Trevor Michael Johnson

-Resume/CV - Summer 2026

San Francisco, CA | 415-300-0810 | forhire@mrjhnsn.com



// About Me:


Endpoint Security Engineer

I am a senior endpoint and identity security engineer who designs, implements, and validates protective controls that reduce risk while enabling business agility. As a Security Administrator at a San Francisco-based IT MSP, I've hardened endpoints across dozens of organizations — law firms, investment firms, and technology businesses — giving me broad exposure to diverse threat models and compliance requirements across Mac, Windows, and Linux environments.

I take a risk-based approach to security: understanding how real adversaries operate, modeling threats against our specific environment, and prioritizing controls that address the highest-impact gaps rather than applying blanket policies. I'm deeply engaged in the security community through BSidesSF, Defcon, and leading the Defcon 415 Group, which keeps me close to evolving attacker tradecraft and emerging threats — including the rapidly changing genAI threat landscape.

I thrive on autonomous ownership of open-ended problems, driving work from concept through implementation. I speak the language of both engineering and business, translating technical risk into clear trade-off decisions for stakeholders. I build systems that leave things better than I found them — whether that's a host hardening standard, a vulnerability management cadence, or a documented incident response process.

I'm seeking an endpoint security role where I can apply my deep hands-on experience with host hardening, vulnerability management, MDM, EDR, and cross-functional collaboration to protect a workforce at scale.


Skills:

Endpoint Security & Hardening:
- Host hardening configuration and deployment across Mac, Windows, and Linux using Intune, Jamf, Jumpcloud, and Group Policy
- Attack surface reduction: ASR rules, PowerShell constraints, application control, privilege restriction
- Configuration drift identification and remediation against security baselines

Vulnerability & Threat Management:
- Patch and vulnerability management strategy: prioritization by exploitability, asset criticality, and threat intelligence
- EDR telemetry analysis to detect vulnerable configurations and validate patch efficacy
- Threat modeling to right-size controls and inform prioritization decisions

Identity & Access Security:
- Azure AD / Entra ID architecture: hybrid migrations, MFA/SSO deployment, conditional access policy design
- IAM operations: AD, LDAP, group policy, role-based access control, account lifecycle automation

Incident Response & Threat Intelligence:
- Phishing, BEC, and malware IR: containment, forensic analysis, control implementation
- Automated response scripting for compromised accounts and employee offboarding via AAD/Intune and SSO APIs
- OSINT and threat intelligence gathering to track evolving attacker TTPs

Communication & Risk Translation:
- Translate technical security risks into business-impact language for stakeholder decision-making
- Security awareness program design: policy authoring, training delivery, phishing simulation campaigns
- Process documentation, playbook creation, and engineer mentoring

Self-direction & Autonomy:
- Drive initiatives from concept through implementation with minimal guidance
- Navigate ambiguity by decomposing strategic goals into actionable project plans
- Use metrics and measurement to drive decisions and validate control effectiveness


Experienced With:

Endpoint & MDM:
Intune, Jamf, Jumpcloud, Group Policy, EDR platforms, BYOD policy frameworks

Identity & Directory:
Active Directory, Azure AD / Entra ID, LDAP, MFA/SSO providers, Okta

Operating Systems:
macOS, Windows, Linux, iOS, Android — security maintenance and troubleshooting across all tiers

Cloud & SaaS:
Azure, AWS, O365, GSuite, Cloudflare, Salesforce, Slack

Network Security:
Meraki, SonicWall, PfSense, Ubiquiti, DNS management, IDS/IPS, Nessus, vulnerability scanning, firewall policy design

Security Operations:
Phishing defense, malware remediation, BEC response, fraud detection, threat intelligence, threat hunting, regulatory compliance

Scripting & Automation:
PowerShell, AAD/Intune Graph APIs, SSO provider APIs — automated incident response and account lifecycle actions

// Work History:


October 2019 – Present: CONFIDENTIAL_SF_BASED_MSP, San Francisco, CA

Senior Information Technology Consultant — Security Administrator
Endpoint security engineer serving multiple organizations (law firms, investment firms, non-profits, technology businesses) in a cross-functional role spanning endpoint hardening, vulnerability management, identity security, and incident response. Drive security outcomes through a risk-based approach — translating technical threats into prioritized remediation plans aligned with each client's business context and risk tolerance.

Endpoint Security & Host Hardening:
- Designed and deployed host hardening configurations across Mac, Windows, and Linux endpoints using Intune, Jamf, Jumpcloud, Group Policy, and Azure AD conditional access — reducing attack surface while maintaining operational usability
- Implemented threat surface reduction policies via domain-wide Group Policy, including ASR rules, PowerShell constraints, and application control policies
- Led Azure AD / Entra ID migrations from hybrid domains, deploying MFA/SSO across multiple identity providers to strengthen authentication posture
- Audited client environments regularly, identifying configuration drift and remediating against established security baselines

Vulnerability Management & Patching:
- Developed and executed patch management strategies prioritizing vulnerabilities by exploitability, asset criticality, and threat intelligence context
- Triaged and remediated OS and application-level vulnerabilities across heterogeneous endpoint fleets
- Leveraged EDR telemetry to identify vulnerable configurations and validate patch efficacy post-deployment

Incident Response & Threat Intelligence:
- Led IR for phishing, BEC, and malware incidents — containing threats, performing forensic analysis, and implementing controls to prevent recurrence
- Scripted automated response actions for employee departure and compromised accounts using AAD/Intune MDM and SSO provider APIs
- Tracked evolving attacker TTPs through community engagement (BSidesSF, Defcon, 'Infosec Twitter') and applied threat intelligence to prioritize endpoint defense investments

Cross-Functional Delivery & Risk Communication:
- Authored security policies, playbooks, and training materials; delivered executive and user security awareness training
- Mentored engineers on endpoint security tooling, IR procedures, and secure configuration practices
- Collaborated with client leadership to translate technical risk findings into business-impact language, enabling informed trade-off decisions
- Used metrics (patch cadence, Mean-Time-to-Remediate, phishing susceptibility rates) to measure control effectiveness and drive continuous improvement


March 2019 – August 2019: Huneeus Vintners, Napa, CA

Information Security Contractor — Desktop Security Engineer
Engaged to assess cybersecurity posture, identify gaps, and deploy prioritized security controls across the organization's endpoint and identity landscape within a fixed-term engagement.

Endpoint Security & Hardening:
- Deployed domain-wide Group Policy objects for attack surface reduction, including application control and privilege restriction
- Implemented Azure AD Connect to enable MFA and MDM enrollment, strengthening authentication and device compliance
- Enforced stronger password complexity and account security policies across the domain

Identity & Access Controls:
- Configured Azure AD / Entra ID for hybrid identity with MFA, securing remote and on-premises access
- Scripted automated employee departure and compromised account remediation actions for AD and MSOL

Security Awareness & Process:
- Authored user security policies and training materials to reduce phishing and social engineering risk
- Documented support processes and incident response procedures to improve team consistency and onboarding


September 2016– February 2019: Huneeus Vintners, Napa, CA

Executive Transport Security Contractor
IT Consulting (tech support, home network administration and design)
Executive Transport
Executive Security
Transportation Logistics


May 2003–Present: EC Development, San Francisco, CA

Owner-Systems Administrator
IT System Administration Consulting (tech support, network administration, network design)
Information Security Research
Executive Transport
Transportation Logistics and Policy Planning
Real Estate Investment Consulting

This is my personal consultancy. I have been doing contract work for companies, individuals and non-profit organizations since 2003, and most of my work experience listed here has been that contracted work.


October 2015 – August 2016: Piggyback Transit Technologies, San Francisco, CA

Director of Product Development
Administered Beta-Test Program
Directed development of iOS and Android apps for taxi drivers
Software testing
UX/UI development


Work history 1997–2015 available on request.

// Cranium Contents:


Interests and Studies:

Information Security, Digital Privacy, Information Technologies, Hacking, Defcon, BSides, Threat Intelligence, Open Source Software, Cloud Architecture, Human Systems, Human Rights, Geography/Mapping, Transportation Policy and Planning, Operating Systems, Penetration Testing, Astronomy/Cosmology, Aviation and Motorcycling.


San Francisco, CA | 415-300-0810 | forhire@mrjhnsn.com | mrjhnsn.com