{
  "schemaVersion": 1,
  "profile": {
    "name": "Brandon Donaly",
    "headline": "Systems architecture across platform, network, security, AI & product engineering",
    "location": "Denver metro, Colorado",
    "email": "me@pakkit.net",
    "website": "https://pakkit.net",
    "summary": [
      "I work across platform automation, infrastructure, security, networking, and AI-assisted development, with 20+ years of hands-on software, networking, systems, and security experience. Most recently I spent 21 months as a Wireless Engineer III on the AAA/RADIUS authentication platform behind a national carrier's WiFi offload service.",
      "There I converted runbook-driven deployments into 6 versioned Ansible collections, owned a Cassandra operations programme, reverse-engineered undocumented RADIUS accounting logic into a behavioural-parity baseline for a platform rewrite, and built automation and test platforms across infrastructure, release engineering, security, and telecom policy.",
      "Later work included a deployed engineering chat assistant, native application SSO, infrastructure inventory reconciliation, and a Cassandra UDF optimization measured in development benchmarks."
    ],
    "preferences": {
      "role": "Senior to principal individual-contributor roles with architectural ownership",
      "engagements": "Employment and independent project work",
      "contactHref": "/contact"
    }
  },
  "presentation": {
    "intro": {
      "eyebrow": "Resume",
      "title": "Brandon Donaly, platform engineer.",
      "provenance": "Selected evidence from the completed Charter engagement. Output counts reflect an early-August 2026 snapshot of the project tracker, GitLab, git history, and internal wiki; later work is described in the experience record."
    },
    "securityResearch": {
      "eyebrow": "Security research",
      "title": "Critical findings, disclosure-safe.",
      "lead": [
        "I identified multiple previously undisclosed critical vulnerabilities rated CVSS 9.8, including SQL injection and unauthenticated remote code execution.",
        "Each finding was confirmed through controlled proof-of-concept testing and accompanied by technical evidence and remediation guidance for coordinated disclosure."
      ],
      "disclosure": "Coordinated disclosure is still open. The vendor, product, product category, application type, affected environment, employer or customer context, and implementation details are intentionally withheld.",
      "earlier": [
        {
          "title": "Own-vehicle embedded research",
          "text": "Reverse-engineered the media control unit of my own Tesla to obtain root access, then studied the embedded environment and application behaviour from the inside. Authorized by ownership."
        },
        {
          "title": "Learning-platform authorization flaw",
          "text": "Found and disclosed an authorization vulnerability in an online learning platform that exposed administrative access. Reported to the operator; the platform is not named here."
        },
        {
          "title": "Compromised game-cache implant",
          "text": "Compared 6,248 client scripts across original and modified releases to isolate an obfuscated chat-handler prologue, reconstruct its runtime-built strings and substitution cipher, and trace a command channel capable of clipboard exfiltration, with a reproducible network-isolated analysis workflow."
        },
        {
          "title": "Owner-authorized attack-surface assessment",
          "text": "Zero-impact external assessment of a multi-service production presence I operate: passive reconnaissance, non-intrusive testing, ranked remediation, and two initial findings disproved by re-testing from public vantage points."
        },
        {
          "title": "Fleet vulnerability audit",
          "text": "Phased audit of an 86-host lab fleet with version-based CVE assessment, evidence-based false-positive rejection, and a gentler profile with post-scan health checks for fragile hosts."
        },
        {
          "title": "Hypervisor isolation analysis",
          "text": "Read-only analysis of a three-host virtualization cluster across workload, management, vMotion, and storage planes, validating layer-2 protections and identifying patch-level exposure to guest-to-host escape classes."
        }
      ]
    },
    "capabilities": [
      {
        "id": "automation",
        "title": "Turn manual, high-risk runbooks into versioned automation",
        "statement": "I turn hand-run deployment procedures into tested, versioned collections with dry-run reports, verification, and rollback paths, and build configuration tooling that keeps environment selection explicit.",
        "claimIds": [
          "carrier-platform-01-01",
          "carrier-platform-01-06",
          "carrier-platform-01-02",
          "carrier-platform-01-04",
          "carrier-platform-01-07"
        ]
      },
      {
        "id": "data-reliability",
        "title": "Own database reliability end to end",
        "statement": "Verified backups, rehearsed restores, topology and upgrade planning, and performance work measured against compatibility constraints—including a development UDF benchmark reduced from 12.47 ms to 0.70 ms.",
        "claimIds": [
          "carrier-platform-02-01",
          "carrier-platform-02-02",
          "carrier-platform-02-07",
          "carrier-platform-02-03",
          "ops-tooling-01-03",
          "carrier-platform-02-08",
          "carrier-platform-02-09"
        ]
      },
      {
        "id": "protocol-parity",
        "title": "Reverse-engineer and rebuild protocol behaviour with evidence",
        "statement": "When the specification is missing I derive it from logs and packet captures, establish a parity baseline, and rebuild against it with replay tooling so the rewrite can be proven, not argued.",
        "claimIds": [
          "carrier-platform-05-01",
          "carrier-platform-05-02",
          "carrier-platform-05-05",
          "carrier-platform-05-06"
        ]
      },
      {
        "id": "test-platforms",
        "title": "Build test platforms that retire manual certification work",
        "statement": "Web and CLI platforms, mobile automation, gRPC contracts, and fleet-scale executors that replace repeated manual passes with repeatable evidence.",
        "claimIds": [
          "carrier-platform-06-01",
          "carrier-platform-06-04",
          "carrier-platform-06-03",
          "carrier-platform-06-07"
        ]
      },
      {
        "id": "secure-fleets",
        "title": "Secure fleets, pipelines, and identities",
        "statement": "Endpoint controls, audit-event forwarding, hardening, service identities, and native SSO with group-driven provisioning and tested allow/deny behavior.",
        "claimIds": [
          "carrier-platform-04-01",
          "carrier-platform-04-02",
          "carrier-platform-04-04",
          "identity-platform-01-01",
          "identity-platform-01-02",
          "carrier-platform-04-06"
        ]
      },
      {
        "id": "networks",
        "title": "Design and run networks from the fiber to the RADIUS policy",
        "statement": "Founder-grade network engineering: multi-frequency wireless plant, captive-portal AAA, TR-069 fleet provisioning, hardened core routers, and identity-gated ingress for everything behind them.",
        "claimIds": [
          "duvall-wifi-01-02",
          "duvall-wifi-02-01",
          "duvall-wifi-01-05",
          "wilderness-awareness-01-01",
          "homelab-platform-01-05",
          "carrier-platform-07-06",
          "carrier-platform-05-07"
        ]
      },
      {
        "id": "software",
        "title": "Ship production software across Java, PHP, Python, and TypeScript",
        "statement": "Lead-generation platforms, identity providers, protocol servers, integrations against third-party APIs, and static-site pipelines, each with tests and a delivery path.",
        "claimIds": [
          "pnw-plumbing-02-01",
          "game-platform-01-01",
          "game-platform-01-04",
          "web-factory-01-01",
          "additional-projects-01-01"
        ]
      },
      {
        "id": "ai-governed",
        "title": "Apply AI agents with real governance",
        "statement": "A deployed engineering chat assistant with separate read-only tool gateways and caller/tier isolation, plus constrained MCP APIs, explicit change controls, and evidence tools challenged with negative tests.",
        "claimIds": [
          "carrier-platform-08-06",
          "carrier-platform-08-07",
          "joblead-system-01-01",
          "joblead-system-01-02",
          "joblead-system-01-03",
          "agent-crew-01-01",
          "agent-crew-01-03",
          "ops-tooling-01-02"
        ]
      },
      {
        "id": "recovery",
        "title": "Recover incidents to root cause and prove the fix",
        "statement": "I trace incidents across application, database, storage, and infrastructure boundaries, verify service recovery, and keep unfinished prevention work visible.",
        "claimIds": [
          "homelab-platform-01-04",
          "homelab-platform-01-08",
          "carrier-platform-03-01",
          "carrier-platform-07-04",
          "carrier-platform-07-07"
        ]
      },
      {
        "id": "founder",
        "title": "Operate as a founder, not only an engineer",
        "statement": "Customer discovery, architecture, delivery, field installation, support, billing, and growth analytics, with measured outcomes such as a customer-acquisition cost cut from roughly $150 to $5.10.",
        "claimIds": [
          "duvall-wifi-01-01",
          "pnw-plumbing-01-01",
          "pnw-plumbing-02-02",
          "duvall-wifi-01-07"
        ]
      },
      {
        "id": "enablement",
        "title": "Document and enable so the work survives me",
        "statement": "Certified installation guides, onboarding suites for undocumented languages, mentoring, IDE tooling, and a curated engineering knowledge base published behind a per-note gate.",
        "claimIds": [
          "carrier-platform-08-01",
          "carrier-platform-08-02",
          "carrier-platform-08-05",
          "carrier-platform-08-04",
          "carrier-platform-08-07",
          "carrier-platform-08-08"
        ]
      }
    ],
    "stats": [
      {
        "value": "21 months",
        "label": "Contract engagement",
        "detail": "Nov 2024 – Aug 2026, start to end of the engagement."
      },
      {
        "value": "5",
        "label": "Platform areas owned concurrently",
        "detail": "Deployment automation, Cassandra, AAA policy, security remediation, and the lab supply chain."
      },
      {
        "value": "180",
        "label": "Tickets delivered",
        "detail": "Shipped and verified across those 5 areas."
      },
      {
        "value": "248",
        "label": "Merge requests merged",
        "detail": "Across 31 repositories; sole author in 21 of them."
      },
      {
        "value": "6",
        "label": "Versioned Ansible collections",
        "detail": "Replacing hand-run runbook deployment. Sole commit author on all 6."
      },
      {
        "value": "29",
        "label": "Tagged releases",
        "detail": "Shipped across those 6 collections."
      }
    ],
    "workingMethod": [
      {
        "title": "Root-cause analysis on release blockers",
        "detail": "Release-blocking CI failures were traced to their actual causes and fixed at the shared infrastructure or template layer instead of being repeatedly retried."
      },
      {
        "title": "QA findings treated as product defects",
        "detail": "Certification findings against backup tooling became validation, autodiscovery, and safer runtime behavior shipped as follow-up releases. The documentation stayed accurate because the product changed."
      },
      {
        "title": "Rehearsal and failure injection",
        "detail": "A database topology change was rehearsed against an isolated replica; deployment tests deliberately injected failures and checked that the previous release remained startable."
      },
      {
        "title": "Removing operator footguns",
        "detail": "Hard-coded defaults became autodiscovery, repetitive operator input was reduced, and fragile maintenance steps were replaced with safer native operations."
      },
      {
        "title": "Documentation as a deliverable",
        "detail": "An 11-page onboarding suite for an undocumented policy language, installation guides that passed formal certification, and CI-published operator documentation kept knowledge aligned with releases."
      },
      {
        "title": "Testing real integration boundaries",
        "detail": "Live chat and SSO tests exposed permission, identity-resolution, and session-isolation defects that isolated tests had missed."
      }
    ],
    "sections": [
      {
        "label": "Recruiter brief",
        "href": "/resume/recruiters",
        "description": "A concise introduction, selected evidence, and résumés organized by role focus."
      },
      {
        "label": "Experience",
        "href": "/resume/experience",
        "description": "The public record: scope owned and selected accomplishments grouped by discipline, with internal operational details deliberately generalized."
      },
      {
        "label": "Skills",
        "href": "/resume/skills",
        "description": "The public skills inventory, category by category, with named technologies kept where they demonstrate useful experience without exposing sensitive environment details."
      }
    ],
    "plainTextResume": {
      "label": "Plain-text resume",
      "href": "/resume.txt",
      "description": "A machine-readable mirror of the sanitized public resume for ATS parsers, AI agents, and anyone who prefers grep to scrolling."
    },
    "cta": {
      "eyebrow": "Contact",
      "title": "Hiring, or have a project in mind?",
      "lead": "I'm looking for a senior individual-contributor role with architectural ownership, and I take on independent project work. Tell me what you're building."
    }
  },
  "roles": [
    {
      "id": "carrier-platform",
      "role": "Wireless Engineer III — AAA Development & Platform Automation",
      "org": "Charter Communications (Spectrum)",
      "kind": "employment",
      "period": "Nov 2024 – Aug 2026",
      "status": "Previous role",
      "summary": [
        "Wireless Engineer III on a national carrier AAA/RADIUS platform supporting subscriber WiFi authentication, roaming, and accounting workflows.",
        "I joined in integration testing and was promoted into development after six months, then expanded into a cross-cutting platform role spanning telecom policy, infrastructure automation, database reliability, release engineering, security, test platforms, lab operations, and technical enablement.",
        "Across 21 months I took on 5 platform areas; the early-August evidence snapshot records 180 completed tickets and 248 merged merge requests across 31 repositories."
      ],
      "scope": [
        "AAA deployment automation: versioned Ansible collections for deployment, upgrades, policy changes, auditing, and rollback.",
        "Cassandra platform operations: backup and restore, topology and upgrade planning, UDF performance optimization, and migration analysis.",
        "AAA policy engineering: behavioural-parity work for a platform rewrite and accounting workflows.",
        "Security and compliance automation: endpoint controls, audit-event forwarding, native application SSO, and group-based access.",
        "Developer and lab enablement: VM provisioning, inventory reconciliation, CI/CD, automated testing, a deployed engineering assistant, and evidence tooling."
      ],
      "tags": [
        "Ansible",
        "Cassandra",
        "Nokia AAA / TAL",
        "RADIUS / RadSec",
        "EAP-AKA / EAP-TTLS",
        "802.1X",
        "Passpoint",
        "GitLab CI",
        "Artifactory",
        "Docker",
        "Kubernetes",
        "Splunk",
        "VMware vSphere",
        "cloud-init",
        "RHEL / Rocky",
        "Ubuntu",
        "Python",
        "Java 23 / Spring Boot",
        "Appium",
        "gRPC / proto3",
        "PowerShell",
        "TypeScript",
        "Webex",
        "MCP",
        "Authentik",
        "SAML / OIDC",
        "phpIPAM",
        "SOPS / age"
      ],
      "links": [],
      "groups": [
        {
          "title": "Infrastructure automation (Ansible)",
          "bullets": [
            "Converted runbook-driven platform deployment into 6 versioned Ansible collections with 29 tagged releases in 76 days, covering deployment, database operations, system administration, VM preparation, orchestration, and preflight checks.",
            "Built the team's first collection release pipeline and test strategy, including 403 automated tests and 96 property-based tests in the earlier suite snapshot, parallel pytest execution, automatic versioning, artifact publication, and shared CI templates. Later deployment safeguards were challenged at 16 injected failure points and with 13 deliberate role mutations, checking preservation of a startable previous release.",
            "Decomposed a monolithic deployment role into separate install, policy, and helper roles so routine policy changes could ship without replacing platform software.",
            "Added dry-run audit reporting so operators could inspect a proposed change before authorizing execution.",
            "Built a systemd-enabled Docker test harness so role changes could be validated locally instead of consuming shared lab capacity.",
            "Replaced a multi-step manual deployment handoff with a single-command, version-pinned, idempotent deployment supporting roughly one-minute policy-only updates, dry-run impact reports, post-deploy verification, offline bundles, and sub-second symlink rollback."
          ]
        },
        {
          "title": "Database engineering (Cassandra)",
          "bullets": [
            "Owned the Cassandra operations programme and shipped 14 tagged releases in roughly four weeks while the work moved through formal QA certification.",
            "Automated backup and restore end to end with scheduling, retention, verification, capacity checks, retries, and alerting, replacing an inconsistent manual process.",
            "Removed a data-integrity footgun in backup naming by adding fail-fast validation and then autodiscovery.",
            "Implemented mutual-TLS support and service-account-safe certificate discovery for production-equivalent environments.",
            "Rehearsed a high-risk multi-node topology change against an isolated replica before executing the live change successfully.",
            "Performed encrypted-data migration analysis, load simulation, and operator-workflow simplification, cutting the planned manual input from roughly twelve variables to four.",
            "Designed a Cassandra 4.1-to-5.0 rolling-upgrade path for the subscriber-authentication clusters.",
            "Optimized a legacy Cassandra decryption UDF, reducing development-benchmark mean latency from 12.47 ms to 0.70 ms and increasing 16-thread throughput from 635 to approximately 13,100 operations per second; scoped equivalence and round-trip compatibility checks to the tested variants.",
            "Released a database-automation fix spanning four CQL roles, correcting credential propagation and variable-precedence defects; tested the published package against operator instructions with a CQL stub and repaired five documentation errors while real-cluster recertification remained pending.",
            "Diagnosed and closed an availability defect in a subscriber-authentication database where crafted input to its encryption and decryption user-defined functions could bring the cluster down."
          ]
        },
        {
          "title": "CI/CD & release engineering",
          "bullets": [
            "Root-caused recurring release blockers across build images, registry routing, and artifact authentication, then replaced repository-local workarounds with shared templates. Reconciled three policy-bundle packaging paths and added checks against overwriting vendor runtime files, resolving inconsistent branch and merge-request validation.",
            "Stood up a self-hosted CI runner for policy validation and built a multi-architecture base image for arm64 and amd64 development workflows.",
            "Moved collection publishing onto a shared tag-driven release pipeline with dedicated service credentials and manual approval gates for deployment-sensitive actions.",
            "Brought the team's repositories to a green compliance pipeline and added automated documentation publication behind approval gates.",
            "Administered a 12+ repository GitLab group, establishing Git Flow, CODEOWNERS, pipeline-gated merges, branch protection, artifact conventions, and reusable templates across the AAA automation portfolio.",
            "Migrated a development policy configuration to templated values and encrypted secrets while preserving byte-identical output across all 62 rendered files; credential rotation remained a separate follow-up."
          ]
        },
        {
          "title": "Security & compliance",
          "bullets": [
            "Automated deployment of endpoint security, endpoint management, software inventory, vulnerability management, and MFA controls across a pre-production fleet.",
            "Delivered SIEM log-forwarding automation covering platform and operating-system logs across multiple fleet layouts. Automated enriched Linux audit-event forwarding across six development nodes, resolving SELinux and audit-daemon integration failures and using queued TCP delivery for centralized investigation.",
            "Remediated tracked vulnerability findings to closure, introduced safer package-manager-native maintenance operations, and delivered a certified upgrade path for legacy Linux hosts.",
            "Moved source-control permissions onto directory-backed groups and moved CI pipelines off personal credentials onto dedicated service accounts.",
            "Added repository safeguards that keep lab secrets out of policy source control.",
            "Automated directory-backed SSO across engineering tools using SAML, OIDC, and OAuth, including group-driven account provisioning and role mapping, tested allow/deny behavior, and preserved local recovery access.",
            "Shipped CIS-aligned kernel and SSH daemon hardening as a fleet role, validating each generated daemon configuration with a syntax check before applying it and ordering the drop-in files so the existing access policy stayed authoritative instead of being silently overridden.",
            "Removed a destructive failure mode from fleet kernel maintenance by replacing two fragile shell steps with an explicit running-kernel check and an old-installs-only removal, so the automation could no longer delete the kernel the host had actually booted."
          ]
        },
        {
          "title": "Network & protocol engineering (RADIUS / EAP)",
          "bullets": [
            "Reverse-engineered undocumented RADIUS accounting field derivations from policy logs and packet captures, establishing a behavioural-parity baseline for a platform rewrite.",
            "Rebuilt individual accounting derivations to verified parity against that baseline and created replay tooling for repeatable protocol validation.",
            "Designed and delivered a state-persistence layer for a telecom policy runtime, then removed 16,390 lines of legacy code using execution evidence to prove what was genuinely unused.",
            "Diagnosed difficult mutual-TLS and protocol-integration failures across RADIUS-over-TLS and a legacy subscriber-state interface.",
            "Sole-engineered a ground-up accounting-policy rewrite in the vendor policy DSL: 181 commits in roughly two and a half months across 15+ modules and 30+ configuration files, with CI/CD, defensive protocol parsing, LDAP failover, RADIUS/RadSec forwarding, and a documented 87-code operational logging registry.",
            "Implemented a single-probe write/read/delete smoke harness for every state model, turning multi-minute manual verification into sub-second post-deploy validation in a DSL with no debugger or stack traces.",
            "Diagnosed two independent causes of silent RADIUS accounting health-check failures—a runtime compatibility issue and missing protocol attributes—and validated the corrected probe with 12 of 12 successful live responses at approximately 140 ms median latency; load-balancer monitor deployment remained pending.",
            "Root-caused a TLS handshake failure blocking OAuth2 token retrieval by isolating the ALPN extension in the ClientHello as the trigger, eliminating DNS resolution, TCP reachability, certificate interception, TLS version negotiation and general HTTPS egress with a positive control for each, then proving with a four-variant differential matrix that the reset followed the extension being present rather than the protocol offered, and restoring token issuance the same day."
          ]
        },
        {
          "title": "Test automation & QA",
          "bullets": [
            "Designed and shipped a Spring-based web platform for 802.1X/EAP supplicant test automation with configuration generation, credential handling, containerized execution, result parsing, dashboards, SIEM query integration, and automated delivery.",
            "Architected the platform as eleven Java 23 / Spring Boot modules with nine reusable Maven modules, multi-architecture Docker delivery, and 70 test classes containing more test code than production code, all sole-authored and able to survive 30-way parallel execution.",
            "Built an end-to-end AAA testing platform spanning a typed Python library, operator CLIs, Android and iOS Appium automation, Docker, and gRPC; it collapsed repeated manual SIEM queries into a single call across 120+ tests and saved an estimated 6–10 engineer-hours in one certification cycle.",
            "Automated 11 previously manual integration tests, reclaiming about 3.7 engineer-hours per full pass, and built a containerized pre-deployment policy validation gate across seven repositories, where policy bundles must boot in the AAA runtime and clear a 13-pattern fatal-error screen before publication.",
            "Defined and executed a roughly 30-case release regression suite spanning multiple EAP methods, mobile platforms, roaming scenarios, Passpoint, and negative cases.",
            "Designed the shared cross-language contract layer (four gRPC services, eight RPC methods, 13 messages, and eight enums) consumed by Java and Python tools for session control, provisioning-cache operations, SIEM queries, and supplicant configuration.",
            "Built the companion portable task-executor agent in Python spanning four CPU architectures, with Kafka result signals, RADIUS/EAPOL probes, REST task discovery, and CI packaging, targeting a roughly 79-host lab fleet across two data centers and four environment tiers.",
            "Produced the certification evidence package for a carrier AAA platform release, assembling roughly 90 attachments of policy logs, packet captures, encryption and decryption traces, protocol replay files and device captures across three months.",
            "Shipped PowerShell automation for reconfiguring wireless settings on Android test devices three weeks into the engagement, extracting profile selection, device serial handling and address validation into a reusable module across nine merged merge requests."
          ]
        },
        {
          "title": "Virtualization & lab platform",
          "bullets": [
            "Automated VM provisioning from template preparation through cloud-init self-deployment, including dual-stack IPv4/IPv6 addressing and an IPv6-only defect that had been breaking unattended provisioning. Built and verified a Rocky Linux golden template, then provisioned eight database VMs and checked unique machine identities and SSH host keys on every running guest.",
            "Built control-node preflight checks that report automation readiness before a run touches infrastructure.",
            "Delivered supporting engineering services including reverse proxying, status reporting, monitoring alerts, and team alert integrations.",
            "Validated a major ESXi upgrade on live infrastructure and surfaced a lifecycle risk early enough for it to be resolved before an outage.",
            "Automated vSphere snapshot restore and environment-aware artifact retrieval, including a SOAP-to-pyVmomi migration, SOCKS5 support, remote DNS, and lab/production artifact-repository fallback so workflows behaved consistently across network segments.",
            "Built repeatable IPAM import and drift-audit tooling, reconciled a 233-VM development inventory, and populated a separate integration-test inventory covering 62 VLANs, 144 subnets, and 176 addresses using hypervisor, host, and telemetry evidence.",
            "Restored an internal application's login service by tracing failed database session writes to disk exhaustion caused by a cascading Redis and container-logging failure; reclaimed capacity and prepared log-rotation controls."
          ]
        },
        {
          "title": "Documentation & enablement",
          "bullets": [
            "Authored 69 internal wiki pages over the engagement, including installation guides carried through formal QA certification.",
            "Wrote an 11-page developer-onboarding suite for an internal policy language and runtime covering language reference, conventions, repository structure, testing, secrets handling, releases, and troubleshooting.",
            "Wrote internal proposals that set direction for collection-based automation, automated deployment, and software lifecycle planning.",
            "Operationalized a 935-note engineering knowledge base as team documentation, publishing a curated 229-note subset behind an explicit per-note publication gate.",
            "Mentored engineers on Git and tooling and built an IDE plugin for the platform's policy language.",
            "Built and deployed a TypeScript Webex assistant for engineering knowledge lookup, with access configured for 12 teammates, separate read-only tool gateways, and conversation isolation by caller and privilege tier; verified lookup and refusal behavior through live messaging.",
            "Built reusable AI-workflow tools for engineering evidence retrieval, outbound sanitization, and document consistency, with 193 passing assertions and negative tests; corrected repository-counting errors caused by duplicate counting of repository history and uninitialized submodules.",
            "Built and maintained a library of roughly 54 reusable AI agent skills across three engineering workspaces, codifying workflows for infrastructure operations, investigation and evidence gathering, security remediation, documentation, configuration management and telecom policy work, and authored an audit that reconciles all three workspace roots in a single run to flag duplicated skills, dead bundled-file references, one-sided skill boundaries, and colliding trigger phrases that would otherwise make agent dispatch nondeterministic.",
            "Carried the platform automation portfolio as its sole maintainer in 21 of the 27 codebases surveyed, spanning configuration management, telecom policy, test platforms and operational tooling with no second commit author."
          ]
        },
        {
          "title": "Infrastructure automation (Ansible) (in progress)",
          "bullets": [
            "Designed deployment-time configuration and secrets tooling that separates reusable policy artifacts from environment values and versioned encrypted secrets; released the deployment component with environment validation, provenance tracking, and compatibility checks while broader rollout remained in progress."
          ]
        },
        {
          "title": "Documentation & enablement (prototype)",
          "bullets": [
            "Prototyped a per-engineer status ledger using two weeks of real work, identified conflicts in hand-maintained reporting, and designed a refreshable contribution model around existing Jira fields; recurring automation and broader adoption remained next steps."
          ]
        },
        {
          "title": "Database engineering (Cassandra) (in progress)",
          "bullets": [
            "Piloted a Kubernetes operator deployment model for a carrier subscriber-authentication database tier and released a dedicated collection for it, with the pilot still open at the end of the evidence window."
          ]
        },
        {
          "title": "Security & compliance (in progress)",
          "bullets": [
            "Scoped an environment-wide security remediation programme into seven tracked work items covering agent staging, operating-system patching, MFA, SIEM forwarding and a follow-up security assessment, delivered the first of them, and kept the rest moving while one item stayed blocked on an approval process outside his control."
          ]
        }
      ]
    },
    {
      "id": "duvall-wifi",
      "role": "Founder / Principal Engineer",
      "org": "Duvall WiFi",
      "kind": "business",
      "period": "Aug 2022 – Nov 2024",
      "status": "Previous role",
      "summary": [
        "Founded and ran a technology and ISP services company, owning customer discovery through implementation, operations, billing, and support."
      ],
      "scope": [],
      "tags": [
        "Founder",
        "Wireless ISP",
        "FreeRADIUS",
        "Spring",
        "Laravel",
        "VMware vSphere / vSAN",
        "PKI",
        "Zero-trust segmentation",
        "SIEM"
      ],
      "links": [
        {
          "href": "/projects/duvall-wifi",
          "label": "Case study"
        }
      ],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Founded and ran a technology and ISP services company covering network engineering, software development, hosting, cybersecurity, and managed IT. I owned customer discovery, architecture, implementation, production operations, sales, billing, and support.",
            "Built a redundant multi-frequency wireless network capable of serving 160 homes with symmetric gigabit, backed by custom captive-portal and RADIUS software plus virtualized infrastructure, PKI, segmentation, monitoring, VPN connectivity, PBX/CRM integrations, and production Laravel and Spring applications.",
            "Built the custom Spring Boot captive-portal and AAA backend implementing the FreeRADIUS REST hook surface for authorization, authentication, interim accounting, post-auth, and proxy phases, plus MikroTik hotspot redirect and prepaid-voucher flows.",
            "Implemented defense-in-depth portal authentication with brute-force throttling, GeoIP impossible-travel detection, device fingerprinting, reCAPTCHA, and JWT-based hotspot session tokens.",
            "Built and operated a three-host VMware vSphere/vSAN environment with data-center colocation, an air-gapped root CA, zero-trust segmentation, secure administrative workstations, SIEM monitoring, VM templates, and hub-and-spoke VPN connectivity across customer networks.",
            "Installed and spliced indoor and outdoor fiber and copper cabling, engineered point-to-point links, performed site surveys, and maintained routers, switches, access points, and RF paths as the company's field engineer.",
            "Operated a GenieACS TR-069/CWMP platform managing 58 MikroTik and Yealink devices through 15 presets and 15 provisions, documented its tag-driven idempotent configuration state machine, and identified security, permissions, provisioning, and device-health defects through live read-only analysis.",
            "Built a communications single pane of glass integrating the VoIP PBX, CRM, missed calls, voicemail, text, and email, with call flows and customer pop-ups that cut spam and sped up resolution."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Performed an owner-authorized, zero-impact attack-surface assessment across a roughly 12-service production presence using DNS and certificate-transparency reconnaissance, endpoint and auth-flow review, CORS and header testing, and vantage verification; delivered ranked remediation and disproved two initial split-horizon false positives before reporting."
          ]
        }
      ]
    },
    {
      "id": "pnw-plumbing",
      "role": "Technology & Growth Consultant",
      "org": "Pacific Northwest Plumbing",
      "kind": "consulting",
      "period": "Jun 2023 – Nov 2024",
      "status": "Previous role",
      "summary": [
        "Delivered technology and growth consulting for a trades business across software, analytics, customer acquisition, and support."
      ],
      "scope": [],
      "tags": [
        "Laravel",
        "Analytics & conversion tracking",
        "Advertising workflows",
        "Helpdesk",
        "IP-camera integrations"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Technology and growth consulting for a trades business. I brought customer acquisition cost down from roughly $150 to $5.10 and shifted 83.67% of inbound calls onto unpaid channels, working across the website, analytics, advertising, reviews, and conversion paths.",
            "Delivery included a Laravel 10 production website, conversion tracking, advertising workflows, helpdesk support, and custom IP-camera security integrations.",
            "Built the lead-generation application in Laravel 10 with Nova administration, reCAPTCHA v3 score-based filtering, Google and Microsoft paid-click attribution, and dual-channel lead alerting, then replatformed it to static Astro once the dynamic attack surface was no longer justified."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Analysed roughly 2,000 jobs, 1,350 customer records, 1,990 invoices, and 570 estimates to produce a constraint-based growth plan, KPI scorecard, CRM clean-up programme, retention strategy, acquisition playbook, and a buyer-ready data-room structure."
          ]
        }
      ]
    },
    {
      "id": "wilderness-awareness",
      "role": "Network & Systems Consultant",
      "org": "Wilderness Awareness School",
      "kind": "consulting",
      "period": "Nov 2022 – Nov 2024",
      "status": "Previous role",
      "summary": [
        "Delivered network and systems consulting for a multi-property school in challenging rural terrain."
      ],
      "scope": [],
      "tags": [
        "Enterprise networking",
        "Point-to-point wireless",
        "Structured cabling",
        "Monitoring",
        "End-user support"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Designed, quoted, installed, and operated a resilient enterprise network across three forested properties using roughly 700 meters of aerial and buried cabling plus point-to-point wireless links. The design avoided the cost of an additional internet circuit and improved outage resilience.",
            "Ongoing support covered routers, switches, access points, point-to-point wireless links, structured cabling, monitoring, and day-to-day technical support for staff."
          ]
        }
      ]
    },
    {
      "id": "beyond-grey-skies",
      "role": "Technical Consultant",
      "org": "Beyond Grey Skies, LLC",
      "kind": "consulting",
      "period": "Mar 2016 – Jun 2021",
      "status": "Earlier chapter",
      "summary": [
        "Provided enterprise network, server, and technical operations consulting."
      ],
      "scope": [],
      "tags": [
        "pfSense",
        "VyOS",
        "MikroTik RouterOS",
        "Cisco IOS",
        "Intrusion monitoring",
        "Data-center fabric"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Supported enterprise networks, data-center fabric, Linux and Windows servers, intrusion monitoring, and emergency technical operations, working across pfSense, VyOS, MikroTik RouterOS, and Cisco IOS."
          ]
        }
      ]
    },
    {
      "id": "identity-platform",
      "role": "Identity Platform Engineering",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "Independent project",
      "summary": [
        "Deployed a self-hosted identity platform with reproducible infrastructure and group-based application access."
      ],
      "scope": [],
      "tags": [
        "Authentik",
        "OIDC",
        "Ansible",
        "Terraform",
        "Docker",
        "Cloudflare Access"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Deployed an Authentik identity platform using Ansible, Docker Compose, declarative Blueprints, and Terraform-managed Cloudflare Access, with OIDC group claims for application authorization.",
            "Verified signed identity tokens, allow/deny behavior, group-removal revocation, deactivated-user denial, and configuration reapplication through 20 infrastructure checks and a ten-check identity suite.",
            "Validated idempotent deployment and unattended reboot recovery, and preserved existing access policies during additive application migration.",
            "Imported the existing edge-access applications into Terraform without recreating them, preserved fallback login paths, and caught destructive nulling of previously unmanaged fields in plan review before it reached production.",
            "Operate the platform as a product: invitation flows, a documented two-change procedure for putting an application behind OIDC or SAML login, service tokens for machine callers, and a maintained trap list so protected applications work the first time."
          ]
        }
      ]
    },
    {
      "id": "joblead-system",
      "role": "AI Integration & Security Engineering",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "Independent project",
      "summary": [
        "Built an authenticated MCP gateway connecting AI tooling to a private CRM, with live reads and controlled write paths."
      ],
      "scope": [],
      "tags": [
        "MCP",
        "OAuth 2.1",
        "Cloudflare Workers",
        "Python",
        "nginx",
        "Threat modeling"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built a Cloudflare Worker MCP gateway with OAuth 2.1 and per-client capability tokens, authenticated origin access, and a constrained API to a private CRM.",
            "Implemented review-first ingestion controls, dry-run/commit binding, rate caps, auditing, and independent kill switches; live read access is verified and write execution remains disabled.",
            "Documented 198 passing service tests and drilled kill switches at the edge, reverse proxy, and application layers, with observed shutdown times of approximately 7, 10, and 19 seconds respectively.",
            "Built a self-hosted CRM and deterministic follow-up engine that converts raw job listings into researched, callable leads with scripts, evidence, reminders, business-hours scheduling, call outcomes, and recovery packets.",
            "Implemented the engine as a dependency-free Python state machine with idempotent ingestion, duplicate protection, signed-webhook verification, replay safety, time-zone/DST/holiday scheduling, and least-privilege HMAC API access, shipping 101 unit tests and 85 of 85 live acceptance checks.",
            "Proved recoverability through checksummed daily and weekly backups, a disposable restore that booted a fresh application container with intact records, cross-host migration by restore, and a full VM reboot after which six services returned healthy without intervention."
          ]
        }
      ]
    },
    {
      "id": "gpu-access",
      "role": "Secure Compute & Network Automation",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "Independent project",
      "summary": [
        "Built and deployed a credential broker and routing automation for ephemeral rented GPU compute."
      ],
      "scope": [],
      "tags": [
        "Tailscale",
        "Cloudflare Workers",
        "TypeScript",
        "nftables",
        "OIDC",
        "GPU infrastructure"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built a broker issuing short-lived, single-use Tailscale enrollment keys while keeping privileged OAuth credentials off rented hardware, with independent JWT validation for administrative access.",
            "Automated deterministic virtual-address allocation, constrained gateway routing, and cleanup of expired nodes; verified the full join, permitted-access, blocked-port, and teardown path using a disposable container.",
            "Validated the implementation with 34 unit tests and 20 gateway ruleset assertions, including fail-closed behavior when configuration is absent.",
            "Operated a vLLM coding endpoint compatible with the OpenAI Chat Completions, OpenAI Responses, and Anthropic Messages APIs, including native streamed tool calls, so coding agents such as Claude Code, Codex CLI, Cline, and OpenCode work without a translation proxy, with the rented-host trust boundary documented."
          ]
        }
      ]
    },
    {
      "id": "observability-as-code",
      "role": "Observability as Code",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "Independent project",
      "summary": [
        "Terraform-managed monitoring and security analytics for a private homelab, with monitors, log pipelines, and dashboards defined as reviewable code."
      ],
      "scope": [],
      "tags": [
        "Datadog",
        "Terraform / OpenTofu",
        "Log pipelines",
        "Security analytics",
        "Monitoring as code"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Managed a Datadog observability stack as code: 53 monitors (30 log, 21 metric, two query), four syslog pipelines totalling 46 processors, four log-derived metrics, an indexed log store, and a 17-widget security dashboard.",
            "Designed a reusable Terraform monitor module with 16 typed, validated inputs, enforced tags, count-gated optional resources, provider locking, and credentials kept out of band."
          ]
        }
      ]
    },
    {
      "id": "homelab-platform",
      "role": "Private Cloud & Homelab Platform Engineering",
      "org": "Independent project",
      "kind": "independent",
      "period": "Ongoing",
      "status": "Ongoing",
      "summary": [
        "Operates a three-host VMware environment as a production-grade lab: provisioning automation, isolation analysis, recovery engineering, and network-edge hardening."
      ],
      "scope": [],
      "tags": [
        "VMware vSphere",
        "vSAN",
        "cloud-init",
        "Ansible",
        "MikroTik RouterOS",
        "Recovery engineering"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Operate a three-host vSphere/vCenter environment inventorying 149 VMs (86 running), 469 allocated vCPUs, roughly 686 GiB of allocated RAM, eight datastores, and 45 networks across Linux, Windows, RHEL, Debian, FreeBSD, and network-appliance workloads.",
            "Built repeatable VM provisioning and golden-template workflows spanning cloud-init guestinfo, clone customization, LVM growth, Docker bootstrap, network and IP validation, sysprep, smoke tests, and reusable Ansible and CLI automation.",
            "Recovered a vCenter outage caused by a full log partition and an expired machine SSL certificate: preserved the valid VMCA root, re-issued only the leaf certificate, restored services with no VM data loss, corrected syslog host attribution, and raised an exhausted file-descriptor limit from 1,024 to 65,536.",
            "Audited the management and service exposure of a colocated RouterOS core router, validated ordered default-deny containment, and executed a no-reboot reduction of SNMP, bandwidth-test, captive-portal, and obsolete RADIUS exposure while preserving recovery access.",
            "Built reusable Windows performance and security triage tooling covering hardware, storage health, patching, Defender, firewall, logons, public connections, persistence surfaces, signatures, remote tools, and high-refresh gaming bottlenecks.",
            "Designed the standard internet ingress for self-hosted services: a Cloudflare edge with WAF and identity-gated Access in front of a core router that admits only Cloudflare's ranges, terminating at an nginx origin with per-hostname Origin CA certificates and authenticated origin pulls across roughly 55 virtual hosts."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Performed read-only isolation and hypervisor-risk analysis across the workload, management, vMotion, and vSAN planes, validating layer-2 protections and blocked routing while identifying patch-level exposure to guest-to-host escape vulnerabilities and a high-blast-radius shared-storage design.",
            "Ran a phased vulnerability audit across an 86-host fleet: port sweep, service and version inventory, advisory-based CVE assessment with false positives rejected on evidence, and a gentler profile plus post-scan health verification for fragile hosts.",
            "Root-caused vSAN write latency to two stacked causes, an in-flight resync landing on one host's consumer-grade cache SSD and a chronic hardware-compatibility mismatch, then benchmarked the cluster against a Ceph deployment to separate fixable latency from latency that is acceptable by design."
          ]
        }
      ]
    },
    {
      "id": "agent-crew",
      "role": "Multi-Agent Engineering System Design",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "Independent project",
      "summary": [
        "A governed crew of thirteen AI engineering agents with least-privilege scopes, policy gates, and honest documentation of what the harness can and cannot enforce."
      ],
      "scope": [],
      "tags": [
        "AI agents",
        "Agent governance",
        "Kiro",
        "Policy gates",
        "Architecture decision records"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Designed and maintain a 13-agent engineering crew on a multi-agent harness, with a canonical YAML roster, agent definitions, architecture decision records, least-privilege command and tool scopes, must-allow/must-deny tests, deterministic policy gates, and resource-guard analysis.",
            "Documented a governance limitation where global permissive settings could bypass agent-level command scopes, separating static scope validation from actual runtime enforcement rather than overstating isolation."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Reverse-engineered the harness's provider architecture across provider factories, backend capability sets, spawn paths, model mapping, environment injection, and tool delivery to design credible extension paths for additional model providers, including self-hosted inference."
          ]
        }
      ]
    },
    {
      "id": "web-factory",
      "role": "Website Factory & Edge Delivery",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "Independent project",
      "summary": [
        "A reusable pipeline that turns sparse profile inputs into container-validated Astro sites with previews, custom domains, and edge APIs on Cloudflare."
      ],
      "scope": [],
      "tags": [
        "Astro",
        "TypeScript",
        "Cloudflare Workers",
        "Docker",
        "GitHub Actions",
        "Brand systems"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built a reusable one-shot website factory that turns profile and context sources into container-validated Astro sites, with structured intake, derived themes, generated brand assets, per-PR preview deployments, a promotion path to production, and post-deploy verification.",
            "Delivered multi-page sites for independent creators from sparse link-page and social inputs, implementing content-safety rules, no-index previews, custom domains, repeatable asset generation, and polling-based certificate and build verification.",
            "Built a caching Cloudflare Worker API for live photo galleries with a route allowlist, upstream and browser compatibility controls, edge caching, static-build isolation, and navigation-lifecycle handling, integrating third-party feeds without exposing a general-purpose proxy.",
            "Built pakkit.net as a strict-TypeScript Astro 6 knowledge and portfolio platform with a data-driven service taxonomy, MDX content collections, machine-readable RSS and llms.txt routes, a canonical career bank behind the résumé section, and more than 130 published technical articles.",
            "Integrated a performer's Astro booking site with their hosted CRM: build-time fetch of upcoming shows with a default-deny public filter, a small proxy that creates contacts and events through the authenticated API after live testing disproved the assumed public form endpoint, UTM lead-attribution passthrough, and a testimonials feed, verified end to end in production.",
            "Rebased the site factory onto a multi-template architecture, separating a shared asset overlay from per-template application layers behind an explicit overlay contract, guarding token substitution against binary files, and migrating roughly twelve dependent generator skills and their documentation in step, re-validated in a container at three different site-name lengths."
          ]
        }
      ]
    },
    {
      "id": "docs-hub",
      "role": "Multi-Vault Documentation Hub",
      "org": "Independent project",
      "kind": "independent",
      "period": "2026",
      "status": "In progress",
      "summary": [
        "A private publishing platform where each Obsidian vault gets isolated builds, search, hostname, and identity policy behind layered authorization."
      ],
      "scope": [],
      "tags": [
        "Obsidian",
        "Quartz",
        "Authentik",
        "Cloudflare Access",
        "JWT",
        "Terraform",
        "Ubuntu"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments (in progress)",
          "bullets": [
            "Architecting a private multi-notebook publishing platform where each vault has isolated source credentials, builds, search index, image, service, hostname, and identity-group policy."
          ]
        },
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Designed layered authorization through Cloudflare Access plus an origin-side gateway that validates JWT signature, issuer, expiry, and exact per-application audience, preventing cross-vault search, graph, attachment, cache, or metadata leakage.",
            "Provisioned and hardened a dedicated Ubuntu documentation VM through the hypervisor console and cloud-init: independently verified host keys, removed inherited administrative access, locked unused accounts, applied explicit SSH policy, patched and reboot-tested the host, and left only SSH listening on routable interfaces.",
            "Built a synthetic fixture vault with nine Markdown documents, 31 validated wikilinks and embeds, seven deliberately publishable notes, negative content fixtures, and complete heading-anchor checks to support authorization and isolation testing without exposing personal content."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Completed the planning and non-live remediation cycle, correcting a zero-match firewall rule, an impossible reverse-proxy and Compose topology, and an unsafe state-backend assumption before any public or identity-system change."
          ]
        }
      ]
    },
    {
      "id": "ops-tooling",
      "role": "Operational Tooling & Agent Skills",
      "org": "Independent work",
      "kind": "independent",
      "period": "2026",
      "status": "Ongoing",
      "summary": [
        "A library of dependency-free command-line tools for the infrastructure I run, each paired with an agent skill that documents triggers, credential handling, and failure modes so AI assistants operate the estate safely."
      ],
      "scope": [],
      "tags": [
        "Python",
        "Agent skills",
        "RouterOS",
        "TR-069",
        "WireGuard",
        "Backup verification",
        "Cloudflare"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built dependency-free, standard-library Python CLIs for the systems I operate: a TR-069 ACS client, a RouterOS API client with vSphere lab snapshot and revert, a WireGuard peer minter with IPAM address allocation and X25519 implemented in-tree, a Home Assistant REST and WebSocket client, a field-service CRM analytics client, and a game-cache script decompiler.",
            "Paired every tool with an agent skill that states when to use it, which credentials it reads and never prints, the privilege level to confirm before writing, and the trap list that makes it work first time, so AI assistants can run the estate under explicit per-change approval.",
            "Established a proof-based change discipline for database-backed upgrades: exact baseline counts, streaming the compressed dump back through a tuple parser to prove the rows are in it, and a post-change row-level diff that classifies every difference as schema migration, live activity, or actual loss.",
            "Shipped a verifier for published services that proves DNS is proxied, the edge gate answers, and, the step everyone skips, that the origin refuses a connection without Cloudflare's client certificate.",
            "Automated the VM lifecycle end to end: golden-template sealing with preflight snapshot, modernization, guestinfo readiness checks and identity wipe; cloud-init guestinfo deployments that prove the guest came up; and unattended multi-hop Ubuntu LTS upgrades over SSH with hypervisor snapshots as the rollback plan."
          ]
        },
        {
          "title": "Selected accomplishments (in progress)",
          "bullets": [
            "Consolidated a 12-repository Ansible estate (roughly 4,400 lines of real automation spanning an Atlassian stack, Active Directory and certificate-services labs, LEMP and Laravel hosting, security hardening, and certificate distribution) into namespaced collections, de-duplicating roles and repairing playbooks that no longer ran."
          ]
        }
      ]
    },
    {
      "id": "device-integration",
      "role": "Device & Systems Integration",
      "org": "Independent project",
      "kind": "independent",
      "period": "2023",
      "status": "Earlier project",
      "summary": [
        "Made devices and business systems speak protocols they did not natively share: an infrared gateway driven over TCP, a USB scanner published straight into a home-automation platform's own MQTT discovery contract, and CRM contacts rendered as the directory format SIP handsets fetch."
      ],
      "scope": [],
      "tags": [
        "Home Assistant",
        "MQTT",
        "Java",
        "Spring Boot",
        "udev",
        "Docker",
        "EspoCRM"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built a Home Assistant custom component for infrared device control that registers its own service and writes vendor control frames to a networked gateway over TCP, with a per-call device override so one integration drives more than one gateway.",
            "Bridged a USB serial tag scanner into a home-automation platform by implementing its MQTT discovery and scan contract directly instead of installing an add-on: a service that selects the device by USB descriptor, publishes its own discovery configuration on connect, republishes each scan as a structured event, and re-establishes the broker session before every publish, paired with udev rules that rebuild the container against the current device node whenever the scanner is plugged in or removed."
          ]
        },
        {
          "title": "Selected accomplishments (prototype)",
          "bullets": [
            "Prototyped a Java service that rendered CRM contacts as the vendor-native XML directory the deployed SIP handsets fetch, so the handset directory tracked the CRM instead of being maintained by hand, structured as a multi-module project separating the CRM client, the directory renderer, and the web tier."
          ]
        }
      ]
    },
    {
      "id": "independent-product",
      "role": "Product Architecture & Engineering",
      "org": "Independent product work",
      "kind": "independent",
      "period": "Independent, after-hours",
      "status": "Current",
      "summary": [
        "Independent, after-hours product architecture exploring scheduled bandwidth orchestration and telecom workflow automation, currently under the working name NexusPort."
      ],
      "scope": [],
      "tags": [
        "Product architecture",
        "Laravel",
        "Network automation",
        "API integration",
        "Workflow design"
      ],
      "links": [
        {
          "href": "/nexusport",
          "label": "NexusPort overview"
        },
        {
          "href": "/projects/nexusport",
          "label": "Project case study"
        }
      ],
      "groups": [
        {
          "title": "Selected accomplishments (prototype)",
          "bullets": [
            "Independent product work exploring scheduled bandwidth orchestration and telecom workflow automation, currently under the working name NexusPort. It takes a class of network change that tends to be manual, repetitive, and timing-sensitive, and gives it a structured product surface with real guardrails: intent separated from execution, validation before anything touches a live service, and an operator approval gate in the loop.",
            "The architecture is original, built after hours from public documentation, standard software libraries, and authorized API integrations where applicable. Final product naming and business structure are still being decided.",
            "The product model covers one-time, paired, recurring, and bulk bandwidth changes across enterprise ports, with customer/reseller separation, execution history, pricing estimates, onboarding, per-port billing, consolidated invoices, and white-label delivery; the implementation is Laravel with Dockerized delivery, staging operations, carrier-sandbox troubleshooting, and operator runbooks."
          ]
        }
      ]
    },
    {
      "id": "config-containment",
      "role": "Infrastructure Configuration & Containment",
      "org": "Independent project",
      "kind": "independent",
      "period": "2020 – 2023",
      "status": "Earlier project",
      "summary": [
        "Put infrastructure state under review and made it fail closed: a Windows domain's policy definitions version-controlled with pinned vendor provenance, and a containerized daemon confined to a supervised tunnel by a default-deny egress policy."
      ],
      "scope": [],
      "tags": [
        "Group Policy",
        "Active Directory",
        "Docker",
        "OpenVPN",
        "Firewall policy"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Put a version-controlled central store behind a Windows domain's Group Policy: 213 administrative templates with a complete English presentation set and five further language packs for the third-party templates, each vendor import landing as its own commit pinned to a named upstream version, so policy-definition changes became reviewable and revertible instead of being hand-copied into the domain share.",
            "Contained a containerized network daemon behind a default-deny egress policy so it could only reach the internet through a supervised VPN tunnel: outbound traffic dropped by default with narrow exceptions for the tunnel, DNS and the VPN endpoint, a management interface reachable from the local network but explicitly dropped on the tunnel side, and process supervision that restarts the tunnel without restarting the daemon."
          ]
        }
      ]
    },
    {
      "id": "embedded-signal",
      "role": "Embedded, Mobile & Signal Engineering",
      "org": "Independent project",
      "kind": "independent",
      "period": "2021 – 2023",
      "status": "Earlier project",
      "summary": [
        "Built instrumented hardware, Android applications, and signal-processing tooling to measure what no off-the-shelf product reported: solar and battery behaviour, water flow and level, charging-cable temperature, vehicle handling, and an undocumented serial protocol."
      ],
      "scope": [],
      "tags": [
        "ESP8266",
        "Embedded C++",
        "MQTT",
        "SNMP",
        "Android",
        "Python",
        "DSP",
        "Reverse engineering"
      ],
      "links": [],
      "groups": [
        {
          "title": "Embedded & IoT",
          "bullets": [
            "Built and deployed nine networked ESP8266 devices in C++, each reporting into a self-hosted MQTT broker or SNMP poller so the readings landed in the same monitoring stack as the rest of the network rather than in a vendor cloud application.",
            "Instrumented an off-grid solar installation with three-channel high-side current and voltage sensing, applying per-channel shunt calibration offsets and deriving panel wattage and PoE draw so battery behaviour could be trended over time instead of guessed at.",
            "Built a charging-cable thermal monitor that reads the handle's NTC thermistors through an external analog-to-digital converter, linearizing against a measured reference voltage and divider resistance, with a local display and an asynchronous web server for remote reads.",
            "Built sensing and actuation devices around the constraint each measurement actually had: a load-cell scale on a 24-bit converter with a remote tare command delivered over MQTT, interrupt-driven flow-pulse counting with switched 12-volt outputs, a time-of-flight liquid-level sensor averaging 25 ranging samples per reading to reject surface noise, and relay actuators that emulate a momentary button press rather than rewiring the appliance.",
            "Built a twelve-channel speaker selector and receiver with digital-potentiometer volume control, driving an increment/decrement potentiometer over GPIO while tracking absolute position in firmware so the web interface could set a level directly rather than only step it."
          ]
        },
        {
          "title": "Mobile",
          "bullets": [
            "Built a driving-feedback Android application that samples the accelerometer, applies a low-pass filter and a user-configurable moving-average window, and reports longitudinal, lateral and vertical g-force with peak-hold and calibration against the vehicle's resting orientation, mapped to published safety-score thresholds.",
            "Instrumented that application with real-user monitoring and crash reporting wired into lifecycle and interaction callbacks so field behaviour was measurable rather than inferred, and put it on a hosted CI pipeline that builds the package on every push.",
            "Built an Android diagnostic that surfaces live LTE serving-cell identity and channel information through the platform telephony APIs, giving a client-side view of the radio link rather than relying on the operator's own reporting."
          ]
        },
        {
          "title": "Signal processing & reverse engineering",
          "bullets": [
            "Built a desktop signal-processing tool with live plotting: multi-tone generation, Hamming-windowed FFT with window correction, power-spectral-density and channel-power computation, peak-to-average power ratio, and BPSK spreading for direct-sequence experiments.",
            "Reverse-engineered the undocumented serial output of a consumer radar detector, deriving its frequency scaling constant empirically and decoding packed little-endian multi-byte fields into the main and secondary target frequencies."
          ]
        }
      ]
    },
    {
      "id": "game-platform",
      "role": "Game Platform, Identity & Reverse Engineering",
      "org": "Independent project",
      "kind": "independent",
      "period": "2015 – 2018",
      "status": "Earlier project",
      "summary": [
        "A three-tier multiplayer game platform built as a two-person project with a software-company-grade toolchain: an original authentication tier, an OAuth2 identity provider, service discovery, and CI/CD delivery."
      ],
      "scope": [],
      "tags": [
        "Java",
        "Netty",
        "RabbitMQ",
        "MySQL",
        "Laravel",
        "OAuth2",
        "Maven",
        "Bamboo"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built an original 23,000-line Java lobby and authentication tier for a three-tier game platform: Netty protocol handling, RSA/XTEA/ISAAC session flow, pluggable MySQL and REST authentication, typed failure mapping, world discovery and handoff, social systems, and RabbitMQ cross-service messaging.",
            "Extended a large open-source game-server base with roughly 18,000 to 35,000 lines of defensible original change across 127 new files, including Netty/TLS administration, AMQP integration, a 15-region grid content system, developer editors, and operational hooks, while preserving honest attribution of the base code.",
            "Replaced hard-coded client hosts with DNS SRV service discovery and liveness probing, added environment-selectable launch modes and private-CA TLS, and built Maven shaded-JAR delivery through Bamboo CI and a CDN.",
            "Built a Laravel OAuth2 identity provider with a first-party/third-party partner trust model over Passport, domain and scope policy, email activation, RSA wrappers, browser tests, and a Java authentication library consumed by game services and Atlassian integration work.",
            "Operated a software-company-grade toolchain for a two-person project: self-hosted Bitbucket Server, Jira smart commits, Bamboo CI/CD, private Nexus artifacts, Confluence, chat-ops, RabbitMQ, DNS service discovery, and shared Maven parent POMs.",
            "Enforced consent policy inside the OAuth2 authorization endpoint rather than trusting registered clients: a partner trust model that reserved session-wide and full-account-control scopes for first-party clients, per-partner scope filtering that rejected an out-of-policy request outright instead of silently narrowing it, and consent-free re-authorization limited to first-party clients holding an explicit passthrough grant."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Audited the historical platform for credential hygiene, unsafe XStream deserialization, weak TLS, authorization-control defects, cryptographic migration gaps, and inherited chat and login tripwires, documenting reachability and authorship without claiming vendored engine or client code as original.",
            "Diagnosed a cross-language credential-format collision (bcrypt variant prefixes and a home-rolled PBKDF2 spread across PHP and Java) that had silently locked new accounts out of one client, and designed a multi-format credential-migration layer over a multi-module Spring Boot 2 project on then-new Java 10."
          ]
        }
      ]
    },
    {
      "id": "additional-projects",
      "role": "Additional Engineering Projects",
      "org": "Independent work",
      "kind": "independent",
      "period": "2002 – present",
      "status": "Ongoing",
      "summary": [
        "Independent learning, prototypes, production utilities, and authorized research spanning two decades of hands-on engineering."
      ],
      "scope": [],
      "tags": [
        "Laravel",
        "Spring Boot",
        "RabbitMQ",
        "Reverse engineering",
        "MikroTik"
      ],
      "links": [],
      "groups": [
        {
          "title": "Selected accomplishments",
          "bullets": [
            "Built a Laravel 11 cloud-VoIP application using OAuth2 authorization code with PKCE, encrypted queued token refresh with overlap protection, call-detail and recording APIs, phone-number and SMS features, Docker, and dual-registry GitHub Actions publishing.",
            "Developed an Atlassian Crowd directory integration, a Spring Boot vSphere VM-provisioning application, an NTLM/Active Directory single sign-on integration for Nginx, and a Laravel RabbitMQ queue driver.",
            "Built a bounded Spring Boot data-extraction web application with authentication, reCAPTCHA, and CSV export from a reusable multi-module Maven/Tomcat scaffold shared across Java projects."
          ]
        },
        {
          "title": "Selected accomplishments (analysis)",
          "bullets": [
            "Reverse-engineered a compromised game client cache by comparing 6,248 scripts across original and modified releases, isolated a 5,027-instruction obfuscated chat-handler prologue, reconstructed its runtime-built strings and substitution cipher, traced a sentinel-gated command channel capable of clipboard exfiltration, and documented a reproducible network-isolated analysis workflow.",
            "Designed a complete hardware, imaging, maintenance, and all-MikroTik 10GbE/LanCache plan for a ten-PC competitive gaming venue, balancing performance, thermals, long daily duty cycles, replacement inventory, and fleet uniformity (planning scope only)."
          ]
        },
        {
          "title": "Selected accomplishments (prototype)",
          "bullets": [
            "Built the web application for a game-item marketplace: third-party identity joined to platform user records, inventory and profile reads against the vendor's Web API, an HTTP command channel dispatching send and receive trade offers to a pool of distributed trading daemons with per-item status reconciliation, card-payment checkout, an AMQP queue driver for the framework, and chat-ops alerting, built by two people on a licensed commercial application base."
          ]
        },
        {
          "title": "Earlier engineering work",
          "bullets": [
            "Published and maintained a Laravel/Sentinel package for LDAP and Active Directory authentication in 2015, released as an installable Composer package.",
            "Maintained a Laravel integration package wrapping the Jira REST API in 2015, built on established upstream Jira and Laravel libraries rather than a from-scratch client.",
            "Operated an integrated team development workflow across Jira Core/Software/Service Desk, Confluence, Bitbucket Server, and Bamboo CI in 2016–2017, and reviewed other developers' code with specific guidance on decomposing oversized command handlers and removing duplicated code paths."
          ]
        },
        {
          "title": "Earlier engineering work (analysis)",
          "bullets": [
            "Designed and publicly shared normalized relational schemas for item constraints and character attributes in 2016, covering foreign-key relationships, typed constraint identifiers, composite-key tradeoffs, and an idempotent upsert pattern."
          ]
        }
      ]
    }
  ],
  "claims": [
    {
      "id": "carrier-platform-01-01",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Converted runbook-driven platform deployment into 6 versioned Ansible collections with 29 tagged releases in 76 days, covering deployment, database operations, system administration, VM preparation, orchestration, and preflight checks.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible",
        "skill-ansible-collections"
      ]
    },
    {
      "id": "carrier-platform-01-02",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Built the team's first collection release pipeline and test strategy, including 403 automated tests and 96 property-based tests in the earlier suite snapshot, parallel pytest execution, automatic versioning, artifact publication, and shared CI templates. Later deployment safeguards were challenged at 16 injected failure points and with 13 deliberate role mutations, checking preservation of a startable previous release.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible",
        "skill-gitlab-ci",
        "skill-pytest",
        "skill-property-based-testing",
        "skill-fault-injection",
        "skill-mutation-testing",
        "skill-rollback-engineering"
      ]
    },
    {
      "id": "carrier-platform-01-03",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Decomposed a monolithic deployment role into separate install, policy, and helper roles so routine policy changes could ship without replacing platform software.",
      "focus": [
        "platform",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible"
      ]
    },
    {
      "id": "carrier-platform-01-04",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Added dry-run audit reporting so operators could inspect a proposed change before authorizing execution.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible"
      ]
    },
    {
      "id": "carrier-platform-01-05",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Built a systemd-enabled Docker test harness so role changes could be validated locally instead of consuming shared lab capacity.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible",
        "skill-docker"
      ]
    },
    {
      "id": "carrier-platform-02-01",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Owned the Cassandra operations programme and shipped 14 tagged releases in roughly four weeks while the work moved through formal QA certification.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-02-02",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Automated backup and restore end to end with scheduling, retention, verification, capacity checks, retries, and alerting, replacing an inconsistent manual process.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-02-03",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Removed a data-integrity footgun in backup naming by adding fail-fast validation and then autodiscovery.",
      "focus": [
        "platform",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-02-04",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Implemented mutual-TLS support and service-account-safe certificate discovery for production-equivalent environments.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-02-05",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Rehearsed a high-risk multi-node topology change against an isolated replica before executing the live change successfully.",
      "focus": [
        "platform",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-02-06",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Performed encrypted-data migration analysis, load simulation, and operator-workflow simplification, cutting the planned manual input from roughly twelve variables to four.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-03-01",
      "roleId": "carrier-platform",
      "group": "CI/CD & release engineering",
      "text": "Root-caused recurring release blockers across build images, registry routing, and artifact authentication, then replaced repository-local workarounds with shared templates. Reconciled three policy-bundle packaging paths and added checks against overwriting vendor runtime files, resolving inconsistent branch and merge-request validation.",
      "focus": [
        "platform",
        "network",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-gitlab-ci",
        "skill-pipeline-templates",
        "skill-jfrog-artifactory",
        "skill-supply-chain-controls",
        "skill-root-cause-analysis"
      ]
    },
    {
      "id": "carrier-platform-03-02",
      "roleId": "carrier-platform",
      "group": "CI/CD & release engineering",
      "text": "Stood up a self-hosted CI runner for policy validation and built a multi-architecture base image for arm64 and amd64 development workflows.",
      "focus": [
        "platform",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-release-engineering"
      ]
    },
    {
      "id": "carrier-platform-03-03",
      "roleId": "carrier-platform",
      "group": "CI/CD & release engineering",
      "text": "Moved collection publishing onto a shared tag-driven release pipeline with dedicated service credentials and manual approval gates for deployment-sensitive actions.",
      "focus": [
        "platform",
        "security",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-release-engineering"
      ]
    },
    {
      "id": "carrier-platform-03-04",
      "roleId": "carrier-platform",
      "group": "CI/CD & release engineering",
      "text": "Brought the team's repositories to a green compliance pipeline and added automated documentation publication behind approval gates.",
      "focus": [
        "platform",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-release-engineering"
      ]
    },
    {
      "id": "carrier-platform-04-01",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Automated deployment of endpoint security, endpoint management, software inventory, vulnerability management, and MFA controls across a pre-production fleet.",
      "focus": [
        "platform",
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-endpoint-management",
        "skill-vulnerability-management",
        "skill-mfa"
      ]
    },
    {
      "id": "carrier-platform-04-02",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Delivered SIEM log-forwarding automation covering platform and operating-system logs across multiple fleet layouts. Automated enriched Linux audit-event forwarding across six development nodes, resolving SELinux and audit-daemon integration failures and using queued TCP delivery for centralized investigation.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-splunk-universal-forwarder",
        "skill-structured-logging-log-pipelines",
        "skill-auditd",
        "skill-rsyslog",
        "skill-selinux-troubleshooting"
      ]
    },
    {
      "id": "carrier-platform-04-03",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Remediated tracked vulnerability findings to closure, introduced safer package-manager-native maintenance operations, and delivered a certified upgrade path for legacy Linux hosts.",
      "focus": [
        "platform",
        "security",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-04-04",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Moved source-control permissions onto directory-backed groups and moved CI pipelines off personal credentials onto dedicated service accounts.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-04-05",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Added repository safeguards that keep lab secrets out of policy source control.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-05-01",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Reverse-engineered undocumented RADIUS accounting field derivations from policy logs and packet captures, establishing a behavioural-parity baseline for a platform rewrite.",
      "focus": [
        "platform",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-radius"
      ]
    },
    {
      "id": "carrier-platform-05-02",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Rebuilt individual accounting derivations to verified parity against that baseline and created replay tooling for repeatable protocol validation.",
      "focus": [
        "platform",
        "network",
        "ai",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-radius"
      ]
    },
    {
      "id": "carrier-platform-05-03",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Designed and delivered a state-persistence layer for a telecom policy runtime, then removed 16,390 lines of legacy code using execution evidence to prove what was genuinely unused.",
      "focus": [
        "platform",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-radius"
      ]
    },
    {
      "id": "carrier-platform-05-04",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Diagnosed difficult mutual-TLS and protocol-integration failures across RADIUS-over-TLS and a legacy subscriber-state interface.",
      "focus": [
        "platform",
        "network",
        "security",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-radius"
      ]
    },
    {
      "id": "carrier-platform-06-01",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Designed and shipped a Spring-based web platform for 802.1X/EAP supplicant test automation with configuration generation, credential handling, containerized execution, result parsing, dashboards, SIEM query integration, and automated delivery.",
      "focus": [
        "platform",
        "network",
        "security",
        "software",
        "ai",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot"
      ]
    },
    {
      "id": "carrier-platform-06-02",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Architected the platform as eleven Java 23 / Spring Boot modules with nine reusable Maven modules, multi-architecture Docker delivery, and 70 test classes containing more test code than production code, all sole-authored and able to survive 30-way parallel execution.",
      "focus": [
        "platform",
        "software",
        "ai",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-docker",
        "skill-java-23-spring-boot",
        "skill-maven"
      ]
    },
    {
      "id": "carrier-platform-06-03",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Built an end-to-end AAA testing platform spanning a typed Python library, operator CLIs, Android and iOS Appium automation, Docker, and gRPC; it collapsed repeated manual SIEM queries into a single call across 120+ tests and saved an estimated 6–10 engineer-hours in one certification cycle.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-docker",
        "skill-python"
      ]
    },
    {
      "id": "carrier-platform-06-04",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Automated 11 previously manual integration tests, reclaiming about 3.7 engineer-hours per full pass, and built a containerized pre-deployment policy validation gate across seven repositories, where policy bundles must boot in the AAA runtime and clear a 13-pattern fatal-error screen before publication.",
      "focus": [
        "platform",
        "software",
        "ai",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-06-05",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Defined and executed a roughly 30-case release regression suite spanning multiple EAP methods, mobile platforms, roaming scenarios, Passpoint, and negative cases.",
      "focus": [
        "platform",
        "network",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-07-01",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Automated VM provisioning from template preparation through cloud-init self-deployment, including dual-stack IPv4/IPv6 addressing and an IPv6-only defect that had been breaking unattended provisioning. Built and verified a Rocky Linux golden template, then provisioned eight database VMs and checked unique machine identities and SSH host keys on every running guest.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-vm-templating",
        "skill-cloud-init",
        "skill-ipv4-ipv6-dual-stack",
        "skill-rocky-linux",
        "skill-guest-customization-sysprep"
      ]
    },
    {
      "id": "carrier-platform-07-02",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Built control-node preflight checks that report automation readiness before a run touches infrastructure.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-07-03",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Delivered supporting engineering services including reverse proxying, status reporting, monitoring alerts, and team alert integrations.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-07-04",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Validated a major ESXi upgrade on live infrastructure and surfaced a lifecycle risk early enough for it to be resolved before an outage.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-08-01",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Authored 69 internal wiki pages over the engagement, including installation guides carried through formal QA certification.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-08-02",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Wrote an 11-page developer-onboarding suite for an internal policy language and runtime covering language reference, conventions, repository structure, testing, secrets handling, releases, and troubleshooting.",
      "focus": [
        "platform",
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-08-03",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Wrote internal proposals that set direction for collection-based automation, automated deployment, and software lifecycle planning.",
      "focus": [
        "platform",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-08-04",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Operationalized a 935-note engineering knowledge base as team documentation, publishing a curated 229-note subset behind an explicit per-note publication gate.",
      "focus": [
        "platform",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "carrier-platform-08-05",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Mentored engineers on Git and tooling and built an IDE plugin for the platform's policy language.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "independent-product-01-01",
      "roleId": "independent-product",
      "group": "Selected accomplishments",
      "text": "Independent product work exploring scheduled bandwidth orchestration and telecom workflow automation, currently under the working name NexusPort. It takes a class of network change that tends to be manual, repetitive, and timing-sensitive, and gives it a structured product surface with real guardrails: intent separated from execution, validation before anything touches a live service, and an operator approval gate in the loop.",
      "focus": [
        "platform",
        "network",
        "ai"
      ],
      "delivery": "prototype",
      "skillIds": []
    },
    {
      "id": "independent-product-01-02",
      "roleId": "independent-product",
      "group": "Selected accomplishments",
      "text": "The architecture is original, built after hours from public documentation, standard software libraries, and authorized API integrations where applicable. Final product naming and business structure are still being decided.",
      "focus": [
        "platform",
        "software"
      ],
      "delivery": "prototype",
      "skillIds": []
    },
    {
      "id": "duvall-wifi-01-01",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Founded and ran a technology and ISP services company covering network engineering, software development, hosting, cybersecurity, and managed IT. I owned customer discovery, architecture, implementation, production operations, sales, billing, and support.",
      "focus": [
        "platform",
        "network",
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "duvall-wifi-01-02",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Built a redundant multi-frequency wireless network capable of serving 160 homes with symmetric gigabit, backed by custom captive-portal and RADIUS software plus virtualized infrastructure, PKI, segmentation, monitoring, VPN connectivity, PBX/CRM integrations, and production Laravel and Spring applications.",
      "focus": [
        "platform",
        "network",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-radius",
        "skill-java-23-spring-boot",
        "skill-php-laravel"
      ]
    },
    {
      "id": "pnw-plumbing-01-01",
      "roleId": "pnw-plumbing",
      "group": "Selected accomplishments",
      "text": "Technology and growth consulting for a trades business. I brought customer acquisition cost down from roughly $150 to $5.10 and shifted 83.67% of inbound calls onto unpaid channels, working across the website, analytics, advertising, reviews, and conversion paths.",
      "focus": [
        "platform",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "pnw-plumbing-01-02",
      "roleId": "pnw-plumbing",
      "group": "Selected accomplishments",
      "text": "Delivery included a Laravel 10 production website, conversion tracking, advertising workflows, helpdesk support, and custom IP-camera security integrations.",
      "focus": [
        "platform",
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel"
      ]
    },
    {
      "id": "wilderness-awareness-01-01",
      "roleId": "wilderness-awareness",
      "group": "Selected accomplishments",
      "text": "Designed, quoted, installed, and operated a resilient enterprise network across three forested properties using roughly 700 meters of aerial and buried cabling plus point-to-point wireless links. The design avoided the cost of an additional internet circuit and improved outage resilience.",
      "focus": [
        "platform",
        "network",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "wilderness-awareness-01-02",
      "roleId": "wilderness-awareness",
      "group": "Selected accomplishments",
      "text": "Ongoing support covered routers, switches, access points, point-to-point wireless links, structured cabling, monitoring, and day-to-day technical support for staff.",
      "focus": [
        "platform",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "beyond-grey-skies-01-01",
      "roleId": "beyond-grey-skies",
      "group": "Selected accomplishments",
      "text": "Supported enterprise networks, data-center fabric, Linux and Windows servers, intrusion monitoring, and emergency technical operations, working across pfSense, VyOS, MikroTik RouterOS, and Cisco IOS.",
      "focus": [
        "platform",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-pfsense",
        "skill-vyos",
        "skill-mikrotik-routeros",
        "skill-cisco-ios"
      ]
    },
    {
      "id": "identity-platform-01-01",
      "roleId": "identity-platform",
      "group": "Selected accomplishments",
      "text": "Deployed an Authentik identity platform using Ansible, Docker Compose, declarative Blueprints, and Terraform-managed Cloudflare Access, with OIDC group claims for application authorization.",
      "focus": [
        "platform",
        "security",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-authentik",
        "skill-oidc-oauth-2-1",
        "skill-ansible",
        "skill-docker-compose",
        "skill-terraform-opentofu",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "identity-platform-01-02",
      "roleId": "identity-platform",
      "group": "Selected accomplishments",
      "text": "Verified signed identity tokens, allow/deny behavior, group-removal revocation, deactivated-user denial, and configuration reapplication through 20 infrastructure checks and a ten-check identity suite.",
      "focus": [
        "platform",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-authentik",
        "skill-oidc-oauth-2-1"
      ]
    },
    {
      "id": "identity-platform-01-03",
      "roleId": "identity-platform",
      "group": "Selected accomplishments",
      "text": "Validated idempotent deployment and unattended reboot recovery, and preserved existing access policies during additive application migration.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible",
        "skill-terraform-opentofu"
      ]
    },
    {
      "id": "joblead-system-01-01",
      "roleId": "joblead-system",
      "group": "Selected accomplishments",
      "text": "Built a Cloudflare Worker MCP gateway with OAuth 2.1 and per-client capability tokens, authenticated origin access, and a constrained API to a private CRM.",
      "focus": [
        "platform",
        "security",
        "software",
        "ai",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-mcp",
        "skill-oidc-oauth-2-1",
        "skill-cloudflare-access-workers",
        "skill-api-design"
      ]
    },
    {
      "id": "joblead-system-01-02",
      "roleId": "joblead-system",
      "group": "Selected accomplishments",
      "text": "Implemented review-first ingestion controls, dry-run/commit binding, rate caps, auditing, and independent kill switches; live read access is verified and write execution remains disabled.",
      "focus": [
        "platform",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-mcp",
        "skill-api-design",
        "skill-ai-agent-workflows",
        "skill-prompt-injection-controls",
        "skill-ai-application-security"
      ]
    },
    {
      "id": "joblead-system-01-03",
      "roleId": "joblead-system",
      "group": "Selected accomplishments",
      "text": "Documented 198 passing service tests and drilled kill switches at the edge, reverse proxy, and application layers, with observed shutdown times of approximately 7, 10, and 19 seconds respectively.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": []
    },
    {
      "id": "gpu-access-01-01",
      "roleId": "gpu-access",
      "group": "Selected accomplishments",
      "text": "Built a broker issuing short-lived, single-use Tailscale enrollment keys while keeping privileged OAuth credentials off rented hardware, with independent JWT validation for administrative access.",
      "focus": [
        "platform",
        "security",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-tailscale",
        "skill-oidc-oauth-2-1",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "gpu-access-01-02",
      "roleId": "gpu-access",
      "group": "Selected accomplishments",
      "text": "Automated deterministic virtual-address allocation, constrained gateway routing, and cleanup of expired nodes; verified the full join, permitted-access, blocked-port, and teardown path using a disposable container.",
      "focus": [
        "platform",
        "network",
        "ai"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-tailscale",
        "skill-nftables"
      ]
    },
    {
      "id": "gpu-access-01-03",
      "roleId": "gpu-access",
      "group": "Selected accomplishments",
      "text": "Validated the implementation with 34 unit tests and 20 gateway ruleset assertions, including fail-closed behavior when configuration is absent.",
      "focus": [
        "platform",
        "software",
        "ai",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-typescript",
        "skill-nftables"
      ]
    },
    {
      "id": "carrier-platform-01-06",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Replaced a multi-step manual deployment handoff with a single-command, version-pinned, idempotent deployment supporting roughly one-minute policy-only updates, dry-run impact reports, post-deploy verification, offline bundles, and sub-second symlink rollback.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ansible",
        "skill-dry-run-check-mode"
      ]
    },
    {
      "id": "carrier-platform-02-07",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Designed a Cassandra 4.1-to-5.0 rolling-upgrade path for the subscriber-authentication clusters.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-apache-cassandra-4-1-5-0",
        "skill-rolling-upgrades"
      ]
    },
    {
      "id": "carrier-platform-03-05",
      "roleId": "carrier-platform",
      "group": "CI/CD & release engineering",
      "text": "Administered a 12+ repository GitLab group, establishing Git Flow, CODEOWNERS, pipeline-gated merges, branch protection, artifact conventions, and reusable templates across the AAA automation portfolio.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-gitlab-ci",
        "skill-release-engineering"
      ]
    },
    {
      "id": "carrier-platform-05-05",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Sole-engineered a ground-up accounting-policy rewrite in the vendor policy DSL: 181 commits in roughly two and a half months across 15+ modules and 30+ configuration files, with CI/CD, defensive protocol parsing, LDAP failover, RADIUS/RadSec forwarding, and a documented 87-code operational logging registry.",
      "focus": [
        "network",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vendor-policy-dsls",
        "skill-radius",
        "skill-radsec-radius-over-tls",
        "skill-ldap-ad-integration"
      ]
    },
    {
      "id": "carrier-platform-05-06",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Implemented a single-probe write/read/delete smoke harness for every state model, turning multi-minute manual verification into sub-second post-deploy validation in a DSL with no debugger or stack traces.",
      "focus": [
        "network",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vendor-policy-dsls"
      ]
    },
    {
      "id": "carrier-platform-06-06",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Designed the shared cross-language contract layer (four gRPC services, eight RPC methods, 13 messages, and eight enums) consumed by Java and Python tools for session control, provisioning-cache operations, SIEM queries, and supplicant configuration.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-grpc-proto3",
        "skill-java-23-spring-boot",
        "skill-python"
      ]
    },
    {
      "id": "carrier-platform-06-07",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Built the companion portable task-executor agent in Python spanning four CPU architectures, with Kafka result signals, RADIUS/EAPOL probes, REST task discovery, and CI packaging, targeting a roughly 79-host lab fleet across two data centers and four environment tiers.",
      "focus": [
        "software",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-python",
        "skill-kafka",
        "skill-802-1x-eapol"
      ]
    },
    {
      "id": "carrier-platform-07-05",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Automated vSphere snapshot restore and environment-aware artifact retrieval, including a SOAP-to-pyVmomi migration, SOCKS5 support, remote DNS, and lab/production artifact-repository fallback so workflows behaved consistently across network segments.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-python",
        "skill-jfrog-artifactory"
      ]
    },
    {
      "id": "carrier-platform-08-06",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Built and deployed a TypeScript Webex assistant for engineering knowledge lookup, with access configured for 12 teammates, separate read-only tool gateways, and conversation isolation by caller and privilege tier; verified lookup and refusal behavior through live messaging.",
      "focus": [
        "ai",
        "software",
        "platform",
        "security",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-typescript",
        "skill-webex-bot-integrations",
        "skill-mcp",
        "skill-ai-agent-workflows",
        "skill-tool-use-governance-approval-gates"
      ]
    },
    {
      "id": "duvall-wifi-02-01",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Built the custom Spring Boot captive-portal and AAA backend implementing the FreeRADIUS REST hook surface for authorization, authentication, interim accounting, post-auth, and proxy phases, plus MikroTik hotspot redirect and prepaid-voucher flows.",
      "focus": [
        "network",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-radius",
        "skill-freeradius",
        "skill-mikrotik-routeros"
      ]
    },
    {
      "id": "duvall-wifi-02-02",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Implemented defense-in-depth portal authentication with brute-force throttling, GeoIP impossible-travel detection, device fingerprinting, reCAPTCHA, and JWT-based hotspot session tokens.",
      "focus": [
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-jwt-validation"
      ]
    },
    {
      "id": "duvall-wifi-01-03",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Built and operated a three-host VMware vSphere/vSAN environment with data-center colocation, an air-gapped root CA, zero-trust segmentation, secure administrative workstations, SIEM monitoring, VM templates, and hub-and-spoke VPN connectivity across customer networks.",
      "focus": [
        "platform",
        "security",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-vmware-vsan",
        "skill-mutual-tls-x-509",
        "skill-vm-templating"
      ]
    },
    {
      "id": "duvall-wifi-01-04",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Installed and spliced indoor and outdoor fiber and copper cabling, engineered point-to-point links, performed site surveys, and maintained routers, switches, access points, and RF paths as the company's field engineer.",
      "focus": [
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-mikrotik-routeros"
      ]
    },
    {
      "id": "duvall-wifi-01-05",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Operated a GenieACS TR-069/CWMP platform managing 58 MikroTik and Yealink devices through 15 presets and 15 provisions, documented its tag-driven idempotent configuration state machine, and identified security, permissions, provisioning, and device-health defects through live read-only analysis.",
      "focus": [
        "network",
        "platform",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-genieacs-tr-069",
        "skill-mikrotik-routeros"
      ]
    },
    {
      "id": "duvall-wifi-01-06",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Performed an owner-authorized, zero-impact attack-surface assessment across a roughly 12-service production presence using DNS and certificate-transparency reconnaissance, endpoint and auth-flow review, CORS and header testing, and vantage verification; delivered ranked remediation and disproved two initial split-horizon false positives before reporting.",
      "focus": [
        "security"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-vulnerability-research"
      ]
    },
    {
      "id": "duvall-wifi-01-07",
      "roleId": "duvall-wifi",
      "group": "Selected accomplishments",
      "text": "Built a communications single pane of glass integrating the VoIP PBX, CRM, missed calls, voicemail, text, and email, with call flows and customer pop-ups that cut spam and sped up resolution.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-api-design"
      ]
    },
    {
      "id": "pnw-plumbing-02-01",
      "roleId": "pnw-plumbing",
      "group": "Selected accomplishments",
      "text": "Built the lead-generation application in Laravel 10 with Nova administration, reCAPTCHA v3 score-based filtering, Google and Microsoft paid-click attribution, and dual-channel lead alerting, then replatformed it to static Astro once the dynamic attack surface was no longer justified.",
      "focus": [
        "software",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel",
        "skill-astro"
      ]
    },
    {
      "id": "pnw-plumbing-02-02",
      "roleId": "pnw-plumbing",
      "group": "Selected accomplishments",
      "text": "Analysed roughly 2,000 jobs, 1,350 customer records, 1,990 invoices, and 570 estimates to produce a constraint-based growth plan, KPI scorecard, CRM clean-up programme, retention strategy, acquisition playbook, and a buyer-ready data-room structure.",
      "focus": [],
      "delivery": "analysis",
      "skillIds": []
    },
    {
      "id": "gpu-access-02-01",
      "roleId": "gpu-access",
      "group": "Selected accomplishments",
      "text": "Operated a vLLM coding endpoint compatible with the OpenAI Chat Completions, OpenAI Responses, and Anthropic Messages APIs, including native streamed tool calls, so coding agents such as Claude Code, Codex CLI, Cline, and OpenCode work without a translation proxy, with the rented-host trust boundary documented.",
      "focus": [
        "ai",
        "platform",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vllm",
        "skill-ai-agent-workflows",
        "skill-api-design"
      ]
    },
    {
      "id": "joblead-system-02-01",
      "roleId": "joblead-system",
      "group": "Selected accomplishments",
      "text": "Built a self-hosted CRM and deterministic follow-up engine that converts raw job listings into researched, callable leads with scripts, evidence, reminders, business-hours scheduling, call outcomes, and recovery packets.",
      "focus": [
        "ai",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-python",
        "skill-docker-compose"
      ]
    },
    {
      "id": "joblead-system-02-02",
      "roleId": "joblead-system",
      "group": "Selected accomplishments",
      "text": "Implemented the engine as a dependency-free Python state machine with idempotent ingestion, duplicate protection, signed-webhook verification, replay safety, time-zone/DST/holiday scheduling, and least-privilege HMAC API access, shipping 101 unit tests and 85 of 85 live acceptance checks.",
      "focus": [
        "software",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-python",
        "skill-api-design"
      ]
    },
    {
      "id": "joblead-system-02-03",
      "roleId": "joblead-system",
      "group": "Selected accomplishments",
      "text": "Proved recoverability through checksummed daily and weekly backups, a disposable restore that booted a fresh application container with intact records, cross-host migration by restore, and a full VM reboot after which six services returned healthy without intervention.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-docker-compose"
      ]
    },
    {
      "id": "independent-product-02-01",
      "roleId": "independent-product",
      "group": "Selected accomplishments",
      "text": "The product model covers one-time, paired, recurring, and bulk bandwidth changes across enterprise ports, with customer/reseller separation, execution history, pricing estimates, onboarding, per-port billing, consolidated invoices, and white-label delivery; the implementation is Laravel with Dockerized delivery, staging operations, carrier-sandbox troubleshooting, and operator runbooks.",
      "focus": [
        "software",
        "network"
      ],
      "delivery": "prototype",
      "skillIds": [
        "skill-php-laravel",
        "skill-docker",
        "skill-api-design"
      ]
    },
    {
      "id": "observability-as-code-01-01",
      "roleId": "observability-as-code",
      "group": "Selected accomplishments",
      "text": "Managed a Datadog observability stack as code: 53 monitors (30 log, 21 metric, two query), four syslog pipelines totalling 46 processors, four log-derived metrics, an indexed log store, and a 17-widget security dashboard.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-datadog",
        "skill-terraform-opentofu"
      ]
    },
    {
      "id": "observability-as-code-01-02",
      "roleId": "observability-as-code",
      "group": "Selected accomplishments",
      "text": "Designed a reusable Terraform monitor module with 16 typed, validated inputs, enforced tags, count-gated optional resources, provider locking, and credentials kept out of band.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-terraform-opentofu",
        "skill-datadog"
      ]
    },
    {
      "id": "homelab-platform-01-01",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Operate a three-host vSphere/vCenter environment inventorying 149 VMs (86 running), 469 allocated vCPUs, roughly 686 GiB of allocated RAM, eight datastores, and 45 networks across Linux, Windows, RHEL, Debian, FreeBSD, and network-appliance workloads.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-vmware-vsan"
      ]
    },
    {
      "id": "homelab-platform-01-02",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Built repeatable VM provisioning and golden-template workflows spanning cloud-init guestinfo, clone customization, LVM growth, Docker bootstrap, network and IP validation, sysprep, smoke tests, and reusable Ansible and CLI automation.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-cloud-init",
        "skill-vm-templating",
        "skill-ansible"
      ]
    },
    {
      "id": "homelab-platform-01-03",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Performed read-only isolation and hypervisor-risk analysis across the workload, management, vMotion, and vSAN planes, validating layer-2 protections and blocked routing while identifying patch-level exposure to guest-to-host escape vulnerabilities and a high-blast-radius shared-storage design.",
      "focus": [
        "security",
        "platform"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-vulnerability-management"
      ]
    },
    {
      "id": "homelab-platform-01-04",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Recovered a vCenter outage caused by a full log partition and an expired machine SSL certificate: preserved the valid VMCA root, re-issued only the leaf certificate, restored services with no VM data loss, corrected syslog host attribution, and raised an exhausted file-descriptor limit from 1,024 to 65,536.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vmware-vsphere-vcenter",
        "skill-mutual-tls-x-509",
        "skill-root-cause-analysis"
      ]
    },
    {
      "id": "homelab-platform-01-05",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Audited the management and service exposure of a colocated RouterOS core router, validated ordered default-deny containment, and executed a no-reboot reduction of SNMP, bandwidth-test, captive-portal, and obsolete RADIUS exposure while preserving recovery access.",
      "focus": [
        "network",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-mikrotik-routeros"
      ]
    },
    {
      "id": "homelab-platform-01-06",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Built reusable Windows performance and security triage tooling covering hardware, storage health, patching, Defender, firewall, logons, public connections, persistence surfaces, signatures, remote tools, and high-refresh gaming bottlenecks.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-powershell"
      ]
    },
    {
      "id": "agent-crew-01-01",
      "roleId": "agent-crew",
      "group": "Selected accomplishments",
      "text": "Designed and maintain a 13-agent engineering crew on a multi-agent harness, with a canonical YAML roster, agent definitions, architecture decision records, least-privilege command and tool scopes, must-allow/must-deny tests, deterministic policy gates, and resource-guard analysis.",
      "focus": [
        "ai",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ai-agent-workflows",
        "skill-agent-skills-steering-docs"
      ]
    },
    {
      "id": "agent-crew-01-02",
      "roleId": "agent-crew",
      "group": "Selected accomplishments",
      "text": "Reverse-engineered the harness's provider architecture across provider factories, backend capability sets, spawn paths, model mapping, environment injection, and tool delivery to design credible extension paths for additional model providers, including self-hosted inference.",
      "focus": [
        "ai"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-reverse-engineering",
        "skill-ai-agent-workflows"
      ]
    },
    {
      "id": "agent-crew-01-03",
      "roleId": "agent-crew",
      "group": "Selected accomplishments",
      "text": "Documented a governance limitation where global permissive settings could bypass agent-level command scopes, separating static scope validation from actual runtime enforcement rather than overstating isolation.",
      "focus": [
        "ai",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ai-agent-workflows"
      ]
    },
    {
      "id": "web-factory-01-01",
      "roleId": "web-factory",
      "group": "Selected accomplishments",
      "text": "Built a reusable one-shot website factory that turns profile and context sources into container-validated Astro sites, with structured intake, derived themes, generated brand assets, per-PR preview deployments, a promotion path to production, and post-deploy verification.",
      "focus": [
        "software",
        "ai",
        "platform",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-astro",
        "skill-typescript",
        "skill-docker",
        "skill-github-actions",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "web-factory-01-02",
      "roleId": "web-factory",
      "group": "Selected accomplishments",
      "text": "Delivered multi-page sites for independent creators from sparse link-page and social inputs, implementing content-safety rules, no-index previews, custom domains, repeatable asset generation, and polling-based certificate and build verification.",
      "focus": [
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-astro",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "web-factory-01-03",
      "roleId": "web-factory",
      "group": "Selected accomplishments",
      "text": "Built a caching Cloudflare Worker API for live photo galleries with a route allowlist, upstream and browser compatibility controls, edge caching, static-build isolation, and navigation-lifecycle handling, integrating third-party feeds without exposing a general-purpose proxy.",
      "focus": [
        "software",
        "security",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-cloudflare-access-workers",
        "skill-typescript",
        "skill-api-design"
      ]
    },
    {
      "id": "web-factory-01-04",
      "roleId": "web-factory",
      "group": "Selected accomplishments",
      "text": "Built pakkit.net as a strict-TypeScript Astro 6 knowledge and portfolio platform with a data-driven service taxonomy, MDX content collections, machine-readable RSS and llms.txt routes, a canonical career bank behind the résumé section, and more than 130 published technical articles.",
      "focus": [
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-astro",
        "skill-typescript",
        "skill-seo-structured-data",
        "skill-docs-as-code"
      ]
    },
    {
      "id": "docs-hub-01-01",
      "roleId": "docs-hub",
      "group": "Selected accomplishments",
      "text": "Architecting a private multi-notebook publishing platform where each vault has isolated source credentials, builds, search index, image, service, hostname, and identity-group policy.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "in-progress",
      "skillIds": [
        "skill-obsidian-quartz",
        "skill-authentik",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "docs-hub-01-02",
      "roleId": "docs-hub",
      "group": "Selected accomplishments",
      "text": "Designed layered authorization through Cloudflare Access plus an origin-side gateway that validates JWT signature, issuer, expiry, and exact per-application audience, preventing cross-vault search, graph, attachment, cache, or metadata leakage.",
      "focus": [
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-oidc-oauth-2-1",
        "skill-jwt-validation",
        "skill-cloudflare-access-workers",
        "skill-authentik"
      ]
    },
    {
      "id": "docs-hub-01-03",
      "roleId": "docs-hub",
      "group": "Selected accomplishments",
      "text": "Completed the planning and non-live remediation cycle, correcting a zero-match firewall rule, an impossible reverse-proxy and Compose topology, and an unsafe state-backend assumption before any public or identity-system change.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-terraform-opentofu",
        "skill-docker-compose"
      ]
    },
    {
      "id": "docs-hub-01-04",
      "roleId": "docs-hub",
      "group": "Selected accomplishments",
      "text": "Provisioned and hardened a dedicated Ubuntu documentation VM through the hypervisor console and cloud-init: independently verified host keys, removed inherited administrative access, locked unused accounts, applied explicit SSH policy, patched and reboot-tested the host, and left only SSH listening on routable interfaces.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ubuntu",
        "skill-cloud-init",
        "skill-sshd-sysctl-hardening"
      ]
    },
    {
      "id": "docs-hub-01-05",
      "roleId": "docs-hub",
      "group": "Selected accomplishments",
      "text": "Built a synthetic fixture vault with nine Markdown documents, 31 validated wikilinks and embeds, seven deliberately publishable notes, negative content fixtures, and complete heading-anchor checks to support authorization and isolation testing without exposing personal content.",
      "focus": [
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-obsidian-quartz",
        "skill-regression-test-design"
      ]
    },
    {
      "id": "game-platform-01-01",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Built an original 23,000-line Java lobby and authentication tier for a three-tier game platform: Netty protocol handling, RSA/XTEA/ISAAC session flow, pluggable MySQL and REST authentication, typed failure mapping, world discovery and handoff, social systems, and RabbitMQ cross-service messaging.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-netty",
        "skill-rabbitmq"
      ]
    },
    {
      "id": "game-platform-01-02",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Extended a large open-source game-server base with roughly 18,000 to 35,000 lines of defensible original change across 127 new files, including Netty/TLS administration, AMQP integration, a 15-region grid content system, developer editors, and operational hooks, while preserving honest attribution of the base code.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-rabbitmq"
      ]
    },
    {
      "id": "game-platform-01-03",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Replaced hard-coded client hosts with DNS SRV service discovery and liveness probing, added environment-selectable launch modes and private-CA TLS, and built Maven shaded-JAR delivery through Bamboo CI and a CDN.",
      "focus": [
        "software",
        "platform",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-maven",
        "skill-release-engineering",
        "skill-mutual-tls-x-509"
      ]
    },
    {
      "id": "game-platform-01-04",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Built a Laravel OAuth2 identity provider with a first-party/third-party partner trust model over Passport, domain and scope policy, email activation, RSA wrappers, browser tests, and a Java authentication library consumed by game services and Atlassian integration work.",
      "focus": [
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel",
        "skill-oidc-oauth-2-1"
      ]
    },
    {
      "id": "game-platform-01-05",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Operated a software-company-grade toolchain for a two-person project: self-hosted Bitbucket Server, Jira smart commits, Bamboo CI/CD, private Nexus artifacts, Confluence, chat-ops, RabbitMQ, DNS service discovery, and shared Maven parent POMs.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-release-engineering",
        "skill-maven"
      ]
    },
    {
      "id": "game-platform-01-06",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Audited the historical platform for credential hygiene, unsafe XStream deserialization, weak TLS, authorization-control defects, cryptographic migration gaps, and inherited chat and login tripwires, documenting reachability and authorship without claiming vendored engine or client code as original.",
      "focus": [
        "security"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-vulnerability-research",
        "skill-java-23-spring-boot"
      ]
    },
    {
      "id": "additional-projects-01-01",
      "roleId": "additional-projects",
      "group": "Selected accomplishments",
      "text": "Built a Laravel 11 cloud-VoIP application using OAuth2 authorization code with PKCE, encrypted queued token refresh with overlap protection, call-detail and recording APIs, phone-number and SMS features, Docker, and dual-registry GitHub Actions publishing.",
      "focus": [
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel",
        "skill-oidc-oauth-2-1",
        "skill-docker",
        "skill-github-actions"
      ]
    },
    {
      "id": "additional-projects-01-02",
      "roleId": "additional-projects",
      "group": "Selected accomplishments",
      "text": "Developed an Atlassian Crowd directory integration, a Spring Boot vSphere VM-provisioning application, an NTLM/Active Directory single sign-on integration for Nginx, and a Laravel RabbitMQ queue driver.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-php-laravel",
        "skill-ldap-ad-integration",
        "skill-rabbitmq",
        "skill-vmware-vsphere-vcenter"
      ]
    },
    {
      "id": "device-integration-01-01",
      "roleId": "device-integration",
      "group": "Selected accomplishments",
      "text": "Built a Home Assistant custom component for infrared device control that registers its own service and writes vendor control frames to a networked gateway over TCP, with a per-call device override so one integration drives more than one gateway.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-home-assistant",
        "skill-python",
        "skill-api-design"
      ]
    },
    {
      "id": "additional-projects-01-04",
      "roleId": "additional-projects",
      "group": "Selected accomplishments",
      "text": "Reverse-engineered a compromised game client cache by comparing 6,248 scripts across original and modified releases, isolated a 5,027-instruction obfuscated chat-handler prologue, reconstructed its runtime-built strings and substitution cipher, traced a sentinel-gated command channel capable of clipboard exfiltration, and documented a reproducible network-isolated analysis workflow.",
      "focus": [
        "security"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-reverse-engineering",
        "skill-vulnerability-research"
      ]
    },
    {
      "id": "additional-projects-01-05",
      "roleId": "additional-projects",
      "group": "Selected accomplishments",
      "text": "Designed a complete hardware, imaging, maintenance, and all-MikroTik 10GbE/LanCache plan for a ten-PC competitive gaming venue, balancing performance, thermals, long daily duty cycles, replacement inventory, and fleet uniformity (planning scope only).",
      "focus": [
        "network"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-mikrotik-routeros"
      ]
    },
    {
      "id": "additional-projects-01-06",
      "roleId": "additional-projects",
      "group": "Selected accomplishments",
      "text": "Built a bounded Spring Boot data-extraction web application with authentication, reCAPTCHA, and CSV export from a reusable multi-module Maven/Tomcat scaffold shared across Java projects.",
      "focus": [
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-maven"
      ]
    },
    {
      "id": "identity-platform-01-04",
      "roleId": "identity-platform",
      "group": "Selected accomplishments",
      "text": "Imported the existing edge-access applications into Terraform without recreating them, preserved fallback login paths, and caught destructive nulling of previously unmanaged fields in plan review before it reached production.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-terraform-opentofu",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "identity-platform-01-05",
      "roleId": "identity-platform",
      "group": "Selected accomplishments",
      "text": "Operate the platform as a product: invitation flows, a documented two-change procedure for putting an application behind OIDC or SAML login, service tokens for machine callers, and a maintained trap list so protected applications work the first time.",
      "focus": [
        "security",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-authentik",
        "skill-oidc-oauth-2-1"
      ]
    },
    {
      "id": "game-platform-01-07",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Diagnosed a cross-language credential-format collision (bcrypt variant prefixes and a home-rolled PBKDF2 spread across PHP and Java) that had silently locked new accounts out of one client, and designed a multi-format credential-migration layer over a multi-module Spring Boot 2 project on then-new Java 10.",
      "focus": [
        "security",
        "software"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-php-laravel",
        "skill-application-security-secure-code-review"
      ]
    },
    {
      "id": "web-factory-01-05",
      "roleId": "web-factory",
      "group": "Selected accomplishments",
      "text": "Integrated a performer's Astro booking site with their hosted CRM: build-time fetch of upcoming shows with a default-deny public filter, a small proxy that creates contacts and events through the authenticated API after live testing disproved the assumed public form endpoint, UTM lead-attribution passthrough, and a testimonials feed, verified end to end in production.",
      "focus": [
        "software",
        "ai",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-astro",
        "skill-cloudflare-access-workers",
        "skill-api-design",
        "skill-attribution-conversion-tracking"
      ]
    },
    {
      "id": "homelab-platform-01-07",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Ran a phased vulnerability audit across an 86-host fleet: port sweep, service and version inventory, advisory-based CVE assessment with false positives rejected on evidence, and a gentler profile plus post-scan health verification for fragile hosts.",
      "focus": [
        "security",
        "platform"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-vulnerability-management",
        "skill-attack-surface-analysis"
      ]
    },
    {
      "id": "homelab-platform-01-08",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Root-caused vSAN write latency to two stacked causes, an in-flight resync landing on one host's consumer-grade cache SSD and a chronic hardware-compatibility mismatch, then benchmarked the cluster against a Ceph deployment to separate fixable latency from latency that is acceptable by design.",
      "focus": [
        "platform"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-vmware-vsan",
        "skill-root-cause-analysis"
      ]
    },
    {
      "id": "homelab-platform-01-09",
      "roleId": "homelab-platform",
      "group": "Selected accomplishments",
      "text": "Designed the standard internet ingress for self-hosted services: a Cloudflare edge with WAF and identity-gated Access in front of a core router that admits only Cloudflare's ranges, terminating at an nginx origin with per-hostname Origin CA certificates and authenticated origin pulls across roughly 55 virtual hosts.",
      "focus": [
        "network",
        "security",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-cloudflare-origin-ca-authenticated-origin-pulls",
        "skill-mikrotik-routeros",
        "skill-zero-trust",
        "skill-cloudflare-access-workers"
      ]
    },
    {
      "id": "ops-tooling-01-01",
      "roleId": "ops-tooling",
      "group": "Selected accomplishments",
      "text": "Built dependency-free, standard-library Python CLIs for the systems I operate: a TR-069 ACS client, a RouterOS API client with vSphere lab snapshot and revert, a WireGuard peer minter with IPAM address allocation and X25519 implemented in-tree, a Home Assistant REST and WebSocket client, a field-service CRM analytics client, and a game-cache script decompiler.",
      "focus": [
        "software",
        "network",
        "ai",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-python",
        "skill-genieacs-tr-069",
        "skill-mikrotik-routeros",
        "skill-vpn-design-wireguard",
        "skill-home-assistant"
      ]
    },
    {
      "id": "ops-tooling-01-02",
      "roleId": "ops-tooling",
      "group": "Selected accomplishments",
      "text": "Paired every tool with an agent skill that states when to use it, which credentials it reads and never prints, the privilege level to confirm before writing, and the trap list that makes it work first time, so AI assistants can run the estate under explicit per-change approval.",
      "focus": [
        "ai",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-agent-skills-steering-docs",
        "skill-ai-agent-workflows",
        "skill-tool-use-governance-approval-gates"
      ]
    },
    {
      "id": "ops-tooling-01-03",
      "roleId": "ops-tooling",
      "group": "Selected accomplishments",
      "text": "Established a proof-based change discipline for database-backed upgrades: exact baseline counts, streaming the compressed dump back through a tuple parser to prove the rows are in it, and a post-change row-level diff that classifies every difference as schema migration, live activity, or actual loss.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-backup-verification",
        "skill-restore-drills",
        "skill-python"
      ]
    },
    {
      "id": "ops-tooling-01-04",
      "roleId": "ops-tooling",
      "group": "Selected accomplishments",
      "text": "Shipped a verifier for published services that proves DNS is proxied, the edge gate answers, and, the step everyone skips, that the origin refuses a connection without Cloudflare's client certificate.",
      "focus": [
        "security",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-cloudflare-origin-ca-authenticated-origin-pulls",
        "skill-python",
        "skill-attack-surface-analysis"
      ]
    },
    {
      "id": "ops-tooling-01-05",
      "roleId": "ops-tooling",
      "group": "Selected accomplishments",
      "text": "Automated the VM lifecycle end to end: golden-template sealing with preflight snapshot, modernization, guestinfo readiness checks and identity wipe; cloud-init guestinfo deployments that prove the guest came up; and unattended multi-hop Ubuntu LTS upgrades over SSH with hypervisor snapshots as the rollback plan.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-vm-templating",
        "skill-cloud-init",
        "skill-ubuntu",
        "skill-vmware-vsphere-vcenter"
      ]
    },
    {
      "id": "ops-tooling-01-06",
      "roleId": "ops-tooling",
      "group": "Selected accomplishments",
      "text": "Consolidated a 12-repository Ansible estate (roughly 4,400 lines of real automation spanning an Atlassian stack, Active Directory and certificate-services labs, LEMP and Laravel hosting, security hardening, and certificate distribution) into namespaced collections, de-duplicating roles and repairing playbooks that no longer ran.",
      "focus": [
        "platform"
      ],
      "delivery": "in-progress",
      "skillIds": [
        "skill-ansible",
        "skill-ansible-collections"
      ]
    },
    {
      "id": "carrier-platform-01-07",
      "roleId": "carrier-platform",
      "group": "Infrastructure automation (Ansible)",
      "text": "Designed deployment-time configuration and secrets tooling that separates reusable policy artifacts from environment values and versioned encrypted secrets; released the deployment component with environment validation, provenance tracking, and compatibility checks while broader rollout remained in progress.",
      "focus": [
        "platform",
        "security",
        "software"
      ],
      "delivery": "in-progress",
      "skillIds": [
        "skill-ansible",
        "skill-jinja2",
        "skill-sops-age",
        "skill-artifact-provenance"
      ]
    },
    {
      "id": "carrier-platform-02-08",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Optimized a legacy Cassandra decryption UDF, reducing development-benchmark mean latency from 12.47 ms to 0.70 ms and increasing 16-thread throughput from 635 to approximately 13,100 operations per second; scoped equivalence and round-trip compatibility checks to the tested variants.",
      "focus": [
        "platform",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-apache-cassandra-4-1-5-0",
        "skill-user-defined-functions",
        "skill-performance-benchmarking",
        "skill-behavioural-parity-testing"
      ]
    },
    {
      "id": "carrier-platform-04-06",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Automated directory-backed SSO across engineering tools using SAML, OIDC, and OAuth, including group-driven account provisioning and role mapping, tested allow/deny behavior, and preserved local recovery access.",
      "focus": [
        "security",
        "platform",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-authentik",
        "skill-saml-jit-provisioning",
        "skill-ldap-ad-integration",
        "skill-ansible",
        "skill-grafana",
        "skill-portainer",
        "skill-oidc-oauth-2-1"
      ]
    },
    {
      "id": "carrier-platform-07-06",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Built repeatable IPAM import and drift-audit tooling, reconciled a 233-VM development inventory, and populated a separate integration-test inventory covering 62 VLANs, 144 subnets, and 176 addresses using hypervisor, host, and telemetry evidence.",
      "focus": [
        "network",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-phpipam",
        "skill-python",
        "skill-vmware-vsphere-vcenter",
        "skill-ipv4-ipv6-dual-stack"
      ]
    },
    {
      "id": "carrier-platform-05-07",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Diagnosed two independent causes of silent RADIUS accounting health-check failures—a runtime compatibility issue and missing protocol attributes—and validated the corrected probe with 12 of 12 successful live responses at approximately 140 ms median latency; load-balancer monitor deployment remained pending.",
      "focus": [
        "network",
        "platform",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-radius",
        "skill-python",
        "skill-health-checks",
        "skill-root-cause-analysis"
      ]
    },
    {
      "id": "carrier-platform-03-06",
      "roleId": "carrier-platform",
      "group": "CI/CD & release engineering",
      "text": "Migrated a development policy configuration to templated values and encrypted secrets while preserving byte-identical output across all 62 rendered files; credential rotation remained a separate follow-up.",
      "focus": [
        "platform",
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-sops-age",
        "skill-jinja2",
        "skill-behavioural-parity-testing"
      ]
    },
    {
      "id": "carrier-platform-07-07",
      "roleId": "carrier-platform",
      "group": "Virtualization & lab platform",
      "text": "Restored an internal application's login service by tracing failed database session writes to disk exhaustion caused by a cascading Redis and container-logging failure; reclaimed capacity and prepared log-rotation controls.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-mariadb-mysql",
        "skill-redis",
        "skill-docker",
        "skill-root-cause-analysis",
        "skill-incident-response-postmortems"
      ]
    },
    {
      "id": "carrier-platform-02-09",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Released a database-automation fix spanning four CQL roles, correcting credential propagation and variable-precedence defects; tested the published package against operator instructions with a CQL stub and repaired five documentation errors while real-cluster recertification remained pending.",
      "focus": [
        "platform",
        "software",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-cql-cqlsh",
        "skill-ansible",
        "skill-release-engineering",
        "skill-mops-runbooks"
      ]
    },
    {
      "id": "carrier-platform-08-07",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Built reusable AI-workflow tools for engineering evidence retrieval, outbound sanitization, and document consistency, with 193 passing assertions and negative tests; corrected repository-counting errors caused by duplicate counting of repository history and uninitialized submodules.",
      "focus": [
        "ai",
        "software",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ai-agent-workflows",
        "skill-agent-skills-steering-docs",
        "skill-python",
        "skill-docs-as-code"
      ]
    },
    {
      "id": "carrier-platform-08-08",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Prototyped a per-engineer status ledger using two weeks of real work, identified conflicts in hand-maintained reporting, and designed a refreshable contribution model around existing Jira fields; recurring automation and broader adoption remained next steps.",
      "focus": [
        "ai",
        "platform"
      ],
      "delivery": "prototype",
      "skillIds": [
        "skill-jira-confluence",
        "skill-docs-as-code"
      ]
    },
    {
      "id": "game-platform-01-08",
      "roleId": "game-platform",
      "group": "Selected accomplishments",
      "text": "Enforced consent policy inside the OAuth2 authorization endpoint rather than trusting registered clients: a partner trust model that reserved session-wide and full-account-control scopes for first-party clients, per-partner scope filtering that rejected an out-of-policy request outright instead of silently narrowing it, and consent-free re-authorization limited to first-party clients holding an explicit passthrough grant.",
      "focus": [
        "security",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel",
        "skill-laravel-passport-sanctum-socialite",
        "skill-oidc-oauth-2-1",
        "skill-application-security-secure-code-review"
      ]
    },
    {
      "id": "additional-projects-01-07",
      "roleId": "additional-projects",
      "group": "Selected accomplishments",
      "text": "Built the web application for a game-item marketplace: third-party identity joined to platform user records, inventory and profile reads against the vendor's Web API, an HTTP command channel dispatching send and receive trade offers to a pool of distributed trading daemons with per-item status reconciliation, card-payment checkout, an AMQP queue driver for the framework, and chat-ops alerting, built by two people on a licensed commercial application base.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "prototype",
      "skillIds": [
        "skill-php-laravel",
        "skill-eloquent-blade",
        "skill-oidc-oauth-2-1",
        "skill-rabbitmq",
        "skill-api-design",
        "skill-stripe-payments",
        "skill-mariadb-mysql",
        "skill-bitbucket-server-bamboo",
        "skill-jira-confluence"
      ]
    },
    {
      "id": "device-integration-01-02",
      "roleId": "device-integration",
      "group": "Selected accomplishments",
      "text": "Bridged a USB serial tag scanner into a home-automation platform by implementing its MQTT discovery and scan contract directly instead of installing an add-on: a service that selects the device by USB descriptor, publishes its own discovery configuration on connect, republishes each scan as a structured event, and re-establishes the broker session before every publish, paired with udev rules that rebuild the container against the current device node whenever the scanner is plugged in or removed.",
      "focus": [
        "software",
        "platform",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-mqtt",
        "skill-home-assistant",
        "skill-udev-serial-device-integration",
        "skill-docker",
        "skill-bash",
        "skill-maven"
      ]
    },
    {
      "id": "config-containment-01-01",
      "roleId": "config-containment",
      "group": "Selected accomplishments",
      "text": "Put a version-controlled central store behind a Windows domain's Group Policy: 213 administrative templates with a complete English presentation set and five further language packs for the third-party templates, each vendor import landing as its own commit pinned to a named upstream version, so policy-definition changes became reviewable and revertible instead of being hand-copied into the domain share.",
      "focus": [
        "platform",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-active-directory-group-policy",
        "skill-ldap-ad-integration",
        "skill-endpoint-management",
        "skill-vendor-policy-dsls"
      ]
    },
    {
      "id": "config-containment-01-02",
      "roleId": "config-containment",
      "group": "Selected accomplishments",
      "text": "Contained a containerized network daemon behind a default-deny egress policy so it could only reach the internet through a supervised VPN tunnel: outbound traffic dropped by default with narrow exceptions for the tunnel, DNS and the VPN endpoint, a management interface reachable from the local network but explicitly dropped on the tunnel side, and process supervision that restarts the tunnel without restarting the daemon.",
      "focus": [
        "platform",
        "network",
        "security"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-docker",
        "skill-docker-compose",
        "skill-firewall-policy",
        "skill-openvpn",
        "skill-bash",
        "skill-ubuntu"
      ]
    },
    {
      "id": "device-integration-01-03",
      "roleId": "device-integration",
      "group": "Selected accomplishments",
      "text": "Prototyped a Java service that rendered CRM contacts as the vendor-native XML directory the deployed SIP handsets fetch, so the handset directory tracked the CRM instead of being maintained by hand, structured as a multi-module project separating the CRM client, the directory renderer, and the web tier.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "prototype",
      "skillIds": [
        "skill-java-23-spring-boot",
        "skill-maven",
        "skill-multi-module-monoliths",
        "skill-espocrm",
        "skill-voip-pbx",
        "skill-api-design",
        "skill-yaml-xml-html-css"
      ]
    },
    {
      "id": "embedded-signal-01-01",
      "roleId": "embedded-signal",
      "group": "Embedded & IoT",
      "text": "Built and deployed nine networked ESP8266 devices in C++, each reporting into a self-hosted MQTT broker or SNMP poller so the readings landed in the same monitoring stack as the rest of the network rather than in a vendor cloud application.",
      "focus": [
        "platform",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-embedded-c-arduino",
        "skill-esp8266",
        "skill-mqtt",
        "skill-snmp"
      ]
    },
    {
      "id": "embedded-signal-01-02",
      "roleId": "embedded-signal",
      "group": "Embedded & IoT",
      "text": "Instrumented an off-grid solar installation with three-channel high-side current and voltage sensing, applying per-channel shunt calibration offsets and deriving panel wattage and PoE draw so battery behaviour could be trended over time instead of guessed at.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-embedded-c-arduino",
        "skill-adc-sensor-calibration",
        "skill-i2c-spi",
        "skill-mqtt"
      ]
    },
    {
      "id": "embedded-signal-01-03",
      "roleId": "embedded-signal",
      "group": "Embedded & IoT",
      "text": "Built a charging-cable thermal monitor that reads the handle's NTC thermistors through an external analog-to-digital converter, linearizing against a measured reference voltage and divider resistance, with a local display and an asynchronous web server for remote reads.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-embedded-c-arduino",
        "skill-adc-sensor-calibration",
        "skill-i2c-spi"
      ]
    },
    {
      "id": "embedded-signal-01-04",
      "roleId": "embedded-signal",
      "group": "Embedded & IoT",
      "text": "Built sensing and actuation devices around the constraint each measurement actually had: a load-cell scale on a 24-bit converter with a remote tare command delivered over MQTT, interrupt-driven flow-pulse counting with switched 12-volt outputs, a time-of-flight liquid-level sensor averaging 25 ranging samples per reading to reject surface noise, and relay actuators that emulate a momentary button press rather than rewiring the appliance.",
      "focus": [
        "platform",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-embedded-c-arduino",
        "skill-interrupt-driven-io",
        "skill-adc-sensor-calibration",
        "skill-mqtt"
      ]
    },
    {
      "id": "embedded-signal-01-05",
      "roleId": "embedded-signal",
      "group": "Embedded & IoT",
      "text": "Built a twelve-channel speaker selector and receiver with digital-potentiometer volume control, driving an increment/decrement potentiometer over GPIO while tracking absolute position in firmware so the web interface could set a level directly rather than only step it.",
      "focus": [
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-embedded-c-arduino",
        "skill-i2c-spi"
      ]
    },
    {
      "id": "embedded-signal-02-01",
      "roleId": "embedded-signal",
      "group": "Mobile",
      "text": "Built a driving-feedback Android application that samples the accelerometer, applies a low-pass filter and a user-configurable moving-average window, and reports longitudinal, lateral and vertical g-force with peak-hold and calibration against the vehicle's resting orientation, mapped to published safety-score thresholds.",
      "focus": [
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-android-sdk",
        "skill-sensor-filtering"
      ]
    },
    {
      "id": "embedded-signal-02-02",
      "roleId": "embedded-signal",
      "group": "Mobile",
      "text": "Instrumented that application with real-user monitoring and crash reporting wired into lifecycle and interaction callbacks so field behaviour was measurable rather than inferred, and put it on a hosted CI pipeline that builds the package on every push.",
      "focus": [
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-android-sdk",
        "skill-real-user-monitoring",
        "skill-sentry",
        "skill-azure-pipelines"
      ]
    },
    {
      "id": "embedded-signal-02-03",
      "roleId": "embedded-signal",
      "group": "Mobile",
      "text": "Built an Android diagnostic that surfaces live LTE serving-cell identity and channel information through the platform telephony APIs, giving a client-side view of the radio link rather than relying on the operator's own reporting.",
      "focus": [
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-android-sdk"
      ]
    },
    {
      "id": "embedded-signal-03-01",
      "roleId": "embedded-signal",
      "group": "Signal processing & reverse engineering",
      "text": "Built a desktop signal-processing tool with live plotting: multi-tone generation, Hamming-windowed FFT with window correction, power-spectral-density and channel-power computation, peak-to-average power ratio, and BPSK spreading for direct-sequence experiments.",
      "focus": [
        "network",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-python",
        "skill-numpy-scipy",
        "skill-fft-spectral-analysis",
        "skill-digital-modulation",
        "skill-pyqt"
      ]
    },
    {
      "id": "embedded-signal-03-02",
      "roleId": "embedded-signal",
      "group": "Signal processing & reverse engineering",
      "text": "Reverse-engineered the undocumented serial output of a consumer radar detector, deriving its frequency scaling constant empirically and decoding packed little-endian multi-byte fields into the main and secondary target frequencies.",
      "focus": [
        "network",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-python",
        "skill-reverse-engineering",
        "skill-udev-serial-device-integration"
      ]
    },
    {
      "id": "additional-projects-01-08",
      "roleId": "additional-projects",
      "group": "Earlier engineering work",
      "text": "Published and maintained a Laravel/Sentinel package for LDAP and Active Directory authentication in 2015, released as an installable Composer package.",
      "focus": [
        "software",
        "security",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel",
        "skill-ldap-ad-integration"
      ]
    },
    {
      "id": "additional-projects-01-09",
      "roleId": "additional-projects",
      "group": "Earlier engineering work",
      "text": "Maintained a Laravel integration package wrapping the Jira REST API in 2015, built on established upstream Jira and Laravel libraries rather than a from-scratch client.",
      "focus": [
        "software",
        "integration"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-php-laravel",
        "skill-jira-confluence",
        "skill-api-design"
      ]
    },
    {
      "id": "additional-projects-01-10",
      "roleId": "additional-projects",
      "group": "Earlier engineering work",
      "text": "Designed and publicly shared normalized relational schemas for item constraints and character attributes in 2016, covering foreign-key relationships, typed constraint identifiers, composite-key tradeoffs, and an idempotent upsert pattern.",
      "focus": [
        "software"
      ],
      "delivery": "analysis",
      "skillIds": [
        "skill-mariadb-mysql"
      ]
    },
    {
      "id": "additional-projects-01-11",
      "roleId": "additional-projects",
      "group": "Earlier engineering work",
      "text": "Operated an integrated team development workflow across Jira Core/Software/Service Desk, Confluence, Bitbucket Server, and Bamboo CI in 2016–2017, and reviewed other developers' code with specific guidance on decomposing oversized command handlers and removing duplicated code paths.",
      "focus": [
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-jira-confluence",
        "skill-bitbucket-server-bamboo",
        "skill-release-engineering"
      ]
    },
    {
      "id": "carrier-platform-08-09",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Built and maintained a library of roughly 54 reusable AI agent skills across three engineering workspaces, codifying workflows for infrastructure operations, investigation and evidence gathering, security remediation, documentation, configuration management and telecom policy work, and authored an audit that reconciles all three workspace roots in a single run to flag duplicated skills, dead bundled-file references, one-sided skill boundaries, and colliding trigger phrases that would otherwise make agent dispatch nondeterministic.",
      "focus": [
        "ai",
        "platform",
        "software",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-ai-agent-workflows",
        "skill-agent-skills-steering-docs",
        "skill-tool-use-governance-approval-gates",
        "skill-docs-as-code"
      ]
    },
    {
      "id": "carrier-platform-05-08",
      "roleId": "carrier-platform",
      "group": "Network & protocol engineering (RADIUS / EAP)",
      "text": "Root-caused a TLS handshake failure blocking OAuth2 token retrieval by isolating the ALPN extension in the ClientHello as the trigger, eliminating DNS resolution, TCP reachability, certificate interception, TLS version negotiation and general HTTPS egress with a positive control for each, then proving with a four-variant differential matrix that the reset followed the extension being present rather than the protocol offered, and restoring token issuance the same day.",
      "focus": [
        "network",
        "security",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-tls-alpn-handshake-analysis",
        "skill-root-cause-analysis",
        "skill-oidc-oauth-2-1"
      ]
    },
    {
      "id": "carrier-platform-08-10",
      "roleId": "carrier-platform",
      "group": "Documentation & enablement",
      "text": "Carried the platform automation portfolio as its sole maintainer in 21 of the 27 codebases surveyed, spanning configuration management, telecom policy, test platforms and operational tooling with no second commit author.",
      "focus": [
        "platform",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-platform-engineering"
      ]
    },
    {
      "id": "carrier-platform-04-07",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Shipped CIS-aligned kernel and SSH daemon hardening as a fleet role, validating each generated daemon configuration with a syntax check before applying it and ordering the drop-in files so the existing access policy stayed authoritative instead of being silently overridden.",
      "focus": [
        "security",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-cis-benchmarks",
        "skill-sshd-sysctl-hardening",
        "skill-ansible",
        "skill-kernel-tuning"
      ]
    },
    {
      "id": "carrier-platform-04-08",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Removed a destructive failure mode from fleet kernel maintenance by replacing two fragile shell steps with an explicit running-kernel check and an old-installs-only removal, so the automation could no longer delete the kernel the host had actually booted.",
      "focus": [
        "security",
        "platform",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-dnf-grubby",
        "skill-ansible",
        "skill-rollback-engineering"
      ]
    },
    {
      "id": "carrier-platform-02-10",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Diagnosed and closed an availability defect in a subscriber-authentication database where crafted input to its encryption and decryption user-defined functions could bring the cluster down.",
      "focus": [
        "security",
        "platform"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-apache-cassandra-4-1-5-0",
        "skill-user-defined-functions",
        "skill-root-cause-analysis",
        "skill-application-security-secure-code-review"
      ]
    },
    {
      "id": "carrier-platform-02-11",
      "roleId": "carrier-platform",
      "group": "Database engineering (Cassandra)",
      "text": "Piloted a Kubernetes operator deployment model for a carrier subscriber-authentication database tier and released a dedicated collection for it, with the pilot still open at the end of the evidence window.",
      "focus": [
        "platform",
        "integration"
      ],
      "delivery": "in-progress",
      "skillIds": [
        "skill-kubernetes",
        "skill-apache-cassandra-4-1-5-0",
        "skill-ansible-collections"
      ]
    },
    {
      "id": "carrier-platform-06-08",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Produced the certification evidence package for a carrier AAA platform release, assembling roughly 90 attachments of policy logs, packet captures, encryption and decryption traces, protocol replay files and device captures across three months.",
      "focus": [
        "quality",
        "network"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-mops-runbooks",
        "skill-radius",
        "skill-docs-as-code"
      ]
    },
    {
      "id": "carrier-platform-04-09",
      "roleId": "carrier-platform",
      "group": "Security & compliance",
      "text": "Scoped an environment-wide security remediation programme into seven tracked work items covering agent staging, operating-system patching, MFA, SIEM forwarding and a follow-up security assessment, delivered the first of them, and kept the rest moving while one item stayed blocked on an approval process outside his control.",
      "focus": [
        "security",
        "platform"
      ],
      "delivery": "in-progress",
      "skillIds": [
        "skill-vulnerability-management",
        "skill-mops-runbooks"
      ]
    },
    {
      "id": "carrier-platform-06-09",
      "roleId": "carrier-platform",
      "group": "Test automation & QA",
      "text": "Shipped PowerShell automation for reconfiguring wireless settings on Android test devices three weeks into the engagement, extracting profile selection, device serial handling and address validation into a reusable module across nine merged merge requests.",
      "focus": [
        "quality",
        "software"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-powershell"
      ]
    },
    {
      "id": "web-factory-01-06",
      "roleId": "web-factory",
      "group": "Selected accomplishments",
      "text": "Rebased the site factory onto a multi-template architecture, separating a shared asset overlay from per-template application layers behind an explicit overlay contract, guarding token substitution against binary files, and migrating roughly twelve dependent generator skills and their documentation in step, re-validated in a container at three different site-name lengths.",
      "focus": [
        "software",
        "platform",
        "quality"
      ],
      "delivery": "delivered",
      "skillIds": [
        "skill-astro",
        "skill-typescript",
        "skill-docker",
        "skill-agent-skills-steering-docs"
      ]
    }
  ],
  "skills": [
    {
      "id": "skill-ansible",
      "name": "Ansible",
      "aliases": []
    },
    {
      "id": "skill-ansible-collections",
      "name": "Ansible Collections",
      "aliases": []
    },
    {
      "id": "skill-jinja2",
      "name": "Jinja2",
      "aliases": []
    },
    {
      "id": "skill-ansible-lint",
      "name": "ansible-lint",
      "aliases": []
    },
    {
      "id": "skill-dry-run-check-mode",
      "name": "Dry-run / check mode",
      "aliases": []
    },
    {
      "id": "skill-apache-cassandra-4-1-5-0",
      "name": "Apache Cassandra 4.1 / 5.0",
      "aliases": [
        "Cassandra"
      ]
    },
    {
      "id": "skill-cql-cqlsh",
      "name": "CQL / cqlsh",
      "aliases": []
    },
    {
      "id": "skill-nodetool",
      "name": "nodetool",
      "aliases": []
    },
    {
      "id": "skill-medusa-backup-restore",
      "name": "Medusa backup/restore",
      "aliases": []
    },
    {
      "id": "skill-user-defined-functions",
      "name": "User-defined functions",
      "aliases": []
    },
    {
      "id": "skill-multi-datacenter-topology",
      "name": "Multi-datacenter topology",
      "aliases": []
    },
    {
      "id": "skill-rolling-upgrades",
      "name": "Rolling upgrades",
      "aliases": []
    },
    {
      "id": "skill-primary-key-design",
      "name": "Primary-key design",
      "aliases": []
    },
    {
      "id": "skill-radius",
      "name": "RADIUS",
      "aliases": []
    },
    {
      "id": "skill-radsec-radius-over-tls",
      "name": "RadSec (RADIUS over TLS)",
      "aliases": []
    },
    {
      "id": "skill-eap-aka",
      "name": "EAP-AKA",
      "aliases": []
    },
    {
      "id": "skill-eap-ttls",
      "name": "EAP-TTLS",
      "aliases": []
    },
    {
      "id": "skill-802-1x-eapol",
      "name": "802.1X / EAPOL",
      "aliases": []
    },
    {
      "id": "skill-passpoint-hotspot-2-0",
      "name": "Passpoint / Hotspot 2.0",
      "aliases": []
    },
    {
      "id": "skill-eapol-test-radclient-radsniff",
      "name": "eapol_test / radclient / radsniff",
      "aliases": []
    },
    {
      "id": "skill-nokia-aaa",
      "name": "Nokia AAA",
      "aliases": []
    },
    {
      "id": "skill-accounting-mediation",
      "name": "Accounting & mediation",
      "aliases": []
    },
    {
      "id": "skill-mvno-roaming",
      "name": "MVNO roaming",
      "aliases": []
    },
    {
      "id": "skill-gitlab-ci",
      "name": "GitLab CI",
      "aliases": []
    },
    {
      "id": "skill-self-hosted-runners",
      "name": "Self-hosted runners",
      "aliases": []
    },
    {
      "id": "skill-pipeline-templates",
      "name": "Pipeline templates",
      "aliases": []
    },
    {
      "id": "skill-tag-driven-releases",
      "name": "Tag-driven releases",
      "aliases": []
    },
    {
      "id": "skill-jfrog-artifactory",
      "name": "JFrog Artifactory",
      "aliases": []
    },
    {
      "id": "skill-multi-arch-builds-arm64-amd64",
      "name": "Multi-arch builds (arm64/amd64)",
      "aliases": []
    },
    {
      "id": "skill-artifact-provenance",
      "name": "Artifact provenance",
      "aliases": []
    },
    {
      "id": "skill-docker",
      "name": "Docker",
      "aliases": []
    },
    {
      "id": "skill-docker-compose",
      "name": "Docker Compose",
      "aliases": []
    },
    {
      "id": "skill-systemd-in-container-harnesses",
      "name": "systemd-in-container harnesses",
      "aliases": []
    },
    {
      "id": "skill-kubernetes",
      "name": "Kubernetes",
      "aliases": []
    },
    {
      "id": "skill-container-registries-proxying",
      "name": "Container registries & proxying",
      "aliases": []
    },
    {
      "id": "skill-vulnerability-research",
      "name": "Vulnerability research",
      "aliases": []
    },
    {
      "id": "skill-responsible-disclosure",
      "name": "Responsible disclosure",
      "aliases": []
    },
    {
      "id": "skill-edr-endpoint-security",
      "name": "EDR / endpoint security",
      "aliases": []
    },
    {
      "id": "skill-endpoint-management",
      "name": "Endpoint management",
      "aliases": []
    },
    {
      "id": "skill-vulnerability-management",
      "name": "Vulnerability management",
      "aliases": []
    },
    {
      "id": "skill-mfa",
      "name": "MFA",
      "aliases": []
    },
    {
      "id": "skill-cis-benchmarks",
      "name": "CIS benchmarks",
      "aliases": []
    },
    {
      "id": "skill-sshd-sysctl-hardening",
      "name": "sshd & sysctl hardening",
      "aliases": []
    },
    {
      "id": "skill-cve-remediation",
      "name": "CVE remediation",
      "aliases": []
    },
    {
      "id": "skill-mutual-tls-x-509",
      "name": "Mutual TLS / X.509",
      "aliases": []
    },
    {
      "id": "skill-splunk",
      "name": "Splunk",
      "aliases": []
    },
    {
      "id": "skill-splunk-universal-forwarder",
      "name": "Splunk Universal Forwarder",
      "aliases": []
    },
    {
      "id": "skill-spl",
      "name": "SPL",
      "aliases": []
    },
    {
      "id": "skill-zabbix",
      "name": "Zabbix",
      "aliases": []
    },
    {
      "id": "skill-status-pages",
      "name": "Status pages",
      "aliases": []
    },
    {
      "id": "skill-vmware-vsphere-vcenter",
      "name": "VMware vSphere / vCenter",
      "aliases": [
        "VMware",
        "vSphere",
        "vCenter"
      ]
    },
    {
      "id": "skill-esxi-upgrades",
      "name": "ESXi upgrades",
      "aliases": []
    },
    {
      "id": "skill-vm-templating",
      "name": "VM templating",
      "aliases": []
    },
    {
      "id": "skill-cloud-init",
      "name": "cloud-init",
      "aliases": []
    },
    {
      "id": "skill-netplan-networkmanager",
      "name": "netplan / NetworkManager",
      "aliases": []
    },
    {
      "id": "skill-ipv4-ipv6-dual-stack",
      "name": "IPv4/IPv6 dual-stack",
      "aliases": []
    },
    {
      "id": "skill-rhel",
      "name": "RHEL",
      "aliases": []
    },
    {
      "id": "skill-rocky-linux",
      "name": "Rocky Linux",
      "aliases": []
    },
    {
      "id": "skill-centos-eol-migration",
      "name": "CentOS (EOL migration)",
      "aliases": []
    },
    {
      "id": "skill-ubuntu",
      "name": "Ubuntu",
      "aliases": []
    },
    {
      "id": "skill-systemd-units-timers",
      "name": "systemd units & timers",
      "aliases": []
    },
    {
      "id": "skill-dnf-grubby",
      "name": "dnf / grubby",
      "aliases": []
    },
    {
      "id": "skill-kernel-tuning",
      "name": "Kernel tuning",
      "aliases": []
    },
    {
      "id": "skill-python",
      "name": "Python",
      "aliases": []
    },
    {
      "id": "skill-bash",
      "name": "Bash",
      "aliases": []
    },
    {
      "id": "skill-powershell",
      "name": "PowerShell",
      "aliases": []
    },
    {
      "id": "skill-java-23-spring-boot",
      "name": "Java 23 / Spring Boot",
      "aliases": [
        "Java",
        "Spring Boot",
        "Spring"
      ]
    },
    {
      "id": "skill-maven",
      "name": "Maven",
      "aliases": []
    },
    {
      "id": "skill-typescript",
      "name": "TypeScript",
      "aliases": []
    },
    {
      "id": "skill-php-laravel",
      "name": "PHP / Laravel",
      "aliases": [
        "PHP",
        "Laravel"
      ]
    },
    {
      "id": "skill-sql-cql",
      "name": "SQL / CQL",
      "aliases": []
    },
    {
      "id": "skill-grpc-proto3",
      "name": "gRPC / proto3",
      "aliases": [
        "gRPC",
        "Protocol Buffers"
      ]
    },
    {
      "id": "skill-soap-xml",
      "name": "SOAP / XML",
      "aliases": []
    },
    {
      "id": "skill-vendor-policy-dsls",
      "name": "Vendor policy DSLs",
      "aliases": []
    },
    {
      "id": "skill-astro",
      "name": "Astro",
      "aliases": []
    },
    {
      "id": "skill-tailwind-css",
      "name": "Tailwind CSS",
      "aliases": []
    },
    {
      "id": "skill-api-design",
      "name": "API design",
      "aliases": []
    },
    {
      "id": "skill-seo-structured-data",
      "name": "SEO & structured data",
      "aliases": []
    },
    {
      "id": "skill-accessibility",
      "name": "Accessibility",
      "aliases": []
    },
    {
      "id": "skill-ai-agent-workflows",
      "name": "AI agent workflows",
      "aliases": [
        "AI agents"
      ]
    },
    {
      "id": "skill-agent-skills-steering-docs",
      "name": "Agent skills & steering docs",
      "aliases": []
    },
    {
      "id": "skill-slice-based-development",
      "name": "Slice-based development",
      "aliases": []
    },
    {
      "id": "skill-docs-as-code",
      "name": "Docs-as-code",
      "aliases": []
    },
    {
      "id": "skill-reverse-engineering",
      "name": "Reverse engineering",
      "aliases": [
        "Static binary analysis",
        "PE analysis",
        "Windows kernel-driver analysis"
      ]
    },
    {
      "id": "skill-behavioural-parity-testing",
      "name": "Behavioural-parity testing",
      "aliases": []
    },
    {
      "id": "skill-root-cause-analysis",
      "name": "Root-cause analysis",
      "aliases": []
    },
    {
      "id": "skill-property-based-testing",
      "name": "Property-based testing",
      "aliases": []
    },
    {
      "id": "skill-regression-test-design",
      "name": "Regression test design",
      "aliases": []
    },
    {
      "id": "skill-appium-android-ios",
      "name": "Appium (Android / iOS)",
      "aliases": []
    },
    {
      "id": "skill-ldap-ad-integration",
      "name": "LDAP / AD integration",
      "aliases": []
    },
    {
      "id": "skill-release-engineering",
      "name": "Release engineering",
      "aliases": []
    },
    {
      "id": "skill-authentik",
      "name": "Authentik",
      "aliases": []
    },
    {
      "id": "skill-oidc-oauth-2-1",
      "name": "OIDC / OAuth 2.x",
      "aliases": [
        "OIDC",
        "OAuth",
        "OAuth 2.1",
        "OAuth 2.0"
      ]
    },
    {
      "id": "skill-cloudflare-access-workers",
      "name": "Cloudflare Access / Workers",
      "aliases": [
        "Cloudflare Workers",
        "Cloudflare Access"
      ]
    },
    {
      "id": "skill-terraform-opentofu",
      "name": "Terraform / OpenTofu",
      "aliases": [
        "Terraform",
        "OpenTofu"
      ]
    },
    {
      "id": "skill-tailscale",
      "name": "Tailscale",
      "aliases": []
    },
    {
      "id": "skill-nftables",
      "name": "nftables",
      "aliases": []
    },
    {
      "id": "skill-mcp",
      "name": "MCP",
      "aliases": []
    },
    {
      "id": "skill-datadog",
      "name": "Datadog",
      "aliases": []
    },
    {
      "id": "skill-mikrotik-routeros",
      "name": "MikroTik RouterOS",
      "aliases": [
        "RouterOS",
        "MikroTik"
      ]
    },
    {
      "id": "skill-vmware-vsan",
      "name": "VMware vSAN",
      "aliases": [
        "vSAN"
      ]
    },
    {
      "id": "skill-freeradius",
      "name": "FreeRADIUS",
      "aliases": []
    },
    {
      "id": "skill-genieacs-tr-069",
      "name": "GenieACS / TR-069",
      "aliases": [
        "TR-069",
        "CWMP",
        "GenieACS"
      ]
    },
    {
      "id": "skill-rabbitmq",
      "name": "RabbitMQ",
      "aliases": [
        "AMQP"
      ]
    },
    {
      "id": "skill-netty",
      "name": "Netty",
      "aliases": []
    },
    {
      "id": "skill-kafka",
      "name": "Kafka",
      "aliases": []
    },
    {
      "id": "skill-home-assistant",
      "name": "Home Assistant",
      "aliases": []
    },
    {
      "id": "skill-vllm",
      "name": "vLLM",
      "aliases": []
    },
    {
      "id": "skill-github-actions",
      "name": "GitHub Actions",
      "aliases": []
    },
    {
      "id": "skill-pfsense",
      "name": "pfSense",
      "aliases": []
    },
    {
      "id": "skill-vyos",
      "name": "VyOS",
      "aliases": []
    },
    {
      "id": "skill-cisco-ios",
      "name": "Cisco IOS",
      "aliases": []
    },
    {
      "id": "skill-obsidian-quartz",
      "name": "Obsidian / Quartz",
      "aliases": [
        "Obsidian",
        "Quartz"
      ]
    },
    {
      "id": "skill-jwt-validation",
      "name": "JWT / JWKS validation",
      "aliases": [
        "JWT"
      ]
    },
    {
      "id": "skill-c",
      "name": "C#",
      "aliases": []
    },
    {
      "id": "skill-javascript",
      "name": "JavaScript",
      "aliases": []
    },
    {
      "id": "skill-hcl",
      "name": "HCL",
      "aliases": []
    },
    {
      "id": "skill-yaml-xml-html-css",
      "name": "YAML / XML / HTML-CSS",
      "aliases": []
    },
    {
      "id": "skill-spring-security",
      "name": "Spring Security",
      "aliases": []
    },
    {
      "id": "skill-spring-data-jpa-hibernate",
      "name": "Spring Data JPA / Hibernate",
      "aliases": []
    },
    {
      "id": "skill-tomcat-war-deployment",
      "name": "Tomcat / WAR deployment",
      "aliases": []
    },
    {
      "id": "skill-junit",
      "name": "JUnit",
      "aliases": []
    },
    {
      "id": "skill-log4j2",
      "name": "Log4j2",
      "aliases": []
    },
    {
      "id": "skill-laravel-nova",
      "name": "Laravel Nova",
      "aliases": []
    },
    {
      "id": "skill-laravel-passport-sanctum-socialite",
      "name": "Laravel Passport / Sanctum / Socialite",
      "aliases": []
    },
    {
      "id": "skill-eloquent-blade",
      "name": "Eloquent / Blade",
      "aliases": []
    },
    {
      "id": "skill-attribution-conversion-tracking",
      "name": "Attribution & conversion tracking",
      "aliases": []
    },
    {
      "id": "skill-diameter",
      "name": "Diameter",
      "aliases": []
    },
    {
      "id": "skill-eap-tls-peap",
      "name": "EAP-TLS / PEAP",
      "aliases": []
    },
    {
      "id": "skill-nokia-sr-os-wag",
      "name": "Nokia SR OS / WAG",
      "aliases": []
    },
    {
      "id": "skill-ruckus-wsg",
      "name": "Ruckus WSG",
      "aliases": []
    },
    {
      "id": "skill-unifi",
      "name": "UniFi",
      "aliases": []
    },
    {
      "id": "skill-vpn-design-wireguard",
      "name": "VPN design / WireGuard",
      "aliases": [
        "WireGuard"
      ]
    },
    {
      "id": "skill-voip-pbx",
      "name": "VoIP / PBX",
      "aliases": []
    },
    {
      "id": "skill-rf-site-surveys",
      "name": "RF & site surveys",
      "aliases": []
    },
    {
      "id": "skill-point-to-point-wireless",
      "name": "Point-to-point wireless",
      "aliases": []
    },
    {
      "id": "skill-dns-srv-service-discovery",
      "name": "DNS SRV service discovery",
      "aliases": []
    },
    {
      "id": "skill-firewall-policy",
      "name": "Firewall policy",
      "aliases": []
    },
    {
      "id": "skill-fiber-copper-installation-splicing",
      "name": "Fiber & copper installation / splicing",
      "aliases": []
    },
    {
      "id": "skill-structured-cabling",
      "name": "Structured cabling",
      "aliases": []
    },
    {
      "id": "skill-racks-equipment-installation",
      "name": "Racks & equipment installation",
      "aliases": []
    },
    {
      "id": "skill-server-workstation-hardware",
      "name": "Server & workstation hardware",
      "aliases": []
    },
    {
      "id": "skill-data-center-colocation",
      "name": "Data-center colocation",
      "aliases": []
    },
    {
      "id": "skill-distributed-switches-port-groups",
      "name": "Distributed switches & port groups",
      "aliases": []
    },
    {
      "id": "skill-guest-customization-sysprep",
      "name": "Guest customization / sysprep",
      "aliases": []
    },
    {
      "id": "skill-snapshot-restore",
      "name": "Snapshot & restore",
      "aliases": []
    },
    {
      "id": "skill-vcenter-drs-vcsa",
      "name": "vCenter / DRS / VCSA",
      "aliases": []
    },
    {
      "id": "skill-postgresql",
      "name": "PostgreSQL",
      "aliases": []
    },
    {
      "id": "skill-mariadb-mysql",
      "name": "MariaDB / MySQL",
      "aliases": [
        "MySQL"
      ]
    },
    {
      "id": "skill-mongodb",
      "name": "MongoDB",
      "aliases": []
    },
    {
      "id": "skill-redis",
      "name": "Redis",
      "aliases": []
    },
    {
      "id": "skill-zookeeper",
      "name": "Zookeeper",
      "aliases": []
    },
    {
      "id": "skill-wazuh",
      "name": "Wazuh",
      "aliases": []
    },
    {
      "id": "skill-graylog",
      "name": "Graylog",
      "aliases": []
    },
    {
      "id": "skill-elk",
      "name": "ELK",
      "aliases": []
    },
    {
      "id": "skill-sentry",
      "name": "Sentry",
      "aliases": []
    },
    {
      "id": "skill-opentelemetry",
      "name": "OpenTelemetry",
      "aliases": []
    },
    {
      "id": "skill-structured-logging-log-pipelines",
      "name": "Structured logging & log pipelines",
      "aliases": []
    },
    {
      "id": "skill-application-security-secure-code-review",
      "name": "Application security & secure code review",
      "aliases": []
    },
    {
      "id": "skill-malware-analysis",
      "name": "Malware analysis",
      "aliases": []
    },
    {
      "id": "skill-pki-ca-operations",
      "name": "PKI / CA operations",
      "aliases": []
    },
    {
      "id": "skill-zero-trust",
      "name": "Zero trust",
      "aliases": []
    },
    {
      "id": "skill-supply-chain-controls",
      "name": "Supply-chain controls",
      "aliases": []
    },
    {
      "id": "skill-hmac",
      "name": "HMAC",
      "aliases": []
    },
    {
      "id": "skill-attack-surface-analysis",
      "name": "Attack-surface analysis",
      "aliases": []
    },
    {
      "id": "skill-pytest",
      "name": "pytest",
      "aliases": []
    },
    {
      "id": "skill-vitest",
      "name": "Vitest",
      "aliases": []
    },
    {
      "id": "skill-selenium",
      "name": "Selenium",
      "aliases": []
    },
    {
      "id": "skill-fault-injection",
      "name": "Fault injection",
      "aliases": []
    },
    {
      "id": "skill-restore-drills",
      "name": "Restore drills",
      "aliases": []
    },
    {
      "id": "skill-cloudflare-tunnel",
      "name": "Cloudflare Tunnel",
      "aliases": []
    },
    {
      "id": "skill-cloudflare-origin-ca-authenticated-origin-pulls",
      "name": "Cloudflare Origin CA / authenticated origin pulls",
      "aliases": []
    },
    {
      "id": "skill-cloudflare-kv-pages",
      "name": "Cloudflare KV / Pages",
      "aliases": []
    },
    {
      "id": "skill-ephemeral-gpu-compute-vast-ai",
      "name": "Ephemeral GPU compute (vast.ai)",
      "aliases": []
    },
    {
      "id": "skill-openai-compatible-apis-chat-completions-responses",
      "name": "OpenAI-compatible APIs (Chat Completions / Responses)",
      "aliases": []
    },
    {
      "id": "skill-anthropic-messages-api",
      "name": "Anthropic Messages API",
      "aliases": []
    },
    {
      "id": "skill-coding-agents-claude-code-codex-cli-cline-opencode",
      "name": "Coding agents (Claude Code / Codex CLI / Cline / OpenCode)",
      "aliases": []
    },
    {
      "id": "skill-tool-use-governance-approval-gates",
      "name": "Tool-use governance & approval gates",
      "aliases": []
    },
    {
      "id": "skill-prompt-injection-controls",
      "name": "Prompt-injection controls",
      "aliases": []
    },
    {
      "id": "skill-incident-response-postmortems",
      "name": "Incident response & postmortems",
      "aliases": []
    },
    {
      "id": "skill-backup-verification",
      "name": "Backup verification",
      "aliases": []
    },
    {
      "id": "skill-certificate-recovery",
      "name": "Certificate recovery",
      "aliases": []
    },
    {
      "id": "skill-change-gates-dry-run-reports",
      "name": "Change gates & dry-run reports",
      "aliases": []
    },
    {
      "id": "skill-rollback-engineering",
      "name": "Rollback engineering",
      "aliases": []
    },
    {
      "id": "skill-health-checks",
      "name": "Health checks",
      "aliases": []
    },
    {
      "id": "skill-espocrm",
      "name": "EspoCRM",
      "aliases": []
    },
    {
      "id": "skill-jira-confluence",
      "name": "Jira / Confluence",
      "aliases": []
    },
    {
      "id": "skill-bitbucket-server-bamboo",
      "name": "Bitbucket Server / Bamboo",
      "aliases": [
        "Bamboo"
      ]
    },
    {
      "id": "skill-gitlab-administration",
      "name": "GitLab administration",
      "aliases": []
    },
    {
      "id": "skill-nexus",
      "name": "Nexus",
      "aliases": []
    },
    {
      "id": "skill-help-desk-itsm",
      "name": "Help desk / ITSM",
      "aliases": []
    },
    {
      "id": "skill-quoting-invoicing-procurement",
      "name": "Quoting, invoicing & procurement",
      "aliases": []
    },
    {
      "id": "skill-advertising-analytics",
      "name": "Advertising & analytics",
      "aliases": []
    },
    {
      "id": "skill-immutable-artifacts-offline-bundles",
      "name": "Immutable artifacts & offline bundles",
      "aliases": []
    },
    {
      "id": "skill-platform-engineering",
      "name": "Platform engineering",
      "aliases": []
    },
    {
      "id": "skill-distributed-systems",
      "name": "Distributed systems",
      "aliases": []
    },
    {
      "id": "skill-multi-module-monoliths",
      "name": "Multi-module monoliths",
      "aliases": []
    },
    {
      "id": "skill-event-driven-systems",
      "name": "Event-driven systems",
      "aliases": []
    },
    {
      "id": "skill-service-contracts",
      "name": "Service contracts",
      "aliases": []
    },
    {
      "id": "skill-product-engineering",
      "name": "Product engineering",
      "aliases": []
    },
    {
      "id": "skill-architecture-decision-records",
      "name": "Architecture decision records",
      "aliases": []
    },
    {
      "id": "skill-mops-runbooks",
      "name": "MOPs & runbooks",
      "aliases": []
    },
    {
      "id": "skill-onboarding-systems",
      "name": "Onboarding systems",
      "aliases": []
    },
    {
      "id": "skill-mdx-content-collections",
      "name": "MDX content collections",
      "aliases": []
    },
    {
      "id": "skill-webex-bot-integrations",
      "name": "Webex bot integrations",
      "aliases": [
        "ChatOps"
      ]
    },
    {
      "id": "skill-saml-jit-provisioning",
      "name": "SAML 2.0 / JIT provisioning",
      "aliases": [
        "SAML",
        "just-in-time provisioning"
      ]
    },
    {
      "id": "skill-sops-age",
      "name": "SOPS / age",
      "aliases": [
        "encrypted configuration"
      ]
    },
    {
      "id": "skill-phpipam",
      "name": "phpIPAM / inventory reconciliation",
      "aliases": [
        "IPAM",
        "asset inventory",
        "drift audit"
      ]
    },
    {
      "id": "skill-mutation-testing",
      "name": "Mutation testing",
      "aliases": []
    },
    {
      "id": "skill-performance-benchmarking",
      "name": "Performance benchmarking",
      "aliases": [
        "latency",
        "throughput"
      ]
    },
    {
      "id": "skill-auditd",
      "name": "auditd",
      "aliases": [
        "Linux Audit"
      ]
    },
    {
      "id": "skill-rsyslog",
      "name": "rsyslog",
      "aliases": []
    },
    {
      "id": "skill-selinux-troubleshooting",
      "name": "SELinux troubleshooting",
      "aliases": []
    },
    {
      "id": "skill-grafana",
      "name": "Grafana",
      "aliases": []
    },
    {
      "id": "skill-portainer",
      "name": "Portainer",
      "aliases": []
    },
    {
      "id": "skill-mqtt",
      "name": "MQTT",
      "aliases": [
        "Eclipse Paho",
        "MQTT discovery",
        "retained topics"
      ]
    },
    {
      "id": "skill-udev-serial-device-integration",
      "name": "udev & serial device integration",
      "aliases": [
        "udev rules",
        "USB CDC serial",
        "hot-plug automation",
        "jSerialComm"
      ]
    },
    {
      "id": "skill-active-directory-group-policy",
      "name": "Active Directory Group Policy (ADMX)",
      "aliases": [
        "Group Policy",
        "ADMX/ADML",
        "central store",
        "SYSVOL"
      ]
    },
    {
      "id": "skill-openvpn",
      "name": "OpenVPN",
      "aliases": [
        "tun interfaces",
        "VPN client configuration"
      ]
    },
    {
      "id": "skill-stripe-payments",
      "name": "Stripe payments",
      "aliases": [
        "Stripe Billing",
        "checkout",
        "payment processing"
      ]
    },
    {
      "id": "skill-embedded-c-arduino",
      "name": "Embedded C++ / Arduino",
      "aliases": [
        "Arduino",
        "C++ (embedded)"
      ]
    },
    {
      "id": "skill-esp8266",
      "name": "ESP8266",
      "aliases": [
        "Espressif",
        "ESP32"
      ]
    },
    {
      "id": "skill-i2c-spi",
      "name": "I²C / SPI",
      "aliases": [
        "I2C",
        "SPI"
      ]
    },
    {
      "id": "skill-adc-sensor-calibration",
      "name": "ADC & sensor calibration",
      "aliases": [
        "Sensor calibration",
        "Analog front end"
      ]
    },
    {
      "id": "skill-snmp",
      "name": "SNMP",
      "aliases": [
        "SNMP agent"
      ]
    },
    {
      "id": "skill-interrupt-driven-io",
      "name": "Interrupt-driven I/O",
      "aliases": [
        "ISR",
        "Pulse counting"
      ]
    },
    {
      "id": "skill-android-sdk",
      "name": "Android SDK",
      "aliases": [
        "Android",
        "Android development"
      ]
    },
    {
      "id": "skill-sensor-filtering",
      "name": "Sensor filtering & smoothing",
      "aliases": [
        "Low-pass filter",
        "Moving average"
      ]
    },
    {
      "id": "skill-real-user-monitoring",
      "name": "Real-user monitoring",
      "aliases": [
        "RUM"
      ]
    },
    {
      "id": "skill-azure-pipelines",
      "name": "Azure Pipelines",
      "aliases": [
        "Azure DevOps"
      ]
    },
    {
      "id": "skill-numpy-scipy",
      "name": "NumPy / SciPy",
      "aliases": [
        "NumPy",
        "SciPy"
      ]
    },
    {
      "id": "skill-fft-spectral-analysis",
      "name": "FFT & spectral analysis",
      "aliases": [
        "FFT",
        "Power spectral density",
        "PAPR"
      ]
    },
    {
      "id": "skill-digital-modulation",
      "name": "Digital modulation",
      "aliases": [
        "BPSK",
        "CDMA spreading"
      ]
    },
    {
      "id": "skill-pyqt",
      "name": "PyQt5 / pyqtgraph",
      "aliases": [
        "PyQt",
        "Qt"
      ]
    },
    {
      "id": "skill-tls-alpn-handshake-analysis",
      "name": "TLS handshake analysis (ALPN)",
      "aliases": [
        "ALPN",
        "TLS handshake troubleshooting",
        "ClientHello analysis",
        "openssl s_client"
      ]
    },
    {
      "id": "skill-threat-modeling",
      "name": "Threat modeling",
      "aliases": [
        "threat model",
        "trust boundary analysis",
        "attack-tree analysis"
      ]
    },
    {
      "id": "skill-ai-application-security",
      "name": "AI application security",
      "aliases": [
        "LLM application security",
        "AI security architecture",
        "context engineering",
        "provenance-aware retrieval",
        "SSRF defense"
      ]
    },
    {
      "id": "skill-multi-tenant-isolation",
      "name": "Multi-tenant isolation",
      "aliases": [
        "tenant isolation",
        "non-inference isolation",
        "cross-tenant leakage prevention"
      ]
    }
  ],
  "skillCategories": [
    {
      "id": "category-configuration-management-iac",
      "title": "Configuration management & IaC",
      "summary": "Versioned Ansible collections, deployment-time configuration and encrypted secrets, explicit environment validation, dry-run reports, and tested rollback safeguards.",
      "tags": [
        "Ansible",
        "Ansible Collections",
        "Jinja2",
        "ansible-lint",
        "Dry-run / check mode",
        "Terraform / OpenTofu",
        "SOPS / age",
        "Active Directory Group Policy (ADMX)"
      ]
    },
    {
      "id": "category-databases-cassandra",
      "title": "Databases — Cassandra",
      "summary": "Cassandra backup and restore, topology and upgrade planning, operator certification fixes, and measured development UDF optimization with compatibility testing.",
      "tags": [
        "Apache Cassandra 4.1 / 5.0",
        "CQL / cqlsh",
        "nodetool",
        "Medusa backup/restore",
        "User-defined functions",
        "Multi-datacenter topology",
        "Rolling upgrades",
        "Primary-key design",
        "Performance benchmarking"
      ]
    },
    {
      "id": "category-telecom-aaa-protocols",
      "title": "Telecom / AAA protocols",
      "summary": "Carrier-grade subscriber authentication, with correctness validated across authentication, roaming, and accounting workflows.",
      "tags": [
        "RADIUS",
        "RadSec (RADIUS over TLS)",
        "EAP-AKA",
        "EAP-TTLS",
        "802.1X / EAPOL",
        "Passpoint / Hotspot 2.0",
        "eapol_test / radclient / radsniff",
        "Nokia AAA",
        "Accounting & mediation",
        "MVNO roaming",
        "FreeRADIUS",
        "Diameter",
        "EAP-TLS / PEAP",
        "Nokia SR OS / WAG",
        "Ruckus WSG"
      ]
    },
    {
      "id": "category-ci-cd-artifact-supply-chain",
      "title": "CI/CD & artifact supply chain",
      "summary": "Versioned releases, shared packaging rules, artifact provenance, and deployment-time configuration tooling with explicit compatibility and rollout gates.",
      "tags": [
        "GitLab CI",
        "Self-hosted runners",
        "Pipeline templates",
        "Tag-driven releases",
        "JFrog Artifactory",
        "Multi-arch builds (arm64/amd64)",
        "Artifact provenance",
        "GitHub Actions",
        "Bitbucket Server / Bamboo",
        "Nexus",
        "Immutable artifacts & offline bundles",
        "SOPS / age"
      ]
    },
    {
      "id": "category-containers-orchestration",
      "title": "Containers & orchestration",
      "summary": "Containerized test harnesses, plus hands-on Kubernetes and operator-based orchestration work.",
      "tags": [
        "Docker",
        "Docker Compose",
        "systemd-in-container harnesses",
        "Kubernetes",
        "Container registries & proxying"
      ]
    },
    {
      "id": "category-security-compliance",
      "title": "Security & compliance",
      "summary": "Critical vulnerability research through coordinated disclosure, plus endpoint-control automation, hardening, CVE remediation, secrets hygiene, and PKI troubleshooting.",
      "tags": [
        "Vulnerability research",
        "Responsible disclosure",
        "EDR / endpoint security",
        "Endpoint management",
        "Vulnerability management",
        "MFA",
        "CIS benchmarks",
        "sshd & sysctl hardening",
        "CVE remediation",
        "Mutual TLS / X.509",
        "Application security & secure code review",
        "Malware analysis",
        "PKI / CA operations",
        "Zero trust",
        "Supply-chain controls",
        "HMAC",
        "Attack-surface analysis",
        "TLS handshake analysis (ALPN)",
        "Threat modeling"
      ]
    },
    {
      "id": "category-observability",
      "title": "Observability",
      "summary": "SIEM log-forwarding automation and enriched Linux audit-event delivery, including queued TCP transport and fixes for SELinux and audit-daemon integration.",
      "tags": [
        "Splunk",
        "Splunk Universal Forwarder",
        "SPL",
        "Zabbix",
        "Status pages",
        "Datadog",
        "Wazuh",
        "Graylog",
        "ELK",
        "Sentry",
        "OpenTelemetry",
        "Structured logging & log pipelines",
        "auditd",
        "rsyslog",
        "SELinux troubleshooting",
        "Grafana"
      ]
    },
    {
      "id": "category-virtualization-provisioning",
      "title": "Virtualization & provisioning",
      "summary": "Golden-template preparation and disposable-clone validation, cloud-init addressing, eight-node VM provisioning with unique guest identities, and infrastructure inventory reconciliation.",
      "tags": [
        "VMware vSphere / vCenter",
        "ESXi upgrades",
        "VM templating",
        "cloud-init",
        "netplan / NetworkManager",
        "IPv4/IPv6 dual-stack",
        "VMware vSAN",
        "vCenter / DRS / VCSA",
        "Distributed switches & port groups",
        "Guest customization / sysprep",
        "Snapshot & restore",
        "phpIPAM / inventory reconciliation"
      ]
    },
    {
      "id": "category-linux-operations",
      "title": "Linux operations",
      "summary": "Four distributions in daily production-adjacent use, including an end-of-life migration carried through formal certification.",
      "tags": [
        "RHEL",
        "Rocky Linux",
        "CentOS (EOL migration)",
        "Ubuntu",
        "systemd units & timers",
        "dnf / grubby",
        "Kernel tuning",
        "udev & serial device integration"
      ]
    },
    {
      "id": "category-languages-runtimes",
      "title": "Languages & runtimes",
      "summary": "Automation in Python and Bash, a Spring test platform in Java, device tooling in PowerShell, and product work in TypeScript and PHP.",
      "tags": [
        "Python",
        "Bash",
        "PowerShell",
        "Java 23 / Spring Boot",
        "Maven",
        "TypeScript",
        "PHP / Laravel",
        "SQL / CQL",
        "gRPC / proto3",
        "SOAP / XML",
        "Vendor policy DSLs",
        "C#",
        "JavaScript",
        "HCL",
        "YAML / XML / HTML-CSS"
      ]
    },
    {
      "id": "category-web-product-engineering",
      "title": "Web & product engineering",
      "summary": "This site (Astro 6, strict TypeScript, static output) and an independent product exploration in the telecom workflow space.",
      "tags": [
        "Astro",
        "Tailwind CSS",
        "API design",
        "SEO & structured data",
        "Accessibility"
      ]
    },
    {
      "id": "category-ai-assisted-engineering",
      "title": "AI-assisted engineering",
      "summary": "A deployed engineering chat assistant with tested read-only gateways, evidence-retrieval and sanitization tools, and maintained agent workflows grounded in documented work.",
      "tags": [
        "AI agent workflows",
        "Agent skills & steering docs",
        "Slice-based development",
        "Docs-as-code",
        "vLLM",
        "OpenAI-compatible APIs (Chat Completions / Responses)",
        "Anthropic Messages API",
        "Coding agents (Claude Code / Codex CLI / Cline / OpenCode)",
        "Tool-use governance & approval gates",
        "Prompt-injection controls",
        "Webex bot integrations",
        "AI application security"
      ]
    },
    {
      "id": "category-engineering-practices",
      "title": "Engineering practices",
      "summary": "The habits the record demonstrates: reverse engineering, parity testing, root-cause analysis, and documentation that survives certification.",
      "tags": [
        "Reverse engineering",
        "Behavioural-parity testing",
        "Root-cause analysis",
        "Property-based testing",
        "Regression test design",
        "Appium (Android / iOS)",
        "LDAP / AD integration",
        "Release engineering"
      ]
    },
    {
      "id": "category-identity-secure-integrations",
      "title": "Identity & secure integrations",
      "summary": "Native SAML, OIDC, and OAuth integrations, directory-backed account provisioning, role mapping and allow/deny tests, plus independent identity and MCP gateway engineering.",
      "tags": [
        "Authentik",
        "OIDC / OAuth 2.x",
        "Cloudflare Access / Workers",
        "Terraform / OpenTofu",
        "Tailscale",
        "nftables",
        "MCP",
        "JWT / JWKS validation",
        "SAML 2.0 / JIT provisioning",
        "Grafana",
        "Portainer",
        "Multi-tenant isolation"
      ]
    },
    {
      "id": "category-network-systems",
      "title": "Network systems",
      "summary": "Wireless and enterprise networking, dual-stack inventory reconciliation, IPAM drift audits, RADIUS health-check diagnosis, and infrastructure from routing to physical installation.",
      "tags": [
        "MikroTik RouterOS",
        "pfSense",
        "VyOS",
        "Cisco IOS",
        "GenieACS / TR-069",
        "FreeRADIUS",
        "UniFi",
        "VPN design / WireGuard",
        "VoIP / PBX",
        "RF & site surveys",
        "Point-to-point wireless",
        "DNS SRV service discovery",
        "Firewall policy",
        "phpIPAM / inventory reconciliation",
        "OpenVPN"
      ]
    },
    {
      "id": "category-messaging-integration",
      "title": "Messaging & integration",
      "summary": "Event and protocol plumbing across game services, test fleets, and home automation: AMQP, Kafka result signals, Netty protocol handling, gRPC contracts, and custom integrations.",
      "tags": [
        "RabbitMQ",
        "Kafka",
        "Netty",
        "gRPC / proto3",
        "Home Assistant",
        "MQTT"
      ]
    },
    {
      "id": "category-knowledge-systems",
      "title": "Knowledge systems",
      "summary": "Certified runbooks and onboarding, evidence and document-consistency tooling, and a status-ledger prototype that reconciles engineering work with reported progress.",
      "tags": [
        "Obsidian / Quartz",
        "Docs-as-code",
        "Agent skills & steering docs",
        "Jira / Confluence",
        "Architecture decision records",
        "MOPs & runbooks",
        "Onboarding systems",
        "MDX content collections"
      ]
    },
    {
      "id": "category-java-jvm",
      "title": "Java / JVM",
      "summary": "Spring Boot services and test platforms, Netty protocol work, multi-module Maven builds, and WAR deployments dating back a decade.",
      "tags": [
        "Java 23 / Spring Boot",
        "Spring Security",
        "Spring Data JPA / Hibernate",
        "Maven",
        "Tomcat / WAR deployment",
        "Netty",
        "Log4j2",
        "JUnit",
        "gRPC / proto3",
        "Appium (Android / iOS)"
      ]
    },
    {
      "id": "category-php-web",
      "title": "PHP / web frameworks",
      "summary": "Laravel 5 through 11 in production: identity providers, lead-generation apps, VoIP integrations, and an Astro replatform when a dynamic surface was no longer justified.",
      "tags": [
        "PHP / Laravel",
        "Laravel Nova",
        "Laravel Passport / Sanctum / Socialite",
        "Eloquent / Blade",
        "Astro",
        "Tailwind CSS",
        "Attribution & conversion tracking"
      ]
    },
    {
      "id": "category-physical-field",
      "title": "Physical & field engineering",
      "summary": "The part of the network you can touch: fiber and copper installation and splicing, structured cabling, racks, hardware upgrades, and colocation, done as the ISP's own field engineer.",
      "tags": [
        "Fiber & copper installation / splicing",
        "Structured cabling",
        "Racks & equipment installation",
        "Server & workstation hardware",
        "Data-center colocation"
      ]
    },
    {
      "id": "category-databases-data-stores",
      "title": "Databases & data stores",
      "summary": "Relational, document, and cache stores behind production applications, plus directory services; Cassandra has its own category.",
      "tags": [
        "PostgreSQL",
        "MariaDB / MySQL",
        "MongoDB",
        "Redis",
        "Zookeeper",
        "LDAP / AD integration"
      ]
    },
    {
      "id": "category-quality-testing",
      "title": "Quality & testing",
      "summary": "Property-based and mutation tests, failure injection that checks previous-release startability, protocol parity, and performance benchmarks scoped to their test environment.",
      "tags": [
        "JUnit",
        "pytest",
        "Vitest",
        "Property-based testing",
        "Appium (Android / iOS)",
        "Selenium",
        "Regression test design",
        "Fault injection",
        "Restore drills",
        "Mutation testing",
        "Performance benchmarking"
      ]
    },
    {
      "id": "category-cloud-edge",
      "title": "Cloud & edge",
      "summary": "Cloudflare Workers, Access, Tunnel, Origin CA and authenticated origin pulls, Pages builds, Tailscale userspace networking, and rented GPU compute behind a broker.",
      "tags": [
        "Cloudflare Access / Workers",
        "Cloudflare Tunnel",
        "Cloudflare Origin CA / authenticated origin pulls",
        "Cloudflare KV / Pages",
        "Tailscale",
        "Ephemeral GPU compute (vast.ai)"
      ]
    },
    {
      "id": "category-recovery-operations",
      "title": "Recovery & operations",
      "summary": "Cross-system incident diagnosis, verified restores, deployment failure testing, and recovery checks that distinguish a restored service from pending prevention work.",
      "tags": [
        "Incident response & postmortems",
        "Backup verification",
        "Restore drills",
        "Certificate recovery",
        "Change gates & dry-run reports",
        "Rollback engineering",
        "Health checks",
        "Root-cause analysis"
      ]
    },
    {
      "id": "category-business-systems",
      "title": "Business systems",
      "summary": "The systems a founder and consultant actually runs: CRM, ticketing, source hosting and CI, artifact repositories, help desk, quoting and invoicing, advertising and analytics.",
      "tags": [
        "EspoCRM",
        "Jira / Confluence",
        "Bitbucket Server / Bamboo",
        "GitLab administration",
        "JFrog Artifactory",
        "Nexus",
        "Help desk / ITSM",
        "Quoting, invoicing & procurement",
        "Advertising & analytics",
        "Stripe payments"
      ]
    },
    {
      "id": "category-architecture-product",
      "title": "Architecture & product",
      "summary": "Platform and product architecture: multi-module monoliths that stay honest, API-first and event-driven designs, explicit service contracts, and products built from customer discovery onward.",
      "tags": [
        "Platform engineering",
        "Distributed systems",
        "Multi-module monoliths",
        "API design",
        "Event-driven systems",
        "Service contracts",
        "Product engineering"
      ]
    },
    {
      "id": "category-embedded-iot",
      "title": "Embedded & IoT",
      "summary": "Nine networked microcontroller devices in C++, each built to measure something real — current, weight, distance, flow, temperature — and report it into an existing monitoring stack.",
      "tags": [
        "Embedded C++ / Arduino",
        "ESP8266",
        "I²C / SPI",
        "ADC & sensor calibration",
        "Interrupt-driven I/O",
        "SNMP"
      ]
    },
    {
      "id": "category-mobile-signal",
      "title": "Mobile & signal processing",
      "summary": "Android sensor and telephony applications with real-user monitoring and CI, plus digital signal-processing tooling and reverse-engineered serial protocols.",
      "tags": [
        "Android SDK",
        "Sensor filtering & smoothing",
        "Real-user monitoring",
        "Azure Pipelines",
        "NumPy / SciPy",
        "FFT & spectral analysis",
        "Digital modulation",
        "PyQt5 / pyqtgraph"
      ]
    }
  ],
  "certifications": [
    {
      "issuer": "CompTIA",
      "name": "A+",
      "issued": "2024"
    },
    {
      "issuer": "CompTIA",
      "name": "Network+",
      "issued": "2024"
    },
    {
      "issuer": "CompTIA",
      "name": "Security+",
      "issued": "2024"
    },
    {
      "issuer": "CompTIA",
      "name": "Server+",
      "issued": "2024"
    },
    {
      "issuer": "Microsoft",
      "name": "MTA: Mobility and Device Fundamentals",
      "issued": "2017"
    }
  ],
  "targets": [
    {
      "id": "platform",
      "label": "Platform & infrastructure",
      "headline": "Platform engineering • automation • reliability",
      "summary": "Infrastructure automation, database operations, release engineering, and reliable developer environments.",
      "keywords": [
        "ansible",
        "cassandra",
        "docker",
        "ci/cd",
        "infrastructure",
        "linux",
        "terraform",
        "reliability"
      ],
      "claimIds": [
        "carrier-platform-01-07",
        "carrier-platform-01-01",
        "carrier-platform-01-02",
        "carrier-platform-02-02",
        "carrier-platform-02-08",
        "carrier-platform-07-01",
        "carrier-platform-07-06",
        "carrier-platform-07-07",
        "identity-platform-01-01"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-01-07",
            "carrier-platform-01-01",
            "carrier-platform-01-02",
            "carrier-platform-02-02",
            "carrier-platform-02-08",
            "carrier-platform-07-01",
            "carrier-platform-07-06",
            "carrier-platform-07-07"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": [
            "duvall-wifi-01-01",
            "duvall-wifi-01-02",
            "duvall-wifi-01-03",
            "duvall-wifi-01-05"
          ]
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": [
            "pnw-plumbing-01-01",
            "pnw-plumbing-01-02"
          ]
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": [
            "wilderness-awareness-01-01",
            "wilderness-awareness-01-02"
          ]
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": [
            "beyond-grey-skies-01-01"
          ]
        },
        {
          "roleId": "identity-platform",
          "claimIds": [
            "identity-platform-01-01",
            "identity-platform-01-02",
            "identity-platform-01-03"
          ]
        },
        {
          "roleId": "homelab-platform",
          "claimIds": [
            "homelab-platform-01-01",
            "homelab-platform-01-02",
            "homelab-platform-01-03"
          ]
        },
        {
          "roleId": "embedded-signal",
          "claimIds": [
            "embedded-signal-01-01",
            "embedded-signal-01-02",
            "embedded-signal-01-03"
          ]
        }
      ]
    },
    {
      "id": "security",
      "label": "Security & identity",
      "headline": "Security engineering • identity • secure automation",
      "summary": "Security controls, identity integration, remediation, and reviewable automation across platform and independent engineering.",
      "keywords": [
        "security",
        "oidc",
        "oauth",
        "mfa",
        "identity",
        "siem",
        "vulnerability",
        "secrets"
      ],
      "claimIds": [
        "carrier-platform-04-06",
        "carrier-platform-04-01",
        "carrier-platform-04-02",
        "carrier-platform-04-04",
        "carrier-platform-01-07",
        "carrier-platform-03-06",
        "carrier-platform-08-06",
        "identity-platform-01-01",
        "identity-platform-01-02",
        "joblead-system-01-01",
        "carrier-platform-05-08"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-04-06",
            "carrier-platform-04-01",
            "carrier-platform-04-02",
            "carrier-platform-04-04",
            "carrier-platform-01-07",
            "carrier-platform-03-06",
            "carrier-platform-08-06",
            "carrier-platform-05-08"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": [
            "duvall-wifi-01-01",
            "duvall-wifi-02-02",
            "duvall-wifi-01-03",
            "duvall-wifi-01-06"
          ]
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": [
            "pnw-plumbing-01-02",
            "pnw-plumbing-02-01"
          ]
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": []
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": []
        },
        {
          "roleId": "identity-platform",
          "claimIds": [
            "identity-platform-01-01",
            "identity-platform-01-02",
            "identity-platform-01-04"
          ]
        },
        {
          "roleId": "joblead-system",
          "claimIds": [
            "joblead-system-01-01",
            "joblead-system-02-02"
          ]
        },
        {
          "roleId": "homelab-platform",
          "claimIds": [
            "homelab-platform-01-03",
            "homelab-platform-01-05",
            "homelab-platform-01-06"
          ]
        }
      ]
    },
    {
      "id": "network",
      "label": "Network & telecom",
      "headline": "Network engineering • AAA • protocol analysis",
      "summary": "Subscriber authentication, RADIUS accounting, wireless infrastructure, and repeatable protocol validation.",
      "keywords": [
        "radius",
        "eap",
        "aaa",
        "network",
        "wireless",
        "routing",
        "passpoint",
        "tls"
      ],
      "claimIds": [
        "carrier-platform-05-01",
        "carrier-platform-05-02",
        "carrier-platform-05-03",
        "carrier-platform-05-07",
        "carrier-platform-07-06",
        "duvall-wifi-01-02",
        "wilderness-awareness-01-01",
        "gpu-access-01-01",
        "carrier-platform-05-08"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-05-01",
            "carrier-platform-05-02",
            "carrier-platform-05-03",
            "carrier-platform-05-07",
            "carrier-platform-07-06",
            "carrier-platform-05-08",
            "carrier-platform-03-01",
            "carrier-platform-05-04"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": [
            "duvall-wifi-01-02",
            "duvall-wifi-01-01",
            "duvall-wifi-02-01",
            "duvall-wifi-01-03",
            "duvall-wifi-01-04",
            "duvall-wifi-01-05"
          ]
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": []
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": [
            "wilderness-awareness-01-01",
            "wilderness-awareness-01-02"
          ]
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": [
            "beyond-grey-skies-01-01"
          ]
        },
        {
          "roleId": "gpu-access",
          "claimIds": [
            "gpu-access-01-01",
            "gpu-access-01-02"
          ]
        },
        {
          "roleId": "homelab-platform",
          "claimIds": [
            "homelab-platform-01-05",
            "homelab-platform-01-09"
          ]
        },
        {
          "roleId": "embedded-signal",
          "claimIds": [
            "embedded-signal-02-03",
            "embedded-signal-03-01",
            "embedded-signal-03-02"
          ]
        }
      ]
    },
    {
      "id": "software",
      "label": "Software & test platforms",
      "headline": "Software engineering • APIs • test automation",
      "summary": "Production applications, typed libraries, protocol integrations, and automation that removes repetitive engineering work.",
      "keywords": [
        "java",
        "spring",
        "python",
        "api",
        "test",
        "grpc",
        "laravel",
        "software"
      ],
      "claimIds": [
        "carrier-platform-06-01",
        "carrier-platform-06-02",
        "carrier-platform-06-03",
        "carrier-platform-02-08",
        "carrier-platform-01-02",
        "carrier-platform-08-06",
        "carrier-platform-03-01",
        "carrier-platform-02-09",
        "joblead-system-01-01",
        "pnw-plumbing-01-02"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-06-01",
            "carrier-platform-06-02",
            "carrier-platform-06-03",
            "carrier-platform-02-08",
            "carrier-platform-01-02",
            "carrier-platform-08-06",
            "carrier-platform-03-01",
            "carrier-platform-02-09"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": [
            "duvall-wifi-01-01",
            "duvall-wifi-01-02",
            "duvall-wifi-02-01",
            "duvall-wifi-02-02",
            "duvall-wifi-01-07"
          ]
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": [
            "pnw-plumbing-01-02",
            "pnw-plumbing-02-01"
          ]
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": []
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": []
        },
        {
          "roleId": "joblead-system",
          "claimIds": [
            "joblead-system-01-01",
            "joblead-system-01-03",
            "joblead-system-02-01"
          ]
        },
        {
          "roleId": "game-platform",
          "claimIds": [
            "game-platform-01-01",
            "game-platform-01-02",
            "game-platform-01-03"
          ]
        },
        {
          "roleId": "additional-projects",
          "claimIds": [
            "additional-projects-01-01",
            "additional-projects-01-02",
            "additional-projects-01-06"
          ]
        }
      ]
    },
    {
      "id": "ai",
      "label": "AI & workflow automation",
      "headline": "AI integration • MCP • guarded workflows",
      "summary": "Useful AI integrations built around constrained tools, explicit authorization, testing, and maintained engineering knowledge.",
      "keywords": [
        "ai",
        "mcp",
        "automation",
        "agent",
        "oauth",
        "knowledge",
        "cloudflare",
        "workflow"
      ],
      "claimIds": [
        "carrier-platform-08-06",
        "carrier-platform-08-07",
        "carrier-platform-08-04",
        "carrier-platform-08-08",
        "joblead-system-01-01",
        "joblead-system-01-02",
        "joblead-system-01-03",
        "gpu-access-01-01",
        "gpu-access-01-02",
        "carrier-platform-08-09"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-08-06",
            "carrier-platform-08-07",
            "carrier-platform-08-04",
            "carrier-platform-08-08",
            "carrier-platform-08-09",
            "carrier-platform-02-03",
            "carrier-platform-02-05",
            "carrier-platform-04-03"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": []
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": [
            "pnw-plumbing-01-01"
          ]
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": [
            "wilderness-awareness-01-01"
          ]
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": []
        },
        {
          "roleId": "joblead-system",
          "claimIds": [
            "joblead-system-01-01",
            "joblead-system-01-02",
            "joblead-system-01-03"
          ]
        },
        {
          "roleId": "gpu-access",
          "claimIds": [
            "gpu-access-01-01",
            "gpu-access-01-02",
            "gpu-access-01-03"
          ]
        },
        {
          "roleId": "agent-crew",
          "claimIds": [
            "agent-crew-01-01",
            "agent-crew-01-02",
            "agent-crew-01-03"
          ]
        }
      ]
    },
    {
      "id": "integration",
      "label": "Integration & interoperability",
      "headline": "Systems integration • protocols • APIs",
      "summary": "Making separate systems, devices and vendors work as one: service contracts, identity federation, message transport, and device protocols implemented against the real specification.",
      "keywords": [
        "api",
        "integration",
        "grpc",
        "rest",
        "oauth",
        "oidc",
        "saml",
        "mqtt",
        "rabbitmq",
        "amqp",
        "kafka",
        "webhook",
        "protocol",
        "tr-069",
        "sip",
        "crm",
        "interoperability",
        "service contract",
        "message queue",
        "middleware"
      ],
      "claimIds": [
        "duvall-wifi-01-07",
        "carrier-platform-06-06",
        "web-factory-01-05",
        "device-integration-01-02",
        "game-platform-01-02"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-06-06",
            "carrier-platform-08-06",
            "carrier-platform-04-06",
            "carrier-platform-02-11"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": [
            "duvall-wifi-01-07",
            "duvall-wifi-01-05"
          ]
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": []
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": []
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": []
        },
        {
          "roleId": "web-factory",
          "claimIds": [
            "web-factory-01-05",
            "web-factory-01-03"
          ]
        },
        {
          "roleId": "device-integration",
          "claimIds": [
            "device-integration-01-02",
            "device-integration-01-01",
            "device-integration-01-03"
          ]
        },
        {
          "roleId": "game-platform",
          "claimIds": [
            "game-platform-01-02",
            "game-platform-01-01"
          ]
        }
      ]
    },
    {
      "id": "quality",
      "label": "Test & release engineering",
      "headline": "Test automation • CI/CD • release engineering",
      "summary": "Proving a change is safe before it ships: automated test platforms, regression suites, reproducible build and release pipelines, and evidence that the tests actually ran.",
      "keywords": [
        "test automation",
        "qa",
        "sdet",
        "regression",
        "ci",
        "cd",
        "pipeline",
        "release engineering",
        "appium",
        "junit",
        "pytest",
        "vitest",
        "selenium",
        "fixtures",
        "coverage",
        "gitlab ci",
        "github actions",
        "artifact",
        "build",
        "parity testing",
        "fault injection"
      ],
      "claimIds": [
        "carrier-platform-06-03",
        "carrier-platform-06-04",
        "carrier-platform-06-05",
        "joblead-system-01-03",
        "gpu-access-01-03",
        "game-platform-01-05",
        "carrier-platform-06-08",
        "carrier-platform-06-09"
      ],
      "roles": [
        {
          "roleId": "carrier-platform",
          "claimIds": [
            "carrier-platform-06-03",
            "carrier-platform-06-04",
            "carrier-platform-06-05",
            "carrier-platform-06-08",
            "carrier-platform-06-09",
            "carrier-platform-01-02",
            "carrier-platform-01-05",
            "carrier-platform-03-01"
          ]
        },
        {
          "roleId": "duvall-wifi",
          "claimIds": []
        },
        {
          "roleId": "pnw-plumbing",
          "claimIds": []
        },
        {
          "roleId": "wilderness-awareness",
          "claimIds": []
        },
        {
          "roleId": "beyond-grey-skies",
          "claimIds": []
        },
        {
          "roleId": "joblead-system",
          "claimIds": [
            "joblead-system-01-03"
          ]
        },
        {
          "roleId": "gpu-access",
          "claimIds": [
            "gpu-access-01-03"
          ]
        },
        {
          "roleId": "game-platform",
          "claimIds": [
            "game-platform-01-05",
            "game-platform-01-03"
          ]
        }
      ]
    }
  ],
  "highlights": [
    {
      "targetId": "platform",
      "claimId": "carrier-platform-01-07",
      "roleId": "carrier-platform"
    },
    {
      "targetId": "security",
      "claimId": "identity-platform-01-01",
      "roleId": "identity-platform"
    },
    {
      "targetId": "network",
      "claimId": "duvall-wifi-01-02",
      "roleId": "duvall-wifi"
    },
    {
      "targetId": "software",
      "claimId": "joblead-system-01-01",
      "roleId": "joblead-system"
    },
    {
      "targetId": "ai",
      "claimId": "gpu-access-01-01",
      "roleId": "gpu-access"
    },
    {
      "targetId": "integration",
      "claimId": "web-factory-01-05",
      "roleId": "web-factory"
    },
    {
      "targetId": "quality",
      "claimId": "game-platform-01-05",
      "roleId": "game-platform"
    }
  ]
}
