Dustin Hall

Identity & Endpoint Security Engineer

Austin, TX · Open to remote and SF Bay Area

Endpoint and identity security engineer with 14 years across Microsoft and Google environments. I currently run lab validation, deployment, and change control for enterprise application releases across a 50,000+ endpoint estate at a Fortune 500 financial services firm, including vulnerability remediation through Qualys and BigFix. Before that I led a company-wide migration of 90 SaaS applications to SAML SSO with SCIM provisioning, and owned a 1,500-device Intune tenant with Defender for Endpoint. Former people manager at VMware, now deliberately focused on hands-on security engineering.

50,000+endpoints in the estate I deploy releases to
90SaaS apps moved to SAML SSO + SCIM
1,500+devices in an Intune tenant I owned end to end
33,000employees served by a Copilot Studio agent I evaluated pre-release

Experience

2025 – Present

Software Deployment Engineer (Contract)

Charles Schwab · Austin, TX

  • Lab-validate and deploy an average of 12 enterprise application releases per month across a 50,000+ endpoint estate through BigFix, executing structured test plans and certification protocols that surface defects and configuration drift before general deployment.
  • Partner with each application’s Product Owner throughout the release lifecycle: defining the deployment schedule, validating their testing and target test devices, reporting status through phased rollout, and delivering the close-out roll-up.
  • Served on the implementation team for a Copilot Studio IT assistant deployed to Microsoft Teams for 33,000 employees, and led pre-release evaluation of its output: validating responses against source knowledge base articles, identifying hallucinated and unsupported answers, verifying escalation triggers, and tracking defects through Jira.
  • Support vulnerability remediation across the estate, identifying end-of-life and out-of-support software through Qualys and authoring targeted BigFix remediation actions to eliminate exposure.
2024 – 2025

Career break

2024

Endpoint Engineer (Contract)

Nature’s Way · Austin, TX

  • Owned the Microsoft Intune tenant for 1,500+ endpoint devices end to end: configuration, compliance policy, and data-protection controls.
  • Remediated endpoint vulnerabilities and threats identified in Microsoft Defender for Endpoint and Qualys, proactively closing exposure and responding to detections.
  • Administered PatchMyPC to automate third-party application patching across the fleet.
  • Built PowerShell automation for device lifecycle tasks including decommissioning, eliminating hundreds of hours of manual work.
2022 – 2023

IT System Administrator

Contentstack · Austin, TX

  • Led migration of the company’s SaaS estate (90 applications including Slack, Zoom, Jira, Monday.com, Smartsheet, and Expensify) to Google SAML SSO with SCIM provisioning, consolidating 90 independent logins into a single managed identity and automating account creation and deprovisioning for 500+ users.
  • Owned the Google Workspace tenant end to end (architecture, security configuration, and identity lifecycle for 500+ users) including MFA enforcement and context-aware access policies.
  • Planned and deployed JumpCloud MDM across a 500+ endpoint mixed Mac and Windows fleet in under six months, moving from unmanaged devices to enforced disk encryption, OS patch compliance, and device trust for SSO.
  • Led IT buildout of a hybrid office: network, access control, physical security systems, and conference AV.
2018 – 2021

Executive Support IT Manager

VMware · Palo Alto, CA

  • Managed a team of 4 direct reports and ~12 dotted-line engineers across regional sites, delivering white-glove IT and AV support to 50 senior executives including the CEO and C-staff.
  • Built and rolled out the global executive IT support program across 10+ countries on a follow-the-sun model, designing the after-hours rotation that delivered 24/7 near-immediate response for executives outside HQ.
  • Hired and onboarded 2 of the team’s 4 engineers and owned performance management and development for the direct team.
  • Led executive-facing technology projects (product deployments, change management, and software training) coordinating across 12+ internal teams.
2016 – 2018

Endpoint Engineer

VMware · Austin, TX

  • Administered Office 365, Active Directory, and Slack environments and provided second-level support for complex Windows and macOS issues.
  • Contributed to the rollout and development of a custom IT ticketing system and managed IT support for executives at regional field offices.
2012 – 2014

Senior Technical Support Advisor

Apple · Austin, TX

  • Delivered advanced macOS and iOS support to end users and tier-one advisors at a 95%+ customer satisfaction rate; served as backup team manager and partnered with product engineering on root cause analysis of call drivers.

Projects

Open source, built and maintained on my own time.

PII Scrub

Finds personal information in a document and replaces it with stable placeholders so the text is safe to paste into an LLM. Runs entirely locally with Microsoft Presidio and spaCy, lets you review every detection, and refuses to write output if a redacted value survived.

PythonData protectionRepo →

Clamshell

macOS menu bar toggle for pmset disablesleep, so a MacBook keeps running with the lid closed. Power assertions can’t do this, since clamshell sleep is decided below them; the app always restores sleep at launch and quit.

SwiftmacOSRepo →

audio-follow

Windows tray app that relaunches apps which ignore changes to the default audio output. Subscribes to the Windows device-change notification instead of polling, so it uses essentially no CPU while idle.

C#WindowsRepo →

Weather Taskbar

Lightweight Windows 11 weather app that lives on the taskbar or in the system tray. .NET 8 and WinForms, Open-Meteo data with no API key, sleep/wake-aware refresh, ~20–25 MB of RAM.

C#WindowsRepo →

Self-hosted infrastructure and production application backends I build and operate.

Zero trust remote access

A WireGuard-based mesh network (Tailscale) providing authenticated, identity-based access to self-hosted services across multiple hosts, with no exposed ports or inbound firewall rules.

Network-layer DNS security

Network-wide DNS filtering with a self-hosted recursive resolver (AdGuard Home + Unbound), removing the third-party resolver dependency and keeping local control of name resolution and query logging.

Serverless application backend

Backend services on Cloudflare Workers with D1, handling API authentication, request validation, and edge-deployed data access for production mobile applications.

LLM integration

Third-party inference APIs integrated into production applications, including API credential handling, prompt construction, and response validation.

Skills

Identity & endpoint

Microsoft Entra ID, Microsoft Intune, BigFix, JumpCloud, Jamf, Okta, SAML SSO / SCIM provisioning, Google Workspace, Microsoft 365, Active Directory

Security & vulnerability management

Qualys VMDR, Microsoft Defender for Endpoint, vulnerability remediation, EOL/EOS software lifecycle, change control, pre-production security validation

Cloud, automation & infrastructure

Microsoft Azure, PowerShell, Cloudflare Workers / D1, Linux (WSL2), WireGuard / Tailscale, DNS security (AdGuard Home, Unbound), Jira / Confluence

AI enablement & assurance

Microsoft Copilot Studio, LLM output evaluation, LLM API integration, prompt design

Certifications

Education

University of Texas at Austin · Bachelor of Journalism