Linux Systems Engineer · Security Operations · Prague

Keep it running.
Keep it secure.
Keep learning.

Twelve years keeping infrastructure alive — six and a half of them running the Linux estate behind DHL's global business. Now I'm moving to the other side of the alert: detection, triage and incident response, with an AWS certification track running alongside it.

Portrait of Juraj Vitko
Juraj Vitko Est. 2014
20,000+Hosts supported
6.5 yrsDHL IT Services
AvailableImmediately · Prague

Scroll

0Years in IT and technical operations
0Linux hosts in the estate I supported
0Vendor certificates and security courses
0Countries worked in: SK, IE, GR

Why me

A defender who has already run the systems

Most people enter security from theory. I'm entering it from six years of 3 a.m. pages, change windows and postmortems on a 20,000-host estate. I know how a fleet is patched, where authentication actually lives, and what normal looks like on a host — which is the whole job when you're deciding whether an alert is real.

Operations depth, not slideware

Veritas clusters, Kerberos, NetBackup, global patch campaigns, hardware acceptance before production release. I've owned the boring parts that keep a business trading.

I automate what hurts twice

Bash, Python and Ansible instead of repeating manual work across thousands of machines. Same instinct applies to triage: if I do it twice, I write it down and script it.

Retraining on purpose, not by accident

Since 2025 I've been studying full time — networking fundamentals, then vulnerability and packet analysis, now SIEM, EDR and MITRE ATT&CK in SOC Level 1, with the AWS architect track running alongside it.

Career uptime

Twelve years, no gaps

Oct 2014 → today · one bar per month · hover for detail

How I work an incident

Five steps from alert to closed ticket

The same discipline I used on production infrastructure, applied to security events. Nothing gets closed without a written reason.

01

Detect

Alert lands from SIEM, EDR or monitoring. First question is always the same: is this signal or noise, and who else is seeing it?

02

Triage

Scope and severity in minutes, not hours. Which hosts, which users, which data, and does it need escalation right now.

03

Investigate

Logs, packets, process trees, authentication history. Map what happened to ATT&CK techniques and build the actual timeline.

04

Contain & recover

Isolate, patch, restore from backup, verify the fix held. Recovery is where sysadmin experience pays for itself.

05

Write it down

Runbook, detection tuning, automation for next time. An incident that teaches nothing will simply happen again.

The difference automation makes

Same outage. Forty minutes, or fifty seconds.

A database node drops at 03:14. What happens next depends entirely on the work done before it. Drag the slider to compare a manual recovery with a properly configured Veritas cluster.

Manual recovery Clustered failover

Drag to compare · illustrative reconstruction of a routine node failure, not a specific customer incident

Toolbox

What I actually use

Self-assessed, and every line of it is something I've run in production or in hands-on labs — not a keyword list for the applicant tracking system.

Linux administration (RHEL, HP-UX)Expert
Bash & shell automationExpert
AnsibleAdvanced
Backup, restore & clusteringAdvanced
Python scriptingIntermediate
Splunk / ELK & log analysisIntermediate
Network & packet analysisIntermediate
SOC operations (SIEM, EDR, ATT&CK)Growing
AWS cloud fundamentalsLearning

Systems

  • RHEL
  • HP-UX
  • Global patch management
  • Veritas InfoScale
  • Kerberos / AAA
  • HPE & Huawei servers
  • Hardware acceptance

Automation

  • Bash
  • Python
  • Ansible
  • Automic (AWA)
  • IBM Workload Scheduler
  • Git

Security & monitoring

  • Splunk
  • ELK
  • SIEM
  • EDR
  • MITRE ATT&CK
  • Wireshark
  • Nmap
  • CyberChef
  • OSINT
  • OWASP
  • Phishing analysis
  • HP OpenView

Cloud (in training)

  • AWS
  • EC2
  • S3
  • IAM
  • VPC
  • CloudWatch
  • High availability design

Continuity

  • Veritas NetBackup
  • LTO tape
  • Restore testing
  • Disaster recovery
  • 24/7 on-call

Track record

Twelve years, four employers, three countries

12/2019 — 05/20266 yrs 6 mos
Praha, CZ

Senior Linux System Administrator

DHL IT Services · Data centres

Part of the team responsible for DHL Global Business Operations servers — an estate of more than 20,000 hosts worldwide. Day-to-day ownership of availability, patching, automation and recovery across physical and clustered Linux and HP-UX systems.

  • Managed and troubleshot hosts across a 20,000+ server estate
  • Ran global Linux patch campaigns end to end
  • Automated repetitive operations with Bash, Python and Ansible
  • Built job flows in Automic (AWA) and IBM Workload Scheduler
  • Operated Veritas Cluster Server on Linux and HP-UX
  • Backup, restore and LTO tape ops with Veritas NetBackup
  • Administered authentication services (Kerberos / AAA)
  • Deployed and troubleshot HPE and Huawei hardware
  • Verified OS and hardware before every production release
  • Monitored the estate with HP OpenView and Splunk
11/2017 — 09/20191 yr 11 mos
Praha, CZ

Network Technician

XXXLutz

Sole technical responsibility for IT operations across 23 retail branches — servers, network, point of sale and everything attached to them.

  • Kept 23 branch sites operational, from switches to checkout lanes
  • Resolved hardware and software incidents on servers and POS
  • Administered IGEL thin clients and Citrix sessions
  • Supported Zebra, OKI, Datalogic, IBM, Honeywell, HP, AXIS, Cisco
11/2016 — 10/20171 yr
Athens, GR

Sales & Service Agent

Teleperformance Hellas

Front-line technical and sales support for the Czech Apple market, including post-purchase service activation.

  • Technical support and service activation for customers
  • Sold Apple products for the Czech market
  • Completed Apple Authorized Sales Agent training
10/2014 — 09/20162 yrs
Dublin, IE

Chef / Waiter

Nando's Chickenland

Two years in a high-volume kitchen abroad — shift work, service under pressure, and the English fluency the rest of my career runs on.

  • Back-of-house through peak service
  • Built working English in a fully English-speaking environment

Proof

Certificates & training

Vendor training paid for by employers, plus the security path I'm working through on my own time. Credential links go live as each one is issued.

2026In progress

SOC Level 1

TryHackMe

SIEM, EDR, Splunk, ELK, phishing analysis, network and web security monitoring, MITRE ATT&CK, malware analysis

Credential — coming soon
2026In progress

AWS Solutions Architect — Associate

Amazon Web Services

Currently on the Architecture & Tools module: VPC design, EC2, S3, IAM, high availability and cost-aware architecture

Credential — coming soon
2025Completed

Cyber Security 101

TryHackMe

Vulnerability assessment, web application security, protocol and packet analysis, Nmap, Wireshark, OSINT, CyberChef, OWASP

View credential
2025Completed

Pre Security

TryHackMe

Networking fundamentals, TCP/IP, HTTP, DNS, TLS/SSL

View credential
2023Completed

Red Hat System Administration II — RH134

Red Hat

Advanced RHEL: storage, networking, scheduling, SELinux, troubleshooting

View credential
2022Completed

Veritas InfoScale Availability 7.3 — Advanced Administration II

Veritas · sponsored by DHL

Clustering and high availability for UNIX and Linux

View credential
2021Completed

Red Hat System Administration I — RH124

Red Hat · sponsored by DHL

RHEL fundamentals: shell, users and permissions, services, networking

View credential
2018Completed

Sales Agent

Apple Authorized Training

Apple product sales and post-purchase service activation

View credential
NextPlanned

SOC Level 2

TryHackMe

Threat hunting, advanced detection engineering, digital forensics and incident response

Starts after SOC L1
NextPlanned

AWS Cloud Practitioner

Amazon Web Services

Cloud fundamentals, core AWS services, shared responsibility model, billing and support

On the roadmap
NextPlanned

AWS SysOps Administrator — Associate

Amazon Web Services

The closest fit to what I already do: deployment, monitoring, automation and operations in AWS

On the roadmap
NextPlanned

AWS Security — Specialty

Amazon Web Services

Where the two tracks meet: identity, detection and response, data protection and incident response in the cloud

On the roadmap

+
Space reserved for
the next certificate

Outside working hours

Courses & labs

Two tracks running in parallel: security operations, and the cloud platform most of that infrastructure is moving to. Both hands-on rather than watch-and-forget.

In progress

AWS certification track

Solutions Architect Associate · Architecture & Tools

Working through the Architecture & Tools module now — VPC design, EC2, S3, IAM and high availability. Cloud Practitioner, SysOps Administrator and Security Specialty follow after it.

In progress

Blue team labs

SOC Level 1 · SIEM · EDR · MITRE ATT&CK

Live investigation rooms rather than theory: triaging alerts in Splunk and ELK, analysing phishing samples, reading packet captures and mapping activity to ATT&CK techniques.

Ongoing

Home lab

Linux VMs · Ansible · logging stack

Where new things get broken safely — Linux servers, log collection and playbooks I can rebuild from scratch. Add your own setup and links here.

Hard-won

Six things 20,000 hosts taught me

Opinions formed in production, not in a course.

01

A backup is a rumour until you restore it

Untested restores fail exactly when it matters. Restore testing belongs in the schedule, not in the plan.

02

Patching is a security control, not chores

Most breaches use something that had a fix months ago. Reliable patch coverage beats a clever tool nobody has time to tune.

03

Noisy monitoring is worse than none

Alerts everyone ignores train the team to ignore the real one. Tune first, add dashboards later.

04

Automate the second time, document the first

Manual work done twice will be done a hundred times. Write the runbook while you still remember why.

05

Know what normal looks like

You cannot spot an anomaly without a baseline. Sysadmin experience is a shortcut to knowing what should be running.

06

Write for the person on the next shift

At 3 a.m. nobody wants tribal knowledge. Clear notes shorten every incident that comes after yours.

References

People who have worked with me

Three managers and colleagues who know my work first hand. I'll pass on their contact details once we've spoken — and once they know to expect the call.

TSTomas SemenecIT Manager · DHL ITS Services

My manager during six years in the data centre teams — day-to-day work, on-call and the global patching and clustering side of the estate.

Contact on request
RVRumen VasilevLinux Sys Admin · DHL ITS Services

Colleague on the same Linux team. Shared shifts, incidents and automation work across the DHL server estate.

Contact on request
TVTomas VotrubaIT Manager · XXXLutz

My manager while I looked after IT operations for 23 retail branches — servers, network and point of sale.

Contact on request

Get in touch

Hiring for a SOC team?

Available immediately, based in Prague, open to on-site, hybrid or remote. Fill this in and it opens a pre-filled email straight to me — or reach me directly below.

Opens your email app with everything filled in, addressed to jurajvitko095@outlook.com — just hit send.