← bertmedia.net

Sean Ciranni

ROLE
IT Analyst
LOCATION
Denver, Colorado
ORG
Highridge Medical
FOCUS
Hybrid Azure · Endpoint · Identity

Summary

IT Analyst administering hybrid Azure infrastructure — Entra ID, Intune, Autopilot, and Exchange Online — for a regulated medical device manufacturer. Resolves escalated Level 2–3 issues spanning identity, endpoint, and network layers. Outside of work, designs and operates a seven-node Linux infrastructure running 80+ containerized services across Docker and Kubernetes — network, identity, monitoring, and backup all built from bare metal. Completing a B.S. in Cybersecurity and Information Assurance; CompTIA Security+, A+, and ITIL v4.

Experience

IT Analyst

04/2026 – Present
Highridge Medical
  • Administer a hybrid Azure environment spanning Entra ID, Intune, Autopilot, and Microsoft 365, building and maintaining device compliance policies, configuration profiles, and enrollment profiles for organization-wide endpoint provisioning.
  • Manage day-to-day identity operations — security and dynamic group membership, license assignment, MFA configuration, and Exchange Online mailbox and mail-flow administration.
  • Administer Microsoft 365 collaboration workloads including Teams and SharePoint, handling provisioning, permissions, and access governance across sites and channels.
  • Review risky sign-in and risky user alerting through Rapid7 and Microsoft Defender, investigating identity anomalies and remediating or escalating them to my director.
  • Resolve escalated Level 2–3 tickets across hardware diagnostics, software deployment, and network access.
  • Support IT operations in a regulated medical device environment, maintaining compliance adherence while managing day-to-day infrastructure and endpoint configuration.

Personal Infrastructure Project

2022 – Present
bertlab · self-directed
  • Design and operate a seven-node Linux fleet (Ubuntu Server, Arch, Kali) running 80+ containerized services across Docker and a two-node Kubernetes cluster, administered entirely headless over SSH — systemd unit and timer authoring, kernel upgrades with one-shot bootloader rollback on a console-less host, and storage and thermal management.
  • Built the network from scratch: flat addressing with wired-primary routing, a WireGuard mesh with SSH authenticated by network ACL rather than static keys, and outbound-only tunnel ingress publishing services publicly with zero inbound ports open at the router. Default-deny firewalling on every host, redundant filtering DNS with automated sync, and IP address management.
  • Deployed and integrated the full service stack — a multi-stage automated media library pipeline, a chained SIEM, IDS, and network-monitoring stack, and single sign-on and secrets management spanning every service — sizing compute, storage, and network per service and mapping the dependencies between them.
  • Manage the fleet as code with Ansible — a version-controlled inventory that separates hosts safe to patch automatically from control nodes that must not be, plus playbooks for patching, SSH hardening, firewall rules, and read-only recon that writes its findings straight into the lab's documentation.
  • Run the lab to production standards: Prometheus, Grafana, and Loki observability across all hosts, a staggered and watchdog-verified backup chain with dead-man's-switch monitoring, and roughly 40 scheduled jobs deliberately placed on always-on hardware.
  • Run an anomaly-detection service over the fleet: every 30 minutes it scores metrics, log volume, and network traffic against each source's own learned baseline, catching the failures fixed thresholds miss — a host going quiet, a disk whose fill rate changed, an unusual combination of traffic — and staying silent otherwise.
  • Mirrors the identity, endpoint, monitoring, and infrastructure disciplines administered professionally — self-designed, self-funded, and documented as a versioned configuration repository.

Tier II Help Desk Technician

03/2025 – 05/2025
ITS LLC
  • Provided Tier II helpdesk support including application and hardware troubleshooting, network connectivity diagnostics, and account administration.
  • Managed and resolved tickets using BMC Remedy, including software distribution, documentation, and system and network status reporting.
  • Deployed and maintained government off-the-shelf software and hardware including servers, firewalls, Cisco switches, and multi-function printers.

IT Support Specialist

04/2024 – 03/2025
Strategic Solutions
  • Diagnosed and resolved technical issues reported by users, ensuring minimal disruption to daily operations.
  • Maintained and updated hardware components and software applications while managing network configurations, security settings, and access permissions.
  • Served as the direct technical contact for non-technical staff, documenting recurring fixes and translating resolutions into steps users could repeat independently.

IT Support Specialist → Senior Technician

10/2022 – 03/2024
Plateau GRP
  • Promoted to senior technician, acting as the escalation point for other technicians on complex hardware, software, and connectivity issues.
  • Refined existing support procedures and escalation paths, giving recurring issues a documented route instead of leaving each technician to re-diagnose them.
  • Developed and maintained IT documentation resources including troubleshooting guides and knowledge base articles, improving team efficiency and knowledge sharing.

Security Officer

04/2019 – 04/2022
SANMINA/SCI
  • Conducted site security inspections, identifying physical access and procedural gaps and reporting them for correction.
  • Prepared incident documentation and security reporting, responding quickly to perimeter and access-control alarms.
  • Ensured all personnel accessing sensitive information and restricted areas met stringent security and clearance requirements.

Health Care Specialist

10/2014 – 11/2016
United States Army
  • Conducted first aid and trauma training for soldiers pre-deployment and provided pre-hospital trauma care during training exercises.
  • Established and maintained remote field medical stations and upheld knowledge of basic pharmacology and field trauma care protocols.