Escalation SME and UFV Networking & Cybersecurity graduate with a proven track record of managing enterprise network operations and complex incident resolution. Specializes in end-to-end fault isolation across VLANs, DNS/DHCP, and proxy layers to deliver permanent fixes rather than temporary workarounds. Brings hands-on expertise in Proxmox/Linux hypervisor administration, AI-driven log telemetry (Gemini API), and a commitment to rigorous root-cause analysis (RCA).
I am a Network & Infrastructure Analyst and Escalation SME, graduating with a Bachelor of Computer Information Systems (BCIS) in Networking & Cybersecurity from the University of the Fraser Valley (UFV) in Abbotsford, BC.
My experience spans full-lifecycle enterprise support: managing high-priority queues for multinational accounts, resolving tier-2 network routing and authentication bottlenecks, and conducting thorough root-cause analysis (RCA) to permanently eliminate repeat tickets. I believe true stability comes from addressing underlying configuration flaws across VLANs, DNS/DHCP, and reverse proxies rather than applying temporary patches.
Beyond operations, I engineer production-grade virtual environments using Proxmox VE, OPNsense, Docker, and Kubernetes (k3s). My recent initiatives include building an AI-monitored firewall pipeline using the Google Gemini API for automated real-time threat detection and webhook alerting.
As President of the UFV Computer Networking Club and the Robotics Club, I mentor peers in network design, hands-on lab orchestration, and competitive technology challenges.
Click any node below to inspect IP subnets, 802.1Q VLAN tags, firewall ACLs, and live Wireshark traces.
Firewall, Router, WireGuard & Tailscale Ingress
| IP / Subnet: | 10.10.10.1 /24 (Gateway) |
| Firewall Rules: | Strict 802.1Q Inter-VLAN ACLs, TLS Termination, Drop Invalid TCP Flags |
Select an adversarial attack vector below to simulate live packet flow and observe defensive countermeasures.
Engineered a production-grade Proxmox hypervisor hosting isolated Ubuntu VMs, secured by an OPNsense edge firewall and segmented VLANs. Developed a custom Python pipeline leveraging the Gemini API to continuously ingest and analyze OPNsense traffic logs, identifying anomalous network behavior in real-time. Configured webhook integrations to trigger instant SMS notifications for critical security events, streamlining incident response and ensuring rapid human-in-the-loop decision-making.
# Python: Real-Time OPNsense Log Ingestion with Google Gemini API
import os
from google import genai
client = genai.Client(api_key=os.environ["GEMINI_API_KEY"])
def evaluate_firewall_telemetry(log_batch):
prompt = f"""
Evaluate the following OPNsense drop logs for anomalous traffic spikes,
unauthorized lateral movement, or brute-force attempts.
Return JSON with fields: 'threat_detected', 'severity', 'recommendation'.
LOGS:
{log_batch}
"""
response = client.models.generate_content(
model="gemini-2.5-flash",
contents=prompt
)
return response.text
Enables instantaneous contextual threat triage, cutting manual log parsing time by 90% and empowering solo administrators with enterprise-grade autonomous monitoring.
Engineered an automated workflow orchestration pipeline using self-hosted n8n and Zapier to continuously aggregate structured data from distributed public APIs and web endpoints. Implemented conditional logic and regex filtering to evaluate incoming data payloads against predefined technical criteria, filtering out noise and flagging high-priority events. Integrated automated webhooks to dispatch real-time summaries and instant notifications, reducing manual tracking overhead and eliminating data lag.
// n8n Custom Code Node: Conditional Filtering & Severity Scoring
const items = $input.all();
const prioritized = items.filter(entry => {
const payload = entry.json;
const isHighSeverity = payload.severity === 'critical' || payload.error_count > 5;
const matchesRegex = /failed|timeout|refused/i.test(payload.status_message || '');
return isHighSeverity || matchesRegex;
});
return prioritized;
Eliminated manual tracking overhead across external data sources, delivering actionable notifications directly to engineers within seconds.
Multi-hypervisor stack on Proxmox VE and XCP-ng. Windows Server 2019 Domain Controller with Active Directory Domain Services, hierarchical Organizational Units (OUs), Group Policy Object (GPO) baselines, RBAC, and DNS/DHCP simulating a 50-user corporate network. VLAN segmentation isolating management, corporate, and DMZ traffic with Tailscale and WireGuard secure remote access.
# PowerShell: Inactive Account Audit & GPO Enforcement
$InactiveCutoff = (Get-Date).AddDays(-90)
$Accounts = Get-ADUser -Filter { LastLogonDate -lt $InactiveCutoff -and Enabled -eq $true } `
-Properties LastLogonDate, Department |
Select-Object Name, SamAccountName, Department, LastLogonDate
foreach ($User in $Accounts) {
Disable-ADAccount -Identity $User.SamAccountName
Write-Host "Disabled inactive account: $($User.SamAccountName)" -ForegroundColor Yellow
}
Maintains 99.98% uptime with complete segment isolation, replicating full enterprise Active Directory governance and zero-trust remote access.
Whether you are seeking an experienced Network & Infrastructure Analyst, an Escalation SME with a proven 100% CSAT track record, or a Systems Administrator ready to make an immediate impact across Canada or remotely — let's talk. I respond promptly.