Joel Hurford, Project Manager in Williamsburg, VA, United States
Joel is available for hire
Hire Joel

Joel Hurford

Verified Expert  in Project Management

Bio

Joel has 30+ years of experience in technical program delivery, emphasizing infrastructure and SaaS solutions in communications, retail, government, and pharmaceutical sectors. In addition to leading IT and IT security in major US government departments, Joel was a solution architect with Accenture for 5+ years. With 12 active certifications, Joel provides program management, solution architecture, and organizational change management to ensure the success of client technology investments.

Project Highlights

USMint.gov | Payment Card Industry Compliance
Kept a $100-million per year eCommerce site online and compliant with PCI DSS requirements. Revenue continued to flow, and customer data was safe.
HHS Office of Inspector General | Data Center Consolidation
Led the migration of 300 physical and virtual servers and the support NetApp Storage Area Network to highly available Equinix managed data centers with Azure and AWS Direct Connects.
Sainsbury's UK Directory Services | Windows Upgrade
Deployed a 17,000-desktop upgrade including Active Directory, Group Policy, and Service Desk readiness.

Expertise

  • Business Management
  • Enterprise Architecture
  • IT
  • IT Security
  • IT Service Management (ITSM)
  • Project Management
  • ServiceNow
  • VMware ESXi

Work Experience

Director of IT Programs

2018 - 2021
United States Department of Health and Human Services
  • Joined HHS as a contractor team lead and was subsequently hired to lead the IT infrastructure for a nationwide 2,000 member law enforcement organization.
  • Received a promotion one year later to director of IT programs, overseeing all IT projects and a $50 million annual IT investment portfolio for the 6,500-member Office of the Assistant Secretary for Health, which oversees the surgeon general.
  • Deployed multiple instances of ServiceNow ITSM, ITBM, and ITOM, achieving an MPV and organization training in under six months.
  • Deployed multiple transformational POC technologies, including Cisco SD-WAN (Viptela), VMware Horizon, VMware disaster recovery as a service, VMware NSX, and attribute-based access control (ABAC) with Radiant Logic and Axiomatics.
  • Migrated 300 physical and remote-hosted virtual servers onto VMware Distributed Resource Cluster; reduced Oracle licensing costs by 40% and eliminated environment-related downtime in the subsequent 12 months.
  • Configured Equinix data center direct connections to Microsoft O365 and AWS to relieve 80% of the load on border gateways and firewalls.

Principal

2005 - 2018
Mitsis Information Technology Services LLC
  • Completed the inventory and upgrade of 300 servers to new hardware and VMware ESXi 6.x at the US Marine Corps Network Operations and Security Center (MCNOSC) and upgraded NetApp clusters to ONTap 8.2.
  • Securely enabled an internal US government case management system for access by Department of Justice collaboration partners through Microsoft Azure Application Proxy and two-factor authentication.
  • Prevented the shutdown of a $100-million annual revenue eCommerce system at US Mint by resolving payment card industry (PCI) audit findings. Architected and implemented a security control overlay for a legacy AS/400 system, including Imperva WAF.
  • Deployed and trained the US Transportation Security Administration (TSA) on enterprise architecture modeling with Mega. Accomplished initial modeling, including full representation of all IT assets and their communications.

Director of Civilian Programs

2014 - 2015
ManTech | Knowledge Consulting Group
  • Led a successful $29 million proposal for the Department of Homeland Security (DHS) continuous diagnostics and mitigation (CDM) program, which relied on Microsoft Project Server Online for a 180,000-hour delivery plan.
  • Deployed Imperva Web Application Firewall at Virginia Commonwealth University (VCU) and Publix Supermarkets.
  • Designed the cloud-based ServiceDesk and learning management solutions to meet the organizational training requirements of the DHS CDM delivery.

Chief Information Security Officer

2004 - 2005
United States Department of the Interior
  • Managed all elements of security policy, training, and architecture for this 80,000-person federal department. Represented the DOI on the federal e-authentication executive steering committee.
  • The DOI scored in the top third of agencies on the evaluation of its IT security policy implementation, which is done for all US federal departments. This was the DOI's first passing grade in the evaluation following my appointment as CISO.
  • Represented the DOI IT security policy in federal court as part of a 10-year $100 billion lawsuit over royalty distributions (Cobell v Norton).

Director of IT Security

2002 - 2004
United States Patent and Trademark Office
  • Joined the USTPO after a material weakness was determined in the financial controls of IT systems. Led the program that resolved the material weakness and scored USPTO the best IT security program in the Dept of Commerce in the next annual audit.
  • Reduced IT security spending by 15% while growing the program and honors as the best IT security program at the Dept of Commerce.
  • Authored IT security content for the exchange of patents between international bodies as part of a treaty. Contributed as an author to the US Government Smartcard Handbook.
  • Was promoted to the chief information security officer at the US Department of the Interior after two years based on my performance in managing the 10,000 person USPTO IT security program.

IT Architect

1997 - 2002
Accenture
  • Managed software releases for the BellSouth order management system that processed 30,000 orders per week. Earned the BellSouth Symphony award for excellence after reducing the defect inventory by 60% in four monthly releases.
  • Led the migration of Windows desktops to the latest version, including software packaging for a policy-based installation at the 17,000-desktop UK Sainsbury's and the 6,000-desktop AstraZeneca Pharmaceuticals.
  • Received the Accenture (Avanade) CEO Award for Excellence for leading successful enterprise migrations.
  • Received a promotion within my first year at Accenture based on deploying a Citrix thin-client solution at Federal Express, including automating the regression testing of thin-client features.

Project History

USMint.gov | Payment Card Industry Compliance

Kept a $100-million per year eCommerce site online and compliant with PCI DSS requirements. Revenue continued to flow, and customer data was safe.

I composed and led the response to financial processor warnings that US Mint was non-compliant with PCI data security standards (DSS) and would be fined several hundred thousand dollars per month. As a federal agency, US Mint would shut down a service considered non-compliant with security requirements.

USMint.gov had simple Unix web servers with content and data management hosted on a legacy IBM AS/400. To meet PCI DSS requirements, many controls and procedures had to be created and layers inserted into the transaction workflow. I leveraged the breadth of my experience composing low-cost and rapidly implementable controls, including deploying and configuring Imperva Web Application Firewall (WAF); coded firewall rules analysis; conducted contingency plan technical tests; and audited backup media to escalate and resolve dozens of missing volumes.

Within four months, and before fines commenced, US Mint received a clean PCI DSS audit.

HHS Office of Inspector General | Data Center Consolidation

Led the migration of 300 physical and virtual servers and the support NetApp Storage Area Network to highly available Equinix managed data centers with Azure and AWS Direct Connects.

The HHS Office of Inspector General had 300 servers and 50TB of NetApp storage. One-hundred servers and the NetApp storage were in an on-premise room subject to frequent power, water, and rodents issues.

I composed the plan and executed the technical details of virtualizing the physical servers and migrating provider-hosted virtual servers to two highly connected Equinix data centers with demonstrated failover using vSphere Site Recovery Manager (SRM).

All plans have issues, and ours were blocked replication traffic from the prior server-hosting provider or the need for expanded power whips to allow SAN and HP C7000 converged chasses in adjacent racks. I quickly identified and resolved these risks—hand-carry local NAS configured with iSCSI, 220V 30A circuits. The point isn't to have me help you provision a data center; the point is that I maintain the necessary teams and communication to elaborate and resolve the full spectrum of risks a project may encounter.

In four months, HHS OIG reduced hosting costs by 30% even while enjoying superior performance of the migrated virtual machines on a vSphere cluster. Another $500,000 was saved on Oracle licensing by licensing a subset of the DRS cluster using host affinity policies.

Sainsbury's UK Directory Services | Windows Upgrade

Deployed a 17,000-desktop upgrade including Active Directory, Group Policy, and Service Desk readiness.

Sainsbury's UK is a nationwide grocer with 17,000 user workstations. The company transitioned to Enterprise Active Directory, Microsoft Exchange messaging, and the latest Windows version. Migrating desktops depends on three key elements:
1. Profiling end-users for existing applications to ensure they are most productive after migration.
2. Packaging applications for automated deployment based on profile mappings.
3. Copious communication to end-users and the service desk on what to expect and what legacy applications will not survive the migration.

I led the Active Directory, Group Policy, Application Packaging, Endpoint upgrade, and Service Desk teams. The project was wildly successful in terms of timeliness and transformation of Sainsbury's end-user experience. It was awarded the Accenture (Avanade) CEO Award.

The Endpoint upgrade team lead could not maintain user profile updates because data on thousands of users was collected in Microsoft Excel, but the automated profile migration tool did not have a batch import capability. Using Visual Test scripting and Windows Accessibility features to identify tool-user interface controls, I automated transcription and reduced three-day manual batches to one hour.

Education

1994 - 1995

Master's Degree in Computer Engineering

United States Air Force Institute of Technology - Dayton, OH, USA

1985 - 1989

Bachelor's Degree in Computer Science

United States Air Force Academy - Colorado Springs, CO, USA

Certifications

NOVEMBER 2021 - NOVEMBER 2023

Certified Scrum Master

Scrum Alliance

MARCH 2021 - PRESENT

IT Service Management Certified Implementation Specialist (CIS)

ServiceNow

DECEMBER 2019 - PRESENT

Sophos Certified Architect

Sophos

AUGUST 2019 - JUNE 2022

Certified System Administrator

ServiceNow

FEBRUARY 2019 - PRESENT

Sophos Certified Engineer

Sophos

SEPTEMBER 2017 - PRESENT

VMware Certified Professional

VMware

MAY 2016 - PRESENT

VMware Certified Associate

VMware

AUGUST 2013 - PRESENT

VMware Certified Professional

VMware

MARCH 2012 - PRESENT

Certified Penetration Tester (CPT)

Information Assurance Certification Review Board (IACRB)

SEPTEMBER 2009 - PRESENT

ITIL Foundation Certification

Exin

AUGUST 2008 - AUGUST 2024

Project Management Professional (PMP)

Project Management Institute (PMI)

JANUARY 2006 - PRESENT

Microsoft Certified Administrator

Microsoft

JANUARY 2006 - PRESENT

Microsoft Certified Engineer

Microsoft

NOVEMBER 2002 - NOVEMBER 2023

Certified Information System Security Professional

(ISC)²

OCTOBER 1999 - PRESENT

Microsoft Certified Developer

Microsoft

Skills

Tools

VMware, Office 365, VMware NSX, VMware Horizon, Terminal, Visual Studio, Microsoft Visual C++, Jira, Splunk

Paradigms

Penetration Testing, TOGAF, Agile, Scrum

Platforms

SharePoint, Windows 7, Citrix

Other

Sophos Firewall, PMI, Project Management, CISSP, ITSM, Firewalls, Incident Management, IT Service Management (ITSM), VMware ESXi, MCSE, MCSA, Microsoft Project Online, IT Security, IT Projects, ServiceNow, C, AI Programming, Antivirus Software, Web Application Firewall (WAF), Capacity Planning, SLA Management, Business Management, Project Portfolio Management (PPM), IT Contracts, Imperva Incapsula, Mega, Enterprise Architecture, NIST, Policy Development, Imperva Web Application Firewall (WAF), VMware Site Recovery Manager (SRM), IT, Database Management, MCSD, McAfee, Check Point, Cisco, Visual Regression Testing, Project Management Professional (PMP), PCI Compliance, Scrum Master, Lean IT, Certified ScrumMaster (CSM)

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring