Operations depth, not slideware
Veritas clusters, Kerberos, NetBackup, global patch campaigns, hardware acceptance before production release. I've owned the boring parts that keep a business trading.
Linux Systems Engineer · Security Operations · Prague
Twelve years keeping infrastructure alive — six and a half of them running the Linux estate behind DHL's global business. Now I'm moving to the other side of the alert: detection, triage and incident response, with an AWS certification track running alongside it.
Scroll
Why me
Most people enter security from theory. I'm entering it from six years of 3 a.m. pages, change windows and postmortems on a 20,000-host estate. I know how a fleet is patched, where authentication actually lives, and what normal looks like on a host — which is the whole job when you're deciding whether an alert is real.
Veritas clusters, Kerberos, NetBackup, global patch campaigns, hardware acceptance before production release. I've owned the boring parts that keep a business trading.
Bash, Python and Ansible instead of repeating manual work across thousands of machines. Same instinct applies to triage: if I do it twice, I write it down and script it.
Since 2025 I've been studying full time — networking fundamentals, then vulnerability and packet analysis, now SIEM, EDR and MITRE ATT&CK in SOC Level 1, with the AWS architect track running alongside it.
Career uptime
Oct 2014 → today · one bar per month · hover for detail
How I work an incident
The same discipline I used on production infrastructure, applied to security events. Nothing gets closed without a written reason.
Alert lands from SIEM, EDR or monitoring. First question is always the same: is this signal or noise, and who else is seeing it?
Scope and severity in minutes, not hours. Which hosts, which users, which data, and does it need escalation right now.
Logs, packets, process trees, authentication history. Map what happened to ATT&CK techniques and build the actual timeline.
Isolate, patch, restore from backup, verify the fix held. Recovery is where sysadmin experience pays for itself.
Runbook, detection tuning, automation for next time. An incident that teaches nothing will simply happen again.
The difference automation makes
A database node drops at 03:14. What happens next depends entirely on the work done before it. Drag the slider to compare a manual recovery with a properly configured Veritas cluster.
Drag to compare · illustrative reconstruction of a routine node failure, not a specific customer incident
Toolbox
Self-assessed, and every line of it is something I've run in production or in hands-on labs — not a keyword list for the applicant tracking system.
Track record
DHL IT Services · Data centres
Part of the team responsible for DHL Global Business Operations servers — an estate of more than 20,000 hosts worldwide. Day-to-day ownership of availability, patching, automation and recovery across physical and clustered Linux and HP-UX systems.
XXXLutz
Sole technical responsibility for IT operations across 23 retail branches — servers, network, point of sale and everything attached to them.
Teleperformance Hellas
Front-line technical and sales support for the Czech Apple market, including post-purchase service activation.
Nando's Chickenland
Two years in a high-volume kitchen abroad — shift work, service under pressure, and the English fluency the rest of my career runs on.
Proof
Vendor training paid for by employers, plus the security path I'm working through on my own time. Credential links go live as each one is issued.
TryHackMe
SIEM, EDR, Splunk, ELK, phishing analysis, network and web security monitoring, MITRE ATT&CK, malware analysis
Credential — coming soonAmazon Web Services
Currently on the Architecture & Tools module: VPC design, EC2, S3, IAM, high availability and cost-aware architecture
Credential — coming soonTryHackMe
Vulnerability assessment, web application security, protocol and packet analysis, Nmap, Wireshark, OSINT, CyberChef, OWASP
View credentialTryHackMe
Networking fundamentals, TCP/IP, HTTP, DNS, TLS/SSL
View credentialRed Hat
Advanced RHEL: storage, networking, scheduling, SELinux, troubleshooting
View credentialVeritas · sponsored by DHL
Clustering and high availability for UNIX and Linux
View credentialRed Hat · sponsored by DHL
RHEL fundamentals: shell, users and permissions, services, networking
View credentialApple Authorized Training
Apple product sales and post-purchase service activation
View credentialTryHackMe
Threat hunting, advanced detection engineering, digital forensics and incident response
Starts after SOC L1Amazon Web Services
Cloud fundamentals, core AWS services, shared responsibility model, billing and support
On the roadmapAmazon Web Services
The closest fit to what I already do: deployment, monitoring, automation and operations in AWS
On the roadmapAmazon Web Services
Where the two tracks meet: identity, detection and response, data protection and incident response in the cloud
On the roadmap+
Space reserved for
the next certificate
Outside working hours
Two tracks running in parallel: security operations, and the cloud platform most of that infrastructure is moving to. Both hands-on rather than watch-and-forget.
Solutions Architect Associate · Architecture & Tools
Working through the Architecture & Tools module now — VPC design, EC2, S3, IAM and high availability. Cloud Practitioner, SysOps Administrator and Security Specialty follow after it.
SOC Level 1 · SIEM · EDR · MITRE ATT&CK
Live investigation rooms rather than theory: triaging alerts in Splunk and ELK, analysing phishing samples, reading packet captures and mapping activity to ATT&CK techniques.
Linux VMs · Ansible · logging stack
Where new things get broken safely — Linux servers, log collection and playbooks I can rebuild from scratch. Add your own setup and links here.
Hard-won
Opinions formed in production, not in a course.
Untested restores fail exactly when it matters. Restore testing belongs in the schedule, not in the plan.
Most breaches use something that had a fix months ago. Reliable patch coverage beats a clever tool nobody has time to tune.
Alerts everyone ignores train the team to ignore the real one. Tune first, add dashboards later.
Manual work done twice will be done a hundred times. Write the runbook while you still remember why.
You cannot spot an anomaly without a baseline. Sysadmin experience is a shortcut to knowing what should be running.
At 3 a.m. nobody wants tribal knowledge. Clear notes shorten every incident that comes after yours.
References
Three managers and colleagues who know my work first hand. I'll pass on their contact details once we've spoken — and once they know to expect the call.
My manager during six years in the data centre teams — day-to-day work, on-call and the global patching and clustering side of the estate.
Contact on requestColleague on the same Linux team. Shared shifts, incidents and automation work across the DHL server estate.
Contact on requestMy manager while I looked after IT operations for 23 retail branches — servers, network and point of sale.
Contact on requestGet in touch
Available immediately, based in Prague, open to on-site, hybrid or remote. Fill this in and it opens a pre-filled email straight to me — or reach me directly below.