Hello! I’m
Aaron Hulett
Retired | Former Microsoft PM/SDE & Managed Service Provider Senior TPM | Cybersecurity & Incident Response | NIST CSF & CIS

About Me
I’m Aaron Hulett, a former Microsoft program manager and software engineer with a background in cybersecurity, incident response, and large-scale technical operations. Throughout my career, from co-inventing patented malware detection systems at Microsoft to streamlining multi-client IT operations and compliance, I specialized in turning technical ambiguity into clarity, resolving complex operational crises, and strengthening organizational resilience.
Beyond my corporate work, I have been deeply committed to civic preparedness. I’ve served in leadership and volunteer roles across CERT, firefighter rehabilitation, and amateur radio emergency communications, including single-handedly reviving the National Traffic System (NTS) infrastructure and sparking ARRL’s national “NTS 2.0” modernization effort. I also completed Emergency Medical Responder (EMR) training and became NREMT-registered to serve as a STOP THE BLEED instructor.
Now fully retired from corporate work, my focus has shifted to personal projects, civic preparedness, and life beyond the corporate grid.
Career Track Record
Decades of experience spanning big tech, IT operations, and emergency management.
Engineered malware detection algorithms, led global escalation workflows for Windows Defender, and co-invented patented antimalware systems (US Patent 9021590).
Led multi-client IT modernization, compliance (NIST CSF, CIS Controls), and system architecture for healthcare and enterprise organizations.
Designed business continuity, disaster recovery, and evidence-retention frameworks, including technical strategy that successfully mitigated $23M in litigation risk.
HSEEP-compliant exercise design, Incident Action Plan (IAP) authoring, NIMS/ICS incident management, and firefighter rehabilitation operations.
Authored Microsoft’s global spyware classification criteria and optimized vendor/partner SLAs, contracts, and compliance frameworks.
Directed complex portfolio projects and cross-functional engineering teams utilizing Agile/Waterfall methodologies.
Featured Publications & Projects
Key threat research, policy frameworks, network telemetry studies, and emergency infrastructure evaluation reports authored throughout my corporate and civic leadership.
West Gulf Division Emergency Communications Functional Exercise
ARRL West Gulf Division • Emergency Architecture & Documentation • Aug 2023
Co-directed and authored the HSEEP-compliant exercise architecture and Incident Action Plan (IAP) package for a multi-section functional exercise simulating a 100-mile telecommunications blackout in the Houston area. Designed inter-section HF/VHF/digital traffic routing infrastructure across Texas and Oklahoma to validate National Traffic System (NTS) disaster welfare message handling under full emergency conditions.
- Incident Command & Planning (ICS): Authored the formal Incident Action Plan (IAP) incorporating ICS 201 Briefing, ICS 202 Objectives, ICS 204 Assignments, ICS 205 Radio Communications Plans, and ICS 208 Safety Messages.
- Field Operations: Authored the Player Handbook establishing exercise scope, rules of engagement, simulated hurricane scenario, traffic routing tables, and radiogram standards.
Mentorfest 2021 Virtual Conference Production
ARRL North Texas Section • Live Event Architecture & Remote Broadcast • Apr 2021
Designed, engineered, and executed the technical architecture for ARRL North Texas’s first-ever virtual Mentorfest conference. Operating as sole technical producer from a single workstation with zero budget, architected a multi-point remote ingest workflow via Zoom, orchestrated 9+ hours of continuous live stream production, and routed low-latency video and audio to YouTube for a worldwide audience of amateur radio operators.
- Remote Production & Video Routing: Managed real-time switching, presenter staging, screen sharing, and audio leveling for 7 distinct technical presentations.
- Live Interactive Operations: Integrated live YouTube chat monitoring, door-prize entry workflows, and real-time Q&A relay.
DFW Metroplex Emergency Communications Functional Exercise
ARRL North Texas Section • HSEEP Planning, Execution & Evaluation • Nov – Dec 2020
Architected, executed, and evaluated a multi-county emergency communications functional exercise simulating a widespread cellular and telecommunications grid collapse across the Dallas/Fort Worth Metroplex.
- Incident Command & Planning (ICS): Authored the formal Incident Action Plan (IAP) incorporating ICS 201 Briefing, ICS 202 Objectives, ICS 204 Assignments, ICS 205 Radio Communications Plans, and ICS 208 Safety Messages.
- Field Operations: Authored the Player Handbook establishing exercise scope, safety protocols, and standardized radiogram reporting templates for participating operators.
- Post-Exercise Evaluation: Authored the formal FEMA HSEEP-compliant After-Action Report / Improvement Plan (AAR/IP), evaluating Operational Communications and Situational Assessment core capabilities to establish corrective action roadmaps.
Hurricane Laura Traffic System Response
ARRL North Texas Section • Emergency Architecture & Whitepaper • Oct 2020
Authored the operational post-incident report and framework whitepaper establishing the Traffic System Incident Response Lifecycle. Developed a real-time NTS Status Dashboard integrating live radar, satellite telemetry, and NHC briefings, and standardized protocol mappings for converting Incident Command System (ICS) forms into over-the-air radiograms during major Gulf Coast hurricane activations.
Astronaut Traffic System Performance Whitepaper
ARRL North Texas Section • Network Telemetry & Data Analysis • July 2020
Authored an empirical analysis whitepaper collecting and evaluating over-the-air radiogram traffic sent to NASA astronauts aboard the International Space Station (ISS). Analyzed network telemetry, geographic distribution trends using 3D mapping, and cross-country radiogram transit times (averaging 2.6 days) to measure routine National Traffic System efficiency and benchmark operational baseline performance.
Microsoft Security Intelligence Reports (SIR)
Microsoft • Threat Intelligence & Global Telemetry • 2007 – 2016
Contributed specialized threat telemetry analysis, malware research, and visual technical evidence (including threat screenshots and trend breakdowns) across SIR volumes to translate complex telemetry into actionable security guidance for enterprise leadership and government partners.
Ransomware Protection in Windows 10 Anniversary Update
Microsoft • Technical Whitepaper • Nov 2016
Authored technical whitepaper detailing Microsoft’s multi-layered strategy (Prevent, Detect, Respond) to engineer ransomware resilience directly into Windows 10 enterprise architecture.
Spyware Detection Mechanism (US Patent 9021590)
Microsoft • Patented Technology & Innovation • Co-Inventor • 2008 / 2015
Co-invented a machine-implemented system and method for detecting surreptitious malware, DLL injection, and keyloggers hidden across operating system processes. Engineered process-monitoring algorithms that isolate non-whitelisted modules across active system events and honeypot execution environments to prioritize threat analysis.
I Know What You Did Last Logon
Virus Bulletin • Threat Research & Case Studies • Oct 2006
Conducted detailed threat analyses and case studies on monitoring software for this peer-reviewed publication, evaluating invasive software behaviors, stealth mechanisms, and privacy boundaries to establish technical classification standards for spyware.
Author Acknowledgement: Cited for conducting primary threat analysis alongside Microsoft’s anti-spyware research team.
Experience
Senior Technical Project Manager
2021 – 2025
Architected technical solutions, guided cybersecurity posture, and led hands-on IT implementation for healthcare and enterprise clients while directing a high-volume portfolio of concurrent projects.
- Enterprise IT Strategy & Portfolio Leadership: Advised healthcare and enterprise organizations across the U.S. on IT strategy and system architecture, directing 15-30 concurrent technical projects to ensure on-time delivery and alignment with client business goals.
- Cybersecurity & Compliance Frameworks: Developed and deployed security policies, controls, and risk assessments aligned with NIST CSF and CIS Controls, strengthening client compliance, data protection, and operational resilience.
- Incident Response & Systems Engineering: Guided organizations through complex technical incidents, system integrations, and infrastructure upgrades, translating high-stakes security challenges into clear, actionable technical plans.
- Service Architecture & Agreement Optimization: Streamlined client contracts and Service Level Agreements (SLAs), clarifying scope, deliverables, and operational boundaries to reduce ambiguity and drive client retention.
- Executive Advisory & Process Optimization: Served as a trusted technical advisor to client leadership, providing actionable recommendations to modernize IT workflows, mitigate operational risk, and improve overall process efficiency.
President & Former VP of Operations
Little Elm Box 620 Support Co.
2023 – 2025
Supported firefighter rehabilitation operations through training design, process improvement, and field response.
-
Executive Leadership (President): Provided overarching leadership for the organization, guiding strategic growth, managing town agency relations, and driving volunteer recognition initiatives.
-
Agency Coordination: Established formal liaison and regular coordination meetings with Town of Little Elm first responders to align support services with active municipal needs.
-
Operational Management (VP of Ops): Directed firefighter rehabilitation operations, introduced recurring training curricula, and oversaw field response logistics to ensure responder safety during critical incidents.
Vice President & Director of Information Technology
Little Elm Friends of the Library
2023 – 2025
Directed IT strategy, cloud modernization, and board governance updates to strengthen operational efficiency and organizational outreach for the local library support foundation.
- Cloud Migration & IT Strategy: Evaluated legacy technology usage and authored an actionable IT roadmap that spearheaded the transition to cloud-based collaboration tools and modernized the web presence.
- Governance & Legal Compliance: Identified critical omissions in the organization’s Articles of Incorporation and drafted formal amendments to resolve compliance gaps and restore governance effectiveness.
- Board Alignment & Leadership: Conducted one-on-one strategic sessions with board members to assess technology needs, align digital tools with organizational goals, and prioritize long-term initiatives.
CERT Instructor & Firefighter Rehab Captain
Denton County Office of Emergency Management
2017 – 2020, 2025
Led volunteer training design, firefighter rehabilitation operations, and field response strategies to strengthen county-wide emergency preparedness and responder support.
- Curriculum & Medical Instruction: Redesigned and updated the FEMA Community Emergency Response Team (CERT) curriculum, incorporating hands-on practical exercises to elevate responder capability and field readiness, and delivered certified STOP THE BLEED life-safety training to community volunteers, elevating operational capability and field readiness.
- Operational Metrics & Reporting: Established performance tracking, operational metrics, and reporting frameworks for firefighter rehab deployments, quantitatively demonstrating program impact to agency leadership.
- Responder Support Operations: Authored recurring training modules, standard operating procedures, and tactical exercise scenarios to ensure responder safety and health during extended incident operations.
Section Traffic Manager
2019 – 2024
Revitalized the emergency communications infrastructure across the North Texas amateur radio network and beyond, sparking national-level program reinvestment.
- National Infrastructure Revitalization: Led a nationwide revitalization of the National Traffic System (NTS), working directly with Section Traffic Managers across the country to bridge operational gaps, re-establish message links, and overcome decades of structural stagnation. By implementing rigorous process development, modern training frameworks, and functional exercises, this comprehensive turnaround directly influenced and inspired ARRL Headquarters to launch its nationwide “NTS 2.0” modernization initiative.
- Inter-Agency Interoperability: Engineered joint operational procedures and specialized training frameworks for nationwide ARRL/MARS exercises, ensuring seamless communications between civilian and military auxiliary networks.
- Incident Lifecycle Architecture: Created a standardized Incident Response Lifecycle to streamline data routing, operational logistics, and information flow during emergency activations.
- Digital Infrastructure & Dashboards: Spearheaded the migration of the section web infrastructure to WordPress and developed a real-time NTS status dashboard to maintain operational awareness during critical incidents.
Founder, Secretary & Treasurer
Coppell Amateur Radio Enthusiasts
2018 – 2019
Founded a 501(c)(3) public charity to advance amateur radio, emergency communications readiness, and STEM education across the Coppell community.
- Organizational Formation & IRS Exemption: Incorporated the non-profit entity, drafted corporate governance documentation, and secured IRS 501(c)(3) tax-exempt status in under eight months.
- Community Partnerships & STEM Outreach: Established formal partnerships with local municipal government, school districts, and charitable groups to organize hands-on STEM education programs for area grade schools.
- Membership & Operational Growth: Recruited and developed a specialized membership base of technical operators, delivering recurring field training to enhance community emergency response capabilities.
Program Manager II
2014 – 2017
Led malware escalation coordination, industry security partnerships, and global threat intelligence communications for the Malware Protection Center to advance Microsoft’s enterprise security posture.
- Global Incident & Escalation Leadership: Directed Windows Defender Labs response workflows for high-priority customer malware escalations, managing analyst teams and cross-functional stakeholders to deliver rapid threat mitigation and clear customer communications.
- Security Ecosystem & Partnership Programs: Managed Microsoft’s strategic security alliance programs, including VIA, MVI, and CME, defining global membership criteria, reviewing legal agreements, and building onboarding frameworks to facilitate secure industry collaboration.
- Threat Intelligence & Executive Communications: Analyzed global telemetry data and authored core content for the Microsoft Security Intelligence Report (SIR), driving public communications, technical blogs, media briefings, and executive presentations.
- Industry Alliance & Event Coordination: Planned and executed the Microsoft Security Response Alliance (MSRA) conference, uniting global industry leaders, government partners, and security researchers to advance joint malware eradication strategies.
Secretary & Treasurer
2016 – 2017
Overhauled financial systems, corporate governance, and operational records to secure federal tax-exempt status for a regional communications organization.
- 501(c)(3) Tax Status Qualification: Spearheaded organizational restructuring, including modernizing corporate purpose, operational policies, and documentation, to successfully qualify the group for IRS 501(c)(3) tax-exempt status.
- Financial Architecture & Budgeting: Implemented the organization’s first formal annual budgeting process, establishing recurring monthly financial reporting and performance tracking.
- Governance & Records Modernization: Standardized board administration workflows, managing agendas, recording minutes, and migrating physical archives to a secure cloud repository.
Treasurer
2013 – 2014
Led financial modernization, digital workflow implementation, and peer support initiatives for a prominent regional community organization.
- Financial Systems Modernization: Transitioned the organization from legacy paper accounting to QuickBooks and built a streamlined digital expense-reporting workflow on SharePoint Online.
- Community Support & Facilitation: Led peer support meetings, providing structured guidance, crisis navigation, and safe discussion spaces for LGBTQ+ individuals and families.
Software Development Engineer
2005 – 2014
Contributed to antimalware research, legal risk mitigation, and threat classification for Microsoft’s antimalware platform, collaborating closely with Microsoft Research, Legal, and the Malware Protection Center to safeguard platform integrity.
- $23M Legal Risk Mitigation: Completed specialized paralegal training to proactively identify international litigation risks and independently design a legally rigorous evidence-retention framework. This foresight ensured the preservation of critical behavioral data that ultimately defeated a $23M lawsuit against Microsoft (Microsoft Corp. v. Aedge Performance Bcn, S.L., Case 560/2012, Juzgado de lo Mercantil, Barcelona). Authored core technical memorandums, compiled decisive evidence, and served as the primary expert witness to protect the platform.
- Patent & Research Innovation: Co-developed a patented malware detection method with Microsoft Research (US Patent 9021590 – link).
- Objective Criteria & Policy Governance: Authored and managed Microsoft’s Objective Criteria guidelines for spyware and adware; educated global research teams on evaluation standards to ensure consistent threat classification while minimizing legal exposure.
- Vendor Dispute Resolution: Evaluated complex software vendor inquiries regarding threat detections, documenting technical evidence and providing strategic recommendations to Legal and Corporate Affairs.
- Operational Continuity & Risk Management: Created the department’s malware sample retention policy to preserve historical evidence and conducted end-to-end gap analyses for external vendor management, validating business continuity through tabletop exercises.

Malware Researcher
Mischel Internet Security
2004 – 2005
Conducted specialized threat research and malware reverse engineering for Mischel Internet Security’s TrojanHunter platform, advancing detection capabilities for high-risk system threats.
- Threat Analysis & Engine Optimization: Analyzed emerging trojans, worms, rootkits, and spyware, authoring custom detection signatures and verifying automated engine remediation workflows.
- Community Technical Leadership: Monitored security forums and online threat research communities, providing high-level technical guidance, incident analysis, and direct support to users facing critical infections.
- Remediation Verification: Evaluated complex malware behaviors to ensure accurate threat classification, minimizing false positives and maintaining platform reliability.

Chief Research Officer
Lavasoft
2003 – 2004
Led threat research, policy development, and detection criteria for Lavasoft’s flagship Ad-Aware anti-spyware platform during the foundational era of desktop privacy and security.
- Threat Intelligence & Detection Standards: Spearheaded research into emerging adware, browser toolbars, and potentially unwanted applications (PUAs), establishing objective classification criteria and verifying core engine remediation rules.
- Vendor Relations & Technical Governance: Directed vendor dispute resolution for flagged software, collaborating directly with the core engineering team to refine detection logic and reduce false positives.
- Executive & Public Communications: Architected and authored the company’s security newsletter, delivering technical analysis, threat trend reports, and best-practice guidance to millions of global users.
- Cross-Functional Engine Optimization: Partnered with internal development teams to strengthen engine capabilities, accelerate definition rollouts, and stay ahead of rapidly evolving desktop threats.
Education
Oakland University
University of Washington
University of Washington
Federal Emergency Management Agency
National Registry of Emergency Medical Technicians
UMBC Emergency Health Services
Get in Touch
I am fully retired from corporate life. If you’re a former colleague, friend, or reaching out regarding personal or community preparedness projects, feel free to drop a message below.













