MSP Lead Project Engineer | End-to-End Infrastructure Modernization

About

SUMMARY

Dedicated and results-driven Information Technology Professional with a strong foundation in server and client system operations, diagnostics, migrations, and upgrades. Passionate about staying current with emerging technologies and continuously expanding technical knowledge. Adept at analyzing business needs and client challenges to deliver effective, accurate solutions. Known for a logical and empathetic approach to problem-solving, strong interpersonal skills, and the ability to manage multiple projects while handling day-to-day administrative tasks efficiently.

TECHNICAL SKILLS

Operating Systems: VMware ESXi and vCenter 5.5, 6.0, 6.5, 6.7, 7, 8, Windows Server 2003 R2, 2008 R2, 2012 R2, 2016, 2019, 2022, and 2025, various Linux distros, Cisco IOS, SonicWall SonicOS, Windows 2000/XP/Vista/7/8.1/10/11, Mac OS X, Google Android, and Apple iOS.

Networking: TCP/IP network design, installation and administration, firewall, switch, and server install, configuration, and upgrade, Cisco VOIP administration, Virtualization setup and administration. Azure virtual networks/subnets, NSGs, and VPN Gateways for Site-to-Site and Point-to-Site connections

Applications/Tools: Active Directory 2025, Windows Server 2025 DHCP, DNS, and File and Print, VMware vSphere 8, VMware Horizon 7 VDI, VMware App Volumes, Hyper-V, Microsoft Failover Clustering, AvePoint Fly Server and SaaS, Datto RMM, Autotask PSA, CyberQP, ITGlue, Cisco Duo MFA, PowerShell, Ivanti Patch for Windows Server, Azure blob storage, Azure Entra Connect, Hybrid Configuration wizard, Microsoft 365, Sophos Enterprise, Endpoint, Central, SafeGuard, and Mobile Device Management, and Web filter, Exchange 2007, 2010, 2013, 2016, and Exchange Online, SharePoint, Teams, OneDrive, Intune, Purview, Defender, Azure, iDRAC, iLO, CIMC, Cisco UCM, Unity, MS Office 365, Sage 100 and 300 CRE, Infor Baan ERP, Numara Track-It!, Continuum MSP, N-Able N-central and Passportal, Mimecast, Barracuda, Symantec Backup Exec, HP Data Protector

Hardware: Cisco 2960, Cisco UCS C220 M4 and M7s, Nutanix, HPE Nimble, Alletra, and MSA arrays, Synology NAS, APC UPSes, PowerConnect, and X-Series switches, Cisco 1841 routers, SonicWall TZ 215 and 300, SonicPoint APs, Dell PowerEdge R470 and HPE DL360 servers, Axis PoE cameras, Nortel and Mitel phone systems, Cisco IP phones, Polycom HDX 9000, Meraki switches

PROFESSIONAL EXPERIENCE

Managed Service Provider | Lead Project Engineer | January 2025 – June 2026

  • Led end-to-end Microsoft 365 tenant-to-tenant migrations, transferring Exchange Online, Teams (chats and channels), OneDrive, and SharePoint data with AvePoint Fly SaaS, and seamlessly transitioned Windows endpoints to Intune in the new tenant with user profile retention via Quest On Demand Migration. Moved 365 licenses and automatically reconfigured Outlook, Teams, and OneDrive apps using the Quest Desktop Update Agent.
  • Managed Datto RMM to onboard new clients and configure site environments, enabling secure remote desktop access. Deployed and updated third-party applications using Datto components and jobs, and developed patch management policies to maintain Windows system compliance and security.
  • Deployed a Microsoft 365 multi-tenant organization (MTO) to enable seamless cross-tenant collaboration between tenants. Configured Entra External ID B2B Collaboration and Cross-Tenant Access Settings, including Teams Shared Channels through B2B Direct Connect, and Cross-Tenant sync. Migrated Standard/Private channel data to Shared channels to eliminate the need for users to switch tenants during communication and collaboration. Enabled secure external access while maintaining compliance and user experience consistency across both environments.
  • Migrated client file shares to SharePoint Online, enabling integration with Microsoft 365 features, improved data security, and simplified user access. Eliminated reliance on remote access VPNs by transitioning to a cloud-based collaboration model.
  • Deployed and configured multiple Synology NAS devices across client environments. Set up select NAS units as VMware datastore LUNs using iSCSI to support the virtual infrastructure, while others were configured as high-availability file servers using Synology High Availability (SHA) clustering. Performed data migrations using Synology Migration Assistant and expanded storage pools by provisioning additional disks and volumes to increase capacity without downtime.
  • Deployed and configured Remote Desktop Services (RDS) on Windows Server, including licensing setup and session host configuration.
  • Converted a VMware environment to Hyper-V using QEMU disk image utility. Powered down the VMs and converted the VMDKs. From iLO I wiped VMware from the host and installed Windows Server 2025 using an image I mounted to a web server I temporarily stood up in a Synology NAS. Added the Hyper-V role, configured a virtual switch in PowerShell for switch embedded teaming. Created VMs using the converted VHDX images. Powered up the VMs to verify proper functionality and relicensed Windows Server for the new environment.
  • Deployed a password management solution for all their clients called CyberQP. Set up admin password rotation and integrated with ITGlue for M365, AD domain controllers, and member servers. Configured self-service password reset and integrated Autotask for contact information sync and identity verification.
  • Created conditional access policies to force MFA, allow sign in from only the United States, and enabled token protection to limit token theft.
  • Set up app protection policies in Intune and created a conditional access policy to protect corporate data on personal devices. Preventing the use of native apps and requiring the use of Microsoft apps.
  • Provisioned a replacement VMware environment with an HPE MSA 2060 fibre channel array and 2 HPE DL360 Gen10 hosts with FC host bus adapters set up in a multipathing configuration. Installed and configured ESXi 8 and vCenter server. Set up a high availability cluster. Migrated the VMs from the old environment using vMotion.
  • Configured Autopilot for a number of tenants with a deployment profile and Enrollment Status Page to install all apps before the user sees the desktop.

Managed Service Provider | Systems Engineer III | March 2023 – November 2024

  • Designed and deployed a 3 node Hyper-V cluster utilizing NIC Teaming for data, management, cluster, and Live Migration traffic using weighted metrics on the QOS based virtual switch giving minimum bandwidths and priority to data and migration traffic. Set trunk ports on Meraki switches. Set up HPE MPIO DSMs, iSCSI, 10 GbE NICs for storage traffic. Created volumes, access groups, and performance polices specific for LOB applications on an HPE Nimble SAN. Used Microsoft’s best practice implantation of converged networking to utilize resources more effectively. Implemented In-Guest iSCSI initiators on SQL servers for improved performance and data protection. Set up Failover clustering and CSVs for high availability. Migrated VMs from an old Hyper-V cluster using Shared-Nothing Live Migration.
  • Migrated Office 365 data from 8 tenants to 1 master tenant. Moved thousands of objects including Exchange mailboxes and public folders, SharePoint and OneDrive sites, M365 Groups, and Teams channel and chat data using AvePoint’s Fly Server. Set up 20 Azure VMs to distribute migration traffic load and move data quicker. Installed the Fly Server manager and 20 agents on each VM. Configured service accounts and Azure Enterprise App profiles. Made the source and destination connections and migration policies. Mapped user accounts between tenants and moved data. Scheduled planned maintenance downtime for the cutover. Removed the domain from the Azure source tenant and added in destination Azure tenant. Updated MX records in the DNS registrar and verified successful mail flow. Created and distributed instructional documentation to end users and service desk for desktop and mobile application reconfiguration.
  • Installed a new HPE Alletra 5010 array. Configured and separated data and management subnets. Connected half the NICs from each controller to separate switches for high availability and fail-over. Set up the volumes, assigned performance policies, data protection with partner replication to another site, and created access policies for the 2 VMware hosts. Added the volumes as VMFS 6 datastores to the hosts and performed storage vMotion of the VMs from the old Nimble array. No downtime incurred.
  • Performed a Cisco UCS and vSphere host refresh by upgrading vCenter from 7 to 8, installing and configuring a custom Cisco image of ESXi 8 on new hosts. Set up an iSCSI software HBA to separate SAN from LAN traffic, created a vSwitch and 2 vmkernel ports and to 2 NICs, and added them to Networking port binding for multipathing, load balancing, and failover. Performed successful tests of path failover by killing switchports to simulate a downed switch. vMotioned VMs to the new hosts and removed the old hosts from the cluster and inventory. Upgraded 2 host in another datacenter from ESXi 7 to 8 by using the vSphere Lifecycle Manager. Applied new licenses to vCenter and the 4 hosts.
  • Installed, configured, and managed Exchange Hybrid. Set up the new Azure tenant and added the custom domain and spf record. Corrected UPNs and account issues with IdFix. Installed and configured Azure AD Connect. Ran the Hybrid Configuration Wizard. Migrated mailboxes with a pilot group of users. Verified correct mail flow inbound, outbound, and between online and on-prem. Completed migration with all users. Configured Sophos email filter to accept and deliver mail from and to Exchange Online and set email routing using connectors to have all mail flow through the Sophos email filter. Set up a connector to receive and relay email from MFPs and on-prem applications.
  • Stood up an Azure tenant to be used as a separate, Geo-redundant, and air-gapped location for disaster recover and ransomware resiliency using immutable storage. Added an Azure subscription to house VNETs, subnets, route tables, NSGs, restored VMs, and backup resource VMs. Set up and configured a Veeam Backup for Microsoft 365 appliance. Created a backup policy for immutability. Configured an Azure block blob storage account using a cold access tier and also configured for immutability. Backed up VMs from the source tenant and restored to the DR tenant. Powered up restored VMs to verify correct functionality. Verified VM backups could not be deleted during the duration of the immutability.
  • Deployed Duo Authentication for Windows Logon for MFA. Enrolled users. Created the sign-in policies and set the offline accessibility. Created GPOs for policy settings and agent deployment. Generated a custom msi using Orca. Tested with a pilot group and then rolled out to all users.
  • Performed a number of ESXi setups for clients. Assembling the hardware, setting up multiple RAID arrays, installing and configuring vSphere, datastores, networking, and migrating VMs. Stood up Synology NAS boxes for repositories and Veeam for VM backups.
  • Created a startup script to detect the presence of a retiring anti-virus application. Build in logic flow so that if detected an entry would be generated in a log file. If it wasn’t detected it would install and license the new AV app. Used a batch script and group policy to deploy this on hundreds of systems.

Local Government | Senior Systems Administrator | February 2022 – March 2023

  • Managed a Hybrid cloud environment with Azure, a Nutanix HCI, VMware cluster, 900 workstations, 100 virtual and cloud Windows and Linux servers, and 10 physical servers.
  • Set up an HA environment in Azure with a site-to-site vpn back to a Cisco FTD backup vpn gateway on premises. Deployed a virtual network, gateway subnet, data subnet, virtual network gateway, local network gateway, network security group, and virtual machine.
  • Created a Server 2019 virtual machine in Azure with Azure Hybrid Benefit licensing. Added it as a member to the domain and promoted it to a domain controller with the DNS role. Added the new Azure virtual network subnet in AD Sites and Services to keep replication traffic to a minimum.
  • Deployed the Network Policy Server role and DHCP role to the Azure vm to be used as a cloud backup radius server, backup DHCP server, and DNS server should the on premises Nutanix VMware cluster go down. Migrated the radius server config from the primary server and configured the client devices, APs and switches, to use the Azure vm as the secondary.
  • Configured the Azure vm to be used as a hot standby failover DHCP server. Reconfigured DHCP scope options to use this server as the tertiary DNS server. Had the network engineer set up a secondary dhcp relay in the network gear to point to this backup DHCP server.
  • Migrated MFA methods from SMS and phone call to Microsoft Authenticator and OATH hardware keys to harden our security posture.
  • Deployed CrowdStrike Falcon Sensor antivirus to almost 900 systems using a combination of PDQ Deploy and group policy. Remotely removed the old antivirus using the server console before performing batch deployments. Ran PDQ Inventory to confirm successful installation.
  • Managed a Nutanix VMware cluster. Added 5 nodes to the cluster, set up a Nutanix file server and migrated files from a Windows file server. Upgraded ESXI and vCenter. Set the EVC mode to the highest compatible baseline CPU feature set.
  • Administered Veeam Backup & Replication using a Scale-out repository to an Azure blob. Added a new performance extent and removed the old while keeping the backup chain intact. Switched the On-site storage protocol from SMB to NFS with a local service account to help improve security of the backups.
  • Sourced, installed, and migrated to new fully redundant UPS stacks. Installed and configured the UPSes, external battery packs, power distribution units, and transformers. Moved datacenter server and network gear to new stacks with minimal downtime. Split the load between the 2 stacks. Added an automatic transfer switch for server and network gear with only one power supply. Went from 11 minutes to 93 minutes of runtime.
  • Rebuilt a failed database server. Reinstalled Windows on the system partition. Worked with the database team to reinstall the application and attach it to the database to restore access.
  • Renewed GoDaddy SSL certificates and installed on various services such as ADFS, IIS, Exchange and Send connectors, a Cisco FTD VPN server, and a Barracuda message archiver. Used an online SSL converter to convert the crt file to a pfx file with private key for simpler installation.
  • Deployed an upgraded version of the Mimecast Security Agent web filter using group policy to almost 900 systems. Used Orca to create an MST transform file to include the license number during installation.
  • Managed a Barracuda message archiver and Mimecast message archiver, email filter, and web filter. Administered block and allow lists, created legal holds, and exported searched emails to a PST file for the legal department.
  • Worked with our ERP and Asset management vendors to set up SSO in our Azure tenant to connect to their cloud based applications.
  • Switched from user auth to computer auth on our radius server’s wireless policy to prevent Active Directory user account lockouts.
  • Enabled MFA 2 digit number matching, geolocation, and application name to further secure our authentication and prevent MFA fatigue.
  • Set up an Exchange Send connector to another organization to bypass our mimecast filter. This allowed email sent to our organizations’ accounts to be forwarded outbound to the other organization without being blocked.
  • Moved our IdP for a third party vendor from ADFS to Azure AD SSO by creating an Enterprise Application. This allowed us to retire our aging and soon to be end of life 2012 R2 server.

Medical Device Company | Systems Engineer | November 2018 – September 2020

  • Manage the VMware vSphere environment using vCenter, SSH, and thick and web clients. vMotion VMs for planned hardware maintenance. Create new VMs from scratch and using clones and templates. Increased VM disk size then increase capacity within the OS. Managed snapshots.
  • Set up new desktop pools in our VMware Horizon VDI environment and created a golden image VM to be used for Linked clone VMs.
  • Expanded a vSAN cluster by setting up a new ESXi host, creating disks groups, vSwitches, VMkernel ports, adding port groups, adding uplinks, and claiming disks.
  • Daily administration of Active Directory environment, including user, group, OU, and GPO management.
  • Migrating our AD environment from server 2008 R2 to 2019, by spinning up new servers, moving services over, DHCP, DNS, and File/Print, transferring FSMO roles and finally raising the domain function level then forest function level to 2016.
  • Manage the Exchange 2016 cluster using DAGs. Activated all mailbox databases on 1 host to perform maintenance then did the same on the other host. Balanced the databases when complete. Updated Exchange to the latest cumulative update by extending the schema.
  • Create new user, shared and resource mailboxes, group, and address lists. Used PowerShell to manage permissions on calendars, to report mailbox folder sizes, find calendar mailboxes that allow conflicts, and to find users with access to a shared mailbox.
  • Use Ivanti Patch for Windows Servers to patch over 200 systems at multiple sites. Worked with various departments and application owners to determine appropriate patch windows to maximize system availability. Set a pre patch rule to take a snapshot before patching and to automatically delete the snapshot 4 days later. This allowed the application owners time to perform their smoke tests.
  • Set up the KACE imaging environment for our helpdesk to use. Spun up a central VM and remote VMs to prevent imaging over the WAN. Set DCHP scope options for systems to PXE boot.
  • Liaison between departments, consultants and vendors to support new and ongoing projects.
  • Lead server life cycle efforts. Perform diagnostic procedures to determine cause of HW and SW failures.
  • In charge of the SolidWorks and PDM 2013 to 2016 migration. Found and purchased SolidWorks certified workstations. Led many planning meetings to coordinate logistics. Worked with helpdesk and our SolidWorks vendor to deploy the new workstations and PDM server all while preventing downtime.
  • Manage our Sophos security environment. Including creating AV policies, deploying client and virtual server software, managing our disk encryption keys, enrolling mobile devices and creating task bundles, and administering our web filter. In the process of migrating to Sophos Central from on-prem to the cloud.
  • Working with Okta to roll out an MFA and SSO solution. Creating rules to enforce MFA while users are outside the corporate network and to suppress MFA while on-network.
  • Researched, purchased, and deployed new software rollouts for various departments, provided training, and coordinated rollout logistics to minimize downtime.
  • Consolidated our domain registrars transferring over 175 domains and hundreds of resource records to simplify dns and ssl certificate management. Found a way to save 50% on our annual ownership costs.

Managed Service Provider | Network Consultant & Support Engineer | February 2017 – October 2018

  • Provided remote and onsite network and server support for multiple clients in the San Diego area.
  • Administered and configured Office 365 tenants adding/removing users and Exchange Online recipient and shared mailboxes.
  • Set up an Office 365 tenant with Exchange Online and added the vanity domain using a TXT DNS record for confirmation. Pointed their public DNS to Office 365 for proper mail flow.
  • Registered, installed, updated, configured, and maintained SonicWall TZ 215 and 300 firewalls.
  • Added SSL VPN licenses to SonicWalls and configured the SSL VPN service for remote access.
  • Configured SonicWall TZ 215 firewall and NAT rules to allow access to a private email server from the WAN zone.
  • Added VLANs to multiple Dell switches and set up trunks to allow VLAN traversal. Connected the main switch to the SonicWall to provide DHCP services, routing, and internet access.
  • Moved to a new ISP and had to update the IP addresses on the SonicWall site to site VPN tunnels. Created new tunnels before the switch so that the tunnels would come up immediately post moving to the new ISP.
  • Added a Dynamic DNS account using NO-IP.com to a SonicWall TZ 300 for a customer with a dynamic IP address.
  • Installed and configured Ubiquiti UniFi and SonicPoint APs.
  • Configured Windows Server 2016 DC, DNS, DHCP roles.
  • Upgraded Sage 100 Contractor client and server from version 19 to 20 to process year-end tax update.
  • Migrated hosted Exchange 2013 to Exchange Online using PST migration.

Managed Service Provider | Network Support Engineer | November 2016 – February 2017

  • Provided remote and onsite network and server support for multiple clients in the San Diego area.
  • Registered, installed, updated, configured, and maintained SonicWall TZ 215 and 300 firewalls
  • Added SSL VPN licenses to SonicWalls and configured the SSL VPN service for remote access.
  • Installed and configured Ubiquiti UniFi APs.
  • Administered Microsoft domain services including, Active Directory, GPO, user and computer accounts, shares, security permissions, DHCP, and DNS.
  • Deployed antivirus software to over 75 systems at multiple locations using Symantec Endpoint Manager server for maintaining up to date virus definitions and monitoring.

Business Services Firm | IT Systems/Network Administrator | July 2008 – October 2016

  • Administered Microsoft domain services including Active Directory, GPO, user and computer accounts, shares, security permissions, DHCP, and DNS.
  • Promoted Microsoft Server 2012 R2 servers to domain controllers then demoted 2003 DCs to member servers and finally removed them from the network due to EOL.
  • Migrated on-prem Exchange Server 2010 mailboxes to Microsoft Exchange Online using batch migration.
  • Installed, configured, and supported a local WSUS server to control Windows updates and improve network bandwidth utilization decreasing by internet usage every patch Tuesday.
  • Migrated over 150 Windows XP systems to Windows 7 due to EOL.
  • Deployed 6 virtual Windows Server 2012 R2 servers into the VMware vSphere datacenter.
  • Headed the installation of an IP PoE camera system utilizing our current network infrastructure providing cost savings from requiring additional PoE switches. Monitored bandwidth usage before and after the installation to confirm correct capacity capabilities.
  • Managed and supported over 125 users, 175 computers, 10 servers, 75 IP phones, and 15 network printers.
  • Maintained daily backups of our file server using Symantec Backup Exec sending the backups to a QNAP NAS.
  • Administered network monitoring using MRTG to collect bandwidth utilization statistics.
  • Created custom GPOs for different departmental needs for our OUs to increase security and prevent unauthorized operating system changes.
  • Deployed antivirus software using Symantec Endpoint Manager server for maintaining current virus definitions on computers.
  • Recommended wide variety of technical solutions in order to improve productivity including correct wireless channel separation, gigabit trunks between switches, layer 3 switching, STP for redundancy, and virtualization utilizing high availability.
  • Worked with systems engineers supporting installation and cabling of our VOIP servers, Cisco switches, routers, wireless controller, access points, and WAN and Internet circuit upgrade and installation.

EDUCATION

Technical Institute
A.S., Computer Networking Systems, 2004

Private University
Studied Computer Engineering Technology, 2000-2001
Studied Network and Communications Management, 2007, 2010, 2011

AWARDS AND RECOGNITION

  • Valedictorian, 2004, Technical Institute
  • CCNA, August 2013
  • MCP 70-346: Managing Office 365 Identities and Requirements, June 2017
  • AZ-900: Microsoft Azure Fundamentals, May 2020
  • AZ-104: Microsoft Azure Administrator, October 2021
  • CLF-C01: AWS Certified Cloud Practitioner, October 2021
  • MS-900: Microsoft 365 Fundamentals, February 2024
  • MD-102: Microsoft 365 Endpoint Administrator, October 2024

Location

Chicago

Salary

$120,000

About the Company 

Bowman Williams is a national specialized staffing firm for Cloud Service Providers and Managed Service Providers. Ranked by Forbes as one of America’s top 200 Best Staffing Firms in America, we are a good resource for candidates looking to advance their careers in the Cloud Solutions and Services industry.

Request this Resume

  • This field is for validation purposes and should be left unchanged.
  • Feel free to let us know if we can do anything else for you - we'd be glad to send sample MSP resumes if you are hiring or information on job opportunities if you're a candidate - thank you!