I build practical tools that turn IT operations, security evidence, and platform standards into clear workflows people can safely use. My portfolio combines hands-on operations knowledge with modern TypeScript applications, structured APIs, automation, observability, and human approval gates.
My current focus is the point where IT operations meets modern developer tooling: internal developer platforms, AI-assisted incident response, MCP integrations, cloud-native observability, identity security, and software supply-chain assurance.
| Project | What it demonstrates | Explore |
|---|---|---|
| Internal Developer Platform Portal | Service catalog, evidence-aware scorecards, golden paths, dependency context, policy-checked self-service plans, approval gates, and audit trails. | Live demo |
| IT Incident Triage Agent | Incident classification, confidence scoring, local runbook retrieval, read-only diagnostics, timelines, and human-approved response plans. | Live demo |
| MCP IT Ops Server | A safe Model Context Protocol server for local knowledge retrieval and allowlisted, read-only IT diagnostics with structured outputs. | Repository |
| Cloud Ops Observability Lab | OpenTelemetry-style metrics, traces, logs, alerts, SLOs, request correlation, and incident timelines in one operational view. | Live demo |
| Identity Security Posture Dashboard | Microsoft Entra-focused posture controls, fail-closed evidence scoring, remediation approvals, and auditable security decisions. | Live demo |
| Secure Software Supply Chain Dashboard | SBOM risk, SLSA provenance, attestations, policy gates, dependency evidence, and human-reviewed exceptions. | Live demo |
- Safe by default — local or synthetic infrastructure, read-only diagnostics, explicit allowlists, and no destructive actions.
- Humans remain accountable — plans and exceptions require an approve/reject decision before any action is represented as accepted.
- Unknown is not healthy — incomplete evidence stays visible as
NoDatainstead of silently improving a score. - Operations are explainable — structured JSON, timelines, evidence sources, runbooks, and audit events make decisions traceable.
- Delivery quality is part of the product — strict TypeScript, automated tests, GitHub Actions, security notes, Docker/Render configuration, screenshots, and demo guides.
Applications and APIs
TypeScript · React · Node.js · Express · Zod · Vite · REST · Structured JSON
Platform and operations
Platform Engineering · Service Catalogs · MCP · OpenTelemetry · SLOs · Incident Response · Runbooks · Docker · Render
Security and identity
Microsoft Entra ID · Active Directory · Microsoft 365 · Identity Lifecycle · SBOM · SLSA · Policy Gates · Auditability
Automation and delivery
GitHub Actions · Dependabot · PowerShell · Python · CI/CD · Human-in-the-Loop Workflows
- Offboarding Runbook Generator — dependency-aware IT offboarding plans with risk callouts, evidence requirements, and copy-ready commands. Live application
- Network Scanner Dashboard — Python and Flask connectivity dashboard with DNS handling, response times, port checks, and CSV export.
