dominick@resume: ~/career
online

Dominick Napodano III

Senior Infrastructure Engineer | Azure · Identity · EUC · Automation

Fairless Hills, PA | dominicknapodano@gmail.com | linkedin.com/in/dominicknapodano | dnapodano.com
dominick@resume:~$ cat profile.md

# Profile

Senior infrastructure engineer who designs, modernizes, and owns Microsoft-centered hybrid environments across Azure, identity, EUC, networking, endpoint management, and automation.

I transform unstable, manual operations into secure, standardized platforms with documented operating models and measurable gains in reliability, deployment speed, and administrator efficiency.

focused_on: infrastructure engineering · Azure engineering · platform modernization · identity · automation

# Selected Engineering Outcomes

Azure Parallels RAS modernization

Independently architected and delivered a greenfield Azure-hosted Parallels RAS platform in three months, replacing an unstable Citrix environment and supporting approximately 120 users with 90 to 105 concurrent sessions.

Designed the Azure virtual network, NSGs, route tables, VNet peering, site-to-site VPN connectivity, Azure Files and FSLogix integration, Entra SSO, MFA, and Conditional Access. Built six Windows Server 2022 session hosts and two redundant broker and Secure Client Gateway servers, automated certificate renewals and authentication changes across approximately 400 endpoints, standardized the image lifecycle and runbooks, and reduced monthly maintenance from as much as 2.5 hours to 45 to 60 minutes.

Enterprise patch automation

Engineered and continue to operate Ansible patch orchestration for 40 Windows and two Linux servers using Ansible Vault, WinRM, the Windows Update API, Linux APT, controlled batches, reboot validation, rescanning, retries, and per-server reporting.

Reduced monthly administrator effort from approximately 4 to 5 hours to approximately one hour, saving about 48 hours annually. The workflow has completed at least 24 successful production cycles since 2022 without causing an outage.

Healthcare endpoint deployment modernization

Reengineered a Microsoft Deployment Toolkit process used for more than 1,000 Windows 10 endpoint deployments across five hardware models, replacing disconnected scripts with selectable task sequences, monthly WIM servicing, model-specific driver injection, automated naming and domain joining, Microsoft Entra hybrid join, Intune enrollment, and documented operating procedures.

Engineered capacity for batches of up to 50 endpoints, with one technician typically supervising approximately 10 concurrent builds. Reduced deployment time from approximately three hours to 40 minutes and saved more than 650 technician hours across the first 1,000 deployments.

# Platform Engineering Scope

  • Design and operate EUC platforms across Azure Virtual Desktop, Citrix DaaS, Parallels RAS, RDS, FSLogix, session hosts, profiles, and published applications.
  • Architect Azure networking and hybrid connectivity using VNets, NSGs, routing, VPNs, Bastion, gateways, segmentation, and secure administrative access.
  • Engineer identity and secure-access patterns across Microsoft Entra ID, Enterprise Apps, SSO, Conditional Access, MFA, and hybrid Active Directory environments.
  • Standardize directory, endpoint, and productivity platforms across Active Directory, Group Policy, Microsoft 365, Exchange, Intune, SCCM, KACE, and RMM/MDM tooling.
  • Automate patching, provisioning, session-host preparation, reporting, validation, and recurring operations with PowerShell and Ansible.
  • Establish monitoring, backup validation, maintenance schedules, operating procedures, and lifecycle practices that make platforms reliable and supportable.

# Architecture & Platform Ownership

Azure-hosted EUC platform ownership

Own the architecture and lifecycle of an Azure-hosted Parallels RAS platform, including networking, identity, profile storage, image management, capacity, maintenance, and operational procedures.

EUC modernization & migration

Design and deliver migration paths across Citrix, Azure Virtual Desktop, and Parallels RAS while preserving user access, application delivery, profiles, and supportability.

Identity & secure access

Engineer Microsoft Entra Enterprise Apps, SSO integrations, Conditional Access, MFA, hybrid identity, and secure application-access patterns.

Directory & endpoint engineering

Standardize Active Directory, Group Policy, Microsoft 365, Intune, SCCM, KACE, RMM/MDM tooling, deployment workflows, and endpoint lifecycle practices.

Reliability & lifecycle operations

Define monitoring, backup validation, patch schedules, maintenance windows, security controls, documentation, and operating procedures for long-term platform health.

Automation engineering

Build PowerShell and Ansible workflows for patch orchestration, provisioning, session-host preparation, validation, reporting, and repeatable platform operations.

# Engineering Principles

Design for the lifecycle

Build platforms with clear paths for maintenance, upgrades, rollback, documentation, and eventual replacement.

Automate the repeatable

Turn predictable operations into tested workflows with validation, reporting, and controlled failure handling.

Standardize before scaling

Reduce technical debt through consistent patterns, baselines, ownership boundaries, and operating procedures.

Secure by design

Integrate identity, least privilege, MFA, access controls, and operational usability into the platform architecture.

# Experience

Senior Network Analyst

ISS Solutions | Dec 2018 - Present

  • Architect, implement, and own Microsoft-centered hybrid infrastructure across Azure, Microsoft Entra ID, Active Directory, Microsoft 365, Windows Server, EUC, networking, endpoint management, and security.
  • Lead platform modernization from technical discovery and architecture through migration, production cutover, documentation, lifecycle management, and ongoing ownership, coordinating technical decisions and change windows directly with IT leadership.
  • Automate repeatable infrastructure operations with PowerShell and Ansible to reduce manual effort, improve consistency, and focus administrator time on higher-value engineering; a recent identity workflow corrected approximately 50 terminated accounts left visible in Exchange address lists and now enforces compliance daily.
  • Establish maintenance schedules, platform monitoring, backup validation, image standards, operating procedures, and runbooks that improve reliability and reduce technical debt.

Systems Administrator

The Kirlin Group | Aug 2015 - Dec 2018

  • Provisioned, secured, monitored, patched, and maintained Windows servers, infrastructure services, and remote-access platforms in a full-time remote operations role.
  • Maintained operational reliability by validating backups and system health, investigating security events, and implementing infrastructure improvements and administrative standards.

Help Desk Administrator

The Kirlin Group | Oct 2013 - Aug 2015

  • Supported more than 1,400 employees across Microsoft 365, Active Directory, Group Policy, endpoint deployment, mobile devices, onboarding, monitoring, and backup operations.
  • Managed KACE patching, software packaging, and operating-system deployment while contributing to an Office 365 email migration and enterprise device rollout.

Information Technology Administrator

Capacity LLC | Mar 2010 - Feb 2013

  • Supported infrastructure across multiple warehouses and remote offices, including switching, server rooms, VoIP systems, endpoint fleets, and administrative scripts that reduced recurring manual work.

# Skills

EUC & virtualization
Azure IaaS Azure Virtual Machines Azure Files Azure Virtual Desktop Citrix DaaS Parallels RAS Remote Desktop Services FSLogix Windows Server 2022
Cloud, identity & networking
Microsoft Entra ID Active Directory Group Policy / GPO Enterprise Apps / SSO Conditional Access Azure Networking VNets / NSGs Route Tables / VNet Peering Site-to-Site VPN Azure Firewall Azure Gateway TCP/IP / DNS / DHCP VLAN / LAN / WAN Cisco Meraki SonicWall
Microsoft 365 & endpoint engineering
Microsoft 365 Exchange Administration Intune SCCM KACE RMM / MDM Microsoft Deployment Toolkit Endpoint Deployment Application Packaging Image Lifecycle Monitoring Backup Operations
Automation & security
PowerShell Ansible Ansible Vault WinRM Windows Update Linux APT Patch Orchestration Runbooks Security Tooling CrowdStrike Rapid7 Zorus

# Education

Bachelor of Science in Networking & Communication Management

DeVry University | North Brunswick, NJ | 2006 - 2010

# Certifications

Microsoft Azure Administrator

Valid through 2027 · verify credential

Microsoft Azure Virtual Desktop Specialty

Valid through 2027 · verify credential

CompTIA CySA+

Valid through 2027 · verify credential

CompTIA Network+

Valid through 2027 · verify credential