Jeffrey Cordova

Security-Focused Systems & Endpoint Professional

Profile

Security-focused systems and endpoint professional with 9+ years of experience across technical support, platform operations, systems administration, and large endpoint environments, including nearly eight years in public-sector IT. Hands-on background spans multi-platform endpoint management, delegated identity and access work, security-sensitive investigations, SentinelOne agent deployment, Windows compliance remediation, change testing, technical documentation, and escalation with enterprise security and infrastructure teams. Independent work includes an open-source credential-handling tool and a versioned AI interaction engineering environment, with emphasis on threat modeling, automated testing, source handling, human review, and validation.

Experience

School-Based Computer Technician II

Aug 2021 - Dec 2025
Clark County School District - Spring Valley High School • Las Vegas, NV

Primary site-level technology professional for a public high school supporting approximately 2,800 students, 150 staff, 100 classrooms, and a 6,000+ endpoint and instructional-technology environment. Initially provided sole-site coverage and later served as the informal technical lead of a three-person site team. Transferred to Spring Valley as a Computer Technician I in August 2021 and was promoted to School-Based Computer Technician II in July 2022.

  • Provisioned, configured, deployed, and maintained Windows, macOS, ChromeOS, and iPadOS devices in a 6,000+ endpoint environment using Microsoft Intune, MDT, Active Directory, Google Admin Console, GoGuardian, and related district systems.
  • Packaged several applications, created or modified Microsoft Intune deployment groups, assigned centrally approved applications, and verified installation and configuration results; tenant-level publication remained with central IT.
  • Standardized reimaged Windows systems with required Windows Registry and Local Group Policy settings, then verified configuration before returning devices to service. Used CCSD internal Windows compliance reporting to identify noncompliant endpoints and prioritize updates, reimaging, and configuration fixes, helping maintain approximately 95% site compliance.
  • Planned and tested endpoint software and configuration changes, using pilot devices or groups when practical before broader deployment. Adjusted or reversed changes when results did not meet operational requirements.
  • Deployed SentinelOne endpoint agents to managed iMacs and MacBooks during the district rollout; console, policy, alert, and response administration remained with centralized district security personnel.
  • Investigated security-sensitive endpoint and account issues using Windows Event Viewer, macOS unified logs, Active Directory sign-in information, district lookup tools, and GoGuardian device or user activity.
  • During security-sensitive incidents, reset credentials, disabled accounts, and restricted devices, sign-ins, applications, or browsers within delegated site authority; documented findings and escalated issues to Enterprise Security, School Police, Networking, Telecom, administrators, or other district teams as needed.
  • Advised administrators and staff on technical feasibility, implementation, and privacy-sensitive information handling within district policy. Maintained procedures, checklists, inventory, audit, deployment, licensing, and other operational records.

Computer Technician I

Mar 2018 - Aug 2021
Clark County School District - Brown Academy of International Studies • Las Vegas, NV

Sole on-site technology professional for a 1,100-student middle school, rebuilding incomplete documentation, inventory, configurations, and support practices while maintaining daily technology support.

  • Supported Windows, macOS, ChromeOS, Google Workspace, Google Admin Console, classroom technology, CA Service Desk Manager, inventory, and other campus technology services.
  • Created and maintained site-specific Windows deployment images from a district-approved base image, adding approved applications and configurations for repeatable workstation deployment and reimaging.
  • Reconstructed undocumented device locations, configurations, dependencies, and local workflows and standardized recurring setup, documentation, ticketing, and inventory practices.
  • Supported growth of the Chromebook fleet from approximately 350 to more than 1,400 devices while standardizing deployment, assignment, refresh, and support practices.
  • Troubleshot endpoint-side TCP/IP, DNS, DHCP, static-IP, VPN, printer, and scan-to-email issues and escalated likely infrastructure problems to the appropriate centralized teams.
  • Served as the site technical liaison for a City of Henderson grant-funded network modernization project, providing information on device density, wireless coverage, instructional needs, and site constraints.

Customer Service Representative | Developer Support Assignment — Data Platform Integrations

May 2016 - Aug 2017
MZ, Inc. • Las Vegas, NV

Supported external developers adopting an internal data platform, troubleshooting high-volume data streams and serving as a technical bridge among developers, Tier-1 support, and internal engineering.

  • Reviewed high-volume data submissions for structure, correctness, data quality, access, operational viability, and platform constraints.
  • Troubleshot integration, configuration, workflow, and access issues; turned ambiguous developer reports into reproducible findings and clear engineering escalations.
  • Trained six Tier-1 support agents on platform review, troubleshooting, documentation, and escalation criteria.

Projects

Built an open-source POSIX shell security tool and continue to maintain it. The wrappers preserve normal GitHub and GitLab CLI use while keeping wrapper-managed authentication state in a GPG-encrypted pass store with defined credential ownership and trust boundaries.

  • Implemented provider-specific authentication handling, validation, private temporary-state handling, conditional credential writeback, signal recovery, cleanup, and automated tests.
  • Documented the threat model, security assumptions, trust boundaries, failure behavior, architecture decisions, maintenance procedures, and release process.
  • Developed behavioral and installation tests across Dash, Bash POSIX mode, and BusyBox ash, covering regression, disclosure prevention, and failure handling.

AI_Interaction_Engineering

Aug 2026

Completed v1.0.0 of a vendor-neutral engineering environment for designing and governing AI-assisted work systems, including prompts, instructions, context configurations, agent and workflow designs, and evaluations. The system reconstructs task context from accepted sources and work products rather than temporary model context, and changes are adopted only after explicit acceptance.

  • Defined 26 requirements and eight architecture rules covering information protection, untrusted content, external tools and dependencies, authorization for consequential actions, traceability, safe failure and incident handling, continuity and recovery, and evaluation.
  • Separated source-backed information from interpretation and defined verification, empirical evaluation, acceptance, version state, and deployment readiness as separate checkpoints.
  • Produced the versioned v1.0.0 package with an installation manifest, SHA-256 file identities, and a curated external-reference register informed by NIST AI RMF, NIST’s Generative AI Profile, NIST CSF 2.0, NIST incident-response and zero-trust guidance, and OWASP guidance.

Education

Undergraduate coursework in Mathematics — 42 semester credits completed

College of Southern Nevada

Skills

Security Operations & Investigation

Endpoint & Account Investigation • Windows & macOS Log Review • SentinelOne Agent Deployment • Delegated Account & Device Containment • Secure Configuration • Windows Endpoint Compliance & Remediation • Identity & Access Operations • Security Control Testing & Validation • Technical Incident Escalation

Endpoint, Identity & Systems Administration

Windows • macOS • Linux • ChromeOS • iPadOS • Microsoft Intune • Microsoft Deployment Toolkit (MDT) • Active Directory • Google Admin Console • GoGuardian • Windows Imaging & Provisioning • Windows Registry • Local Group Policy • CA Service Desk Manager

Change, Testing & Automation

Change Planning & Validation • Pilot & Staged Deployment Testing • Audit & Inventory Support • Technical Documentation • Root-Cause Analysis • POSIX Shell • Git & GitHub Actions • Test Automation • Threat Modeling • NIST-Informed AI System Design • AI-Assisted Technical Research & Review