ABOUT · JOE ROMAINE SSgt · USAF

I'm Joe.

Nuclear & Cyber Defense Architect. Military by formation, engineer by trade, builder by habit. I came up through operations-heavy environments where the question is never "is the system elegant" but "does the system survive contact with reality." That bias bleeds into everything I ship: small surface area, boring tools, honest documentation.

Twenty-five years in: nuclear-mission systems administration in the Air Force, then global enterprise infrastructure, hospital integration under change control, and now security operations and detection engineering. I still hold the rank of E-5, Staff Sergeant, United States Air Force — the values it taught me are not decoration; they are how I work.

RESUME · 30,000 FT PDF ↓

Altitude over detail — no employer names, no dates. Twenty-five years; specifics on request.

What I do

  • Identity hardening across hybrid AD ↔ Entra ID estates
  • Detection engineering & SOC triage — Sentinel (KQL) / CrowdStrike Falcon
  • Incident response & the post-mortems that follow
  • Email security, phishing response & tenant-wide remediation
  • Vulnerability & risk management — prioritize, patch, prove it
  • PowerShell / Graph automation that retires manual queues
  • Endpoint management & hardening — Intune / SCCM / JAMF
  • Backup, DR & continuity for regulated environments
  • Compliance-aligned operations — NIST, HIPAA, DoD RMF, cGMP
  • Executive communication — translating risk for the board

Stack

  • security: conditional access, detection eng, IR, threat hunting, vuln mgmt
  • cloud: Microsoft 365, Azure, AWS, Entra ID, Exchange / SharePoint / Teams, Power Platform
  • detect: Sentinel, KQL, CrowdStrike Falcon, Defender XDR
  • endpoint: Intune, SCCM/MECM, JAMF, MDM, ASR / STIG hardening
  • code: PowerShell, Python, Microsoft Graph, REST, Power Automate, bash
  • network: Meraki, Palo Alto, Fortinet, pfSense, VPN, DNS filtering
  • data/DR: Veeam, Rubrik, Druva, Commvault, Azure / AWS Backup
  • compliance: NIST 800-53/171, CIS, HIPAA, DoD RMF, DISA STIG, cGMP
  • lead: small high-trust teams, written-first, exec briefings

Certifications

ISC2 CISSP badge
CISSP
CompTIA Security+ ce badge
Security+
CompTIA A+ ce badge
A+
Jamf Certified Tech badge
Jamf Certified Tech

B.S. Information Technology — Advanced Cybersecurity

Skills & platforms

Identity & access Active Directory, Entra ID / Azure AD, ADFS, Duo, SAML, OIDC, MFA, Conditional Access, RBAC, privileged access, on/offboarding, access reviews, account lifecycle
Cloud & M365 Microsoft 365, Azure, AWS, Exchange Online, SharePoint, OneDrive, Teams, Power BI / Apps / Automate, tenant administration, cloud ↔ on-prem migrations
Endpoint & device Intune, SCCM / MECM, JAMF (certified), MDM, imaging, patching, endpoint hardening, ASR, Windows 10/11, Windows Server, Linux, macOS
Detection & SecOps Microsoft Sentinel, KQL, CrowdStrike Falcon, Microsoft Defender XDR, detection engineering, alert tuning, incident correlation, IR, malware & ransomware investigation, threat hunting
Email security Defender for Office 365, Exchange Online Protection, Proofpoint, Barracuda, KnowBe4, message trace, tenant allow/block, phishing campaigns, message purge & recovery
Vulnerability & risk Defender Vulnerability Management, vuln scanning, exposure review, patch prioritization & validation, remediation tracking, risk reporting
Network & secure access Cisco Meraki / ASA / Firepower, Fortinet, Palo Alto, SonicWall, pfSense, Ubiquiti, Pi-hole, VPN, DNS filtering, segmentation, high-risk / China travel connectivity
Automation & scripting PowerShell, Python, Microsoft Graph, REST APIs, Power Automate, bulk administration, migration automation, scheduled reporting, custom integrations
Backup, DR & data Veeam, Rubrik, Commvault, Druva, Barracuda, Azure / AWS Backup, Synology, QNAP, DR planning, restore testing, retention, storage & cost optimization
ITSM & operations ServiceNow, BMC Remedy, Jira Service Management, Freshservice, Zendesk, SolarWinds, change control, continuity planning, runbooks & knowledge bases
Compliance & governance NIST CSF / 800-53 / 800-171 / 800-61, CIS Controls, HIPAA / HITECH, DoD RMF, DISA STIG, FISMA, FIPS, FDA / cGMP, Joint Commission, audit readiness
Specialized Healthcare & Epic (HL7, DICOM-aware, clinical / lab / OR / NICU device support), Citrix / RDS / terminal services, security awareness training, C-suite & board reporting
CONTACT CHANNELS

In rough order of how reliably I'll answer:

For collaboration or "hey can you look at this" — DM on X is the fastest path.