# Curriculum Vitae
**Linux Infrastructure & Security Operations Engineer** based in Brno, Czechia.
I work best where **Linux**, infrastructure, product support, security hygiene, and documentation meet. I like diagnosing strange technical problems, turning repeated work into scripts or runbooks, and making systems easier to operate, explain, and trust.
> [!abstract]+ Summary
> - **Linux-first engineering:** 4+ years of hands-on Linux experience across professional roles, personal labs, product environments, and daily-driver systems.
> - **Infrastructure & product operations:** mixed on-prem/cloud environments, Linux-based products, RF systems, VMware exposure, AWS VM operations, and customer interconnects.
> - **Troubleshooting:** log analysis, packet triage, hardware/software diagnostics, Linux desktop/server issues, reproducible bug reports, and cross-team technical support.
> - **Automation & reproducibility:** Bash, Ansible, Git/GitLab CI, Docker/Podman, and Markdown/pandoc pipelines for repeatable operations and documentation.
> - **Security-minded operations:** WireGuard, MFA, certificate lifecycle, privacy-first workflows, E2EE preference, and practical hardening mindset.
> - **Documentation & enablement:** runbooks, support templates, handover notes, internal guides, and knowledge sharing that reduce repeated questions and key-person risk.
> [!success]+ Best-fit work
> I am most interested in roles around **Linux infrastructure**, **security operations**, **professional services engineering**, **technical operations**, **product-adjacent engineering**, and **open-source-friendly infrastructure work**.
>
> I like environments where I can combine hands-on troubleshooting with automation, documentation, technical ownership, and practical security improvements. Longer-term, I would like to grow toward stronger technical ownership, small-team coordination, or product-adjacent decision-making — especially where real user pain can be translated into better tooling, docs, or product behavior.
>
> **Location/work mode:** Brno preferred; open to on-site, hybrid, or remote roles. No relocation.
>
> **Less ideal fit:** roles centered mainly around Windows administration, backup tooling, or process-heavy corporate operations without meaningful technical ownership.
## Experience
> [!info] **Dec 2023 – Present — Professional Services Engineer**
> > Invasys a.s. (Brno, on-site)
> - Provide product-adjacent technical engineering support across RF systems, Linux-based tooling, customer environments, and internal operations.
> - Diagnose RF hardware/software issues through log triage, manual verification, board re-installations, and return-to-service workflows.
> - Administer mixed **on-prem + cloud** operational environments, including distributed **AWS VM** infrastructure and local components.
> - Configure and verify customer interconnects over **WireGuard VPN** tunnels; prepare clear handover instructions for repeatable operation.
> - Conduct exploratory/manual testing of RF product areas where automation is impractical; document reproducible scenarios for development teams.
> - Build **GitLab CI** pipelines for **pandoc**-based documentation, producing consistent versioned documentation bundles shipped with product releases.
> - Create reusable Markdown/plain-text support templates for recurring requests, improving response consistency and reducing repeated manual writing.
> - Develop Linux utilities and workflow scripts, including Ubuntu-based **MBTiles** conversion tooling and small Bash helpers for internal operations.
> - Act as a cross-team **Linux SME**, helping support, netops, and development teams resolve Linux, tooling, and operational issues.
> - Run **local LLMs in Docker** for privacy-sensitive workflows where data should not be sent to third-party services.
>
> *Impact:* stronger technical handovers, more reproducible documentation, faster recurring support workflows, and fewer avoidable escalations to engineering.
> [!info] **Jan 2023 – Nov 2023 — System Engineer**
> > Konica Minolta Business Solutions Czech, spol. s r.o. (Brno, on-site)
> - Worked in a large multi-country European infrastructure environment, gaining enterprise operations experience across VMware, patching, certificates, MFA, and internal procedures.
> - Performed routine **VMware vSphere** maintenance and administration in an established corporate infrastructure environment.
> - Automated configuration updates for a fleet of **Raspberry Pi** monitoring devices, migrating legacy **Bash** workflows toward repeatable **Ansible** playbooks.
> - Supported certificate lifecycle tasks, OS patching, and **MFA** rollout/maintenance as part of standard security hygiene.
> - Handled **Veeam** restore/test-recovery tasks as part of infrastructure operations, while building practical awareness of backup/restore discipline.
> - Authored concise **Confluence** documentation with deep cross-linking to improve incident handling and internal knowledge sharing.
> - Created Linux administration guides that helped colleagues become more independent with common Linux tasks.
>
> *Impact:* improved internal documentation, reduced Linux knowledge bottlenecks, and converted some repeated manual work into more maintainable procedures.
> [!info] **Apr 2021 – Dec 2022 — Technical Support Engineer**
> > Comprimato Systems s.r.o. (Brno, on-site)
> - Supported Linux-based high-performance video transcoding products (**Bridge Live / Live Transcoder**) running on **CentOS** with **NVIDIA GPU** acceleration.
> - Diagnosed customer and product issues through logs, configuration review, reproduction steps, performance data, and internal knowledge notes.
> - Executed performance benchmarks covering stream counts, bitrate, FPS, and GPU-accelerated workloads to validate R&D changes and release readiness.
> - Authored standardized bug reproduction guidelines covering scenarios, logs, parameters, and expected evidence for developer handoff.
> - Improved **Jira** dashboard hygiene and queue workflows to make priorities, ownership, and ticket state clearer.
> - Performed early regression spotting using checklists and internal notes to help stabilize releases.
>
> *Impact:* better developer handoffs, clearer reproduction data, and shorter feedback loops between support, QA, and engineering.
> [!info]- **Sep 2018 (1 month) — Early experience: IT Services & Computer Repair**
> > EL office, s.r.o. (Znojmo, on-site apprenticeship)
> - End-user support and **HW/SW diagnostics** for PCs, notebooks, tablets, and phones.
> - Used **Ninite** and standardized reinstall steps to speed up Windows work.
## Public Lab & Projects
> [!example]+ Selected public notes and technical projects
> - **[[CachyOS]] / Arch Linux community:** long-term Linux involvement around CachyOS/Arch-based systems, including occasional wiki/community contributions and daily Linux use.
> - **[[Network Infrastructure]]:** documented home network design using a 5G WAN edge, Wi‑Fi 6, and wired 2.5GbE backbone for workstation-heavy usage.
> - **[[Syncthing - Sync & Backup]]:** privacy-first file synchronization design across devices using Syncthing, E2EE, versioning, and a hub-and-spoke topology.
> - **[[Workstation]]:** high-performance Linux workstation used for local LLMs, image processing, package/kernel builds, and general experimentation.
> - **[[Art of prompting]] / AI notes:** practical LLM prompting, local/private AI workflows, and critical notes about AI tooling and open documentation.
## Skills
> [!tip]+ Linux & Platforms
>
> | Platform | Typical use | Notes |
> |---|---|---|
> | Ubuntu | Servers, tooling, customer/product workflows | Primary production/tooling OS in recent roles |
> | Debian | Servers, stable base systems | Comfortable with admin and troubleshooting |
> | Fedora | Workstation/server usage | Fast-moving Linux environment; daily-driver familiarity |
> | Arch/[[CachyOS]] | Personal/pro labs, workstation | Reproducible setups; deep Linux-first mindset |
> | CentOS | Product support environments | GPU/video transcoding product experience |
> [!tip]+ Automation, CI/CD & Documentation
>
> | Tool | Typical use | Notes |
> |---|---|---|
> | Bash | Admin utilities, glue scripts, fleet tasks | Practical Linux automation and incident tooling |
> | Ansible | Repeatable configuration updates | Used to replace legacy Bash workflows where appropriate |
> | Git | Change tracking and review habits | Git-driven operational/documentation workflows |
> | GitLab CI | Documentation/build pipelines | Versioned **pandoc** documentation bundles |
> | Markdown / Obsidian | Runbooks, templates, knowledge base | Plain-text documentation mindset |
> | pandoc | Documentation packaging | Markdown → product-bundled documentation |
> | Confluence / Jira | Enterprise KB and ticket workflows | Cross-linking, queue hygiene, clearer handoffs |
> [!tip]+ Networking & Security Operations
>
> | Tool / Area | Typical use | Notes |
> |---|---|---|
> | WireGuard | Customer/site interconnects | Config validation, handovers, operational checks |
> | Wireshark | Packet/log triage | Troubleshooting RF/product/network issues |
> | Nmap | Discovery and quick audits | Port/service mapping and baselines |
> | Certificates | Lifecycle and hygiene | Enterprise and service operations exposure |
> | MFA | Access security hygiene | Microsoft Authenticator / operational rollout experience |
> | E2EE / privacy tooling | Personal and professional preference | Prefer data-minimizing, transparent workflows |
> | Tor-based ops | Restricted operational access patterns | Mentioned carefully; not anonymity research |
> [!tip]+ Virtualization, Containers & Lab
>
> | Tool / Area | Typical use | Notes |
> |---|---|---|
> | Docker / Podman | Local services, local LLMs, reproducible tooling | Privacy-preserving workloads and build environments |
> | VMware vSphere | Routine operations/maintenance | Enterprise infrastructure exposure |
> | AWS VM operations | Distributed VM environments | Operational administration, not deep cloud architecture |
> | VirtualBox | Lab & troubleshooting | Lightweight repro environments |
> | Homelab / workstation | Linux experiments, builds, local AI | See [[Lab]] and [[Workstation]] |
> [!tip]+ Product / Professional Services Engineering
>
> | Area | Typical use | Notes |
> |---|---|---|
> | Reproducible bug reports | Engineering handoff | Scenarios, logs, parameters, expected evidence |
> | Exploratory/manual testing | Product areas hard to automate | RF/product workflows and release confidence |
> | Support templates | Recurring customer/internal requests | Faster, more consistent first responses |
> | Handover documentation | Customer interconnects and operational procedures | Reduces repeated questions and fragile tribal knowledge |
> | Cross-team Linux SME | Support, netops, development | Practical Linux help where teams overlap |
> [!tip]+ Hardware / RF / Mapping
>
> | Area | Typical use | Notes |
> |---|---|---|
> | RF device diagnostics | Log triage, exploratory tests | When automation is impractical |
> | Board-level re-installs | Teardown/reassembly | Return-to-service workflows |
> | NVIDIA GPU platforms | Video transcoding products | Linux/CentOS product support experience |
> | MBTiles tooling (Ubuntu) | Map generation | Public formats → MBTiles, standardized workflows |
> [!tip]+ AI & Local-First Workflows
>
> | Tooling | Typical use | Notes |
> |---|---|---|
> | Local LLMs in Docker | Sensitive workflows | No third-party data exposure; on-prem friendly |
> | OpenAI Whisper / local models | Transcription and experimentation | Local compute where practical |
> | Prompt systems | Reusable instructions and templates | See [[Art of prompting]] and AI lab notes |
> [!info]- Enterprise technologies handled
>
> | Technology | Experience | Notes |
> |---|---|---|
> | Windows Server / Active Directory | Routine operational exposure | Not my primary focus |
> | Veeam | Restore/test-recovery tasks | Practical exposure, not target specialization |
> | Microsoft Authenticator MFA | Enterprise auth hygiene | Rollout/maintenance context |
> | Corporate ITSM/processes | Jira/Confluence and infrastructure workflows | Useful experience, but I prefer technical ownership over process-heavy work |
> [!info]- Technology keywords
> Linux, Ubuntu, Debian, Fedora, Arch Linux, CachyOS, CentOS, Bash, Git, GitLab CI, Ansible, Docker, Podman, VMware, AWS VM operations, WireGuard, Wireshark, Nmap, MFA, certificate management, security operations, Linux hardening, runbooks, Markdown, Obsidian, pandoc, Jira, Confluence, RF hardware support, NVIDIA GPU platforms, MBTiles, local LLMs, privacy-first workflows, E2EE, open-source.
## Education
> [!note] 2015–2019 — SPŠEIT Brno — *Secondary Industrial School of Electrical Engineering & IT*
> **Mechanik elektrotechnik** (*Electrotechnics Technician*) — **Maturita** (CZ secondary school graduation exam) · Code `26-41-L/01` · **School:** [purkynka.cz](https://www.purkynka.cz/) · **Program:** [Mechanik elektrotechnik](https://www.purkynka.cz/pro-uchazece/vyber-si-obor/technicke-obory/mechanik-elektrotechnik/)
## Languages
> [!note] Czech (native) · **English (B2)**
## Security & Work Principles
> [!tip]- How I operate
> - Linux-first; prefer transparent systems that can be understood, repaired, and documented.
> - Open-source by default when it meets security, usability, and maintainability needs.
> - Privacy-first — prefer E2EE, local-first workflows, and data-minimizing tools.
> - Minimal, maintainable solutions over hype, unnecessary complexity, or vendor lock-in.
> - Evidence-based decisions: logs, reproduction steps, packet captures, docs, and tests beat assumptions.
> - I write things down so future me — and the rest of the team — do not have to rediscover the same fix twice.
## Contact card
Here are publicly available contacts; feel free to choose your preferred way to communicate with me.
> [!info]- Get in touch
> ![[Contact]]