# Matt James

IT & Security Systems Engineer

- Email: matt.aaron.james@gmail.com
- Phone: +1 (205) 386-0178
- Web: https://mattaaronjames.com
- LinkedIn: https://www.linkedin.com/in/matt-james33/
- GitHub: https://github.com/CowboyMatt
- Location: relocating to Austin, TX or the Washington, DC metro (Northern VA / MD). Available within one month.
- Looking for: a startup that is growing fast and needs IT and security to keep up.
- Work authorisation: U.S. citizen. Clearance-eligible, no active clearance held. U.S. person for ITAR-controlled work.

## Summary

IT and security engineer who has owned IT end to end at fast-growing companies. Hired as ROLLER's first IT employee, built the IT and security function from the ground up, and now run identity, endpoints, security and collaboration for a 300-person company at CreditorWatch. Master's degree, CISM, Security+ and AWS Solutions Architect. Outside work I built and launched TensorFit, an AI form-coaching fitness app, and run a self-built RTX 5090 home lab hosting OpenClaw agents and local models through Ollama.

## Experience

### CreditorWatch, IT Systems Engineer (10/2025 to current, Melbourne)

- Scaled IT provisioning and support as CreditorWatch grew from 200 to around 300 employees in a year, serving as the escalation point for identity, endpoint, network and SaaS issues, mentoring IT and help desk colleagues, running 1Password training, and maintaining the IT knowledge base and user guides.
- Administer Microsoft 365 and Exchange Online with AvePoint backup, and Entra ID across the SaaS stack: SSO (SAML/OIDC), Conditional Access, MFA, Entra ID Protection, access reviews and SCIM provisioning.
- Automated onboarding, offboarding and account provisioning end to end with n8n, Microsoft Graph, REST APIs and webhooks, and defined the offboarding data retention and mailbox handover process.
- Built a least-privilege Microsoft Graph integration for the Databricks pipeline to publish reports to SharePoint for Copilot indexing.
- Review AI tool requests against the AI acceptable-use policy, manage AI licensing and seat allocation, and enforce the policy through Netskope web filtering and DLP controls.
- Manage the Mac and iPad fleet through Iru (formerly Kandji): deployment, configuration profiles, compliance policies, FileVault encryption, patching, and scripted installs and audits.
- Operate CrowdStrike Falcon with Falcon Complete MDR, triaging alerts and working incidents with the MDR team, including phishing and compromised-account response, and Netskope NG-SWG/SSE with DLP controls and Exchange Online email security.
- Operate under Australian data-residency requirements for sensitive tax and financial data at a regulated credit reporting bureau, keeping processing and storage onshore and reviewing SaaS and AI tools for data residency before approval.
- Redesigned and redeployed the Melbourne office network on UniFi: Wi-Fi, VLANs, firewall rules, VPN, DNS and DHCP, and dual-ISP WAN failover, and upgraded the office A/V.

### ROLLER Software, IT Officer / Security Specialist (09/2021 to 10/2025, Melbourne)

- Hired as ROLLER's first IT employee, built the IT and security function from the ground up as the company grew from 60 to over 300 people, and onboarded, trained and mentored the IT staff hired as the team grew, building the IT knowledge base and user guides along the way.
- Negotiated vendor pricing and contracts and managed hardware procurement, software licensing, and ISP and office fit-out vendors, tracking usage and licences across 40+ apps in Zluri.
- Set laptop hardware standards and the refresh cycle, and overhauled asset tracking by rebuilding it in Jira Asset Management.
- Deployed Microsoft Entra ID across the organization, configuring SSO (SAML/OIDC) and SCIM provisioning for 40+ enterprise applications and enforcing Conditional Access and MFA policies.
- Set up OOBE zero-touch enrollment so new laptops joined Entra ID on first boot.
- Deployed Iru, Intune, Automox and CrowdStrike Falcon across the Mac and Windows fleet, scripting patching, installs, security baselines and disk encryption (FileVault, BitLocker), and remediating critical vulnerabilities.
- Authored the policies, procedures and audit documentation for SOC 2 Type 1, established change management, and ran KnowBe4 security awareness and 1Password training.
- Served as primary Google Workspace administrator, managing email security, responding to phishing and compromised-account incidents, and scripting bulk administration with the GAM CLI.
- Designed and installed the Melbourne and Sydney office networks on UniFi (Wi-Fi, VLANs, firewall rules, comms room and rack build-out, structured cabling) and the Zoom Rooms and conference room A/V.

### Harris HMC, Information Technology Intern (02/2021 to 09/2021, Melbourne)

- Managed a 150-device Windows fleet across the full hardware lifecycle (procurement, SOE imaging, asset tagging and secure decommissioning) and updated Active Directory and remote-management systems.
- Delivered Level 1 to 3 desktop and laptop support and repair, ran IT onboarding/offboarding, and administered Slack, Jira and Confluence.

## Featured project: TensorFit (founder and developer, 2026)

A cross-platform AI fitness coach, built solo and launched end to end on React Native / TypeScript with a fully serverless AWS backend (Lambda, API Gateway, S3) defined as Infrastructure-as-Code, live on the App Store and Google Play.

- Multi-model AI form analysis: MediaPipe pose extraction on device, then a Claude + Gemini pipeline on Lambda turns joint angles into scored coaching feedback.
- Conversational exercise coach on the same pipeline, with prompt caching to cut repeat-inference cost.
- A coach that remembers user history, so generated workouts and answers build on what the user has logged.
- Secured end to end: JWT-verified identity on every request, Apple/Google SSO, per-user data isolation, usage quotas, AWS Secrets Manager and S3 lifecycle auto-expiry.

## Automation and AI at work

- Offboarding and onboarding automation on n8n and Microsoft Graph: ticket in Jira Service Management, scheduled for the finish time, sign-in blocked, sessions revoked, groups and licences removed, mailbox handed to the manager, SCIM deprovisioning for Google Workspace, Slack, Zoom and Atlassian, laptop locked and wiped through Iru or Intune, Slack summary and ticket log.
- Pilot of Microsoft Scout for internal IT with agents running under Entra-governed identities.
- AI tool governance: requests reviewed against the acceptable-use policy, Netskope web filtering and DLP to enforce which tools are sanctioned, CrowdStrike AI detection on endpoints.
- Databricks reports published to SharePoint through a site-scoped Microsoft Graph integration so Copilot can index them.
- Home lab: self-built RTX 5090 workstation. OpenClaw runs always-on agents (assistant, automations, research), Claude Code handles coding on Claude Fable 5.1, and DeepSeek Harness is the open-source agent runtime run locally. Everything defaults to a local Qwen 3.8 27B served by Ollama and switches to Claude Fable 5.1 only when a task needs a frontier model.

## Frameworks and standards

- SOC 2 Type 1: wrote the policies and procedures and assembled the audit evidence at ROLLER.
- ISO 27001, NIST CSF, MITRE ATT&CK: used day to day for identity, endpoint and vendor controls and for tuning CrowdStrike policies.
- Data residency: Australian tax data must stay onshore; checked for every SaaS and AI tool before approval.
- CMMC 2.0 Level 2 and NIST SP 800-171: mapping existing SOC 2 and ISO 27001 controls to the 110 practices (in progress).
- ITAR / EAR: U.S. citizen, so I meet the U.S. person requirement for ITAR and EAR controlled work.

## Skills

- Identity and access: Microsoft Entra ID, SSO (SAML / OIDC), Conditional Access, MFA, ID Protection, SCIM provisioning and automated user lifecycle, Google Workspace, access reviews and audits, OAuth 2.0, JWT, least privilege, RBAC, 1Password.
- Endpoint and device management: Iru (formerly Kandji), Intune, Automox, OOBE zero-touch enrollment, device certificates (SCEP / PKCS), security baselines and compliance policies, patch management, FileVault, BitLocker, macOS, iPadOS, Windows.
- Security and compliance: CrowdStrike Falcon and Falcon Complete MDR, incident triage and response, Netskope NG-SWG / SSE and DLP, email security (SPF / DKIM / DMARC), KnowBe4, vulnerability and patch management, SOC 2 Type 1, ISO 27001, NIST CSF, MITRE ATT&CK, IT policy and audit documentation, change management.
- Collaboration and SaaS: Microsoft 365, Exchange Online, SharePoint, licensing, Google Workspace and GAM CLI, Slack, Zoom and Zoom Rooms, Jira and Jira Service Management, Confluence, Zluri, vendor management and procurement.
- Automation and scripting: Python, Bash, PowerShell, Claude Code, n8n, Microsoft Graph API, REST APIs and webhooks, GAM CLI, MDM scripting, CI/CD with GitHub Actions.
- Networking: TCP/IP, DNS, DHCP, VPN, VLANs and segmentation, firewall rules, wireless design, UniFi multi-site with RADIUS, dual-ISP WAN failover.
- Cloud and development: AWS (Lambda, S3, API Gateway), Azure, GCP, Linux, Kali, JavaScript / TypeScript, Node.js, React Native, Git.
- AI and agentic tooling: AI acceptable-use governance and tool evaluation, AI licensing and seat management, Microsoft Scout pilot with Entra-governed agent identities, Claude API, MCP, multi-model Claude + Gemini pipelines, OpenClaw, DeepSeek Harness, Ollama local models, pose estimation with MediaPipe.

## Certifications

- CISM, ISACA (2024)
- CompTIA Security+ 701
- CrowdStrike Falcon Administrator
- Microsoft MS-101 (Microsoft 365)
- AWS Certified Solutions Architect, Associate
- AWS Certified Cloud Practitioner
- GitHub Actions certification

## Education

- Master's degree in Business Information Technology, RMIT University, Melbourne (2021)
- Bachelor's degree in Business Administration, Birmingham-Southern College, Alabama (2019)

## Beyond the day job

- AI automation tool for ROLLERthon 2024, built with the Claude API to automate Salesforce data extraction, cPanel config and report setup, projected to cut venue onboarding 25% and save 2,000+ hours and $100k annually across 1,000+ venues.
- Founded and ran The Athletes Gun, a Shopify drop-shipping business selling recovery massage guns for athletes.
- Designed and tuned a 210 MH/s Ethereum mining rig.
- Led a university team redesigning the Australian Psychological Society's website, with desktop and mobile prototypes.
