Jevell Angelo Acebedo

✦ IT Systems Engineer · 15+ years experience ✦

Jevell Angelo
Acebedo

Endpoint, Identity & Security Operations

15+ years running enterprise IT for multi-site and regulated environments — endpoint fleets, identity and access management, network and endpoint security, and physical access control. Comfortable owning a system end to end, from architecture through automation.

LinkedIn GitHub Blog
scroll

About Me

I'm an IT Systems Engineer with 15+ years of experience running enterprise IT for multi-site and regulated environments — Windows and macOS endpoint fleets, identity and access management, network and endpoint security, and physical access control.

I'm comfortable owning a system end to end, from architecture through automation, and serving as the escalation point for the service desk team. I'm known for building solutions that are secure by design, not as an afterthought, and for closing skill gaps through hands-on practice before they become requirements on the job.

Based in the San Francisco Bay Area, serving multi-site environments across the region and beyond.

// Contact

linkedin jevellacebedo
location San Francisco Bay Area

Experience

Systems Administrator Lyntris (formerly Vitesse Systems)
2023 – Present·Newark, CA
  • Own Windows endpoint compliance using Microsoft Intune — conditional access policies, compliance baselines, and automated remediation — supplemented by PDQ Deploy and Group Policy for packaging and configuration enforcement
  • Administer identity and access for 450+ users across Active Directory, Entra ID, and Duo, including SSO integrations for Salesforce, VPN, Windows login, SecureMail, Smartsheet, and the employee training LMS
  • Led the Newark site's migration into a single consolidated Active Directory domain, down from four across the company — moving roughly 150 users and 200 endpoints with minimal downtime
  • Supported deployment of a UniFi-based access control and video surveillance system across the site, including networking, badge reader, and camera installation
  • Took over a stalled gate integration project under a CMMC 2.0 self-assessment deadline, with little handoff from the previous owner; worked directly with vendors and integrators to close it out, integrating three vehicle gate controllers with the UniFi access control platform — eliminating manual gate locking and confining vendor site access to staffed hours
  • Replaced non-compliant wireless access points with Cisco Meraki hardware to meet FIPS 140-2 requirements; the site was the first in the organization to reach wireless compliance
  • Built a proof-of-concept certificate renewal pipeline using a self-hosted acme-dns server to handle ACME DNS-01 challenges, removing the need to store DNS provider credentials on disk for critical mail relay services; currently moving from PoC into production
  • Deployed a virtualized Tenable Nessus appliance and rolled out agents across servers, workstations, and OT endpoints for vulnerability scanning
  • Manage a hyperconverged vSphere/vSAN compute cluster (VxRail) as the backbone of on-prem infrastructure across a multi-site environment
  • Deployed monitoring and enforced network access controls for OT communication in the machine shop environment
  • Participated in the company's CMMC 2.0 self-assessment process, including audit-style control walkthroughs with compliance consultants and tabletop exercises to pressure-test incident response scenarios
  • Serve as escalation point for complex issues across infrastructure and endpoint teams; participate in monthly cyber threat review meetings
IT Manager / IT Consultant — Part-Time, Freelance JAceIT (Self-Employed)
June 2025 – Present·Remote
  • Own infrastructure, security, and technology strategy for engineering-firm clients as a part-time IT Manager, including Proxmox virtualization, tiered backup strategy (local + offsite via Backblaze B2), and Microsoft 365 tenant administration
  • For client Radius Design LLC, designed and deployed a self-hosted secure remote access platform — NetBird (WireGuard-based Zero Trust mesh VPN), Traefik reverse proxy, and Keycloak SSO with separate internal and external identity realms — replacing an unreliable commercial VPN; automated wildcard TLS via Let's Encrypt DNS-01
  • Hardened the platform with a CrowdSec intrusion detection/prevention pipeline, locked down admin interfaces with IP allowlisting and Basic Auth, and built and tested a break-glass recovery procedure for the identity infrastructure
  • Diagnosed a multi-layered outbound email delivery failure — an SPF hard-fail plus a Microsoft 365 Defender content-filtering issue — via mail server logs, SPF/DMARC analysis, and M365 Message Trace; resolved through a DNS correction and targeted mail-flow policy changes
Computer Systems Engineer II Lawrence Berkeley National Laboratory
2019 – 2023·Berkeley, CA
  • Spearheaded the division's Jamf Pro deployment, building the MDM infrastructure, configuration standards, and onboarding/offboarding workflow from the ground up; the division became a model for the rollout across other divisions through Central IT
  • Implemented CIS baseline hardening controls on macOS ahead of it becoming a formal requirement
  • Automated Linux server and workstation deployment with Ansible and wrote onboarding/offboarding scripts that significantly cut repetitive admin work
  • Supported an AV infrastructure upgrade across multiple buildings division-wide, including deployment of Zoom-enabled Neat Bar video conferencing equipment; provided live IT/AV support during Zoom webinar broadcasts
Systems Administrator / Web Developer Bently Enterprises
2015 – 2019·San Francisco, CA
  • Designed and deployed a company-wide, cloud-hosted Jamf Pro environment covering the full macOS and iOS fleet — enrollment, configuration profiles, application deployment, and automated patch management
  • Managed corporate-owned iOS devices through Jamf, including zero-touch enrollment and app distribution via VPP
  • Built the company's physical access control monitoring system in-house instead of outsourcing it, saving roughly $25,000
  • Configured and operated livestream hardware to broadcast meetings between company sites
Computer Resource Specialist II UC Davis — College of Biological Sciences
2010 – 2015·Davis, CA
  • Administered Active Directory and managed hardware, OS, and network operations, including Windows updates via SCCM/WSUS; promoted from Level 1 to Level 2 based on demonstrated technical expertise

Selected Projects

Okta Identity Lab Self-Directed
2024 – Present
  • Built a full SCIM provisioning lifecycle in Okta: an HR system as source of truth, driving Okta group rules that automatically create, license, and deprovision Google Workspace accounts on hire, change, and termination
  • Integrated Okta with a self-hosted Active Directory domain via the Okta AD Agent, mirroring the same automated provisioning pattern used for the Google Workspace integration
  • Built and debugged a custom Okta Workflows integration pulling user data from a second HR system into Okta via scheduled API calls and bulk import — traced and fixed data-type mismatches, malformed JSON nesting, and a mislabeled output field using Okta's execution history and syslog exports
  • Wrote a Python/AWS Lambda function against the Okta API that flags inactive users and MFA enrollment gaps, exports findings to S3, and posts a summary to Slack

Self-directed project built to develop hands-on Okta depth; not production experience.

Self-Hosted Transactional Mail Infrastructure Self-Directed
2025
  • Deployed Postal (open-source mail delivery platform) via Docker Compose — web, SMTP, worker, and MariaDB services — behind Traefik v3, as a self-hosted alternative to a commercial transactional email relay
  • Automated wildcard TLS issuance via Let's Encrypt DNS-01 challenges against a self-hosted acme-dns instance; debugged DNS delegation, NS/glue record conflicts, and propagation failures across a multi-host ACME setup
  • Solved certificate sharing between Traefik and the mail server using traefik-certs-dumper with a post-hook script to auto-fix file permissions on every renewal
  • Configured SPF, DKIM, DMARC, and PTR records across multiple domains; diagnosed a Gmail spam-placement issue traced to a mismatched PTR record and resolved a stale Barracuda (BRBL) blacklist entry
  • Integrated CrowdSec for intrusion detection, and connected two independent applications as SMTP relay clients — troubleshooting a residential ISP blocking outbound port 25 and a separate cloud firewall's missing egress rule
  • Diagnosed Gmail's per-sender-identity spam reputation model and proactively migrated notification traffic to a dedicated subdomain to isolate a new sender's reputation from established business mail flow
Self-Hosted Portfolio + GitOps Deploy Pipeline Self-Directed
2026
  • Designed and built this site — hand-drawn aesthetic, dark/light theme toggle, fully responsive typography — deployed on a cloud-hosted VPS via Docker and Traefik, with automated wildcard TLS through Cloudflare DNS-01
  • Built a GitLab CI/CD pipeline using Vault-issued, short-lived credentials via JWT auth — the same zero-static-secret, least-privilege model used to secure production access at enterprise scale — with automated validation and a manual production gate before anything goes live
  • Modeled the release flow on staging-to-production change management: every push is staged, not live, with a Slack notification showing a diffstat and change preview before a human approves the deployment

Key Skills

Endpoint & MDM

Microsoft IntuneJamf Pro PDQ DeployPDQ Inventory Group PolicyAnsible SCCM / WSUS

Identity & Access Management

Active DirectoryEntra ID OktaDuo KeycloakFreeIPA SAML / SSOSCIM Passkeys

Security & Compliance

CrowdStrike FalconTenable Nessus CrowdSecPKI & Certificate Lifecycle ACME / Let's EncryptNIST 800-171 Rev 3 CMMC 2.0Physical Access Control

Networking

Cisco MerakiUbiquiti UniFi NetBird / WireGuardZero Trust Network Access 802.1XFIPS 140-2 VPN

Virtualization & Cloud

VMware vSphere / vSAN / VxRailProxmox Microsoft 365Google Workspace AWS LambdaAzure Ceph

Containerization & DevOps

DockerDocker Compose TraefikGit / GitHub

Scripting & Automation

PowerShellPython BashSQL

Education &
Certifications

Certification
CompTIA Security+ CE
CompTIA
Issued October 2022
Certificate
Cybersecurity Certificate
UC Berkeley Extension
2021 – 2022
Degree
BS, Mechanical Engineering
University of California, Davis
2005 – 2010

Volunteer

Information Technology Advisor HealthWays Non-Profit
2022 – Present·Daly City, CA
  • Built and manage a Microsoft 365 environment with Intune-based device management, improving productivity and streamlining endpoint deployment for the organization
IT Volunteer (As-Needed) Local Church
Ongoing·Bay Area, CA
  • Called in on an as-needed basis to resolve network and livestream issues the church's IT staff can't solve themselves
  • Diagnosed and fixed a content-filtering rule on the livestreaming VLAN that was blocking staff from viewing their own broadcast while it was live; reconfigured the rule to allow simultaneous viewing and streaming

Let's Connect

Have a role, project, or question? I'd love to hear from you — reach out on LinkedIn or check out my work on GitHub.