Devices provisioned or redeployed
Windows, macOS, ChromeOS, and mobileZachary Woo · San Francisco Bay Area
Security-Aware IT Technician
Endpoint Support · IAM · IT Operations · Security Documentation
I support users, endpoints, accounts, and IT processes in a real multi-site environment while applying practical security principles to everyday technology operations.
Helpdesk backlog reduced to 57
Down from approximately 160–180 tickets after 80+ follow-ups.Employees onboarded
Enterprise password manager adoptionEndpoints audited
Health, software, and configuration reviewProfessional experience
Real IT work, measured by service and follow-through.
My strongest experience comes from supporting real users, endpoints, accounts, and operational priorities across a multi-site environment.
Current role
IT Technician
Futures Explored, Inc.
- Tenure
- April 2026 – Present
- Environment
- Multi-site nonprofit IT
- Primary scope
- Endpoints, users, IAM, helpdesk
Cross-platform endpoint lifecycle
Provisioned and redeployed 35+ employee, mobile, participant-use, and shared-use devices, including Entra joins, software configuration, MDM verification, inventory updates, and user handoff.
Helpdesk operations
Reduced a Jira backlog from approximately 160–180 tickets to 57 by following up on 80+ requests, closing stale or resolved items, and prioritizing active work by operational impact.
Identity and credential hygiene
Contributed to enterprise password manager adoption through product evaluation, rollout materials, role-based access organization, onboarding 16 employees, and migration and recovery follow-up.
Endpoint monitoring
Used Datto to audit approximately 20 systems, remediate authorized update issues, and escalate monitoring, activation, storage, and configuration risks.
Malware response
Detected and quarantined malware on a shared endpoint with Microsoft Defender, initiated deeper scanning, expanded endpoint review, and documented concerns for escalation.
IAM and documentation
Supported Google Workspace, Microsoft 365, Microsoft Admin, and Entra account workflows while creating provisioning SOPs, phishing training, secure-deletion procedures, and authentication guidance.
Professional experience
Tech Support
Bay Alarm Company · Mar–Apr 2026
Troubleshot alarm, access-control, CCTV, and IP-connected security system issues using remote programming tools, service logs, documentation, and defined escalation paths.
Community experience
Volunteer IT Support
St. Raymond Catholic Church · Jan–Mar 2026
Troubleshot public-facing AV and livestream systems, restricted unauthorized wireless access, validated changes, and documented baseline configurations and operational risk.
Selected projects
Labs that reinforce production-relevant skills.
Each project focuses on implementation, validation, and honest limits. The labs support my professional experience, not substitute for it.
Active Directory Domain Deployment & RBAC
Built an isolated Windows domain to demonstrate identity administration, role-based access, and least-privilege validation.
- Windows Server 2022
- Windows 10
- AD DS
- DNS
- VirtualBox
Objective
Deploy a functional Active Directory environment and enforce different access levels for IT, HR, and Finance users.
What I implemented
Configured domain services and DNS, created an OU hierarchy, added users and security groups, joined a Windows 10 client, and assigned access through group membership rather than direct user permissions.
How I validated it
Tested the shared resource as representative users. HR and Finance accounts were denied write access, while the IT administrator group retained full file operations.
Security relevance
Demonstrates foundational IAM, RBAC, permission inheritance, domain authentication, and least-privilege thinking.
Limitations & lessons
Single-domain home lab with no Group Policy deployment, centralized logging, network segmentation, or enterprise-scale lifecycle automation.
Wazuh SIEM Incident Response
Investigated correlated Linux authentication activity, mapped observed behavior, and documented the response as a concise incident report.
- Wazuh SIEM
- Ubuntu Linux
- SSH
- PAM
- sudo
- MITRE ATT&CK
Objective
Use centralized alerting to detect and analyze repeated SSH authentication failures and related privilege activity.
What I implemented
Reviewed Wazuh alerts across SSH, PAM, and sudo sources, correlated repeated failures, reconstructed the event sequence, and mapped observed behavior to password guessing and SSH techniques.
How I validated it
Checked for successful logins, unauthorized account creation, privilege escalation, and follow-on alerts. No successful unauthorized authentication or privilege escalation was observed.
Security relevance
Shows alert triage, timeline analysis, evidence-based scoping, ATT&CK mapping, and careful incident documentation.
Limitations & lessons
Controlled home-lab activity with a narrow Linux endpoint scope. It does not represent production SOC ownership or enterprise incident authority.
SSH Brute-Force Detection & Mitigation
Detected a simulated authentication attack in native Linux logs, reconstructed its timeline, and validated automated blocking.
- Ubuntu Linux
- OpenSSH
- auth.log
- Bash
- fail2ban
Objective
Detect repeated SSH failures, identify the source pattern, reconstruct the event timeline, and reduce repeated login attempts.
What I implemented
Filtered authentication logs, counted failures by source, separated remote SSH activity from local PAM events, and configured fail2ban to respond to repeated attempts.
How I validated it
Repeated the simulation and confirmed that fail2ban banned the source after the configured threshold and refused subsequent connections.
Security relevance
Demonstrates command-line log analysis, signal validation, automated containment, and verification after a control change.
Limitations & lessons
A small, simulated environment. Production controls would also include key-based authentication, MFA where supported, centralized monitoring, and formal change management.
Secure Router Provisioning & Hardening
Reprovisioned a previously used consumer router for a local-only workload while documenting security trade-offs and residual risk.
- ASUS Router
- WPA3
- Protected Management Frames
- Isolated LAN
Objective
Create a functional WAN-isolated network while reducing exposure from unknown prior configuration and unnecessary services.
What I implemented
Factory-reset and securely reprovisioned the router, set non-default administrative credentials, separated wireless bands, used WPA3 with protected management frames, and disabled UPnP, cloud services, and remote management.
How I validated it
Verified firmware state, local packet flow, physical WAN isolation, disabled remote services, and successful operation of the intended local workload.
Security relevance
Applies secure baseline configuration, attack-surface reduction, defense in depth, and explicit residual-risk documentation.
Limitations & lessons
Personal lab design without centralized management, automated patching, or enterprise monitoring. Manual firmware maintenance remains necessary.
Detailed sanitized project documentation is available upon request.
Skills & tools
A practical toolkit for reliable, security-aware support.
Organized around the work I can discuss and defend, without arbitrary proficiency scores.
Endpoint & systems
- Windows 10/11
- macOS
- ChromeOS
- iOS / iPadOS
- Ubuntu Linux
- Device provisioning
- Entra device joins
- MDM verification
- Software configuration
- Printer & connectivity troubleshooting
IAM & administration
- Google Workspace
- Google Admin
- Microsoft 365
- Microsoft Admin Center
- Microsoft Entra ID
- User provisioning
- Password resets
- Account termination
- Security groups
- MFA & passkeys
- Dashlane
IT operations
- Jira Helpdesk
- Datto
- AssetTiger
- Addigy
- Splashtop
- OneDrive
- Microsoft Teams
- Google Drive
- Google Forms
- Google Sheets
- Asset tracking
- Multi-site support
Security & documentation
- Microsoft Defender
- Wazuh SIEM
- BitLocker
- Secure deletion
- Encrypted archives
- Endpoint audits
- Least privilege
- Incident documentation
- SOP development
- Phishing training
- Authentication guidance
- AI acceptable-use guidance
About
Reliable technology support, grounded in practical security.
I am a San Francisco Bay Area IT Technician with a B.S. in Software Engineering and a minor in Justice Studies from San José State University.
My work combines user support, endpoint lifecycle management, IAM workflows, helpdesk operations, secure data handling, and clear documentation. My primary direction is endpoint support and IAM, with additional interest in GRC, IT compliance, and security operations.
- 2025
B.S. Software Engineering
San José State University · Minor in Justice Studies
- DEC 2025
Google Cybersecurity Certificate
Completed all eight courses
- FEB 2026
CompTIA Security+
SY0-701 certified
- NOW
Production IT experience
Endpoint support · IAM · operations · documentation
Let's connect
Looking for security-aware IT support talent?
I am open to meaningful opportunities in endpoint support, IAM, IT compliance, and security operations.