Mat Rospierski

Systems Administrator

Panama City, FL (Relocating to Erie, PA) mat.rospierski@gmail.com linkedin.com/in/matrospierski

Professional Summary

Systems Administrator managing identity, endpoint, and hybrid infrastructure for a 1000+ user environment spanning on-premises virtualization and Azure. Day to day responsibilities span Microsoft Entra ID, Intune, and Microsoft 365 administration, VMware and Hyper-V virtualization with iSCSI shared storage, Azure Arc governance across the full server estate covering tag-scoped patching and access control, SaaS ERP administration for Deltek Costpoint, CMMC Level 2 compliance efforts through managing a secure enclave in Microsoft GCC High (CuickTrac), SSP documentation, CUI data handling, and delivering monthly infrastructure updates, guidance and technical consultations directly to executive leadership.

Experience

Systems Administrator

Eastern Shipbuilding Group / Brightlink Solutions Inc. Panama City, FL to Present

  • Manage 120+ Windows/Linux servers with a hybrid cloud vSphere Environment and over 3 petabytes of SAN Infrastructure.
  • Onboarded the organization's entire server estate to Azure Arc, automating Connected Machine agent deployment through NinjaOne and applying an eight-class resource tagging taxonomy across Hyper-V clusters, standalone hosts, and VMware guests to scope policy, monitoring, and access control.
  • Designed and implemented an update ring framework in Azure Update Manager, replacing manual per-host patching with tag-scoped maintenance configurations and phased pilot to production rollout, and deployed Windows Admin Center in the Azure portal to administer Arc-enabled servers without VPN, public IP, or inbound RDP exposure.
  • Built an Azure RBAC model on role-assignable Entra ID security groups, scoping administrative access to least privilege and closing a privilege escalation path in the existing group structure.
  • Built and administered a Hyper-V failover cluster with iSCSI shared storage on an IBM FlashSystem 5200, including MPIO configuration, Cluster Shared Volumes, and a File Share Witness, as part of an in-progress 10 Node VMware to Hyper-V infrastructure migration.
  • Redesigned and relaunched the organization's Intune hybrid Entra join and Windows Autopilot process end to end, resolving a backlog of unmanaged and noncompliant devices and moving enrollment from a manual, admin-driven process to self-service for end users, including endpoint application deployment.
  • Led an SSO migration for the Deltek Costpoint ERP system to Microsoft Entra ID across 4 separate environments ahead of a vendor-mandated deprecation of legacy database authentication, and rolled out SSO to 1000+ users across additional vendors (Adobe, Autodesk, SafetyCulture) including domain claim, just-in-time provisioning, and bulk migration of existing accounts to Federated ID.
  • Manage the organization's Microsoft GCC High secure enclave, administering virtual desktops and physical endpoints through CuickTrac while ensuring secure CUI access, and own CMMC Level 2 compliance workstreams including System Security Plan and Customer Responsibility Matrix documentation and tabletop incident response testing against NIST SP 800-171.
  • Serve as the go-to technical advisor within IT, with recommendations on vendor selection, infrastructure strategy, and compliance decisions regularly sought out by executive management.

Desktop Support Technician

Eastern Shipbuilding Group / Brightlink Solutions Inc. Panama City, FL to

  • Managed 1000+ devices across Active Directory, Microsoft 365, Entra ID, and Intune.
  • Migrated 1000+ users from legacy systems to new systems, including VOIP, Print Servers, and SaaS solutions.
  • Developed PowerShell scripts for software deployment automation, Active Directory data reconciliation, and routine remediation tasks, and deployed a Windows server (WDS and MDT) to automate machine imaging with unattended installs across multiple sites.

System Specialist Level II - Security

Siemens Smart Infrastructure Tyndall AFB, FL to

  • Served as lead technician on multiple projects within the 200+ project Tyndall AFB "Base of the Future" rebuild initiative, covering Desigo CC building automation integration and FireFinder XLS fire alarm system programming.
  • Installed, configured, and commissioned gunshot detection systems, network switches, and IP-based security and fire alarm systems (SIPASS, Cerberus, Siemens panels).

Certifications

Certified
CompTIA Security+, CompTIA Network+, CompTIA A+, CompTIA IT Operations Specialist, CompTIA Secure Infrastructure Specialist, Microsoft Certified: Azure Fundamentals (AZ-900)
In Progress
Microsoft Certified: Azure Administrator Associate (AZ-104)

Technical Skills

Cloud & Hybrid Infrastructure
Azure Arc, Azure Update Manager, Windows Admin Center in Azure, Azure Monitor, Azure Migrate, Azure Resource Manager, resource tagging and governance, Azure CLI
Identity & Endpoint
Microsoft Entra ID, Microsoft Intune, Windows Autopilot, Microsoft 365, Conditional Access, SSO/SAML, Azure RBAC, Duo MFA
Virtualization & Infrastructure
VMware vSphere/ESXi, Hyper-V failover clustering, iSCSI SAN (IBM FlashSystem), Windows Server, DNS, DFS
Automation & Scripting
PowerShell, Python, Microsoft Graph API, MSAL, REST API integration
Security & Compliance
CrowdStrike Falcon, Microsoft Purview, CMMC Level 2, NIST SP 800-171, CUI handling, Co-Authoring SSP
Backup & Monitoring
Veeam Backup & Replication, PRTG, NinjaOne RMM, Datto RMM
Stakeholder & Vendor Management
Executive collaboration with CFO and General Counsel on IT strategy, infrastructure planning, and technology roadmaps. Technical evaluation and cost/quote comparison across enterprise purchases including DLP platforms, enterprise storage systems, and CMMC C3PAO assessors.

Education

Associate of Science, Engineering Technology: Electronics

Gulf Coast State College, Panama City, FL