TANIUM SME · 5× TANIUM CERTIFIED

I design and run Tanium at enterprise scale.

Senior Tanium SME with 7+ years in enterprise endpoint management and security operations, and 5+ years hands-on with Tanium across estates of 10,000+ endpoints on Windows, macOS, and Linux.

  • Tanium Certified Operator (TCO)
  • Tanium Certified Administrator (TCA)
  • Tanium Certified Professional, Endpoint Management (TCP-EM)
  • Tanium Certified Professional, Endpoint Risk & Security (TCP-ERS)
  • Tanium Certified Specialist, Cloud Deployment (TCS-Cloud)

5× TANIUM CERTIFIED

Toronto area · Open to contract engagements

ABOUT

About

I've spent 7+ years in enterprise endpoint management and security operations, and the last 5+ working hands-on with Tanium across the full platform: Core, Patch, Deploy, Asset, Discover, Comply, Enforce, Threat Response, Impact, Interact, Connect, Trends, and Provision.

I've designed Tanium architecture for enterprises with 10,000+ endpoints, onboarded clients end to end from client rollout to production handover, and built the custom sensors, packages, and playbooks that turn a platform into daily operations. I work directly with security, risk, and compliance teams to hit patch SLAs, vulnerability targets, and audit reporting requirements.

Before Tanium I came up through the Microsoft endpoint stack (SCCM/MECM, Intune, Autopilot, AD and Group Policy, Defender for Endpoint), which is why I'm effective at migrating organizations off legacy tooling.

7+ yrs
Endpoint security
5+ yrs
Hands-on Tanium
10,000+
Endpoints per estate

CERTIFICATIONS

Certifications

Five Tanium certifications, spanning platform operation, administration, and specialist cloud deployment.

Tanium Certified Operator (TCO)

TCO

Tanium Certified Operator

Day-to-day platform operation, questions, sensors, and actions.

Tanium Certified Administrator (TCA)

TCA

Tanium Certified Administrator

Platform administration, RBAC, content, and client health.

Tanium Certified Professional, Endpoint Management (TCP-EM)

TCP

Tanium Certified Professional, Endpoint Management

Patch, Deploy, Provision, and endpoint lifecycle.

Tanium Certified Professional, Endpoint Risk & Security (TCP-ERS)

TCP

Tanium Certified Professional, Endpoint Risk & Security

Comply, Enforce, Threat Response, Impact, and risk reduction.

Tanium Certified Specialist, Cloud Deployment (TCS-Cloud)

TCS

Tanium Certified Specialist, Cloud Deployment

Tanium Cloud deployment and architecture.

Also: MCSA, Windows Server · Citrix CCV-A

EXPERTISE

Expertise

TANIUM CORE

Architecture & Onboarding

Zone server topology, linear chain configuration, module server sizing, and bandwidth planning. End-to-end client onboarding through production handover.

PATCH · DEPLOY

Patch & Deploy

OS and third-party patching with scan management, maintenance windows, and dynamic patch lists. Zero-day remediation. Reusable Deploy packages.

COMPLY · ENFORCE

Compliance & Hardening

CIS baselines in Comply, Enforce policy design, GPO-to-Enforce migration, and audit-ready reporting.

THREAT RESPONSE · IMPACT

Threat & Risk

Threat Response, Interact, and Live Response investigations. Impact for lateral-movement risk and remediation priority.

AUTOMATE · CONTENT

Automation & Custom Content

Custom sensors in PowerShell (VBScript to PowerShell migration), custom packages, and Automate playbooks.

ASSET · CONNECT · TRENDS

Visibility & Integration

Asset and Discover inventory, Trends boards, Connect-driven reporting, ServiceNow integration, and RBAC and content set design for least privilege.

SELECTED WORK

Selected Work

COMPLIANCE

27% → 62%

CIS compliance, 27% → 62%

I migrated a bank's Windows 11 hardening from Group Policy to Tanium Enforce. I baselined with Comply CIS assessments, reproduced existing GPO settings in Enforce before retiring them, then rolled out the approved fail findings, and I now manage drift through a compliance profile.

AUTOMATION

Zero-touch Windows 11 upgrades

I built a linear Tanium Automate playbook that takes devices from user confirmation through cleanup, pre-cache, and upgrade phases, using only Automate and Deploy. Pre-flight checks run as Deploy target criteria.

REMEDIATION

VBScript retirement

I'm leading a fleet-wide conversion of Tanium sensors from VBScript to PowerShell ahead of Microsoft's VBScript deprecation.

FIRMWARE

Fleet BIOS updates

I built a single Deploy package for Dell BIOS updates using Dell Command | Update, with an encrypted BIOS password, Tanium-owned reboots, and fail-fast checks.

CONTACT

Need a Tanium SME on your team?

I take on contract engagements directly: architecture reviews, module rollouts, compliance and hardening programs, patch operations, and automation builds. Email is the fastest way to reach me.

Full résumé available on request.