Currently leading the vCTO practice at Abacus Group as a player/coach — leading a team of 5 senior engineers while owning the assessment and advisory relationship for a portfolio of financial services clients representing $70B+ in combined AUM and $3M+ in client ARR. I built the Python-based reporting engine the practice runs on, deploy it directly with clients, and set the assessment methodology every engineer follows. CISSP · CISM.
"The best IT and security programs start with clear goals and the discipline to work through ambiguity to get there."

Fully automated PowerShell-based collection and scoring pipeline covering 16 assessment modules across Entra ID, Exchange Online, SharePoint, Defender, and AI Tool Discovery. Produces structured output consumed directly by Power BI for client reporting.
Python-based reporting engine (~8,600 lines, 161 functions) that reconciles data across five independent sources — RMM inventory, on-prem AD, endpoint protection, file-server permissions, and M365/Entra — into a single self-contained HTML report with live filtering and drill-down. Replaced the practice's earlier Power BI and desktop-app tooling.
Power BI dashboard on Varonis exports providing structured permission visibility across NTFS ACLs and SharePoint sites. Features disconnected slicer patterns for reviewer-driven filtering and exception tracking.
Compliance architecture for a financial services client deploying Claude Enterprise. Maps Web/Desktop, Cowork, and Direct API paths against device management, Conditional Access, and compliance capture — identifying gaps and required controls for each path.
Power BI reporting layer on Auvik network monitoring data — surfacing uptime, alert volume, bandwidth, and critical device status across sites and endpoints. Tied directly to MBR/QBR reporting cadence.
Technology advisory for Federally Qualified Health Centers — covering HIPAA SRAs, full infrastructure modernization (SD-WAN, Meraki, HCI), M365 and Azure migrations, EHR transitions, and multi-year IT budgets in the $500K–$1M+ range.
Built and operationalized a cybersecurity practice framework at BlueNovo grounded in NIST CSF 2.0 — covering all six functions and mapping 18 controls. SmartSheet-based Security Assessment Plan deployed across 10+ healthcare clients with a portfolio dashboard.
You put in the work, fixed the obvious issues, tightened controls, and suddenly the environment behaves the way it always could. That's a win — but it's also when your value proposition has to change. On showing value after the chaos is gone.
NIST, ISO, and CIS aren't out of reach for smaller organizations. Most teams are already patching, backing up, running MFA, and managing EDR — they just don't think of it in control numbers.
AI is great at aggregating and connecting data. End users are notoriously bad at providing it. "It just doesn't work" isn't a ticket — it's a guess. The next improvement in support isn't automation, it's better intake.
Tickets closed, MTTR, CSAT, uptime — the numbers tell you what changed, but connecting the dots takes context and judgment. A drop in ticket volume could mean users are happier, or it could mean they've given up.
Diversification reduces single-vendor exposure — but every tool you add creates new pathways for incidents to travel. Before expanding your stack, understand the connections you already have.
When a single provider touches auth, DNS, WAF, and CDN simultaneously, an outage isn't just an inconvenience — it's a design conversation. On concentration risk in modern infrastructure.
Building pipelines, automated assessments, and reporting infrastructure that surface real intelligence from raw operational data — replacing manual work with repeatable, scalable tooling.
Security program design from the ground up — risk assessment, control frameworks, policy development, and audit readiness — built to be operational, not just documented.
Deep expertise across the M365 stack — Intune, Entra ID, Purview, Defender — including zero-touch provisioning, conditional access design, and device compliance at scale.
NOC/SOC operations, ITSM process maturity, and service delivery across multi-client MSP and enterprise environments — with a focus on SLA discipline and team development.
IAM strategy across Active Directory, Entra ID, SSO, and PAM — including lifecycle management, MFA rollouts, role-based access, and Zero Trust architecture.
Azure and AWS migrations, SaaS and hybrid deployments, DR/BCP design, and infrastructure modernization — including 20+ M365 and Azure migrations across healthcare and financial services clients.
IT and security programs succeed when they're built to scale — not just to pass an audit.
I manage the vCTO practice at Abacus Group, a financial services MSP, as a player/coach leading a team of 5 senior engineers. I own the assessment and advisory relationship for a portfolio of financial services clients with $70B+ in combined assets under management and $3M+ in client ARR. My work sits at the intersection of technical delivery, practice automation, and client-facing security leadership — building the tooling and frameworks that let a team deliver consistent, credible advisory at scale.
Before Abacus, I spent eleven years at BlueNovo / Medicus IT rising through four roles from Senior IT Consultant to VP, IT — running NOC and Help Desk operations with manager-level direct reports, driving M365 and Azure migrations for 20+ clients, and scoping $3M+ in signed technology remediation engagements across a healthcare MSP/MSSP environment. I also led the integration workstream following the Medicus IT acquisition of BlueNovo.
I hold the CISSP and CISM and bring a practitioner's perspective to every engagement. I actively use AI tooling across assessment development, reporting, and client advisory work, and I'm genuinely interested in how automation and AI change what's possible for an IT team — and building toward it.
Open to Director and VP-level conversations in IT leadership, security, and operations — across enterprise, MSP, financial services, and healthcare environments.

"Jason was not only technically skilled but also a great communicator who made complex problems understandable and worked collaboratively with teams across the organization. I highly recommend Jason for any organization looking for a capable, dependable, and forward-thinking IT professional."
"Jason is a go-to for technical knowledge and a strong people leader. His ability to distill complex technical information into clear, understandable language makes him an effective communicator with both internal and external stakeholders."