Infrastructure and Security Engineer. Currently specializing in security operations.
Securing Infrastructure. Specializing in Security.
Five years managing production infrastructure, web security and incident response. Currently specializing in Security Operations with a long-term focus on Cloud Security.
professional evolution
Every stage, building on the last.
Read it like a commit history. Nothing here is a rewrite. It's one continuous branch: understanding how systems work, then how they break, then how to defend them, each stage a specialization of the one before it.
-
a3f9c1
WordPress Developer
5+ years shipping and maintaining production sites for remote agencies.
merged -
7b2e88
Servers & Infra
Linux administration, cPanel, deployment pipelines, uptime ownership.
merged -
e41d0a
Cloudflare & DNS
WAF rules, CDN configuration, DNS architecture for client fleets.
merged -
9c7f42
Web Security
Hardening, malware remediation, brute force mitigation, incident response.
merged -
HEAD
Security Operations
Formalizing threat detection and response with Security+, TryHackMe and LetsDefend, on top of existing operational experience.
current focus -
origin/next
Cloud Security Engineer
AWS security and cloud architecture, extending infrastructure and operations experience into cloud-native environments.
next specialization
capabilities
Production experience. Current specialization.
The left column is live production experience, already load-bearing across real client infrastructure. The right column is where that foundation is being formalized, on a fixed weekly schedule.
system --production
- LinuxShell, cPanel, sysadminproficient
- CloudflareWAF, CDN, DNSproficient
- GitVersion control, deploysproficient
- Web SecurityHardening, remediationproficient
- WordPressThemes, plugins, WooCommerceproficient
- Server AdminHosting, performance tuningproficient
system --specializing
- Security+CompTIA, exam scheduled
- TryHackMeSOC learning path
- LetsDefendLive SOC simulations
- PythonBoot.dev, automation scripting
- SIEM & Windows/ADHome lab environment
- AWSCloud Practitioner track
field notes
Incident investigation and threat mitigation, on live systems.
These weren't logged in a SIEM. They were investigated over SSH, under client pressure, with production traffic live: real compromise, real mitigation, real operational response. The discipline transfers directly to a SOC seat.
-
INC-0142high
WooCommerce store compromised via outdated plugin
Malicious injection served fake checkout redirects to customers. Isolated infected files, patched the vulnerable plugin, rotated all credentials, and rebuilt wp-config with hardened permissions.
WP-CLICloudflare WAFSSH -
INC-0098medium
Sustained brute force against client admin login
Rotating IP ranges hammering wp-login. Configured Cloudflare rate limiting and geo rules, disabled XML-RPC, enforced MFA, and documented the response for the client's runbook.
CloudflareWordfence.htaccess -
INC-0071low
DNS misconfiguration during hosting migration
Intermittent mail delivery failures traced to a stale zone file. Audited MX, SPF and DKIM records, rebuilt the zone, verified propagation, and wrote the migration runbook for future moves.
digCloudflare DNSmail-tester
career progression
Three specializations. One line of work.
-
foundation
Infrastructure & Security Engineer
Five years securing and administering production web infrastructure for remote agency clients across the US, UK and Europe.
-
current focus, HEAD
Security Operations
Formalizing threat detection and incident response through Security+, TryHackMe and LetsDefend, on top of existing operational experience.
-
next specialization
Cloud Security Engineer
AWS security and cloud architecture, extending an infrastructure and security operations foundation into cloud-native environments.
contact