Skip to content

Hello! I’m

Aaron Hulett

Retired | Former Microsoft PM/SDE & Managed Service Provider Senior TPM | Cybersecurity & Incident Response | NIST CSF & CIS

1530 P B Ln # H5702, Wichita Falls TX 76302-2612

About Me

I’m Aaron Hulett, a former Microsoft program manager and software engineer with a background in cybersecurity, incident response, and large-scale technical operations. Throughout my career, from co-inventing patented malware detection systems at Microsoft to streamlining multi-client IT operations and compliance, I specialized in turning technical ambiguity into clarity, resolving complex operational crises, and strengthening organizational resilience.

Beyond my corporate work, I have been deeply committed to civic preparedness. I’ve served in leadership and volunteer roles across CERT, firefighter rehabilitation, and amateur radio emergency communications, including single-handedly reviving the National Traffic System (NTS) infrastructure and sparking ARRL’s national “NTS 2.0” modernization effort. I also completed Emergency Medical Responder (EMR) training and became NREMT-registered to serve as a STOP THE BLEED instructor.

Now fully retired from corporate work, my focus has shifted to personal projects, civic preparedness, and life beyond the corporate grid.

Co-invented a patented malware detection system at Microsoft.
Led global malware incident coordination for Windows Defender.
Advised organizations on IT strategy, security, and resilience.

Career Track Record

Decades of experience spanning big tech, IT operations, and emergency management.

Cybersecurity & Threat Telemetry

Engineered malware detection algorithms, led global escalation workflows for Windows Defender, and co-invented patented antimalware systems (US Patent 9021590).

Enterprise IT Strategy & Architecture

Led multi-client IT modernization, compliance (NIST CSF, CIS Controls), and system architecture for healthcare and enterprise organizations.

Operational Resilience & Risk Mitigation

Designed business continuity, disaster recovery, and evidence-retention frameworks, including technical strategy that successfully mitigated $23M in litigation risk.

Crisis Operations & Emergency Management

HSEEP-compliant exercise design, Incident Action Plan (IAP) authoring, NIMS/ICS incident management, and firefighter rehabilitation operations.

Policy Governance & Legal Review

Authored Microsoft’s global spyware classification criteria and optimized vendor/partner SLAs, contracts, and compliance frameworks.

Program & Project Leadership

Directed complex portfolio projects and cross-functional engineering teams utilizing Agile/Waterfall methodologies.

Featured Publications & Projects

Key threat research, policy frameworks, network telemetry studies, and emergency infrastructure evaluation reports authored throughout my corporate and civic leadership.

West Gulf Division Emergency Communications Functional Exercise

ARRL West Gulf Division • Emergency Architecture & Documentation • Aug 2023

Co-directed and authored the HSEEP-compliant exercise architecture and Incident Action Plan (IAP) package for a multi-section functional exercise simulating a 100-mile telecommunications blackout in the Houston area. Designed inter-section HF/VHF/digital traffic routing infrastructure across Texas and Oklahoma to validate National Traffic System (NTS) disaster welfare message handling under full emergency conditions.

  • Incident Command & Planning (ICS): Authored the formal Incident Action Plan (IAP) incorporating ICS 201 Briefing, ICS 202 Objectives, ICS 204 Assignments, ICS 205 Radio Communications Plans, and ICS 208 Safety Messages.
  • Field Operations: Authored the Player Handbook establishing exercise scope, rules of engagement, simulated hurricane scenario, traffic routing tables, and radiogram standards.

Mentorfest 2021 Virtual Conference Production

ARRL North Texas Section • Live Event Architecture & Remote Broadcast • Apr 2021

Designed, engineered, and executed the technical architecture for ARRL North Texas’s first-ever virtual Mentorfest conference. Operating as sole technical producer from a single workstation with zero budget, architected a multi-point remote ingest workflow via Zoom, orchestrated 9+ hours of continuous live stream production, and routed low-latency video and audio to YouTube for a worldwide audience of amateur radio operators.

  • Remote Production & Video Routing: Managed real-time switching, presenter staging, screen sharing, and audio leveling for 7 distinct technical presentations.
  • Live Interactive Operations: Integrated live YouTube chat monitoring, door-prize entry workflows, and real-time Q&A relay.

DFW Metroplex Emergency Communications Functional Exercise

ARRL North Texas Section • HSEEP Planning, Execution & Evaluation • Nov – Dec 2020

Architected, executed, and evaluated a multi-county emergency communications functional exercise simulating a widespread cellular and telecommunications grid collapse across the Dallas/Fort Worth Metroplex.

  • Incident Command & Planning (ICS): Authored the formal Incident Action Plan (IAP) incorporating ICS 201 Briefing, ICS 202 Objectives, ICS 204 Assignments, ICS 205 Radio Communications Plans, and ICS 208 Safety Messages.
  • Field Operations: Authored the Player Handbook establishing exercise scope, safety protocols, and standardized radiogram reporting templates for participating operators.
  • Post-Exercise Evaluation: Authored the formal FEMA HSEEP-compliant After-Action Report / Improvement Plan (AAR/IP), evaluating Operational Communications and Situational Assessment core capabilities to establish corrective action roadmaps.

Hurricane Laura Traffic System Response

ARRL North Texas Section • Emergency Architecture & Whitepaper • Oct 2020

Authored the operational post-incident report and framework whitepaper establishing the Traffic System Incident Response Lifecycle. Developed a real-time NTS Status Dashboard integrating live radar, satellite telemetry, and NHC briefings, and standardized protocol mappings for converting Incident Command System (ICS) forms into over-the-air radiograms during major Gulf Coast hurricane activations.

Astronaut Traffic System Performance Whitepaper

ARRL North Texas Section • Network Telemetry & Data Analysis • July 2020

Authored an empirical analysis whitepaper collecting and evaluating over-the-air radiogram traffic sent to NASA astronauts aboard the International Space Station (ISS). Analyzed network telemetry, geographic distribution trends using 3D mapping, and cross-country radiogram transit times (averaging 2.6 days) to measure routine National Traffic System efficiency and benchmark operational baseline performance.

Microsoft Security Intelligence Reports (SIR)

Microsoft • Threat Intelligence & Global Telemetry • 2007 – 2016

Contributed specialized threat telemetry analysis, malware research, and visual technical evidence (including threat screenshots and trend breakdowns) across SIR volumes to translate complex telemetry into actionable security guidance for enterprise leadership and government partners.

Ransomware Protection in Windows 10 Anniversary Update

Microsoft • Technical Whitepaper • Nov 2016

Authored technical whitepaper detailing Microsoft’s multi-layered strategy (Prevent, Detect, Respond) to engineer ransomware resilience directly into Windows 10 enterprise architecture.

Spyware Detection Mechanism (US Patent 9021590)

Microsoft • Patented Technology & Innovation • Co-Inventor • 2008 / 2015

Co-invented a machine-implemented system and method for detecting surreptitious malware, DLL injection, and keyloggers hidden across operating system processes. Engineered process-monitoring algorithms that isolate non-whitelisted modules across active system events and honeypot execution environments to prioritize threat analysis.

I Know What You Did Last Logon

Virus Bulletin • Threat Research & Case Studies • Oct 2006

Conducted detailed threat analyses and case studies on monitoring software for this peer-reviewed publication, evaluating invasive software behaviors, stealth mechanisms, and privacy boundaries to establish technical classification standards for spyware.

Author Acknowledgement: Cited for conducting primary threat analysis alongside Microsoft’s anti-spyware research team.

Experience

Senior Technical Project Manager

Oversee My IT

2021 – 2025

Architected technical solutions, guided cybersecurity posture, and led hands-on IT implementation for healthcare and enterprise clients while directing a high-volume portfolio of concurrent projects.

  • Enterprise IT Strategy & Portfolio Leadership: Advised healthcare and enterprise organizations across the U.S. on IT strategy and system architecture, directing 15-30 concurrent technical projects to ensure on-time delivery and alignment with client business goals.
  • Cybersecurity & Compliance Frameworks: Developed and deployed security policies, controls, and risk assessments aligned with NIST CSF and CIS Controls, strengthening client compliance, data protection, and operational resilience.
  • Incident Response & Systems Engineering: Guided organizations through complex technical incidents, system integrations, and infrastructure upgrades, translating high-stakes security challenges into clear, actionable technical plans.
  • Service Architecture & Agreement Optimization: Streamlined client contracts and Service Level Agreements (SLAs), clarifying scope, deliverables, and operational boundaries to reduce ambiguity and drive client retention.
  • Executive Advisory & Process Optimization: Served as a trusted technical advisor to client leadership, providing actionable recommendations to modernize IT workflows, mitigate operational risk, and improve overall process efficiency.

President & Former VP of Operations

Little Elm Box 620 Support Co.

2023 – 2025

Supported firefighter rehabilitation operations through training design, process improvement, and field response.

  • Executive Leadership (President): Provided overarching leadership for the organization, guiding strategic growth, managing town agency relations, and driving volunteer recognition initiatives.

  • Agency Coordination: Established formal liaison and regular coordination meetings with Town of Little Elm first responders to align support services with active municipal needs.

  • Operational Management (VP of Ops): Directed firefighter rehabilitation operations, introduced recurring training curricula, and oversaw field response logistics to ensure responder safety during critical incidents.

Vice President & Director of Information Technology

Little Elm Friends of the Library

2023 – 2025

Directed IT strategy, cloud modernization, and board governance updates to strengthen operational efficiency and organizational outreach for the local library support foundation.

  • Cloud Migration & IT Strategy: Evaluated legacy technology usage and authored an actionable IT roadmap that spearheaded the transition to cloud-based collaboration tools and modernized the web presence.
  • Governance & Legal Compliance: Identified critical omissions in the organization’s Articles of Incorporation and drafted formal amendments to resolve compliance gaps and restore governance effectiveness.
  • Board Alignment & Leadership: Conducted one-on-one strategic sessions with board members to assess technology needs, align digital tools with organizational goals, and prioritize long-term initiatives.

CERT Instructor & Firefighter Rehab Captain

Denton County Office of Emergency Management

2017 – 2020, 2025

Led volunteer training design, firefighter rehabilitation operations, and field response strategies to strengthen county-wide emergency preparedness and responder support.

  • Curriculum & Medical Instruction: Redesigned and updated the FEMA Community Emergency Response Team (CERT) curriculum, incorporating hands-on practical exercises to elevate responder capability and field readiness, and delivered certified STOP THE BLEED life-safety training to community volunteers, elevating operational capability and field readiness.
  • Operational Metrics & Reporting: Established performance tracking, operational metrics, and reporting frameworks for firefighter rehab deployments, quantitatively demonstrating program impact to agency leadership.
  • Responder Support Operations: Authored recurring training modules, standard operating procedures, and tactical exercise scenarios to ensure responder safety and health during extended incident operations.

Section Traffic Manager

ARRL North Texas

2019 – 2024

Revitalized the emergency communications infrastructure across the North Texas amateur radio network and beyond, sparking national-level program reinvestment.

  • National Infrastructure Revitalization: Led a nationwide revitalization of the National Traffic System (NTS), working directly with Section Traffic Managers across the country to bridge operational gaps, re-establish message links, and overcome decades of structural stagnation. By implementing rigorous process development, modern training frameworks, and functional exercises, this comprehensive turnaround directly influenced and inspired ARRL Headquarters to launch its nationwide “NTS 2.0” modernization initiative.
  • Inter-Agency Interoperability: Engineered joint operational procedures and specialized training frameworks for nationwide ARRL/MARS exercises, ensuring seamless communications between civilian and military auxiliary networks.
  • Incident Lifecycle Architecture: Created a standardized Incident Response Lifecycle to streamline data routing, operational logistics, and information flow during emergency activations.
  • Digital Infrastructure & Dashboards: Spearheaded the migration of the section web infrastructure to WordPress and developed a real-time NTS status dashboard to maintain operational awareness during critical incidents.

Founder, Secretary & Treasurer

Coppell Amateur Radio Enthusiasts

2018 – 2019

Founded a 501(c)(3) public charity to advance amateur radio, emergency communications readiness, and STEM education across the Coppell community.

  • Organizational Formation & IRS Exemption: Incorporated the non-profit entity, drafted corporate governance documentation, and secured IRS 501(c)(3) tax-exempt status in under eight months.
  • Community Partnerships & STEM Outreach: Established formal partnerships with local municipal government, school districts, and charitable groups to organize hands-on STEM education programs for area grade schools.
  • Membership & Operational Growth: Recruited and developed a specialized membership base of technical operators, delivering recurring field training to enhance community emergency response capabilities.

Program Manager II

Microsoft

2014 – 2017

Led malware escalation coordination, industry security partnerships, and global threat intelligence communications for the Malware Protection Center to advance Microsoft’s enterprise security posture.

  • Global Incident & Escalation Leadership: Directed Windows Defender Labs response workflows for high-priority customer malware escalations, managing analyst teams and cross-functional stakeholders to deliver rapid threat mitigation and clear customer communications.
  • Security Ecosystem & Partnership Programs: Managed Microsoft’s strategic security alliance programs, including VIA, MVI, and CME, defining global membership criteria, reviewing legal agreements, and building onboarding frameworks to facilitate secure industry collaboration.
  • Threat Intelligence & Executive Communications: Analyzed global telemetry data and authored core content for the Microsoft Security Intelligence Report (SIR), driving public communications, technical blogs, media briefings, and executive presentations.
  • Industry Alliance & Event Coordination: Planned and executed the Microsoft Security Response Alliance (MSRA) conference, uniting global industry leaders, government partners, and security researchers to advance joint malware eradication strategies.

Secretary & Treasurer

Puget Sound Repeater Group

2016 – 2017

Overhauled financial systems, corporate governance, and operational records to secure federal tax-exempt status for a regional communications organization.

  • 501(c)(3) Tax Status Qualification: Spearheaded organizational restructuring, including modernizing corporate purpose, operational policies, and documentation, to successfully qualify the group for IRS 501(c)(3) tax-exempt status.
  • Financial Architecture & Budgeting: Implemented the organization’s first formal annual budgeting process, establishing recurring monthly financial reporting and performance tracking.
  • Governance & Records Modernization: Standardized board administration workflows, managing agendas, recording minutes, and migrating physical archives to a secure cloud repository.

Treasurer

PFLAG Seattle

2013 – 2014

Led financial modernization, digital workflow implementation, and peer support initiatives for a prominent regional community organization.

  • Financial Systems Modernization: Transitioned the organization from legacy paper accounting to QuickBooks and built a streamlined digital expense-reporting workflow on SharePoint Online.
  • Community Support & Facilitation: Led peer support meetings, providing structured guidance, crisis navigation, and safe discussion spaces for LGBTQ+ individuals and families.

Software Development Engineer

Microsoft

2005 – 2014

Contributed to antimalware research, legal risk mitigation, and threat classification for Microsoft’s antimalware platform, collaborating closely with Microsoft Research, Legal, and the Malware Protection Center to safeguard platform integrity.

  • $23M Legal Risk Mitigation: Completed specialized paralegal training to proactively identify international litigation risks and independently design a legally rigorous evidence-retention framework. This foresight ensured the preservation of critical behavioral data that ultimately defeated a $23M lawsuit against Microsoft (Microsoft Corp. v. Aedge Performance Bcn, S.L., Case 560/2012, Juzgado de lo Mercantil, Barcelona). Authored core technical memorandums, compiled decisive evidence, and served as the primary expert witness to protect the platform.
  • Patent & Research Innovation: Co-developed a patented malware detection method with Microsoft Research (US Patent 9021590 – link).
  • Objective Criteria & Policy Governance: Authored and managed Microsoft’s Objective Criteria guidelines for spyware and adware; educated global research teams on evaluation standards to ensure consistent threat classification while minimizing legal exposure.
  • Vendor Dispute Resolution: Evaluated complex software vendor inquiries regarding threat detections, documenting technical evidence and providing strategic recommendations to Legal and Corporate Affairs.
  • Operational Continuity & Risk Management: Created the department’s malware sample retention policy to preserve historical evidence and conducted end-to-end gap analyses for external vendor management, validating business continuity through tabletop exercises.

Malware Researcher

Mischel Internet Security

2004 – 2005

Conducted specialized threat research and malware reverse engineering for Mischel Internet Security’s TrojanHunter platform, advancing detection capabilities for high-risk system threats.

  • Threat Analysis & Engine Optimization: Analyzed emerging trojans, worms, rootkits, and spyware, authoring custom detection signatures and verifying automated engine remediation workflows.
  • Community Technical Leadership: Monitored security forums and online threat research communities, providing high-level technical guidance, incident analysis, and direct support to users facing critical infections.
  • Remediation Verification: Evaluated complex malware behaviors to ensure accurate threat classification, minimizing false positives and maintaining platform reliability.

Chief Research Officer

Lavasoft

2003 – 2004

Led threat research, policy development, and detection criteria for Lavasoft’s flagship Ad-Aware anti-spyware platform during the foundational era of desktop privacy and security.

  • Threat Intelligence & Detection Standards: Spearheaded research into emerging adware, browser toolbars, and potentially unwanted applications (PUAs), establishing objective classification criteria and verifying core engine remediation rules.
  • Vendor Relations & Technical Governance: Directed vendor dispute resolution for flagged software, collaborating directly with the core engineering team to refine detection logic and reduce false positives.
  • Executive & Public Communications: Architected and authored the company’s security newsletter, delivering technical analysis, threat trend reports, and best-practice guidance to millions of global users.
  • Cross-Functional Engine Optimization: Partnered with internal development teams to strengthen engine capabilities, accelerate definition rollouts, and stay ahead of rapidly evolving desktop threats.

Education

B.S. Computer Engineering

Oakland University

Project Management Certificate Program

University of Washington

Paralegal Studies Certificate Program

University of Washington

EMI Professional Development Series

Federal Emergency Management Agency

Emergency Medical Responder (EMR)

National Registry of Emergency Medical Technicians

Certification in Critical Incident Stress Management (CISM)

UMBC Emergency Health Services

Get in Touch

I am fully retired from corporate life. If you’re a former colleague, friend, or reaching out regarding personal or community preparedness projects, feel free to drop a message below.

LinkedIn

Address

1530 P B Ln # H5702
Wichita Falls, TX 76302-2612

Contact me