RGBRyan Brackenrig
CLOUD ENGINEERING / SECURITY / AUTOMATION

RyanBrackenrig.

Secure foundations.
Useful technology.

I build and secure the systems businesses rely on — from Microsoft 365 and cloud identity to automation and governed AI.

Explore my work Download resume
8+ yearsIT & managed services
Microsoft certifiedAzure Security Engineer · AZ-500
Engineer & team leadImplementation through operations
Connecticut basedUnited States Marine Corps veteran

01 / Applied expertise

Engineering with
a business purpose.

How I turn technical experience into stronger operations and new service opportunities.

Scroll or choose an example

Technical depth. Business perspective.
From secure systems to service development.

01 Cloud identity & security

Secure access.
Keep people working.

The business need

Employees need dependable access to their tools. The business needs clear rules for who can sign in, from which devices, and under what conditions.

My contribution

I design Conditional Access policies, administer identity lifecycles and privileged access, and investigate risky users and sign-ins across client tenants.

Engineering judgment

Stronger controls must be balanced with legitimate access requirements and a supportable administrative model.

Delivered capability

Policy-driven access based on identity, device compliance, sign-in risk, and location.

  • Microsoft Entra ID
  • Conditional Access
  • MFA
  • Identity Protection

02 Endpoint & infrastructure engineering

Consistent devices.
Repeatable setup.

The business need

The business needs a defined way to configure and manage employee devices, rather than treating every setup as an individual task.

My contribution

I deploy Intune configuration profiles, compliance policies, and applications across Windows and mobile devices. I configure Windows Autopilot to automate Windows endpoint provisioning.

Engineering judgment

A consistent management approach still needs to account for differences between Windows, iOS/iPadOS, and Android.

Delivered capability

Repeatable Windows provisioning, with centrally managed configuration, application, and compliance policies.

  • Microsoft Intune
  • Windows Autopilot
  • Windows
  • iOS / Android

03 Automation & applied AI

Automate the routine.
Validate the result.

The business need

Recurring administration and reporting should not require rebuilding the same steps each time. The business needs an approach that can be checked and reused.

My contribution

I build PowerShell and Microsoft Graph automation for administration and reporting, using AI-assisted development with engineering validation before production use.

Engineering judgment

Generated code is a starting point, not proof that a workflow is correct. Validation remains an engineering responsibility.

Delivered capability

Reusable administration and reporting workflows, with engineering validation before production use.

  • PowerShell
  • Microsoft Graph
  • AI-assisted development

04 Business development & service strategy

Build the service.
Grow the business.

Employee-led initiative

The business opportunity

Turn technical expertise into a new service offering, with a clear approach to delivery, revenue, and growth.

My contribution

I developed a service model and revenue plan, connecting hands-on technical experience with the development of a new offering.

  1. PlanDevelop the service model
  2. LaunchEstablish the offering
  3. GrowSupport revenue growth

Business contribution

Expanded the service offering and contributed to revenue growth.

  • Service development
  • Revenue planning
  • Business growth

Tools and systems shaped by the work
of supporting real businesses.

PROJECT 01 SECURITY OPERATIONS
VISIBILITY ACROSS TENANTS

Microsoft 365
security visibility.

Conceived, built, and operate a self-hosted platform that consolidates Microsoft 365 security findings into per-tenant dashboards.

The problem

Security findings across multiple Microsoft 365 tenants needed to be consolidated into per-tenant views.

Delivered capability

Consolidated visibility into MFA coverage, privileged-role exposure, Conditional Access gaps, Intune compliance, risky users, and security alerts.

PROJECT 02 IN DEVELOPMENT
brigd.

A governed bridge to AI.

Developing a governed AI workspace for small businesses, delivered through IT providers.

The focus

Give employees a clear, sanctioned way to use AI while helping the business retain oversight of sensitive data and access.

My approach

Develop a practical workspace that helps businesses adopt AI responsibly, with clear oversight and a focus on everyday operations.

Visit Brigd
November 2024–PresentTrumbull, CT

Cloud Engineer

Talix IT

Serve as the primary cloud security engineer across multiple client tenants, combining Microsoft 365 security, identity administration, endpoint management, and Azure infrastructure delivery. Develop automation for administration and reporting alongside hands-on client project work.

  • Identity and access engineering

    Design Conditional Access policies covering multifactor authentication, device compliance, sign-in risk, and location restrictions. Administer identity lifecycles, privileged access, licensing, and least-privilege role assignments in Entra ID, and investigate risky users and sign-ins.

  • Endpoint management and provisioning

    Deploy Intune configuration profiles, compliance policies, and applications across Windows, iOS/iPadOS, and Android. Configure Windows Autopilot to automate endpoint provisioning and apply consistent device configurations.

  • Endpoint and application security

    Implement Defender for Endpoint, BitLocker, Windows LAPS, attack surface reduction rules, and Huntress EDR. Configure SAML/OIDC single sign-on and scope application permissions.

  • Microsoft 365 security hardening

    Harden Exchange Online, SharePoint, OneDrive, and Teams. Align client configurations with CIS Level 1/Level 2 benchmarks and applicable PCI-DSS requirements.

  • Azure infrastructure delivery

    Scope and provision Azure compute and virtual networking for a compliance-sensitive client environment, translating security requirements into network topology and resource design.

  • Engineering automation

    Build PowerShell and Microsoft Graph automation for administration and reporting. Use AI-assisted development with engineering validation before production use.

May 2024–November 2024Ardsley, NY

System Administrator

Blindtek Designer Systems

Managed day-to-day IT operations for a 20+ user business, combining end-user support with security improvements, maintenance automation, backup and disaster recovery, and secure remote access.

  • Daily IT operations

    Managed user support, proactive monitoring, patch management, and incident response across the business environment.

  • Security configuration

    Deployed SaaS security controls aligned with CIS Level 1/Level 2 benchmarks.

  • Maintenance automation

    Automated routine maintenance through PowerShell and RMM scripting.

  • Business continuity and remote access

    Implemented backup and disaster recovery solutions and secured and optimized remote access to support business continuity and user productivity.

October 2017–April 2024Ossining, NY

Service Manager / Lead Engineer

ServiceByte LLC

Combined hands-on infrastructure engineering with service leadership for SMB and professional-services clients. Led projects from scoping through delivery, resolved complex escalations, mentored junior technicians, and developed support practices for repeatable service delivery.

  • Infrastructure project delivery

    Led domain migrations, firewall upgrades, and Microsoft 365 / Entra ID onboarding projects from initial scoping through implementation.

  • Windows and identity infrastructure

    Administered Active Directory and Windows Server environments, including Group Policy, DNS, DHCP, and domain services.

  • Technical escalations and service delivery

    Delivered Tier 2/3 support across multiple client environments, resolving escalated infrastructure and end-user issues while maintaining SLA compliance.

  • Security standards and documentation

    Aligned client environments with CIS Level 1/Level 2 benchmarks and PCI-DSS requirements. Documented configurations and support procedures for repeatable service delivery.

  • Technician development

    Mentored junior technicians and improved troubleshooting and ticket-resolution practices.

  • Service expansion

    Established a Home Services division that contributed to revenue growth.

CERTIFICATION

Azure Security Engineer Associate

Microsoft Certified · AZ-500

EDUCATION

Computer Information Systems

Associate Degree · SUNY Westchester Community College

SERVICE

United States Marine Corps

Veteran

LET’S CONNECT

Have something
worth building?

For professional opportunities and conversations
about cloud, security, or applied AI.

Email Ryan LinkedIn