Dominick Napodano III
Senior Infrastructure Engineer | Azure · Identity · EUC · Automation
# Profile
Senior infrastructure engineer who designs, modernizes, and owns Microsoft-centered hybrid environments across Azure, identity, EUC, networking, endpoint management, and automation.
I transform unstable, manual operations into secure, standardized platforms with documented operating models and measurable gains in reliability, deployment speed, and administrator efficiency.
focused_on: infrastructure engineering · Azure engineering · platform modernization · identity · automation
# Selected Engineering Outcomes
Independently architected and delivered a greenfield Azure-hosted Parallels RAS platform in three months, replacing an unstable Citrix environment and supporting approximately 120 users with 90 to 105 concurrent sessions.
Designed the Azure virtual network, NSGs, route tables, VNet peering, site-to-site VPN connectivity, Azure Files and FSLogix integration, Entra SSO, MFA, and Conditional Access. Built six Windows Server 2022 session hosts and two redundant broker and Secure Client Gateway servers, automated certificate renewals and authentication changes across approximately 400 endpoints, standardized the image lifecycle and runbooks, and reduced monthly maintenance from as much as 2.5 hours to 45 to 60 minutes.
Engineered and continue to operate Ansible patch orchestration for 40 Windows and two Linux servers using Ansible Vault, WinRM, the Windows Update API, Linux APT, controlled batches, reboot validation, rescanning, retries, and per-server reporting.
Reduced monthly administrator effort from approximately 4 to 5 hours to approximately one hour, saving about 48 hours annually. The workflow has completed at least 24 successful production cycles since 2022 without causing an outage.
Reengineered a Microsoft Deployment Toolkit process used for more than 1,000 Windows 10 endpoint deployments across five hardware models, replacing disconnected scripts with selectable task sequences, monthly WIM servicing, model-specific driver injection, automated naming and domain joining, Microsoft Entra hybrid join, Intune enrollment, and documented operating procedures.
Engineered capacity for batches of up to 50 endpoints, with one technician typically supervising approximately 10 concurrent builds. Reduced deployment time from approximately three hours to 40 minutes and saved more than 650 technician hours across the first 1,000 deployments.
# Platform Engineering Scope
- Design and operate EUC platforms across Azure Virtual Desktop, Citrix DaaS, Parallels RAS, RDS, FSLogix, session hosts, profiles, and published applications.
- Architect Azure networking and hybrid connectivity using VNets, NSGs, routing, VPNs, Bastion, gateways, segmentation, and secure administrative access.
- Engineer identity and secure-access patterns across Microsoft Entra ID, Enterprise Apps, SSO, Conditional Access, MFA, and hybrid Active Directory environments.
- Standardize directory, endpoint, and productivity platforms across Active Directory, Group Policy, Microsoft 365, Exchange, Intune, SCCM, KACE, and RMM/MDM tooling.
- Automate patching, provisioning, session-host preparation, reporting, validation, and recurring operations with PowerShell and Ansible.
- Establish monitoring, backup validation, maintenance schedules, operating procedures, and lifecycle practices that make platforms reliable and supportable.
# Architecture & Platform Ownership
Own the architecture and lifecycle of an Azure-hosted Parallels RAS platform, including networking, identity, profile storage, image management, capacity, maintenance, and operational procedures.
Design and deliver migration paths across Citrix, Azure Virtual Desktop, and Parallels RAS while preserving user access, application delivery, profiles, and supportability.
Engineer Microsoft Entra Enterprise Apps, SSO integrations, Conditional Access, MFA, hybrid identity, and secure application-access patterns.
Standardize Active Directory, Group Policy, Microsoft 365, Intune, SCCM, KACE, RMM/MDM tooling, deployment workflows, and endpoint lifecycle practices.
Define monitoring, backup validation, patch schedules, maintenance windows, security controls, documentation, and operating procedures for long-term platform health.
Build PowerShell and Ansible workflows for patch orchestration, provisioning, session-host preparation, validation, reporting, and repeatable platform operations.
# Engineering Principles
Build platforms with clear paths for maintenance, upgrades, rollback, documentation, and eventual replacement.
Turn predictable operations into tested workflows with validation, reporting, and controlled failure handling.
Reduce technical debt through consistent patterns, baselines, ownership boundaries, and operating procedures.
Integrate identity, least privilege, MFA, access controls, and operational usability into the platform architecture.
# Experience
Senior Network Analyst
ISS Solutions | Dec 2018 - Present
- Architect, implement, and own Microsoft-centered hybrid infrastructure across Azure, Microsoft Entra ID, Active Directory, Microsoft 365, Windows Server, EUC, networking, endpoint management, and security.
- Lead platform modernization from technical discovery and architecture through migration, production cutover, documentation, lifecycle management, and ongoing ownership, coordinating technical decisions and change windows directly with IT leadership.
- Automate repeatable infrastructure operations with PowerShell and Ansible to reduce manual effort, improve consistency, and focus administrator time on higher-value engineering; a recent identity workflow corrected approximately 50 terminated accounts left visible in Exchange address lists and now enforces compliance daily.
- Establish maintenance schedules, platform monitoring, backup validation, image standards, operating procedures, and runbooks that improve reliability and reduce technical debt.
Systems Administrator
The Kirlin Group | Aug 2015 - Dec 2018
- Provisioned, secured, monitored, patched, and maintained Windows servers, infrastructure services, and remote-access platforms in a full-time remote operations role.
- Maintained operational reliability by validating backups and system health, investigating security events, and implementing infrastructure improvements and administrative standards.
Help Desk Administrator
The Kirlin Group | Oct 2013 - Aug 2015
- Supported more than 1,400 employees across Microsoft 365, Active Directory, Group Policy, endpoint deployment, mobile devices, onboarding, monitoring, and backup operations.
- Managed KACE patching, software packaging, and operating-system deployment while contributing to an Office 365 email migration and enterprise device rollout.
Information Technology Administrator
Capacity LLC | Mar 2010 - Feb 2013
- Supported infrastructure across multiple warehouses and remote offices, including switching, server rooms, VoIP systems, endpoint fleets, and administrative scripts that reduced recurring manual work.
# Skills
# Education
DeVry University | North Brunswick, NJ | 2006 - 2010
# Certifications
Microsoft Azure Administrator
Valid through 2027 · verify credential
Microsoft Azure Virtual Desktop Specialty
Valid through 2027 · verify credential
CompTIA CySA+
Valid through 2027 · verify credential
CompTIA Network+
Valid through 2027 · verify credential