IT Professional / Phoenix, Arizona

Infrastructure. Security. Automation.

Building toward Cybersecurity and DevOps

I run a hands-on home lab focused on network security, identity management, and infrastructure monitoring. Comfortable across Windows and Linux, Active Directory and Entra ID, packet analysis and scripting. Currently on a 30-day homelab sprint to deepen practical skills.

Active challenge

30-Day Homelab Sprint

Building, breaking, and documenting one new skill or system per day. Every session gets a writeup.

What I work with

Skills

Identity and access

  • Active Directory users, groups, and OUs
  • Microsoft 365 and Entra ID, licenses, MFA
  • Group Policy configuration
  • Password policy and lockout remediation

Systems and networking

  • Windows 10/11, Windows Server
  • Linux — Ubuntu, Debian, server management
  • DNS, DHCP, VPN, SSH, Tailscale
  • Docker, container networking

Security and monitoring

  • Wireshark, packet capture, traffic analysis
  • Pi-hole, Unbound, DNS filtering
  • Uptime Kuma, alert pipelines
  • Log analysis and incident documentation

Scripting and automation

  • PowerShell — AD automation and scripting
  • Bash — server management and backups
  • Python — utilities and tooling
  • SLA design and runbook documentation

Built and documented

Projects

Hands-on lab work across security, infrastructure, and automation. Configs and scripts live on GitHub.

Active Directory

Domain controller and Group Policy lab

Stood up a Windows Server domain, managed users, OUs, and security groups, and automated account operations through the PowerShell Active Directory module.

Automated bulk account tasks with PowerShell, cutting repetitive setup to a single command.

Microsoft 365 and Entra ID

Cloud identity administration

Configured a Microsoft 365 tenant, managed accounts, licenses, and groups, enforced multi-factor authentication, and built onboarding and offboarding runbooks.

Built a repeatable provisioning checklist covering AD, Entra ID, and mailbox setup in one pass.

Wireshark and DNS

Packet capture and network analysis

Captured real traffic across Wi-Fi and Tailscale interfaces, filtered DNS and TCP handshakes, and identified Chrome DoH bypassing Pi-hole plus Windows WPAD proxy-discovery noise.

Remediated both findings and documented packet evidence, interface-selection lesson, TLS visibility limits, and practical analysis workflow.

Pi-hole and Unbound

Recursive DNS filtering lab

Deployed Pi-hole with Unbound for fully recursive DNS resolution, eliminating third-party resolver dependencies and enabling network-wide filtering with per-client query logging.

Analyzed my own DNS traffic to surface noisy clients, unusual query patterns, and logging anomalies.

Monitoring and Docker

Self-hosted observability stack

Deployed Uptime Kuma in Docker, configured HTTP and ping checks across services, and wired push alerts through a scoped ntfy account for real-time notifications.

Diagnosed a silent alert failure from container network isolation and fixed it with internal Docker service routing.

Ticketing and ITSM

Service desk workflow design

Built a working ticket queue with categories, priorities, and SLA targets, then designed triage rules and documented resolution playbooks for the most common request types.

Triage rules routed common requests automatically, keeping first response inside target.

Open to the right opportunity

Targeting roles in cybersecurity and DevOps engineering. Remote or Phoenix, AZ. Let's connect.