Amir Khodakarami

Endpoint Security Engineer

  • Vulnerability Management
  • Host Hardening
  • Mac / Windows / Linux
6,500+ endpoints Windows, macOS, Linux
98%+ patch compliance sustained, not a peak
5,000+ findings cleared standing backlog to steady state
60% less manual remediation via Graph API workflows

Summary

Endpoint security engineer working across Mac, Windows, and Linux fleets at enterprise scale. At NVR I expanded vulnerability scanning from on-prem-only Tenable to Tenable Cloud, then designed the automation program that took a standing backlog of 5,000+ open findings down to a steady state holding 98%+ patch compliance across 6,500+ devices. The mechanism was a library of Ivanti Neurons bots enforcing configuration uniformity — killing whole classes of finding at the source rather than re-remediating the same ones every cycle. I threat-model systems before they enter the environment, evaluate CVEs in a sandbox against our own configuration rather than trusting vendor severity, and hunt embedded dependencies across the software estate when something like Log4Shell lands. I own the full loop: find the exposure, decide what matters, write the fix when no vendor patch exists, and land it without taking the business offline.

Capabilities

Vulnerability Management

  • Tenable on-prem and Cloud
  • scan policy design
  • CrowdStrike EDR
  • sandbox CVE impact evaluation
  • risk-ranked triage
  • remediation verification

Endpoint Management

  • JAMF Pro (certified)
  • Microsoft Intune
  • SCCM / MECM
  • Ivanti Neurons
  • Apple Business Manager
  • Windows Autopilot
  • MDT

Host Hardening

  • CIS Benchmarks — Mac, Windows, Linux
  • Intune Settings Catalog
  • Group Policy
  • macOS configuration profiles
  • NIST framework alignment

Scripting & Automation

  • PowerShell (advanced)
  • Bash
  • Microsoft Graph API
  • Terraform
  • Ansible
  • self-healing workflows

Security Design

  • Threat modeling
  • least-privilege architecture
  • control right-sizing
  • identity-centric access design
  • embedded dependency hunting
  • vendor escalation

Identity & Access

  • Entra ID (Azure AD)
  • Conditional Access
  • zero-trust enforcement
  • Okta integration
  • JAMF / Intune co-management

Infrastructure

  • VMware vSphere
  • Nutanix HCI
  • VDI at scale
  • Proxmox
  • Ceph
  • ServiceNow
  • Active Directory

GenAI

  • Microsoft 365 Copilot production deployment
  • Entra ID prerequisites
  • data governance for AI adoption
  • GenAI-assisted scripting

Experience

Senior Systems Engineer — Acting Lead, Endpoint Engineering

NVR, Inc. Reston, VA

February 2021 — Present

Vulnerability Identification & Dependency Hunting

  • Own Tenable as the primary vulnerability identification platform — led onboarding of Tenable Cloud alongside an existing on-prem-only deployment, materially expanding scan surface coverage and finding accuracy.
  • Design and tune scan policies across a mixed Windows, macOS, and Linux fleet, balancing scan depth against impact on production and manufacturing systems that cannot tolerate disruption.
  • Separate real exposure from scan noise, ranking findings by severity, exploitability, asset criticality, and fleet spread — then translate that into a remediation queue the business can act on.
  • Evaluate significant CVEs in an isolated sandbox against our own configuration rather than trusting vendor severity, reproducing published proof-of-concept code where warranted.
  • Ran fleet-wide dependency hunts for Log4Shell and embedded-Chromium exposure, inventorying the desktop estate for applications bundling the affected components internally rather than waiting on vendor advisories that under-report them.
  • Escalated directly to the vendors shipping those components as prerequisites and drove them to issue remediated builds — closing exposure we could not patch ourselves and that scanners alone would never have surfaced.
  • Re-scan after every deployment to verify fixes landed, catching cases where a patch reported success without remediating the underlying finding.

Remediation at Scale

  • Took a standing backlog of 5,000+ open vulnerability findings down to a sustained 98%+ patch compliance posture across 6,500+ endpoints — the result of an automation program I designed, and it has held rather than regressing.
  • Root-caused that backlog to configuration inconsistency — endpoints drifting into non-standard states generated findings faster than manual patching could close them. Built automation enforcing uniformity, eliminating whole classes of vulnerability at the source.
  • Built an extensive library of Ivanti Neurons bots that push fixes and configuration corrections to thousands of endpoints in a single action rather than device by device, and that self-heal drift autonomously — the mechanism that makes this scale sustainable.
  • Write custom PowerShell and Bash remediation scripts where no vendor patch exists or would break a dependent system — registry hardening, service disablement, permission corrections — deployed via Intune, SCCM, and Ivanti.
  • Built compliance and remediation workflows on PowerShell, Bash, and Microsoft Graph API, cutting manual remediation effort 60% and shortening the window between disclosure and fleet-wide fix.
  • Coordinate with software and equipment vendors across a mixed fleet that includes manufacturing floor systems, validating patch compatibility in staging so security fixes never take production offline.

Host Hardening & Access Control

  • Designed and deployed Windows Security Baselines through Intune Settings Catalog, Group Policy, and MDT task sequences, enforcing CIS hardening across the managed fleet.
  • Integrated Intune with Entra ID Conditional Access so device compliance state gates access to corporate resources automatically — zero-trust enforcement aligned to CIS and NIST.

Security Design & Threat Modeling

  • Threat-model every application and environment before it enters the enterprise — mapping identity and access paths first, then designing to minimum necessary privilege.
  • Size controls to actual exposure rather than applying everything uniformly, and treat identity as the primary control surface — over-provisioned access is the attack path that matters most in a workforce environment, and it is cheaper to design out than to detect later.

Ownership & Cross-functional Work

  • Function as the hands-on security execution layer for the endpoint estate — the security org sets requirements and monitors posture; endpoint engineering builds, tests, and deploys the controls that close findings.
  • Translate technical risk into operational impact for business stakeholders and equipment owners, so patching trade-offs get decided on business terms rather than escalated as blockers.

GenAI Adoption

  • Lead enterprise deployment of Microsoft 365 Copilot — semantic indexing, Entra ID prerequisites, and data governance policy so AI adoption does not outrun the controls around it.

Endpoint Engineer — Linux / Windows / macOS

ATPCO Herndon, VA

July 2019 — January 2021

  • Administered JAMF Pro for 300+ macOS devices — configuration profiles, patch policies, and scoped deployments — alongside Apple Business Manager for zero-touch provisioning of hardened devices.
  • Ran SCCM (MECM) and Intune co-management for a mixed Windows, macOS, and Linux fleet, migrating legacy workloads to cloud-native management.
  • Integrated JAMF and Intune with Azure AD and Okta to automate onboarding, offboarding, and configuration enforcement from identity signals.
  • Hardened endpoints through Group Policy and migrated legacy settings into modern Intune policy; wrote PowerShell and Bash diagnostic and auto-repair scripts across all three operating systems.
  • Optimized VDI environments for 800+ remote users, maintaining login performance and application responsiveness.

IT Systems Specialist

Neustar, Inc. Sterling, VA

2017 — 2019

  • Managed Windows endpoint lifecycle with Intune and Ivanti Neurons, overseeing patch deployment and vulnerability remediation.
  • Automated administrative and configuration workflows through PowerShell, standardizing system builds and reducing manual error.

Homelab

The proving ground

Everything I deploy at work gets built and broken here first. It is a production-grade environment I run end to end — compute, storage, networking, identity, secrets, monitoring, and CI — which means I hit the failure modes on my own time instead of during a change window.

3 Proxmox nodes clustered, quorate, Ceph-backed
23 VMs & containers live guests under HA
46 service stacks 72 containers running
2 edge regions primary + mirrored failover

Compute & Storage

Three-node Proxmox VE cluster with Ceph distributed storage and shared CephFS, plus two Unraid servers for bulk and backup. HA failover across nodes; serial reboots gated on verified kernel/boot-id change rather than SSH reachability.

  • Proxmox VE
  • Ceph
  • CephFS
  • Unraid
  • HA

Edge & Networking

Public traffic terminates on a cloud VPS running Pangolin, tunnels in over WireGuard-based Newt agents, and lands on Traefik for routing and ACME certificates via DNS challenge. Segmented VLANs separate management, VM, and IoT traffic behind a UDM.

  • Pangolin
  • Newt
  • Traefik
  • VLAN segmentation
  • Cloudflare DNS-01

Identity & Secrets

Authentik provides SSO and forward-auth in front of internal services. OpenBao holds every stack secret in KV v2 — machine access via a read-only AppRole, human access via OIDC, auto-unseal on restart, and the initial root token revoked in favour of a documented break-glass path.

  • Authentik
  • OpenBao
  • OIDC
  • AppRole
  • forward-auth

Hardening Lessons

Trimmed Traefik from blanket trust of forwarded headers down to an explicit trusted-proxy list after proving a LAN client could forge X-Forwarded-For and poison downstream audit logs and brute-force reputation. Fixing it at the proxy corrected every backend at once — the same reasoning I apply to enterprise control placement.

  • X-Forwarded-For
  • trusted proxies
  • audit integrity
  • defence in depth

Automation & CI

Kestra and n8n orchestrate scheduled and event-driven jobs; Semaphore drives Ansible; Gitea hosts source and act-runner executes pipelines. Infrastructure and stack definitions live in git and deploy with secrets rendered at deploy time, never committed.

  • Kestra
  • n8n
  • Ansible
  • Semaphore
  • Gitea Actions
  • Terraform

Observability

Prometheus and Grafana for metrics, Uptime Kuma for external probes, node-exporter across hosts, PatchMon for patch state, and ntfy for alert delivery — so drift and outages surface before anyone notices them.

  • Prometheus
  • Grafana
  • Uptime Kuma
  • PatchMon
  • ntfy

Education & Certifications

A.S., Information Technology

Northern Virginia Community College · 2015

  • JAMF Certified Tech (CCT)
  • ITIL Foundations v4 — in progress