🟒 Open to conversations

Patrick de Ruiter

Senior Platform Engineer

25+ years bridging classic Linux infrastructure and modern cloud-native platforms.

Experience

Each role includes a collapsible β€œhonest backstory” β€” the real story behind the bullets.

Senior Platform Engineer

Benerail

2022-11-01 – present

Own the platform engineering stack across a primary + DR on-prem datacenter setup, Terraform, Packer images and Ansible roles deploy identically to both sites, with Vault and observability replicated for failover. Introduced Terraform as the IaC standard. Designed and shipped a Prometheus/Grafana observability platform. Built golden-image lifecycle management with Packer. Automated VMware vSphere provisioning with Ansible + Terraform. Migrated the estate from RHEL 8 to RHEL 9 with SELinux enforcing as the platform standard. Designed an end-to-end certificate management system using Terraform, Let's Encrypt, Event Driven Ansible and HashiCorp Vault β€” including a custom Go module for the DNS-01 challenge. Professionalized the on-prem Kubernetes platform. Deployed Databricks on Azure with Terraform and stood up Azure ↔ on-prem VPN. Implemented Ansible Automation Platform for centralised automation, including a self-hosted Ansible Galaxy-NG for distributing internal collections. Designed and implemented Keycloak and Hashicorp Vault sollution for Kubernetes and portal authentication using OIDC,SAML and 2FA, that integrated with the existing IaM systems Red Hat Idm, and Microsoft Entra ID.

Senior Cloud Infrastructure Engineer

DeltaFiber

2022-03-01 – 2022-10-31

Hybrid-cloud platform engineering at a multi-DC ISP β€” designed and implemented an Azure Kubernetes Service (AKS) platform from scratch, including all Terraform modules, federated with the existing on-prem datacenters. Deployed HashiCorp Consul for service discovery and mesh spanning the hybrid estate, and design and deploy an IaM solution based on HashiCorp Vault for secrets management and Microsoft Entra ID for user group and role management across both Azure and on-prem environments. Introduced Terraform as the IaC standard.

Lead CI/CD Engineer

Sanoma Learning

2020-04-01 – 2022-03-31

Migrated applications from conventional stacks to Kubernetes on EKS. Phased out Red Hat Satellite as the estate moved to cloud + Kubernetes. Standardized RHEL AMI images, built automatically with Packer + Ansible β€” updating an EC2 image became a one-click redeploy. Owned deployment pipelines on Jenkins and Bitbucket Pipelines. Selected and implemented Datadog as the monitoring solution. Embedded security and compliance procedures in CI/CD. Designed Docker base images for application teams. Maintained the AWS environment via CloudFormation and Terraform.

Cloud Infrastructure Engineer

CarNext

2019-01-01 – 2020-04-30

Migrated CarNext out of Leaseplan AWS accounts into dedicated ones. Designed and shipped the EKS cluster using Terraform + GitLab CI/CD. Replaced CloudFormation with Terraform. Built a CI/CD toolkit for ECS deployments, later extended for Kubernetes. Implemented Kong API Gateway, OpenVPN for secure access, and templated git repositories. Configured cross-account IAM roles in a multi-account AWS setup. Rolled out AWS Transit Gateway to replace VPC peerings. Implemented GuardDuty, Config and CloudTrail in a central audit account.

Cloud Infrastructure Engineer

TNT Digital

2018-04-01 – 2018-12-31

Managed production Kubernetes clusters. Upgraded and operated OTAP environments running Adobe AEM CMS for the company portal. Rewrote Terraform modules for AEM EC2 instances on AWS. Refactored the Ansible codebase. Created and maintained Helm charts plus Docker / Docker Compose configurations. Operated Jenkins servers and embedded developers into the CI/CD flow. Ran a federated Prometheus + Grafana setup. Scripted ETCD backup via a oneshot Kubernetes container. Wired Alertmanager into Slack and PagerDuty.

Cloud Specialist

TripleIT

2018-02-01 – 2018-03-31

Short engagement: designed and built a multi-tier web application framework. Translated customer requirements into technical design and produced the LLD from the HLD.

Senior Linux Infrastructure Specialist

SSC-I Dienst JustitiΓ«le Inrichtingen

2017-01-01 – 2017-12-31

Deployed and managed RHEL systems via Red Hat Satellite 6. Automated VM deployments to VMware vSphere via Satellite. Automated operations using Ansible and Puppet. Migrated RHEL 5/6 systems to RHEL 7. Introduced GitFlow for structured version control.

Senior Unix Infrastructure Specialist

Tele2

2016-06-01 – 2016-12-31

Operated a heterogeneous fleet (Red Hat, CentOS, Debian, Ubuntu, Solaris, HP-UX) across two active/active datacenters. Deployed DTAP environments for application development. Wrote and extended Puppet modules. Managed and configured DNS infrastructure (BIND, PowerDNS, Unbound).

Senior Linux Infrastructure Consultant

Nationale Nederlanden Investment Partners

2014-03-01 – 2016-06-30

Owned Linux infrastructure across two active/active datacenters. Upgraded all RHEL 5 nodes to RHEL 6. Designed and implemented CFEngine for configuration management, including Operational Security Guidelines (OSG) policy. Enabled SELinux in enforcing mode across the entire fleet and authored / modified targeted-policy modules so every service (Tomcat, Tibco, Apache, the in-house Java apps) ran cleanly without permissive fallback. Automated VM provisioning. Replaced an end-of-life Red Hat Satellite with Pulp for update and package management. Introduced Git for version control of infrastructure code. Designed and implemented a master-master replicated MySQL platform as a standardized building block, spanning both DCs. Insourced a complete multi-tier OTAP application landscape for pension insurances. Designed the Linux infrastructure for the main website and the Financial API. Designed a central authn/authz platform on FreeIPA.

Senior Linux Infrastructure Consultant

Global Collect Services

2013-01-01 – 2013-12-31

Built infrastructure across two active/active datacenters. Stood up a private vCloud from the ground up for test, development and staging. Designed a fully automated Kickstart environment for VM deployment (including OS hardening) and a parallel one for ESXi node deployment. Enabled SELinux in enforcing mode fleet-wide and authored / modified the targeted-policy modules so every running service complied, no permissive escapes. Implemented CFEngine 3 for configuration management. Implemented an Iam platform based on Red Hat Idm, and used Microsoft Active Directory as a federation source, so that the complete authentication and authorisation process could be centralized. Designed monitoring + trending solution based on Nagios and Cacti. Tuned RHEL vms and VMware platform for performance.

Senior Linux Infrastructure Consultant

Ministerie van Economische Zaken, Landbouw en Innovatie

2012-04-01 – 2012-12-31

Built greenfield Linux infrastructure on Red Hat Enterprise Linux for the ministry. Designed monitoring on Nagios, implemented Puppet for configuration management (with custom modules where the Forge fell short), and built HA failover with Pacemaker + Corosync. Operated multi-tier web stacks on jBoss + PostgreSQL clusters. Owned patch + security management and incident response. Stack: RHEL, jBoss, PostgreSQL, Puppet, Cobbler, NetApp, NetBackup.

Senior Unix Consultant

KPN Hosting Services

2011-07-01 – 2012-01-31

Operated and configured RHEL and Solaris systems at scale within KPN's hosting business. Monitored services with Nagios + Cacti, ran multi-tier web stacks on Tomcat / jBoss, managed Varnish caching and Memcached, MS SQL and MySQL. Daily change/incident management.

Senior Unix Beheerder

Vancis B.V.

2010-02-01 – 2011-03-31

Designed, installed and operated RHEL, Debian, Solaris and AIX systems for hosting customers across two datacenters. Redesigned and upgraded the VMware ESX 3.5 cluster to vSphere 4. Designed a new CFEngine 3 configuration management framework, managed Postfix / Exim mail platforms with anti-spam/anti-virus, EMC Clarion storage, Cisco ASA + Fortigate firewalls, PostgreSQL clusters, PowerDNS + BIND, NFS + Samba file servers, Tivoli Storage Manager backups, Linux LVS for failover and load balancing.

Senior Unix Beheerder

EspritXB Managed Hosting

2009-02-01 – 2010-02-28

ISP-grade Linux + Solaris operations for managed hosting. Designed and shipped a new mail platform on Postfix + Amavisd + PolicyD + Spamassassin. Operated 2Γ—12 clustered VMware ESX servers with HP Left Hand virtual SAN, Tomcat / jBoss / Glassfish application servers, Netvault backup against 40 TB of storage, Linux LVS for failover. Tuned the kernel and TCP/IP stacks on Linux and Solaris. Designed a CFEngine configuration management framework. Operated Confluence + Jira + CVS/SVN, and Tridion CMS.

Linux Consultant

Tweede Kamer der Staten-Generaal

2008-07-01 – 2009-02-28

Linux consultancy for the Dutch House of Representatives. Upgraded the Red Hat Enterprise Linux estate and kept the public websites β€” tweedekamer.nl, eerstekamer.nl, derdekamer.nl β€” plus the intranet running. Implemented a central authentication platform on OpenLDAP + Kerberos + Samba, set up the backup environment, owned Unix-side security across the fleet, monitored all systems and designed new capabilities. Stack: RHEL, Tridion CMS, Apache, PHP, MySQL, OpenLDAP, Kerberos, Samba, Oracle 10.

Linux Consultant

KPMG Meijburg & Co

2008-03-01 – 2008-07-31

Short engagement at the tax-advisory practice. Built a SAN environment on NetApp Filers, implemented GFS Cluster File System, designed data collection for performance metrics and wrote shell-based intelligent monitoring scripts. Analysed performance of the existing Oracle platform and advised on the upgrade. Stack: RHEL, Windows 2003, VMware, Oracle, GFS, NetApp, ITIL.

Linux Consultant

Ministerie van Verkeer en Waterstaat

2007-11-01 – 2008-02-29

Linux consultancy on the Capgemini outsourcing of ~14,000 workplaces for Rijkswaterstaat. Inventoried the in-use applications and wrote the transition strategy for the "Basishosting" application cluster β€” the portal underpinning every other web app β€” moving operations from RWS to Capgemini. Stack: RHEL, SUSE Linux, Apache, ITIL, Prince2.

Unix System Specialist

@Home

2006-12-01 – 2007-10-31

ISP operations at scale β€” ~600 Ubuntu/Debian servers and ~160 Sun Solaris servers. Designed and operated network + system monitoring (Cacti, SNMP, RRDTool), managed Veritas NetBackup with a Sun L100 tape robot and a NetApp VTL, ran DNS, mail, news, LDAP, NTP and web infrastructure. Patch + security management across the fleet, Oracle 10g and MySQL administration.

Unix Systeem Beheerder

Nedstat B.V.

2004-02-01 – 2006-11-30

Unix systems engineering for the Sitestat web-analytics ASP platform on Solaris, RHEL, Debian, FreeBSD and OpenBSD. Designed and operated the SMTP stack (Postfix + DSPAM) with virus + spam filtering, an OpenLDAP authentication infrastructure, redundant MySQL database servers, Apache for the Sitestat ASP, NFS + Samba storage on a SAN, and a Nagios + MRTG + RRD monitoring platform. VPN infrastructure, DNS infrastructure, security tooling (Nmap, Nessus, Snort), Cisco PIX firewalls + load balancers + switches. Wrote scaling advisories for customers running Sitestat on-premise.

Unix Systeem Beheerder

Backbone Consultancy and Services

2003-06-01 – 2003-12-31

Datacenter Unix administration. Operated a wireless mesh routing network, designed and managed RHEL / Mandrake / SUSE Linux servers and firewalls, MySQL, Apache, and PPTP VPN servers on Linux / FreeBSD / OpenBSD. Patch, change and security management.

Windows–Unix Systeem Beheerder

Bourse Du Vin International

2001-11-01 – 2003-05-31

Retail multi-OS operations across NL, Belgium and France. Managed Windows NT 4 / 2000 / XP servers + workstations, Mac OS 9 and OS X workstations + servers, Solaris database servers, MS SQL and MySQL. Designed DHCP / DNS / WINS, an OpenBSD-based network monitoring stack (Nagios + MRTG + RRD), Veritas / ArcServe / ufsdump backups, Sendmail on DG-UX, networking (routers, switches, frame-relay, ISDN). 3rd-line support for Solaris + Windows + VPN, remote operations across three countries.

Unix Systeem Beheerder

Getronics Network Services

2001-06-01 – 2001-11-30

Unix administration on Solaris, Linux, FreeBSD and OpenBSD systems. Kernel and TCP/IP stack tuning. Daily admin, software installation, user/group management. HP OpenView NNM + Nagios for monitoring. Firewall installation and management across Checkpoint FW-1, Cisco PIX, iptables, IPF and PF. Operated mail (Sendmail / Qmail-LDAP / Postfix), web (Apache / iPlanet), LDAP (OpenLDAP / iPlanet Directory Server) and DNS. Change/incident management via Aplix helpdesk; monthly customer reporting + advisories.

3rd-line Helpdeskmedewerker

Freeler

2000-06-01 – 2001-05-31

3rd-line helpdesk at the ISP β€” resolved technical incidents via phone, email, fax and IRC. Escalated systemic incidents to systems administration, maintained the customer database, identified recurring problem patterns and engineered solutions. Stack: Solaris, FreeBSD, Linux, Qmail, Roxen, Oracle.

Medewerker Technische Dienst

Computer Point Almere

1999-10-01 – 2000-04-30

Technical-services role at a computer retailer β€” troubleshooting hardware and software on Windows, Linux and Mac. Installed and configured computers and networking gear (Windows NT 4, Mac OS, Linux). Advised customers on hardware/software configurations, assembled and upgraded computers, supported sales and procurement.

Skills

Honest self-assessment β€” including what I'm not.

βœ“ Strong

  • Kubernetes8y

    On-prem, EKS and AKS. Production clusters with Flux GitOps in the homelab and at Benerail.

  • Container image authoring (multi-stage builds, minimal base, CI/CD-driven)9y

    Author Dockerfiles with multi-stage builds and minimal base images (distroless / Alpine / scratch where it fits) β€” final images are typically well under 100 MB. Aggressive layer-cache ordering so rebuilds reuse layers cheaply and the registry doesn't churn. Automate the whole flow through CI/CD pipelines (the wbyc ci-cd-toolkit does build β†’ Hadolint β†’ SonarQube β†’ Trivy β†’ push β†’ image-tag commit on every push), so a developer never builds a production image by hand. Smaller images ripple into faster K8s rollouts and Flux reconciles.

  • VM β†’ container migration (on-prem + cloud: Docker, K8s, EKS, AKS, ECS, ACI)8y

    Planned and executed VM-to-container migrations across multiple orgs and clouds β€” Sanoma (legacy app stacks β†’ EKS), CarNext (EKS greenfield + AWS ECS for the services that didn't justify a K8s footprint), DeltaFiber (AKS from scratch, hybrid into Azure), Benerail (on-prem K8s + RHEL). The pattern: triage what containerises cleanly vs what stays a VM; dockerise without init-system kludges; wire health / readiness probes, secrets, config and observability properly from day one; then GitOps the rollout. Comfortable picking the right runtime per workload β€” K8s for stateful/multi-service, ECS / AKS managed for thin services, ACI for one-shot batch.

  • Terraform8y

    Have introduced it as the IaC standard in four separate orgs. Modules, state migrations, cross-account.

  • Ansible10y

    Built and refactored multiple Ansible codebases. Run Ansible Automation Platform / EDA in anger.

  • Linux (RHEL / CentOS / Debian / Ubuntu)25y

    Started 25+ years ago and never stopped. RHEL 5 β†’ 9 migrations across multiple roles.

  • Multi-DC active/active design12y

    Designed and operated platforms spanning two or more datacenters from Global Collect (2013) through NNIP, Tele2, DeltaFiber (hybrid Azure + on-prem) to Benerail (primary + DR). Replicated state stores, cross-DC service mesh, identical IaC deploys to every site.

  • Packer7y

    End-to-end golden-image lifecycle pipelines at Benerail, Sanoma, CarNext and in my homelab.

  • HashiCorp Vault6y

    3-node Raft cluster in the homelab. Designed Vault-backed cert management with EDA. Implemented multiple Vault clusters varying in size and integrated it with CI/CD processes, Using Entra ID, OpenLDAP and Keycloak as base components of an IaM system

  • HashiCorp Consul4y

    Designed service discovery + mesh at DeltaFiber and run a cluster in my homelab. Configure HaProxy and Consul to automatically add and remove nodes from backends for scalability and automation purposes.

  • GitLab CI/CD6y

    Wrote and maintain the wbyc ci-cd-toolkit. GitLab is the org standard. at Deltafiber, Carnext, Centric and in my homelab, extensive knowldge of Implementation and usage of GitLab, including the builtin CI/CD tooling.

  • Flux CD3y

    GitOps for the homelab infrastructure-config; comfortable with image automation, source controllers, dependencies.

  • Prometheus + Grafana + Alertmanager7y

    Designed observability platforms top-to-bottom; federated setups; PagerDuty/Slack wiring.

  • Go4y

    Wrote a Let's Encrypt DNS-01 verification module for Traefik and Terraform ACME integration. Use it for tooling.

  • Python12y

    Daily-driver for automation glue and small services.

  • Bash25y

    It's like breathing.

  • VMware vSphere15y

    VCP since 2009. Automated provisioning, golden images, performance tuning. vApp

  • AWS (EKS, IaM, Transit Gateway, GuardDuty)7y

    Multi-account designs, cross-account IaM, EKS clusters, audit-account security tooling.

  • Azure (AKS, Databricks, VPN to on-prem)4y

    Designed AKS platforms; ran Databricks via Terraform; site-to-site VPN to on-prem.

  • PostgreSQL + CloudNativePG6y

    CNPG cluster in the homelab as the central DB platform; replication, backups, recovery.

  • Traefik5y

    Primary ingress at home and on Pangolin/Hetzner. Let's Encrypt DNS-01 via TransIP.

  • Cert-manager + Let's Encrypt5y

    cluster-issuer setups, DNS-01 webhooks (incl. TransIP), Vault-backed PKI.

  • External-DNS4y

    Use external-dns in every K8s cluster I run to keep DNS records in sync with Ingress / Service resources. Comfortable with the TransIP webhook for my own zones, RFC2136 against BIND for the homelab, and the AWS Route53 / Azure DNS providers from the cloud work. Owner-ID + TXT-record bookkeeping understood β€” no orphan-record surprises.

  • External-Secrets Operator3y

    ClusterSecretStore with Vault backend in every K8s app I run.

  • Event Driven Ansible (EDA)3y

    Built the cert renewal pipeline at Benerail; rulebooks triggered from CI/CD events.

  • Ansible Galaxy-NG (private hosting)3y

    Run a self-hosted Galaxy-NG instance for distributing internal Ansible collections β€” synced against public Galaxy + Automation Hub upstreams, RBAC and namespace ownership, signed-content workflow, integrated with the Ansible Automation Platform stack at Benerail. Comfortable with the Pulp underneath when something needs unpicking.

  • Kustomize4y

    Primary tool for my Flux-managed apps.

  • BIND / DNS15y

    Self-hosted DNS with DNSSEC in the homelab. BIND, PowerDNS, Unbound across past roles.

  • Loki3y

    Part of the observability stack at home; cross-cluster log push via Alloy.

  • Argo CD2y

    Familiar with the operating model; Flux is my primary but I'm fluent in ArgoCD patterns.

  • Apache HTTP Server22y

    Operated Apache across nearly every Linux role from 2001 onward. Still my default when Nginx or Caddy aren't the right fit.

  • HAProxy8y

    L4/L7 LB across multiple roles. Comfortable with stick-tables, sticky sessions, ACL routing, runtime API, and the HAProxy + Keepalived HA pattern, Data Plane Api and Automations, including using Consul to automatically scale and automate backend management.

  • Postfix / SMTP platforms20y

    Designed and operated ISP-grade Postfix stacks at Nedstat, @Home, EspritXB and Vancis (Amavisd + Spamassassin + PolicyD + Dovecot + LDAP). Comfortable with deliverability, SPF/DKIM/DMARC, transport maps and large-scale relay design.

  • FreeIPA / Red Hat IdM10y

    Designed central authn/authz on FreeIPA at Global Collect and NNIP, integrated SSSD on the host side. Comfortable with replication topology, HBAC/sudo rules, cert services. Integrated it with Active Directory, Keycloak and Hashicorp Vault.

  • Pacemaker / Corosync / DRBD10y

    Linux HA stack for active/passive failover from Red Hat Cluster Suite onwards. Comfortable with fencing/STONITH and split-brain debugging.

  • LVS + Keepalived10y

    Linux Virtual Server for L4 load balancing + Keepalived for VIP failover. Used at EspritXB, Vancis and earlier before HAProxy became dominant.

  • SELinux (policy authoring + fleet enforcement)10y

    Used extensively at Benerail, NNIP and Global Collect. At Global Collect and NNIP I enabled SELinux fleet-wide and modified the targeted-policy modules to make every service comply with enforcing mode β€” auditing AVC denials, writing custom .te / .fc / .if rules, building and shipping policy packages alongside the rest of the infrastructure code.

β—‹ Moderate

  • Docker Swarm6y

    Run a Swarm cluster at home for legacy self-hosted apps. Kubernetes is my primary now.

  • Jenkins8y

    Owned Jenkins at Sanoma and TNT Digital. Functional but I'd default to GitLab CI today.

  • Bitbucket Pipelines3y

    Used at Sanoma; fine but not my first pick.

  • CloudFormation3y

    Maintained at Sanoma; replaced with Terraform whenever I could.

  • Puppet6y

    Heavy use up to ~2017 (Manageable Puppet Infrastructure cert). Could pick it back up if needed.

  • CFEngine8y

    Built whole platforms on it 2008–2016. Would recommend it for environments where speed and resource consumption is important ,I can both read and write it fluently.0

  • OpenLDAP + Kerberos8y

    Designed an HA IAM stack on these in the homelab and at NNIP. Very light weight compared to all the enterprise solutions.

  • Longhorn3y

    Production block storage in the homelab. Have lived through the capacity-management pain.

  • MinIO4y

    Backs Terraform state + Restic in the homelab. Worked with it extensively at Benerail from automating bucket and policy management with Terraform and Ansible as well as troubleshooting performance issues on multi node clusters

  • Datadog3y

    Selected and rolled out at Sanoma. Capable, but I'd build on Prometheus/Grafana given the choice.

  • Helm5y

    Use it daily but prefer Kustomize for what I own.

  • Keycloak3y

    Run it in the cluster as the SSO provider. Comfortable with realms, clients, identity federation.

  • Kong API Gateway1y

    Implemented at CarNext; functional knowledge.

  • Adobe AEM operations1y

    TNT Digital. Operated it, did not develop on it.

  • Solaris / HP-UX10y

    SCSA 1 & 2 (2007). Haven't touched either in years; included for completeness only.

  • IBM WebSphere6y

    Older role exposure. Wouldn't volunteer to run it again.

  • Elasticsearch3y

    Operated ELK as part of observability stacks; not a search-relevance expert, but know my way around and can solve common problems

  • Sealed Secrets2y

    Have used it; External-Secrets is what I default to now for Vault-backed K8s secrets.

  • Tomcat / jBoss / Glassfish12y

    Operated Java application servers at @Home, EspritXB, Vancis, KPN Hosting and the ministry. Functional, not a Java developer.

  • MariaDB / Percona / MySQL18y

    Designed and operated MySQL family clusters since 2001. Built a master-master MySQL platform at NNIP. Galera, Percona XtraDB, MariaDB β€” workable, not deep DBA.

  • MongoDB4y

    Operated production replica sets; not my first datastore pick.

  • iptables / nftables18y

    Linux netfilter since the early 2000s, IPF/PF on BSD before that. Still hand-roll rules when nothing else fits.

  • Nagios / Cacti / SNMP18y

    Pre-Prometheus monitoring world β€” designed Nagios + Cacti + RRDTool at @Home, Nedstat and earlier. Still useful for poll-based equipment without a Prom exporter.

  • Red Hat Satellite / Spacewalk / Pulp12y

    Lifecycle + content at Tele2, SSC-I and NNIP, plus Pulp after Satellite EOL. Could pick it back up but cloud-native registries are my default now.

  • Enterprise storage (NetApp / EMC / HP 3Par / Dell Compellent / Huawei OceanStor)15y

    Hands-on operations across these arrays through Vancis / Global Collect / Tele2. SAN/NAS, snapshots, replication, capacity planning β€” solid generalist, not vendor-cert deep.

  • F5 BIG-IP / A10 load balancers5y

    F5 at NNIP and A10 at Tele2 β€” VIPs, basic iRules, SSL offload. Reach for HAProxy first when I get the choice.

  • Cisco ASA / Checkpoint FW1 / PIX8y

    Enterprise firewall operations across multiple roles. ASA as VPN concentrator with RSA SecurID, FW1 perimeter at NNIP, PIX legacy.

  • OpenSCAP / CIS hardening5y

    Inventoried + remediated compliance gaps with OpenSCAP at SSC-I, plus CFEngine-driven OSG hardening at NNIP.

  • Snort / Nessus / IDS tooling8y

    Snort across multiple roles, Nessus for vuln scanning at NNIP and earlier. Useful baseline, not a SOC analyst.

  • OpenBSD / FreeBSD15y

    Run OpenBSD in the homelab (PF firewalls, DNS, mail relays) and operated FreeBSD heavily at Nedstat and earlier. PF + IPF rule sets, base-system upgrades.

  • VMware vSphere / vCloud Director15y

    Built the private vCloud at Global Collect from the ground up; operated ESX 3.x β†’ vSphere 6 across nearly every role. Listed as moderate because cloud-native is my daily driver now β€” not because the depth isn't there.

βœ— Gaps

No gaps listed (suspicious).

Languages

Honest fit assessment

Paste a job description. Get an honest assessment of whether I'm the right person β€” including when I'm not.

minimum 50 characters
This signals something different than β€œplease consider my resume.” You're being qualified. Your time is valuable too.