Systems Architect
Sole systems architect with full ownership of the organization's infrastructure — spanning network security, server administration, telephony, cloud platforms, authentication, CI/CD automation, and internal tooling. Operates independently and self-managed, proactively identifying opportunities to deliver real business value across cost, reliability, security, and efficiency.
- Reduced AWS monthly spend from ~$1,500 to $600 — a recurring savings of $10,800/year — through resource right-sizing, elimination of unused services, and architectural consolidation. Recognized directly by company leadership.
- Identified ~100,000 wasted SIP minutes/month (~$2,000/month) through SIP trunk provider analysis, surfacing a previously undetected cost leak.
- Replaced legacy AutoSSH tunnel infrastructure with WireGuard VPN across all AWS-to-on-premises connections, improving security, reliability, and maintainability.
- Executed a full FortiGate firewall replacement — migrating two 60E units to 60F models by directly editing configuration files to resolve model-mismatch import failures, restoring HA cluster operation with zero data loss.
- Diagnosed and resolved a network-wide routing conflict caused by two independently operating firewalls sharing overlapping configurations.
- Responded to an active server intrusion — removed cryptominer malware, eliminated the compromised account, hardened SSH to key-only auth, and deployed fail2ban across affected systems.
- Completed full Ubuntu 20.04 → 22.04 migration across all production servers using a staged validation approach — testing on cloned environments before production execution — with zero data loss.
- Migrated OpenLDAP backend from legacy HDB to MDB for Ubuntu 22.04 compatibility, configured LDAPS with a self-signed CA, and deployed SSSD organization-wide for centralized authentication.
- Resolved a RAID 5 disk failure on a production backup server, executing a controlled drive replacement and monitored rebuild to restore full array redundancy.
- Managed VMware ESXi virtualization — snapshot management, storage optimization, VM lifecycle across the server fleet.
- Executed full 3CX v18 → v20 upgrade, including OAuth 2.0 API reconfiguration to restore support metrics dashboards.
- Rewrote all call flow scripts from scratch after the migration broke existing configurations, restoring full inbound call routing.
- Built a Linux service using inotifywait and FFmpeg to auto-compress 3CX call recordings, cutting per-recording storage ~90%.
- Developed a voice-to-text transcription and summarization pipeline using Google Speech-to-Text and Gemini APIs, letting managers review 45-minute calls in minutes.
- Built a UPS address validation integration across account creation, leads dashboard, and Five9 — verifying addresses in real time with full audit trails.
- Cleaned up and modernized Jenkins CI/CD pipelines, removing outdated dependencies and improving job organization.
- Customized Zabbix monitoring with descriptive failure messages, RAID health triggers, and PHP-FPM worker exhaustion alerting.
- Optimized Nakivo backup infrastructure, resolving repository corruption and restructuring job scheduling.
- Profiled and optimized slow queries across internal MySQL/MariaDB systems supporting call center analytics.
- Maintained MySQL master/slave replication through the Ubuntu upgrade cycle with zero integrity loss.