Cloud Security · Zero Trust · AI Platform Engineering · Identity at Scale

Benjamin Villanueva
builds platforms enterprises trust at scale.

Engineering leader with 20+ years architecting secure enterprise Azure platforms. I designed, secured, and led the platform behind a $150M global managed-services business. I build at the frontier, write about what holds up in production, and still ship the code.

System Readout● Operational
0
Platform Business Owned
0
Annual Cost Reduction · 84%
0
Engineering Team Built
0
Azure Expert MSP · Consecutive
0
Azure Resources Governed
0Policy
0Alert
Baselines Governed
0
Years Engineering Leadership
0
Incident Response · from 5h
01

Profile

// who you're hiring

I architect and lead the platforms enterprises depend on. At Rackspace I built, secured, and ran the governance control plane behind a $150M global managed-services business, managing 29 million resources, 315,000 policy baselines, and 600,000 alert baselines across 36,000+ tenants, 5,000 subscriptions, and 13 global sites.

The outcomes are what I'm measured on. I refactored that platform from $56K to $9K per month, an 84% cut while increasing capacity, drove mean-time-to-resolution from five hours to fifteen minutes with AIOps, cut deployments from 48 minutes to 6, and passed every annual Azure Expert MSP audit with zero findings. I grew the team from myself to eight engineers and championed AI adoption across the org.

I lead by building. I architect the systems my teams run on and stay close to the code, so my technical decisions hold up and my team trusts them. That work runs from the enterprise identity practice I stood up on Entra ID and federation, through the Zero Trust security model, to the agentic systems I build now: MCP services, custom agent coding skills, and Borg, my open-source and enterprise agent-memory platform.

02

Cloud Security

// secure-by-default operations

Security is part of how I build platforms, not a review gate bolted on afterward. I set the operating model for Zero Trust, IAM governance, SIEM/SOAR, DevSecOps, and compliance readiness across a multi-tenant Azure estate where automation had to be trusted at fleet scale.

Zero Trust & IAM

Identity-bound platform controls

Designed a multi-layered Zero Trust model across WAF, API Management, network segmentation, managed identities, Entra ID Conditional Access, PIM, RBAC, and federated identity patterns.

SIEM / SOAR

Fleet-scale detection and response

Established multi-workspace Microsoft Sentinel operations across 500+ customer tenants, with telemetry onboarding standards, content deployment pipelines, AIOps correlation, and governed remediation.

DevSecOps

Controls embedded in delivery

Standardized secure delivery with Bicep IaC, GitHub Actions, self-hosted runners, SAST, DAST, container and dependency scanning, policy-as-code, detection-as-code, and pre-commit enforcement.

AI / MCP Security

Agentic workloads with guardrails

Built MCP security patterns mapped to the OWASP LLM Top 10, hardening tenant scoping, OAuth/SAML authentication, token handling, and audit trace correlation for AI-facing platform surfaces.

5 yearsAzure Expert MSP audits with zero findings
94 rulesSecurity governance enforced through Azure Policy
315K + 600KPolicy and alert baselines governed at fleet scale
5h → 15mIncident response improvement with AIOps correlation
03

AI Engineering

// building at the frontier

My AI work is real engineering, not a list of tools I've tried. I built the agentic surface of a production platform, led AI adoption across my team, and created open-source and enterprise AI infrastructure with published benchmarks. The work below is grouped by where it happened: production, leadership, and product engineering.

Production · Rackspace

Agentic Platform Surface

Built the platform's programmatic and agentic layer: REST APIs, Model Context Protocol services, agent frameworks, and custom agent coding skills, with the documentation to make it usable inside and out.

MCPAgent FrameworksCustom SkillsREST APIs
Production · Rackspace

AIOps · 5h → 15min MTTR

Integrated an AIOps framework using machine-learning event correlation that cut mean-time-to-resolution from five hours to fifteen minutes across a multi-tenant estate.

AIOpsML Event CorrelationObservability
Leadership

AI Champion & Trainer

Served as my team's AI champion and trainer, running demos and proofs of concept, upskilling engineers, and integrating AI-assisted workflows into production engineering practice.

EnablementDemos & POCsWorkflow Integration
Product Engineering · Sole creator

Borg — Enterprise Agent Memory

Built a Postgres-native memory stronghold with an Apache-2.0 open-source edition and a commercial enterprise deployment. Benchmarked at 10/10 task success and 91.3% retrieval precision. See details ↓

MCPPostgreSQLKnowledge GraphEntra JWTApache 2.0
Daily practice

AI-Native Development

I build with agents daily, writing custom agent coding skills and MCP integrations that extend what they can do and speed up delivery across the stack.

Claude CodeCodexGitHub CopilotKiro
Architecture

Agentic Workflow Design

I design how agents fit into real engineering systems, using namespace isolation, token-budgeted context, drift detection integration, and bitemporal fact supersession in production Sentinel pipelines. AIOps detects and recommends; a separately governed automation plane validates and remediates.

Workflow DesignContext EngineeringDrift DetectionGuardrails
04

Experience

// 1994 → present
2022 — 2026 · Rackspace Technology

Director of Azure Engineering

$150M platform · 36K tenants · 5K subscriptions · 13 sites

Architected and led a versioned governance control plane managing 5,000 subscriptions, 29 million resources, 315,000 policy baselines, and 600,000 alert baselines across 36,000+ tenants and 13 global sites, underpinning a $150M managed-services business.

  • Fleet Governance: engineered versioned fleet state and drift detection with Durable Functions, Event Hubs fan-out, and Azure Lighthouse.
  • Multi-Workspace Sentinel: governed security operations across 500+ customer tenants with custom tables, content deployment pipelines, and telemetry onboarding.
  • Refactored the platform from $56K to $9K/month (84% reduction) while increasing capacity and capability.
  • Cut MTTR from 5 hours to 15 minutes with an AIOps framework using machine-learning event correlation.
  • Architected a multi-layered Zero Trust model spanning WAF, API Management, data isolation, and Entra ID Conditional Access and PIM, with Azure Sentinel SIEM for real-time detection and automated response.
  • Standardized secure delivery (Bicep IaC, GitHub Actions with self-hosted runners, SAST and container scanning), cutting deploys from 48 to 6 minutes.
  • Built the platform's agentic surface: REST APIs, MCP services, agent frameworks, and custom agent coding skills.
  • Team AI champion and trainer; grew the function from one to eight engineers.
  • Perfect record through every annual Azure Expert MSP audit, protecting partner and co-sell revenue.
2015 — 2022 · Rackspace Technology

Senior Azure Architect

Identity & Access Management · Fortune 500

Built out the Identity and Access Management practice on Azure AD, ADFS, and Microsoft Identity Manager, delivering single sign-on and federated identity at scale across cloud and on-premises.

  • Lead Azure architect for major Fortune 500 customers, delivering proofs of concept, custom solutions, and AAD integrations.
  • Primary pre-sales contact across all IAM engagements; ran solution workshops.
  • Delivered IAM and federation webinars reaching 500+ customers per session.
  • Designed Azure Arc lifecycle management for hybrid and multi-cloud estates, standardizing onboarding, governance, update management, and secure retirement.
2013 — 2015 · Catapult Systems

Senior Lead Consultant

Austin Practice Lead · Top 5% billable

Local practice lead for the Austin business unit, owning delivery across Azure, Office 365, and federation, managing the full project lifecycle from sales to closure.

  • Consolidated LDAP, AD, and eDirectory onto Azure with sync from 100 to 500,000 accounts, including M&A integration.
  • Designed ADFS solutions: SSO, MFA, claims-based identity, and access control across on-prem and Azure.
2008 — 2013 · Dell Technologies

Systems Senior Engineer

Enterprise Support Advisor → Product Support Engineer → Systems Senior Engineer

Progressed from enterprise support advisor to systems engineer, designing private-cloud, identity, virtualization, and systems-management solutions across Microsoft and VMware platforms.

  • Architected Microsoft private-cloud reference solutions using Hyper-V, VMware, System Center, Exchange, SharePoint, and Lync.
  • Automated the Exchange Solutions Review Program end to end with PowerShell, including storage configuration, OS deployment, and Jetstress validation.
  • Supported the complete PowerEdge server-management lifecycle through iDRAC, Lifecycle Controller, OpenManage, and Microsoft System Center.
  • Authored Dell technical whitepapers that generated approximately 40,000 downloads.
2001 — 2008 · University of Wisconsin–Whitewater

Senior Information Systems Consultant

IS Networking Services Senior → Senior Information Systems Consultant

Built the networking, systems, and university IT consulting foundation that later shaped my enterprise architecture work.

1994 — 1999 · Tegucigalpa, Honduras

Network & Telecom Engineer

Network Systems Engineer · Network/Telecom Engineer

Began my career designing and supporting business networks and telecommunications systems for Comercial e Inversiones SuperMart and Agencias Panamericanas de Sula.

05

Leadership

// people first

The team I built is the part of this work I'm proudest of. I care about it more than any platform I've shipped.

I grew my engineering function from one person to eight. Hiring was only the start. The harder, more important work was building a place where strong engineers could do their best work and want to stay.

I mentor directly rather than manage from an org chart. I have been the escalation point and the person who teaches since my early engineering roles. As my team's AI champion and trainer, I ran the demos, proofs of concept, and hands-on sessions that got everyone comfortable with tools that were changing fast.

I protect my team's focus, give credit generously, and take the heat when something breaks. People do their best work when they feel valued, trusted, and appreciated, so that is the environment I work to create.

01People over org charts
I lead humans, not headcount. Careers, growth, and wellbeing come before process.
02Grow the people, not only the systems
Mentorship and training are core to the role. I bring the team up with me as the work gets harder.
03Trust by default
Autonomy and clear context beat micromanagement. I give the why, then get out of the way.
04Credit out, accountability in
Wins belong to the team. When something fails, it stops with me.
05Lead from the front
I stay close to the work, so my decisions are credible and I never ask the team to do what I would not.
06

Product Engineering

// I still ship

Borg Enterprise + OSS

Sole creator & maintainer · PostgreSQL-native agent memory

A memory stronghold for AI coding agents, available as an Apache-2.0 open-source project and a commercial enterprise deployment. Every session across Claude Code, Codex, Copilot, and Kiro flows into one Postgres knowledge graph, so the next agent arrives already briefed. No Qdrant, no Neo4j, no sync daemons.

Its five-stage borg_think pipeline classifies intent, retrieves across facts, episodes, and graph relationships, ranks on relevance, recency, stability, and provenance, then compiles token-budgeted context for the target model.

Built for enterprise deployment with Entra JWT, RBAC, namespace isolation, and per-compilation audit trails. Seven MCP tools cover context compilation, learning, recall, fetch, soft deletion, action guardrails, and deterministic project summaries.

Engineering-task benchmark
Borg · compiled91.3%
Top-10 vector RAG81.0%
No memory6.0%
Task success · 10/10 vs 8/10 RAG · 78% fewer stale facts
07

Technical Writing

// 4 series · 34 articles

Field notes on the platforms, operating models, and engineering decisions that hold up at enterprise scale.

I write for practitioners making the architecture work and leaders accountable for what happens after it ships.

Explore the complete writing library →
  1. 01 Thinking at MSP Scale MSP platform engineering 7 articles
  2. 02 Building a Fleet-Scale Azure Platform Azure platform engineering 9 articles
  3. 03 Building Memory for AI Coding Agents AI coding agent memory 6 articles
  4. 04 Azure Failure Labs Azure reliability engineering 12 articles
08

Capabilities

// the instrument panel
Engineering Leadership
Global Platform EngineeringFinOps & Cost OptimizationMulti-Site DeliveryTeam Building & MentorshipAI EnablementPre-Sales & Solution ArchitecturePartner / Co-Sell Strategy
Cloud Architecture
Azure IaaS / PaaSKubernetes (AKS)Multi-Tenant ArchitectureHybrid CloudAzure LighthouseAzure ArcDurable FunctionsASE v3Networking & VNetSite-to-Site VPNEvent-Driven ArchitectureTerraform
Data & Messaging
PostgreSQLPgBouncerCosmos DBpgvectorAzure Service BusEvent HubsAzure FunctionsDurable FunctionsLogic Apps
AI & Agentic Systems
Model Context Protocol (MCP)Agent FrameworksCustom Agent Coding SkillsAgentic Workflow DesignAIOpsClaude CodeCodexGitHub CopilotKiro
Identity & Access
Microsoft Entra IDManaged IdentitiesSingle Sign-OnPrivileged Identity ManagementConditional AccessRBAC / Least PrivilegeOAuth 2.0SAML / OIDCAD Federation ServicesMicrosoft Identity ManagerHybrid & Federated Identity
Security & Governance
Zero Trust ArchitectureMicrosoft Defender XDRCSPM / CNAPPAzure Sentinel (SIEM)Multi-Workspace SIEM ArchitectureThreat ModelingPolicy-as-CodeDetection-as-CodeSecrets ManagementMCP SecurityOWASP LLM Top 10Audit ReadinessDrift Detection & Auto-RemediationWeb Application FirewallAPI ManagementAzure PolicyAzure Monitor & AlertingContainer SecurityPCI · NIST · CIS · SOC 2
Languages & Frameworks
PythonNode.jsReactPowerShellTypeScript / JavaScriptBicepSQL
DevOps & Code Quality
CI/CD PipelinesInfrastructure as Code (Bicep)GitHub ActionsAzure DevOpsSelf-Hosted RunnersPre-Commit HooksRuff (Python lint)ESLint (React / Node)PSScriptAnalyzer (PowerShell)SAST / DASTDependency ScanningContainer Scanning
Automation & BI
REST API DesignPower AutomatePower BIWorkflow AutomationMicrosoft Partner Center
Education & Certifications
Education
Master of Science, Information Technology Management
Master of Science, Supply Chain Management
University of Wisconsin–Whitewater
Certifications
Microsoft Certified Master (MCM): Directory Services
Microsoft Certified: Azure Solutions Architect Expert
Microsoft Certified Systems Engineer (MCSE): Core Infrastructure
Currently Focused On
Agentic platform engineering
AI developer tooling & enablement
Cloud cost & reliability at scale
Open to VP & senior engineering leadership roles

Let's build something
enterprises can trust.

Your details are used only to respond to this message. Do not include confidential or sensitive information.