Sunnyvale, CA

Chris Larson

Systems Architect who builds infrastructure the way I read terrain. Deliberately, load-tested, and built to hold weight under real conditions. 14 years of hands-on systems administration spanning legacy systems decades past their expected lifespan to the self-built homelab I run today.

Sec. A — Profile

I'm an autodidact who has spent 18 years at Musson Theatrical ($14M revenue), the last 14 as sole technical owner of every core platform, with no formal handoff and no legacy playbook to inherit.

My range runs from legacy hardware to modern cloud identity: I led a full NetSuite ERP implementation off a 34-year-old legacy system (95 SuiteScripts, 34 forms, and 134 custom fields) alongside Adobe Commerce/Magento 2, Microsoft 365 and Entra ID, and the network infrastructure underneath all of it.

Security isn't a checklist item, it's a decade-long track record. Zero major security incidents or data breaches in over 10 years, held through proactive monitoring, least-privilege access design, and a security culture people actually buy into rather than route around.

Off the clock, I read terrain the same way I read systems, behind a camera in the mountains, chasing light and mapping the same kind of structure I build at a keyboard.

150+Automation scripts documented & standardized
141Workflow bottlenecks resolved
34-yrLegacy system fully replaced
0Security breaches in 10+ years
Sec. B — Capabilities

Infrastructure, identity, and automation — end to end.

Data Center & Hardware

Rack-mounted server deployment, server room build-outs (redundant power & cooling), structured fiber/CAT6A termination, managed switches, and full hardware lifecycle from procurement to decommission.

Virtualization & Hybrid Cloud

VMware ESXi, AWS (EC2, Route 53), and Docker administration across a hybrid fleet of RHEL/Rocky/Ubuntu and Windows Server hosts, professionally and in a self-built 210TB homelab.

Networking & Security

OSI-model root-cause troubleshooting, DNS/DHCP/VLAN administration, site-to-site IPsec, and firewall management on Aruba/HP/UniFi hardware, plus 10 years running New Relic for APM and infrastructure monitoring, and a decade of zero major security incidents.

Identity & Access Management

Migrated on-prem AD to Azure AD/Entra ID and built a secure-by-default M365 tenant (conditional access, MFA, and Autopilot), cutting onboarding tickets 40%. Administer Apple Business Manager and Intune across a mixed device fleet.

ERP & Business Systems

NetSuite (SuiteScript 2.1, SuiteQL, Suitelet, Map/Reduce, RESTlet) and Adobe Commerce/Magento 2, including a full ERP implementation off a 34-year-old legacy system spanning Finance, Order-to-Cash, Distribution, and WMS, plus an e-commerce platform built from scratch and iPaaS evaluation (Celigo, Boomi, MuleSoft).

Automation & AI-Assisted Scripting

Bash, Python, PowerShell, and SuiteScript scripting that cut manual operational tasks 40%, plus 150+ scripts and integration workflows documented and standardized with AI as a development partner.

Sec. C — Field Log

Experience

IT Manager / Systems Architect
MUSSON THEATRICAL
  • Delivered a full NetSuite ERP implementation off a 34-year-old MPE/iX legacy system: 95 SuiteScripts, 34 custom forms, 134 custom fields, and 28 advanced PDF templates, resolving 141 identified workflow bottlenecks across Finance, Order-to-Cash, Distribution, and WMS.
  • Built and own middleware integrating ERP, e-commerce, and the company's largest vendor for two-way pricing, inventory, and order synchronization, cutting manual reconciliation by roughly 95%.
  • Serve as a trusted technical advisor to ownership and executive leadership, navigating sensitive, high-stakes situations with discretion and tact.
  • Personally diagnosed and repaired a legacy 1991-era mainframe in production through July 2025, resolving hardware and software-level failures on legacy equipment for 5+ years.
  • Administer Apple Business Manager for the organization's Apple device fleet (3+ years): enrollment, MDM policy push, and lifecycle management; previously administered Jamf prior to platform transition.
  • Established least-privilege access standards across Entra ID and server accounts, and partnered with an external cybersecurity provider for 2 years on threat monitoring and incident-response readiness.
  • Used generative AI to document and standardize 150+ automation scripts; led org-wide SOP and knowledge-base development, raising platform adoption from 50% to 90% and cutting data errors 20%.
Full Stack Developer
MUSSON THEATRICAL
  • Led a full network infrastructure overhaul across 3 sites: rebuilt server rooms with redundant power, cooling, and managed switches; deployed structured copper/fiber, site-to-site IPsec VPN, VLANs, and a new Avaya IP Office phone system with SIP trunking.
  • Migrated the organization from on-prem AD to Azure AD/Entra ID and engineered a secure-by-default M365 tenant (conditional access, MFA, Autopilot), cutting onboarding tickets by 40%.
  • Designed and maintained a custom automated backup and recovery system for Linux infrastructure: hourly and daily backups replicated to cloud storage with tested restore procedures, delivering backup/disaster-recovery functionality without a commercial tooling budget.
  • Built the Adobe Commerce/Magento 2 storefront from scratch: custom modules supporting 140,000 product variations, doubling YoY sales in its first year.
  • Led a phased migration from on-premises file shares to SharePoint, cutting IT storage costs 20% with 95% adoption in 3 months.
  • Administered and expanded the legacy ERP, building a SQL export process that enabled analytics the 34-year-old platform couldn't natively support.
  • Own and maintain company DNS infrastructure for over a decade, applying working knowledge of the OSI model to diagnose issues at every layer.
Webmaster & Sales
MUSSON THEATRICAL
  • Led the technical recovery of a Magento 1 storefront after a failed external vendor implementation, self-teaching PHP and the Magento ecosystem to finish unbuilt components.
  • Owned full-stack website operations (Linux, PHP, MariaDB, SSL/TLS, and SELinux) prior to transitioning fully into IT.
  • Progressed from Sales into full technical ownership of company systems.
Sec. D — Personal Infrastructure

What I build when nobody's asking.

Six years ago I started building a homelab and never really stopped. It's a custom-built VMware ESXi host on server-grade hardware with 210TB of storage, a VLAN-segmented network built on Aruba, HP, and UniFi hardware, and site-to-site IPsec. Run with the same discipline as the corporate networks I manage.

I rewired an entire house myself: 2,000+ feet of structured CAT6A across 48 individual runs, terminating in a purpose-built network closet. Planned, pulled, terminated, and tested personally. I also pulled a permit and general-contracted a full 120V/240V electrical service replacement, coordinating subcontractors and inspections. Before Musson, I set up large-scale 3-phase power (up to 400A) for live events.

I also built a custom 11-camera CCTV system, entirely hardwired to eliminate Wi-Fi interference and jamming risk, with 24/7 recording on a rolling 21-day window and live streaming to Apple Home for family notifications, plus a personal media server for home streaming. I run personal AWS infrastructure (EC2, Route 53) hosting production sites and mail on a custom domain, manage a M365 Business Premium tenant with the same MFA and conditional-access practices I use at work, and provide hands-on iOS support and device-purchasing guidance for company and personal contacts.

210TBHomelab storage, self-built
2,000'+CAT6A cable pulled & terminated
48Structured cabling runs
6 yrsRunning & expanding the homelab
Sec. E — Credentials

Certifications

Earned CompTIA Security+ September 2026
Earned ITIL 4 Strategist: Direct, Plan & Improve June 2026
Earned ITIL 4 Foundation April 2026