Building Secure Infrastructure with AWS, Linux and Networking
IT professional with a background in aviation maintenance, bringing precision and accountability
to cloud infrastructure, Linux systems administration, networking, and cybersecurity.
This site is deployed on an AWS EC2 Ubuntu instance using Nginx, secured with HTTPS.
Certifications: CompTIA A+ • Security+ • AWS Certified Cloud Practitioner • Linux Essentials • ITIL Foundation
About Me
I bring a disciplined background in aviation maintenance — an environment where precision,
accountability, and systems thinking are non-negotiable — and have applied that same rigor
to building a strong technical foundation in cloud infrastructure, Linux administration,
and network engineering. I pursue hands-on projects and lab work that reflect real-world
production environments, and I hold multiple industry certifications with more in progress.
Education
B.S. Information Technology
Western Governors University
Concentration spanning cloud computing, network infrastructure, and cybersecurity —
reinforced by hands-on lab work and industry certifications earned throughout the program.
In Progress · Expected September 2026
Certifications
CompTIA A+
IT support, troubleshooting, hardware, and operating systems.
CompTIA Security+
Security fundamentals, risk management, and network security.
AWS Certified Cloud Practitioner
AWS services, cloud concepts, pricing, and architecture basics.
Linux Essentials
Linux fundamentals, command line, and system navigation.
ITIL 4 Foundation
IT service management, incident management, change control, service delivery, and operational best practices.
CCNA (Expected 2026)
Routing, switching, VLANs, and network infrastructure design.
CompTIA CySA+ (Expected 2026)
Threat detection, SIEM analysis, and incident response.
Skills
Linux Administration
Ubuntu Server, package management, service management, terminal navigation, and system configuration.
UbuntusystemctlSSH
Web & Security
Nginx configuration, HTTPS enablement, certificate management, and production deployment workflow.
NginxTLS/SSLCertbot
Cloud & Networking
AWS EC2 provisioning, DNS configuration, VLANs, switching, routing, and network infrastructure design.
AWS EC2DNSVLANs
Projects
Cloud / Linux
AWS EC2 Linux Portfolio Server
Designed and deployed a production-grade Ubuntu server on AWS EC2, configured Nginx as a web server,
established DNS routing for a custom domain, and secured the site end-to-end with HTTPS via Let's Encrypt.
Provisioned and hardened a cloud-hosted Linux instance, managing access via SSH key authentication.
Installed, configured, and managed Nginx as a production web service.
Configured DNS records and propagation for a custom domain.
Implemented HTTPS with automated certificate renewal using Certbot.
Networking / Lab
Enterprise VLAN Segmentation & Inter-VLAN Routing
Designed and deployed a multi-VLAN enterprise network in Cisco Packet Tracer, implementing
inter-VLAN routing via router-on-a-stick, enforcing traffic policies with extended ACLs,
and validating end-to-end connectivity across segmented departments.
Segmented network traffic across four VLANs — HR, Finance, IT, and Server/Infrastructure.
Configured 802.1Q trunk links across multiple switches with Spanning Tree Protocol for redundancy.
Implemented extended ACLs to enforce least-privilege access between network segments.
Deployed centralized DHCP on the router with per-VLAN pools and validated dynamic lease assignment.
Enterprise VLAN Segmentation Lab
Security / SIEM
Splunk SIEM Log Analysis & Threat Detection Lab
Deployed Splunk SIEM in a Linux environment to ingest, analyze, and monitor logs from
Windows and Linux systems — building detection logic and dashboards aligned with
real-world security operations workflows.
Deployed Splunk SIEM to ingest and analyze Windows and Linux logs.
Configured Universal Forwarders for centralized log collection across systems.
Built custom dashboards to visualize authentication activity and system events.
Developed alert rules to detect brute-force login attempts and suspicious behavior.
Documentation coming soon
Windows / IAM
Active Directory Domain Services & Group Policy Management Lab
Built a Windows Server domain environment with Active Directory, configuring users,
groups, organizational units, and Group Policy to simulate enterprise identity and
access management operations.
Deployed Windows Server as a Domain Controller and configured Active Directory Domain Services (AD DS).
Created and managed users, groups, and organizational units (OUs).
Implemented Group Policy Objects (GPOs) to enforce password policies and system restrictions.
Joined domain clients and validated centralized authentication and access control.
Documentation coming soon
Linux / SysAdmin
Linux System Administration & Service Management Lab
Administered an Ubuntu Linux system through hands-on configuration of user management,
SSH hardening, service control, and firewall rules — reflecting production-level
Linux administration practices.
Administered Ubuntu Linux system with user account management and privilege control.
Secured remote access via SSH hardening and key-based authentication.
Managed services using systemd and automated recurring tasks with cron jobs.
Configured UFW firewall rules and file permissions to enforce system security.
Documentation coming soon
Cloud / AWS
AWS Secure VPC Architecture & Network Design
Designed and deployed a custom AWS VPC with segmented public and private subnets,
implementing layered network security and controlled internet access to reflect
production-grade cloud infrastructure design.
Designed and implemented a custom AWS VPC with public and private subnets.
Configured route tables, Internet Gateway, and NAT Gateway for controlled internet access.
Applied security groups and network ACLs to enforce layered network security.
Deployed EC2 instances in private subnets and validated secure connectivity.
Roles in systems administration, cloud operations, network engineering, and
security-focused infrastructure — where technical depth and operational discipline matter.
PDF
Enterprise VLAN Segmentation & Inter-VLAN Routing