Hands in the Architecture. Eyes on the Outcome.

Damarius McNair, governance and risk-focused technology leader

Damarius McNair is a governance and risk-focused technology leader with eight-plus years across operations management, data analytics, and HIPAA-regulated cloud architecture. He built a 501(c)(3)'s compliance and financial control environment from the ground up — a NIST-aligned risk register, a multi-jurisdiction regulatory calendar, and HIPAA and 42 CFR Part 2 safeguards — while carrying a track record of measurable P&L outcomes across $89M and $97M operations.

His approach is direct: name the control, map it to the citation, and build the system that enforces it. Whether that means specifying audit logging against HIPAA §164.312(b), excluding a Google service from a design because it falls outside BAA coverage, or running a SQL model that found a $221K overtime leak hiding in scheduling data — McNair builds for durability.

He holds an MBA in Business Analytics from UNC Pembroke, a BS in Management Information Systems from East Carolina University, PSM I, and a Lean Six Sigma Green Belt. He combines hands-on technical capability with P&L ownership and executive-level communication — equally at home presenting financial reporting to a board as he is debugging a data pipeline at 11 p.m.

Career

  1. Featured

    Independent Technology Consultant

    Durham, NC

    Aug 2024 – Present

    Ongoing contract engagement delivering the public website and authenticated staff platform for a development-stage nonprofit client operating under HIPAA obligations.

    • Designed and built a layered platform separating the public WordPress site from an authenticated staff application, keeping regulated data off the public surface entirely
    • Implemented the API tier on Cloud Functions with Firebase Auth, role-based custom claims, and enforced MFA for any role touching regulated data
    • Separated storage by sensitivity: Cloud SQL PostgreSQL 15 on private IP with no public endpoint for PHI, Firestore under deny-all security rules for non-regulated operational data
    • Scoped the environment so no live PHI is processed until a Google Cloud BAA is executed — compliant ahead of go-live rather than remediated afterward
  2. Governance

    Director of Strategy & Technology | Treasurer, Board Officer

    Kingdum Living Ministry, Inc.  ·  501(c)(3), volunteer board officer

    2024 – Present

    Board officer for a development-stage nonprofit designing ten integrated recovery, reentry, and housing programs. Owns the organization's financial controls, regulatory compliance calendar, and technology governance during its pre-operational build-out.

    • Stood up the treasury function from nothing: QuickBooks nonprofit configuration, written financial policies, banking and signatory controls, and the FY2026 operating budget against a three-month reserve target
    • Built and maintains a multi-jurisdiction compliance calendar spanning IRS Form 990, NY CHAR500, NC Secretary of State annual reporting, and HHS breach-log obligations
    • Authored the architecture governance framework covering incident response, audit controls, and a NIST-aligned risk register
    • Designed a HIPAA and 42 CFR Part 2 aligned reference architecture on a strict three-layer model in which PHI never reaches the public or operational tiers
    • Specified safeguards against named HIPAA Security Rule citations — audit logging to §164.312(b), private-IP-only database access, deny-all datastore rules, MFA for clinical roles, and session timeouts
    • Excluded Firebase Realtime Database from the design after determining it falls outside Google's BAA coverage, selecting a covered service for non-PHI operational data instead
    • Qualified a nine-funder grant pipeline with award ranges and eligibility gating, identifying that government funding remains unavailable until program licensure
    • Presents financial reporting to the board and holds review authority over grant financial reports and Form 990 schedules prior to filing
  3. Operations

    Process Operations Manager

    Enterprise Mobility  ·  Raleigh, NC

    Jan 2022 – Nov 2025

    Led analytics, systems optimization, and operational strategy for an $89M market managing a 4,600 to 5,600+ vehicle fleet. Served as the bridge between operations, IT, and executive leadership.

    • Designed SQL-based analytics systems identifying labor inefficiencies, reducing overtime costs 23% for roughly $221K in annual savings
    • Built demand forecasting and fleet optimization models supporting expansion from 4,600 to 5,600+ vehicles, enabling approximately $15.9M in additional annual capacity
    • Developed Power BI executive dashboards and API-integrated reporting pipelines consolidating workforce systems (Dayforce, Workday) into unified leadership visibility
    • Governed SLA performance and vendor accountability across operating partners, standardizing exception reporting and escalation paths
    • Engineered data-driven fleet allocation models using real-time operational and external demand signals, including airline and reservation data, to reduce idle inventory
  4. Operations

    Assistant Store Manager, Operations

    Lowe's Home Improvement  ·  Greenville, NC

    Jan 2020 – Jan 2022

    Ran operations for a $97M store with 230+ employees through COVID-era supply chain disruption.

    • Reworked inventory and procurement controls, reducing shrink from 2.3% to 1.6% and recovering roughly $680K annually
    • Cut monthly open roles by 50%, from four to seven down to under three, through stay interviews, schedule restructuring, and management development in one of the worst labor markets in recent memory
  5. Operations

    Department Manager

    Walmart  ·  Greenville, NC

    2017 – 2020

Featured Work

Cloud / Compliance

HIPAA GCP Landing Zone

Reusable GCP landing zone for small HIPAA-regulated organizations, with every control mapped back to the HIPAA Security Rule and NIST 800-53. The org-project-factory and iam-baseline modules are implemented and validated; VPC Service Controls, CMEK, and audit-logging modules are scheduled through September 2026. Published alongside a companion Firebase and GCP reference architecture covering multi-vendor boundaries, RBAC design, and cost.

View the reference architecture →

Analytics / Operations

Fleet Ops Analytics

SQL-driven fleet operations analytics for overtime cost analysis and KPI tracking at scale. Built from the real problem of an $89M market where scheduling inefficiency was costing roughly $221K a year.

View on GitHub →

Nonprofit / Automation

Grant Opportunity Matcher

AI matching engine connecting nonprofit profiles to live federal grant opportunities from the Grants.gov API, using hybrid scoring that combines TF-IDF with semantic analysis, multi-model orchestration, and caching.

View on GitHub →

Field Notes

Frameworks, failures, and field notes from the data layer.

Tools & How-Tos

A Simple Framework for Deciding Which AI Tool to Use First

July 2025

There's a pattern playing out inside operations teams right now that I recognize immediately: someone returns from a conference, or reads a vendor case study, and suddenly the team is evaluating tools before they've asked a single question about their own processes.

TOGAF / EA

What TOGAF Actually Is and Why Operations Leaders Should Care

AI Operations

How I Reduced Overtime Costs 23% Without Cutting Headcount

AI Operations

Why Most AI Implementations Fail

AI Operations

What Lean Six Sigma Taught Me About AI

Nonprofit Tech

The Nonprofit Sector Has a Technology Access Problem

BI & Data

Why Nobody Used My Power BI Dashboard