Pakkit.net
Contact Brandon Other role focuses

Security & identity

Brandon Donaly

Security engineering • identity • secure automation

Denver metro, Colorado · me@pakkit.net · pakkit.net/resume

Security controls, identity integration, remediation, and reviewable automation across platform and independent engineering.

Experience

Wireless Engineer III — AAA Development & Platform Automation · Charter Communications (Spectrum)

Nov 2024 – Aug 2026 · Previous role

  • Automated directory-backed SSO across engineering tools using SAML, OIDC, and OAuth, including group-driven account provisioning and role mapping, tested allow/deny behavior, and preserved local recovery access.
  • Automated deployment of endpoint security, endpoint management, software inventory, vulnerability management, and MFA controls across a pre-production fleet.
  • Delivered SIEM log-forwarding automation covering platform and operating-system logs across multiple fleet layouts. Automated enriched Linux audit-event forwarding across six development nodes, resolving SELinux and audit-daemon integration failures and using queued TCP delivery for centralized investigation.
  • Moved source-control permissions onto directory-backed groups and moved CI pipelines off personal credentials onto dedicated service accounts.
  • Designed deployment-time configuration and secrets tooling that separates reusable policy artifacts from environment values and versioned encrypted secrets; released the deployment component with environment validation, provenance tracking, and compatibility checks while broader rollout remained in progress. (in-progress)
  • Migrated a development policy configuration to templated values and encrypted secrets while preserving byte-identical output across all 62 rendered files; credential rotation remained a separate follow-up.
  • Built and deployed a TypeScript Webex assistant for engineering knowledge lookup, with access configured for 12 teammates, separate read-only tool gateways, and conversation isolation by caller and privilege tier; verified lookup and refusal behavior through live messaging.
  • Root-caused a TLS handshake failure blocking OAuth2 token retrieval by isolating the ALPN extension in the ClientHello as the trigger, eliminating DNS resolution, TCP reachability, certificate interception, TLS version negotiation and general HTTPS egress with a positive control for each, then proving with a four-variant differential matrix that the reset followed the extension being present rather than the protocol offered, and restoring token issuance the same day.

Founder / Principal Engineer · Duvall WiFi

Aug 2022 – Nov 2024 · Previous role

  • Founded and ran a technology and ISP services company covering network engineering, software development, hosting, cybersecurity, and managed IT. I owned customer discovery, architecture, implementation, production operations, sales, billing, and support.
  • Implemented defense-in-depth portal authentication with brute-force throttling, GeoIP impossible-travel detection, device fingerprinting, reCAPTCHA, and JWT-based hotspot session tokens.
  • Built and operated a three-host VMware vSphere/vSAN environment with data-center colocation, an air-gapped root CA, zero-trust segmentation, secure administrative workstations, SIEM monitoring, VM templates, and hub-and-spoke VPN connectivity across customer networks.
  • Performed an owner-authorized, zero-impact attack-surface assessment across a roughly 12-service production presence using DNS and certificate-transparency reconnaissance, endpoint and auth-flow review, CORS and header testing, and vantage verification; delivered ranked remediation and disproved two initial split-horizon false positives before reporting. (analysis)

Technology & Growth Consultant · Pacific Northwest Plumbing

Jun 2023 – Nov 2024 · Previous role

  • Delivery included a Laravel 10 production website, conversion tracking, advertising workflows, helpdesk support, and custom IP-camera security integrations.
  • Built the lead-generation application in Laravel 10 with Nova administration, reCAPTCHA v3 score-based filtering, Google and Microsoft paid-click attribution, and dual-channel lead alerting, then replatformed it to static Astro once the dynamic attack surface was no longer justified.

Network & Systems Consultant · Wilderness Awareness School

Nov 2022 – Nov 2024 · Previous role

Delivered network and systems consulting for a multi-property school in challenging rural terrain.

Technical Consultant · Beyond Grey Skies, LLC

Mar 2016 – Jun 2021 · Earlier chapter

Provided enterprise network, server, and technical operations consulting.

Independent projects

Identity Platform Engineering · Independent project

2026 · Independent project

  • Deployed an Authentik identity platform using Ansible, Docker Compose, declarative Blueprints, and Terraform-managed Cloudflare Access, with OIDC group claims for application authorization.
  • Verified signed identity tokens, allow/deny behavior, group-removal revocation, deactivated-user denial, and configuration reapplication through 20 infrastructure checks and a ten-check identity suite.
  • Imported the existing edge-access applications into Terraform without recreating them, preserved fallback login paths, and caught destructive nulling of previously unmanaged fields in plan review before it reached production.

AI Integration & Security Engineering · Independent project

2026 · Independent project

  • Built a Cloudflare Worker MCP gateway with OAuth 2.1 and per-client capability tokens, authenticated origin access, and a constrained API to a private CRM.
  • Implemented the engine as a dependency-free Python state machine with idempotent ingestion, duplicate protection, signed-webhook verification, replay safety, time-zone/DST/holiday scheduling, and least-privilege HMAC API access, shipping 101 unit tests and 85 of 85 live acceptance checks.

Private Cloud & Homelab Platform Engineering · Independent project

Ongoing · Ongoing

  • Performed read-only isolation and hypervisor-risk analysis across the workload, management, vMotion, and vSAN planes, validating layer-2 protections and blocked routing while identifying patch-level exposure to guest-to-host escape vulnerabilities and a high-blast-radius shared-storage design. (analysis)
  • Audited the management and service exposure of a colocated RouterOS core router, validated ordered default-deny containment, and executed a no-reboot reduction of SNMP, bandwidth-test, captive-portal, and obsolete RADIUS exposure while preserving recovery access.
  • Built reusable Windows performance and security triage tooling covering hardware, storage health, patching, Defender, firewall, logons, public connections, persistence surfaces, signatures, remote tools, and high-refresh gaming bottlenecks.

Skills demonstrated here

  • Ansible
  • Jinja2
  • Artifact provenance
  • Docker Compose
  • Vulnerability research
  • Endpoint management
  • Vulnerability management
  • MFA
  • Mutual TLS / X.509
  • Splunk Universal Forwarder
  • VMware vSphere / vCenter
  • VM templating
  • Python
  • PowerShell
  • Java 23 / Spring Boot
  • TypeScript
  • PHP / Laravel
  • Astro
  • API design
  • AI agent workflows
  • Behavioural-parity testing
  • Root-cause analysis
  • LDAP / AD integration
  • Authentik
  • OIDC / OAuth 2.x
  • Cloudflare Access / Workers
  • Terraform / OpenTofu
  • MCP
  • MikroTik RouterOS
  • VMware vSAN
  • JWT / JWKS validation
  • Structured logging & log pipelines
  • Tool-use governance & approval gates
  • Webex bot integrations
  • SAML 2.0 / JIT provisioning
  • SOPS / age
  • auditd
  • rsyslog
  • SELinux troubleshooting
  • Grafana
  • Portainer
  • TLS handshake analysis (ALPN)

Certifications

CompTIA A+ · CompTIA Network+ · CompTIA Security+ · CompTIA Server+ · Microsoft MTA: Mobility and Device Fundamentals