.
• Developed and maintained multiple internal tools for fleet management, access controls, and user support. Written primarily in Python, Ruby, and Shell, as well as some Go and Obj-C.
• Deployed and maintained Munki, coupled with Simian (a platform for dynamic software manifest generation), for efficient and scalable package management.
• Collaborated with security and other infrastructure teams to ensure the safety, usability, and maintainability of the fleet.
• Primary engineer for configuration management, inventory, and trusted platform data collection tools, ensuring consistent configurations and accurate data collection.
2005 — 2006
2005 — 2006
New York, New York, United States
Leveraged expertise in Mac, Linux, and Windows to provide comprehensive technical support for a diverse user base, both locally and remotely. Successfully diagnosed and resolved hardware, software, and network connectivity issues, ensuring user productivity and system uptime. Additionally, proficient in troubleshooting networking components, contributing to a reliable and secure IT environment.
* Implemented automated imaging for Macs for the local inventory team, increasing speed of imaging and reducing hands-on time.
* Successfully resolved complex technical issues, including hardware malfunction, software configuration, and network connectivity challenges, during on-site support visits in Toronto, Waterloo, and Montreal, ensuring user productivity and minimizing downtime.
2002 — 2005
2002 — 2005
New York, New York, United States
Provided comprehensive technical support and systems administration to the creative and marketing team, including troubleshooting hardware and software issues, managing user accounts and permissions, maintaining network connectivity, and offering guidance on software applications.
* Led a complete Mac OS 9 to OS X migration rollout and a workflow switch from QuarkXPress to InDesign.
* Created a NetBoot/NetInstall image for efficient initial installation of macOS, streamlining the onboarding process for new hires. Additionally, established a centralized software deployment system using Radmind, enabling controlled and efficient push of future software updates and security patches, reducing deployment time.
* Migrated AppleShare IP to Mac OS X Server. Upgraded server hardware infrastructure to Xserve and Xserve RAID.
* Configured and maintained Open Directory and managed preferences, web server, DNS and DHCP services, integration with Windows NT/2000 network, and an externally-available FTP site.
* Deployed and managed Open Directory using LDAP for centralized managed preferences and user and group management, administered and secured a highly reliable Apache web server, facilitated seamless integration with Windows NT/2000 network, and managed an externally accessible FTP site.
* Used Apple Remote Desktop and VNC. Setup and configured Cisco VPN, L2TP, IPSec and PPTP for remote access capabilities.
* Set up and maintained high-end color printers and inkjets as well as RIPs. Implemented color management.
2001 — 2002
2001 — 2002
New York City Metropolitan Area
Worked with numerous small businesses to support and maintain their systems.
* Coordinated and implemented the integration of Canto Cumulus digital asset management system, including integration testing with Quark, InDesign, Photoshop, and Illustrator; training of IT and production managers; and roll-out. Set-up web interface to the Cumulus asset store via Apache-based web server.
* Help desk triage and troubleshooting for Mac and Windows users covering day-to-day problems. Used and helped to maintain a help desk trouble-ticket database.
Education
New Mexico State University
1991 — 1994
New Mexico Military Institute
1987 — 1991