I build the AI agents, data pipelines, and analytics platforms that Amazon's Global Security Operations Center relies on to detect, classify, and respond to real-world safety incidents affecting drivers and worksites. As a Certified Risk Management Professional (CRMP — DRI International), I bring formal business-continuity and disaster-recovery discipline to how I design these systems — building them to fail safely, stay accurate under pressure, and keep the right signal reaching decision-makers when a real emergency is unfolding. Pairing that risk-and-resilience foundation with modern AI (Amazon Bedrock, agentic automation) is what lets me turn fragmented, high-stakes operational data into reproducible, decision-grade intelligence leaders can trust. MBA in Business Analytics (STEM) and 6+ years delivering to senior stakeholders.
Systems relied on daily by 36+ managers and 200+ agents, and reviewed at the executive level. Toggle to see my work through a BI/AI or a Data Engineering lens.
Leaders assembled the center's operational picture by hand from four disconnected sources — inconsistent, delayed, sometimes contradictory.
An automated executive report fusing EMT incidents, live incident-room status, email intake, and Slack signals into one authoritative brief, 3×/day. A deterministic JSON-first architecture (LLM extracts, code renders) yields SHA-256 byte-identical, tamper-resistant output.
Replaced the prior VP dashboard; reviewed at the executive level; issued daily by ~36 managers.
GSOC had no centralized analytics — a manual weekly Excel process distributed 2–3 days after period close.
GSOC's unified QuickSight platform: six role-based views with Row-Level Security. I modeled 6 Redshift sources into a single source of truth, normalizing 900+ raw fields into 84 governed KPIs and cutting a core query from 810s to 35s.
Serves 200+ agents through VP-level leadership across three global regions; 88% legacy match, 99%+ on core metrics; 10+ analyst hrs/week saved.
-- Corrected EMT-Sent undercount (status-based undercounted 20-40%)
-- and de-duplicated transfer-inflated call counts
SELECT COUNT(DISTINCT ctr."contact_id") AS "true_calls",
COUNT(DISTINCT emm."emailid") AS "emt_sent"
FROM bi_prod.v_connect_contact_trace_records ctr
LEFT JOIN account_amazongsoc.email_message_mapping emm
ON ctr."whatistheconnectid" = emm."incidentid"
WHERE ctr."created_mst" >= '2026-09-01';An AI tool giving floor agents, Loss Prevention, and HR an instant, explained determination on whether a situation qualifies as a Workplace Incident Management case — reasoning over the governing SOPs.
Won the People's Choice Award at the GSRR AI PartyRock Hackathon 2025 by org-wide vote (1,300 views, 108 votes, from 20 submissions).
A three-phase shift-compliance model (Start → Lunch → End) across 641 agent-days; partnered with Finance to model ROI on overage minutes at $18/hr.
Quantified $10.9K/week ($46.9K/month) of previously invisible labor waste; surfaced that only 4.4% of agent-days were fully compliant — first-ever financial visibility into compliance cost.
Automated ETL pipelines on AWS (S3, Lambda, Redshift, CLI) with data modeling and automated refresh powering reporting and downstream AI/ML — plus a weighted-scoring anomaly-detection model enforcing integrity on live streams.
Blocks 65 erroneous notifications/week to 500+ stakeholders; eliminated 10+ analyst hrs/week.
The first cross-channel duplicate-incident detection within GSOC — entity resolution matching the same event reported via phone, telematics, LSC, and digital forms on Transporter ID, phone, and Connect ID within a 48-hour window.
Blocks redundant safety notifications before they reach responders; protects data quality across GSOC, GRS, and Last Mile.
WITH pairs AS (
SELECT a."incident_id" AS orig, b."incident_id" AS newer,
DATEDIFF('minute', a."created_utc", b."created_utc") AS mins
FROM emt a JOIN emt b
ON (a."transporter_id"=b."transporter_id"
OR a."caller_phone"=b."caller_phone"
OR a."connect_id"=b."connect_id")
AND b."created_utc" > a."created_utc"
AND DATEDIFF('hour', a."created_utc", b."created_utc") <= 48
AND a."incident_id" <> b."incident_id")
SELECT COUNT(*) AS duplicate_pairs FROM pairs; -- 7,418 YTDA fully automated monthly pipeline: an AWS Glue Python-Shell job calling Bedrock against a RAG knowledge base, doing LLM-based semantic deduplication of root-cause text, writing six dimensional tables to Redshift — with secrets management, VPC endpoints, and a dedicated IAM role.
Replaced 2–3 weeks of manual review with day-one automated reporting; consolidates 300+ root-cause strings monthly.
Leadership-assigned validator on a VP-reviewed AI program, independent of the build team. Proved method fidelity by reproducing the dashboard's own figure exactly (2,547 = 2,547), then applied a six-state outcome model.
Measured true containment at 4.9% vs a claimed ~70%, materially correcting what leadership was told; my sizing replaced an inflated estimate with a defensible 3.9–6.3 FTE range. Validated queries publish to code.amazon.com.
Beyond my own systems, I serve as the analytics execution engine for the GSOC "EMT of the Future" intake pipeline — personally scoping and delivering requests raised by stakeholders across GSOC, Global Risk Services, Operations, and Process Improvement. Each item below is a completed, delivered project that saved time, labor hours, or cost.
Verified the correct business_segment methodology, computed create-to-close by severity, and sized the Sev4/5 out-of-scope opportunity (~0.26 FTE floor). Delivered as datasets + analysis.
Quantified how many Netradyne telematics callback calls convert to incident notifications (1,205 calls / 284 EMTs / 23.6% rate, monthly breakdown). Delivered as a live analysis sheet in Balance Scorecard 4.0.
Built the metric tracking time from incident-room launch to the first immediate mitigation call, added to the Balanced Scorecard for weekly business-review tracking of GSOC mitigation responsiveness.
Added visibility for digitally-reported incidents emailed to GSOC but not actioned — preventing missed or delayed high-severity incidents. Also resolved the incomplete IMC-data completeness issue on the same dashboard.
Delivered a SEV1/SEV2 firearms-incident data pull for leadership risk context, and a full 2025 EMT data extract for cross-team MTTR analysis and event-validation clean-up (after PII-scope alignment).
Built the Fast-Start → Operational Readiness Tracker (labor-punch vs. availability compliance to reduce paid idle time) for Ken Bae, and a multiple-incident download capability that removed a manual bottleneck in bulk incident retrieval.
GSRR AI PartyRock Hackathon 2025 — "Is this WIM?"
Amazon WWOS/GSRR, Q3 2025 — AI incident management
Global Cleveland, 2024 — civic leadership
If you're looking for someone who builds AI agents to solve real problems — I'm your guy.