Gavin Leonard

Cloud & Security Engineer | Microsoft-Certified in Azure & M365 | Zero Trust, SIEM, Identity Governance & Network Infrastructure

Richland, Washington, United States

About

Cybersecurity and IT professional with hands-on experience in cloud security, network infrastructure, and enterprise endpoint management. Microsoft-certified in Azure and Microsoft 365, with a strong foundation in Zero Trust architecture, SIEM deployment, and identity governance. Proven success implementing secure hybrid networks, optimizing compliance, and raising security posture across diverse environments. Skilled in cloud migration, VPN configuration, Group Policy development, and endpoint hardening. Experienced in deploying Microsoft Defender, Entra ID, Purview, and MDM solutions to protect assets and enforce policy. Adept at designing and managing scalable infrastructure—including wireless networks, access control systems, and centralized logging platforms. Driven by curiosity and problem-solving, I’ve led multiple enterprise-grade projects from concept to execution, including digital security overhauls, physical surveillance upgrades, and cloud-integrated network redesigns.

Experience

  • Plant Cyber Security Analyst I at Energy Northwest
    Mar 2026 - Present · 4 mos

    - Design and implement cybersecurity architectures protecting critical infrastructure in compliance with 10 CFR 73.54 nuclear cybersecurity regulations. - Develop and maintain enterprise cybersecurity programs, including policy development, vulnerability management, incident response planning, and workforce training. - Implement and oversee security controls for digital computer and communication systems supporting operational technology (OT) and enterprise environments. - Perform vulnerability assessments and risk analysis, identifying security gaps and recommending remediation strategies to strengthen system resilience. - Monitor and analyze network traffic within SCADA/industrial control system environments to detect, investigate, and respond to potential cyber threats. - Produce and maintain regulatory documentation, including cybersecurity procedures, compliance artifacts, and audit evidence. - Lead self-assessments, regulatory audits, and program change reviews to ensure continued adherence to nuclear cybersecurity requirements. - Serve as a subject matter expert in regulatory cybersecurity, advising technical teams and leadership on compliance and security best practices. - Support critical plant operations including Emergency Response Organization (ERO) participation, cyber on-call rotation, and refueling outage support. - Continuously track emerging cyber threats, vulnerabilities, and regulatory changes impacting critical infrastructure and nuclear sector cybersecurity.

  • Warehouse Manager at Luke's Carpet and Design Center
    Aug 2019 - Present · 6 yrs 11 mos

    - Collaborate with team members to ensure both efficient operations and order fulfillment. - Serve as the link between the warehouse and other departments, ensuring communication is clear and processes efficient. - Manage store inventory utilizing the RFMS database. - Implemented process improvements to reduce errors and boost productivity. - Maintain current knowledge of products, company policies, and industry updates. - Troubleshoot software and hardware issues to support operations - Provide customer support over the phone and in person, addressing inquiries and resolving issues promptly. - Conduct training sessions for employees on RFMS database use and warehouse responsibilities to ensure consistency and efficiency.

  • Cloud & Security Engineer | IT Assistant at Douglas Fruit Co
    Apr 2025 - Mar 2026 · 1 yr

    - Delivered Tier 1–3 technical support for 100+ end users across office, production, and orchard environments, resolving hardware, software, and network issues. - Managed user provisioning, access control, and endpoint operations, overseeing onboarding/offboarding, software deployments, patching, and system updates. - Configured and optimized the help desk platform, building the IT knowledge base and automating ticketing and monitoring workflows. - Implemented a secure asset-tracking system, cataloging 300+ devices to improve inventory control and lifecycle visibility. - Deployed and managed Microsoft-based security solutions, achieving 95% compliance with modern cybersecurity standards and a 90% Microsoft Defender Secure Score. - Configured a cloud-based SIEM for centralized logging, alerting, and incident-response workflows. - Designed and integrated Microsoft cloud infrastructure to deliver a secure, redundant, and scalable hybrid network. - Directed a full wireless-network overhaul, deploying access points, mesh extenders, and cloud-managed controllers to improve coverage and reliability. - Integrated cloud-based IAM with remote client VPN, implementing conditional access and MFA to secure remote connectivity. - Led organization-wide cybersecurity awareness initiatives and phishing simulations to strengthen defenses against social engineering. - Managed PBX systems to maintain secure, stable connectivity across all organizational VoIP devices. - Strengthened organization networks via VLAN & VPN IP access restrictions, group policies, RADIUS certificate authentication, and assigned DNS servers.

  • IT Field Tech at Kennewick School District
    Jul 2024 - Oct 2024 · 4 mos

    - Supported district-wide IT operations, helping ensure effective communication and resource allocation. - Tracked multiple technical issues, prioritizing tasks while maintaining focus on detailed problem resolution. - Remotely diagnosed and resolved computer, software, printer, and phone issues using analytical techniques. - Installed software updates and provided users with brief orientations to ensure smooth transitions. - Updated and maintained data in PowerSchool to support accurate and accessible information for users.