Professional Summary
Network and IT professional with 10 years of experience in enterprise and DoD environments spanning network engineering, systems administration, and infrastructure security. Supported 500+ workstations and 1,000+ endpoints, including classified SIPR/NIPR networks, with hands-on vulnerability remediation and adversary-simulation lab experience. Currently building a cloud/AI portfolio — AWS serverless architecture, Terraform IaC, and Anthropic Claude API applications — while pursuing AWS Solutions Architect Associate certification. Active Top Secret clearance.
Technical Skills
Professional Experience
- Studying for AWS Solutions Architect Associate (SAA-C03) certification, targeting August 2026, covering VPC design, IAM policy, high availability, and cost optimization.
- Built the AWS Cloud Resume Challenge (S3, CloudFront, Route 53, Lambda, DynamoDB, API Gateway, GitHub Actions CI/CD), live at paul-giff.com, including automated deployment on every commit.
- Rebuilt the same architecture as reusable Terraform modules to practice Infrastructure as Code and repeatable, version-controlled deployments.
- Built the Claude Task Agent, an autonomous Python agent using the Claude API with a tool registry (web search, file I/O, math evaluation) and session memory across multi-step reasoning loops.
- Built Interview Copilot, a real-time AI interview assistant integrating Deepgram speech-to-text with the Claude API, packaged as a standalone Windows .exe via PyInstaller and published on GitHub.
- Maintaining an active GitHub portfolio for both cloud/AI and DoD network engineering roles.
- Managed and maintained shipboard wireless networks across 4 vessels, supporting 40+ access points per ship and 100+ concurrent users in a maritime RF environment.
- Configured, hardened, and monitored Aruba wireless controllers/APs and EdgeConnect SD-WAN appliances, maintaining 99.9% uptime across all vessels.
- Designed and implemented 4-VLAN network segmentation to isolate operational, guest, and administrative traffic and reduce attack surface.
- Conducted 2 shipboard site surveys to plan AP placement, identify RF interference, and validate coverage before deployment.
- Troubleshot connectivity and performance issues in a challenging shipboard RF environment, coordinating with ship's crew and remote engineering support.
- Documented network configurations and change history to support handoff and future maintenance.
- Administered NIPR, SIPR, and ICP networks supporting classified DoD surveillance operations, ensuring continuous availability and compliance with DoD security standards.
- Managed 40 VMware ESXi virtual machines (20 NIPR / 20 SIPR), handling provisioning, patching, and resource allocation across both classification enclaves.
- Applied STIG hardening and supported RMF compliance activities to keep systems audit-ready and aligned with DoD cybersecurity requirements.
- Ran weekly ACAS/Tenable vulnerability scans and tracked remediation through POA&Ms, maintaining zero unresolved findings across all scan cycles.
- Monitored network and system health via Splunk, using dashboards and alerts to proactively identify and resolve issues before they impacted operations.
- Managed 30 user accounts across 10 security groups using role-based access control (RBAC), enforcing least-privilege access on classified networks.
- Troubleshot satellite (SATCOM) connectivity issues affecting shipboard data links, achieving a 30–60 minute average recovery time.
- Maintained IAVM compliance by tracking and applying required security patches and configuration changes on a recurring schedule.
- Operated and maintained TACLANE encryption devices to secure classified data in transit between NIPR and SIPR enclaves.
- Monitored 10,000+ systems and endpoints across a distributed network, using monitoring tools to detect and triage outages and performance issues.
- Resolved 10–20 tickets per week covering connectivity, hardware, and software issues, prioritizing based on operational impact.
- Performed patching and remediation across the monitored environment to maintain security posture and system stability.
- Authored standard operating procedures (SOPs) for recurring network operations tasks, improving consistency and onboarding for new team members.
- Provided on-site IT support for 500+ workstations and 1,000+ endpoints across NAS Oceana and Dam Neck under the Navy Marine Corps Intranet (NMCI) contract.
- Resolved 50–100 tickets per week spanning hardware failures, software issues, account access, and network connectivity for a high-volume DoD user base.
- Imaged and deployed 200+ systems as part of ongoing infrastructure refresh cycles, following DoD configuration and security baselines.
- Diagnosed and repaired desktop, laptop, and peripheral hardware issues, minimizing user downtime in a fast-paced operational environment.
- Served 7 years of active duty, supervising 3+ junior sailors and mentoring them on technical proficiency and military readiness standards.
- Delivered medical training to unit personnel, ensuring readiness for both routine and emergency medical response.
- Managed day-to-day administrative duties, including scheduling, documentation, and compliance reporting, in a high-tempo operational environment.
Live Infrastructure
This page is one of the projects below — a serverless static site with a real-time request counter. Here's how it's wired.
Technical Projects
AWS Cloud Resume Challenge
GitHub →Built and deployed a fully serverless personal site and resume API, live at paul-giff.com.
Cloud Resume Challenge — Terraform IaC Rebuild
GitHub →Rebuilt the Cloud Resume Challenge architecture as reusable Infrastructure as Code.
Claude Task Agent
GitHub →Built an autonomous agent with a tool registry (web search, file I/O, math evaluation) and session memory across multi-step reasoning loops.
Interview Copilot
Windows .exeBuilt a real-time AI interview assistant, packaged as a Windows .exe via PyInstaller and published on GitHub.
Hybrid Virtual Pentest Lab
Home LabBuilt a 5-VM, 4-subnet lab with a DMZ and an Active Directory domain (Windows Server 2022, Windows 10, Kali, Metasploitable 2) for adversary-simulation practice.
Education & Certifications
- CompTIA Security+
- CompTIA A+
- AWS Certified Solutions Architect – Associate (SAA-C03) — in progress, target August 2026