Cloud & Microsoft 365
- Microsoft 365 Admin
- Exchange Online
- SharePoint
- Teams
- Entra ID / Azure AD
- Cloud Migration
- AWS S3 / Lambda
- Cloudflare Workers
Houston, TX · Infrastructure · Security · Automation
IT Systems Architect & Cybersecurity Engineer
I design, secure, and automate the entire technology stack of a growing company — cloud, telephony, security, and the apps that hold it all together.
01 — About
I'm Jonathan — the entire technology department for a Houston-based financial services company. For nine years I've owned every layer of the stack: the network, the servers, Microsoft 365, the phone system, the CRM, security, and the help desk.
Since 2024 I've run all of it solo. When something doesn't exist yet, I build it — cloud migrations, call-routing logic inside the dialer, AI voice agents that qualify inbound calls, internal web and desktop apps, and the automations that keep everything talking to each other.
I hold a B.S. in Cybersecurity and am completing a Master of Science in Cybersecurity (GPA 3.73) — all while raising my daughter full-time. I like hard problems, clean systems, and shipping things that actually work.
02 — Skills
Built over nine years of being the person everything lands on.
03 — What I Build
Moving entire companies off on-prem and into the cloud — phone systems, CRMs, file storage, and every user — with zero downtime.
Penetration tests, incident response, hardened Linux servers, intrusion detection, honeypots, and dashboards that watch the network in real time.
Inbound call routing inside the dialer — state-based queues, custom AGI logic, SIP trunks, and vendor integrations that get callers to the right agent fast.
Voice AI that answers, pre-qualifies, and transfers live calls — plus the platform migrations and cost models that decide which vendor runs it.
Power Automate + Graph API flows, cloud archiving pipelines, Zapier and webhook integrations that wipe out repetitive manual work.
Laravel and Node web apps, Electron desktop tools, and internal portals that solve problems no off-the-shelf product does.
Turning messy call-center and sales data into clean reports, funnel diagnostics, and interactive dashboards that drive decisions.
Fast, modern, responsive sites — from WordPress business builds to hand-coded portfolios and Next.js applications.
04 — Featured Projects
Real work, described at a high level — no client data, company names, or internal numbers shown.
Authorized external penetration test of a Houston art museum's dual-WAN Meraki MX95 firewall. Scoped, documented, and executed under a signed rules-of-engagement and authorization letter, then delivered as an actionable remediation report to the client's Director of IT.
Designed and shipped an AI voice layer that answers inbound vendor calls, pre-qualifies the caller, and hands them to a licensed agent — one agent per vendor line. Then diagnosed a platform-level billing defect where the AI leg kept metering after handoff, built the business case, and re-architected the whole voice layer onto a new provider.
A body of work on a hosted ViciDial dialer: audited and mapped the full inbound flow (router → silent IVR → area-code lookup → per-state queues → overflow), then engineered targeted changes to fix real business problems.
A Laravel web portal that replaces a paper-and-email onboarding process. Admins manage a library of multi-carrier fillable PDF contracts, assign them to new agents, and control field-by-field who can edit what. Agents fill, sign, upload supporting docs, and submit.
Digitized every carrier underwriting guide into a rules engine. An agent enters a client's demographics, conditions, and medications and gets back the carriers they qualify for, the policy tier, a quote, and carrier-specific underwriting notes — in seconds instead of flipping through spreadsheets.
Replaced a broken, decade-old quote form on the company website with a fast, hand-built quoter that returns real carrier pricing from age, tobacco status, state, and coverage amount — and feeds every lead straight into the dialer and a tracking sheet.
Ground-up rebuild of a financial services company's public site — replacing a decade-old, plugin-choked WordPress install with a clean WordPress + Elementor build on managed cloud hosting behind Cloudflare. Owned it end to end: server provisioning, page builds, a 311-post blog migration, and the go-live strategy.
A single fatal-error email led to an orphaned WordPress server on legacy shared hosting that nobody knew was still running — on PHP unpatched since 2018 and publicly reachable. Ran the full investigation from external recon through evidence-preserving containment, and wrote the decision memo management used to safely shut it down.
Self-hosted Flask dashboard with Suricata IDS, a honeypot, auto-banning via Fail2Ban + UFW, nmap device discovery, and a clickable live threat map.
End-to-end lockdown of Debian 13 servers — SSH hardening, firewall rules, log parsing, automated HTML reports, and a public status dashboard.
Led a suspected-data-exposure investigation across M365, identity, CRM, and SaaS systems: playbook, evidence log, cluster analysis, containment, and findings mapped to breach-notification law.
Power Automate flows that parse phishing-report PDFs and Microsoft 365 alert emails into SharePoint lists with a single sortable dashboard.
Migration tooling and a nightly reconciled ledger that moves cold data and call logs from SharePoint to AWS S3 — thousands of rows a day with zero pipeline losses.
Server-to-Server OAuth exporter that inventoried and bulk-archived years of cloud recordings to S3, then enforced a retention policy so storage never overflows again.
Multi-phase Power Automate + Graph API pipeline that pulls AI call recordings and transcripts from the voice platform into SharePoint, then cleans up at the source.
Python + Graph API script that mined every Teams channel for reported tech issues, plus a nightly flow that keeps a searchable SharePoint tracker current.
Email-triggered Power Automate flow that hands the raw report to an Excel Office Script, rebuilds it as a clean table, and posts it to the sales team's Teams channel every night — no one touches a spreadsheet.
Zapier and Twilio automations for client welcome letters and SMS notifications, plus reverse-engineered and repaired Power Automate reporting flows.
A voice AI that plays the customer — random personas, randomized difficulty, realistic-but-fake details — so agents can drill objections and closes on demand.
A rules engine wearing a chat interface — not generative — that walks a lead through health questions and returns the three best carrier quotes they actually qualify for.
Electron desktop assistant with an animated avatar, voice in/out, screen vision, agentic actions, and persistent memory — built on the Claude API.
Authored reusable AI workflow skills — interruption-resilient project memory, a full website scaffolder with a design search engine, and a call-flow analyzer.
Python pipeline that scripts, renders, and schedules daily IT tips with animated backgrounds and karaoke-style captions synced to recorded voice.
Decision-tree support bot embedded as a Teams tab — zero AI cost — that walks staff through fixes and escalates the full transcript to IT when it can't.
Standalone Node/Express app with JSON storage and JWT admin/worker roles that tracks projects, tasks, notes, and activity — plus a Cloudflare email worker.
Next.js 16 + Prisma + MariaDB app for a gaming community: inventory, crafting library, rank-based permissions, tasks, and a threaded message board with @mentions. Public over HTTPS.
A WordPress-admin-meets-Elementor platform: drag-and-drop visual editor, responsive controls, form and popup builders, plugin architecture, and a one-click installer.
Self-hosted study app with a rewards tracker, curriculum-aligned lessons, and an admin back-end — shipped with user and setup manuals.
SuiteCRM deployed on a hardened home server behind Nginx, plus a Plaid-connected personal finance dashboard (Flask + React + SQLite).
Pulled and analyzed a month of dialer data — agent and vendor performance, funnels, capacity math — and delivered written findings to ownership.
Reconciled eight months of platform invoices to within one percent and built the side-by-side cost model that justified a voice-AI vendor switch.
Single-pane dashboard pulling security and error signals from nine SaaS and infrastructure sources. Flask on Debian behind nginx + Let's Encrypt, gated by Cloudflare Zero Trust with the origin locked to Cloudflare IPs only.
A local mechanical-bull rental business site with a DevTools shield, an actor portfolio (Astro), an author site, anime-themed art sites, and this portfolio.
05 — Education
Coursework: Risk Management, Information Security Governance, Incident Response Planning, NIST CSF 2.0, CMMC / NIST 800-171 Compliance, Cyberterrorism, and Healthcare Cybersecurity.
Foundations in security architecture, networking, systems administration, and risk — the groundwork behind everything on this page.
06 — Contact
Got a project, a role, or a problem that needs solving? Reach out directly.
Email me