The security engineer behind the infrastructure
I'm an Erasmus Mundus CyberMACS Scholar 🇪🇺 with 5+ years of hands-on experience in enterprise IT infrastructure, system administration, and infrastructure operations, gained across both utility and banking environments.
My experience covers the full infrastructure lifecycle: deploying and supporting end-user and network infrastructure, and administering enterprise servers, virtualization platforms, identity services, storage, databases, and high-availability environments.
🏢 Enterprise IT Experience
Throughout my career, I've worked hands-on with:
⚙️ System Administration & Infrastructure Operations
Provisioning, configuration, troubleshooting, monitoring, patching, and maintenance of enterprise IT environments.
🖥️ Servers & Virtualization
IBM Power Systems/AIX, VMware, Linux, and Windows server environments supporting enterprise services.
🔐 Identity, Access & Endpoint Security
Active Directory Domain Services, user and group administration, permissions, OUs, GPOs, endpoint security, antivirus, and DLP.
🌐 Network & IT Infrastructure
Deployment and troubleshooting of routers, switches, firewalls, LAN connectivity, workstations, printers, and distributed branch infrastructure.
🔄 Automation & Infrastructure Management
Designed and implemented Ansible automation for AIX server provisioning and PowerHA operations, making infrastructure management more consistent and efficient.
🏦 Critical & Regulated Environments
Supported infrastructure and services within a large banking environment, including enterprise storage, databases, virtualization, and high-availability platforms.
🛡️ Security Operations & Remediation
Worked with security teams to investigate server security findings and implement corrective configurations and hardening measures.
📚 Process Standardization & Knowledge Management
Contributed to a team effort that consolidated infrastructure procedures into a centralized internal knowledge repository, improving standardization, knowledge transfer, and onboarding.
🚀 Where I'm Taking This Experience
My infrastructure background shaped my interest in cybersecurity from the infrastructure side.
I care not just about how systems get secured, but how secure environments are designed, deployed, operated, automated, monitored, and governed.
Right now I'm building expertise in:
Cybersecurity & Security Engineering
Cloud & AWS Security
Identity & Access Management (IAM) & Zero Trust
DevSecOps & Infrastructure as Code
Security Automation with Python & Terraform
Kubernetes & Container Security
Security Governance & Compliance
NIS2, DORA & ISO 27001 aligned security practices
🧩 Learning Through Practice
I learn best by building things and applying concepts to realistic environments.
My projects and labs explore areas including:
🔹 AWS security baselines and cloud hardening
🔹 Terraform based secure infrastructure
🔹 Cloud security monitoring and detection
🔹 IAM hardening and access governance
🔹 Kubernetes and container security
🔹 Security automation
🔹 Infrastructure and security as code
🔹 Compliance and security control mapping
I'm especially drawn to the intersection of enterprise infrastructure, cybersecurity, cloud, identity, automation, and governance, and to turning security requirements into practical, measurable, repeatable technical solutions.
🎯 Career Direction
My goal is to grow into a well rounded cybersecurity professional with a strong infrastructure foundation, specializing across security engineering, cloud security, identity, automation, and governance.
I want to combine the practical perspective I gained running real enterprise environments with modern security engineering and cloud technologies, building systems that are functional and resilient, but also secure, automated, and governed by design.
Experience
- Enterprise Server Administration: Provisioned, configured, monitored, and troubleshot enterprise server infrastructure supporting multiple internal teams across IBM Power Systems/AIX and VMware environments running Linux and Windows.
- Infrastructure Provisioning & Operations: Managed server provisioning, resource allocation, configuration, performance monitoring, troubleshooting, patching, and operational maintenance across production and standby datacenter environments.
- Automation & Infrastructure-as-Code:Designed and implemented Ansible automation for AIX server provisioning, reducing provisioning time from ~2 hours to ~ 30 minutes and standardizing configuration across 150+ servers.
- Security Remediation: Collaborated closely with the information security team to address server security findings, reviewing reported vulnerabilities and implementing corrective configurations and hardening measures across affected systems.
- High-Availability Infrastructure: Supported PowerHA clustering and enterprise storage environments, contributing to the availability and resilience of infrastructure supporting critical banking services.
- Cross-Platform Infrastructure Support: Provided infrastructure support across AIX, Linux, Windows, VMware, and enterprise storage platforms, troubleshooting complex server and virtualization issues for internal technology teams.
- Process Standardization & Knowledge Management: Collaborated as part of a 5-member team to consolidate infrastructure provisioning, configuration, and operational procedures from senior technical teams into a centralized internal knowledge repository, improving documentation, knowledge transfer, and onboarding of new team members.
- Operational Knowledge Transfer: Helped transform previously distributed and team-specific infrastructure procedures into standardized, accessible documentation, reducing dependency on individual team knowledge and improving consistency in day-to-day operations.
- Active Directory & Identity Administration: Administered Active Directory Domain Services (AD DS), managing the full user lifecycle including account creation and deletion, password resets, account unlocks, group membership, permissions, and domain joining.
- Directory & Policy Management: Managed Organizational Units (OUs) and Group Policy Objects (GPOs) to support standardized user, workstation, and access configurations across the organization.
- Access & Incident Resolution: Served as a second-level escalation point for AD/DS access issues raised by regional offices, diagnosing authentication, account, permission, and domain-related problems and restoring user access.
- Enterprise Systems Infrastructure Support: Collaborated with infrastructure and application teams to support the underlying infrastructure of SAP and other enterprise systems, troubleshooting connectivity, availability, and infrastructure-related issues.
- ICT Operations: Performed system monitoring, troubleshooting, maintenance, patching, and performance-related activities within the ICT Operations Support environment.
- IT Service Management & Support: Delivered second-level IT support for 500+ employees across 15 locations (14 branch offices and the regional office), resolving 50+ incidents per month across hardware, software, network, and enterprise systems.
- Infrastructure Deployment: Deployed and configured on-premises IT infrastructure for 10+ branch openings and upgrades, including PCs, printers, routers, switches, and firewalls, ensuring operational readiness before go-live.
- Network & Connectivity: Diagnosed and resolved LAN, network, and connectivity issues through remote and on-site troubleshooting, minimizing service disruptions across geographically distributed offices.
- Endpoint Security: Deployed and maintained antivirus and DLP controls across 500+ devices, supporting standardized workstation configurations and strengthening protection against malware, unauthorized access, and data leakage.
- Enterprise Application Deployment: Deployed and configured SAP client applications across 300+ workstations in 14 branch offices, providing technical support to users throughout implementation.
- User Enablement: Delivered remote and face-to-face technical training and guidance to 100+ employees on enterprise systems, IT procedures, and security tools, improving users' ability to resolve common issues independently.
Education
MSc in Applied Cybersecurity
MSc in Computer Science — Cyber Security
MSc in Computer Networking
BSc in Information Science
Let's work together
I'm looking for Werkstudent and internship roles across cybersecurity - cloud security, IAM, GRC, SOC/security operations, and beyond - based in Germany. If you have an opportunity or just want to talk security, reach out.