whoami
Systems Administrator & DevOps Engineer — Linux + Windows Enterprise Infrastructure
I sit at the intersection of people and systems: enterprise infrastructure modernization, cloud cost and architecture, and the automation that keeps it all reliable. Deep hands-on experience across AWS/GCP, virtualization (VMware, KVM, Hyper-V), containers, and both Linux and Windows Server environments — backed by a self-hosted homelab I run to the same standard as production.
Competed on a randomly-assigned 5-person team in AWS's timed security jam: real-world breach scenarios spanning website and JavaScript vulnerabilities through S3 and Lambda integrations behind VPC load balancers. My team completed the most challenges in the time given and took first place.
Planned and executed a ground-up infrastructure refresh: Active Directory rebuilt from Server 2003 to 2016, domain controllers migrated, Exchange 2003 virtualized ahead of a later Google Workspace migration, and consumer networking gear replaced with HP Enterprise equipment to support a new VOIP system. Weeks of planning and testing kept business-critical systems available through a 48-hour cutover window.
Spearheaded a cloud-based delivery pipeline for legacy Delphi desktop products using AWS AppStream 2.0, EC2, S3, Route 53, and Lambda. Trained and deployed the same pattern for other legacy applications as the company grew through two acquisitions — the platform is still running in production today.
Everything below runs on hardware I own and administer to production standards — version-controlled, documented per host, and treated as a real environment rather than a toy. It's also where I test things before I'd ever trust them at work.
A Proxmox host runs dedicated containers for storage/NAS, a media automation stack, reverse-proxy/TLS termination, and a management & Ansible control node — each isolated by function, each with its own runbook.
A single physical workstation serves as both an Arch/Fedora Linux host and, via libvirt/KVM with full PCIe GPU passthrough, a Windows 11 guest with near-native GPU performance. Along the way: raw NVMe passthrough, Secure Boot key enrollment through virt-firmware, VFIO hook automation, and tracking down a Core Isolation/VBS bug that was silently pegging a virtual CPU.
Grafana, Prometheus, and Loki cover metrics and logs across every host, with systemd-journal-remote centralizing logs for post-incident diagnostics. Tailscale ties every device into a private mesh, with Funnel used to selectively expose specific services.
Every homelab host runs an agent server that a central Claude Code instance can delegate real file edits and command execution to directly — plus local API-backed integrations for Proxmox and Grafana. It's a practical testbed for how much day-to-day sysadmin work can be safely delegated to an AI agent, and where the guardrails need to be.
Open to Systems Engineer, Systems Administrator, and DevOps roles. Reach out directly: