Linux & cloud at the core, security everywhere

My core is Linux systems administration in the cloud. On top of it I build automation and SRE practices, and security runs through all of it.

Daily use Proficient Practicing
Core

Linux & Cloud

  • Linux / Unix administration
  • Bare-metal hypervisors at scale
  • Patching with zero unplanned downtime
  • OCI: Compute · VCN · IAM
  • OCI Autonomous DB · mTLS
  • VMware ESXi
  • Windows Server
  • Networking · iptables · firewalls
  • Nginx · Tomcat · Java runtime
SRE

SRE & Automation

  • Python
  • Bash
  • Incident response · on-call
  • Runbooks & knowledge base
  • KPI / SLO dashboards
  • Docker · Compose
  • CI/CD · GitHub Actions
  • Splunk · ELK
  • PowerShell
  • Kubernetes
DevSecOps

Security

  • Least privilege · IAM
  • Credential hygiene
  • Vulnerability remediation
  • Server hardening
  • TLS · mTLS · PKI
  • Nessus
  • Burp Suite
  • Ethical hacking & OSINT (labs)
  • Cloud security (CCSK in progress)

What I use day to day

Systems & cloud

Oracle LinuxUbuntuWindows ServerOCIAutonomous DBOracle XEVMware ESXiRaspberry Pisystemdiptables

Automation & delivery

PythonBashPowerShellGitGitHub ActionsDockerDocker ComposeKubernetes

Web & runtime

NginxApache TomcatJava (Temurin)Let's Encrypt · CertbotCloudflare · Tunnel

Observability & security

SplunkELKNessusBurp SuiteKali LinuxffufSecLists

About the levels: they're an honest self-assessment. The evidence for each one is in Experience and Projects.

Measured, not just claimed

I took the Aramis:Insight self-assessment, aligned to the NIST NICE framework. It compares what you think you know against what you demonstrate in scenarios. Here are my results, including the area where I have the most to learn.

Specialized practice

Demonstrated > self-rating
Doing
83%
Concepts
n/a

Executive Cybersecurity Leadership

Demonstrated > self-rating
Doing
67%
Concepts
n/a

Security Control Assessment

Growth area
Doing
33%
Concepts
67%

I know the theory; I need more hands-on practice applying control frameworks. It's my top study priority.

Cybersecurity Architecture

Being assessed

Not enough answers yet for a score. Area to work on: maturity models and frameworks.

My study roadmap

Priority 1

Security Control Assessment

  • Assess controls with NIST SP 800-53A and SP 800-53 r5
  • Risk Management Framework activities and documentation
  • Practice it on my homelab and write it up here
  • CCSK: target exam October 2026
Priority 2

Cybersecurity Architecture

Priority 3

Executive Cybersecurity Leadership

Priority 4

Specialized practice

Preliminary results: Aramis:Insight is a new assessment still being calibrated, and several areas need more answered questions to be read in full. Assessment taken September 2026.

Looking for this stack?

Whether it's a freelance project or an opportunity, drop me a line.

Get in touch