Self-taught. Trained in Uruguay, based in Pamplona. Fifteen years moving up the stack one layer at a time, from repairing hardware to running Linux support for enterprise monitoring.
From the workbench to L3 Linux.
Linux & security
Enterprise support
Infrastructure
Networks
Hardware
2005
Learning the machine
Instituto BIOS, Uruguay · 2005 – 2009
PC repair and IT first, then Systems Administration & Networked IT Systems. The foundations: hardware, operating systems, networks.
Hardware
2011
Technical Department Manager
Composystem · 2011 – 2012
First team: five technicians
Ran daily operations, quality control and process improvement, and kept the Windows Server 2008 machines backed up and patched.
Hardware
2012
Fiber Optics Activation Technician
Antel · 2012 – 2014
In the field, at customers' homes
Installed and configured ONT routers, activated fiber services and verified connectivity on site.
Networks
2015
IT & Administration Manager
Local hospitality business · 2015 – 2020
Owned the whole infrastructure: POS systems, LAN, CCTV cameras, hardening and basic network administration.
Infrastructure
2020
IT Helpdesk
Helphone · 2020 – 2022
Enterprise remote support, L1/L2
Active Directory users and permissions on Windows Server, remote support over CITRIX and TeamViewer, procedures documented to shorten response times.
Enterprise support
2022
Senior IT Support Engineer
Pandora FMS · 2022 – today
Linux support for enterprise monitoring, L2/L3
Red Hat and CentOS administration, Apache and custom plugins in Bash and Python, automation, hardening and pentesting audits.
2025CompTIA Security+
PyPIEight of my own open-source tools published
Linux & security
Tools I built for problems I kept meeting.
Nine open-source tools, eight of them published on PyPI. Here are three, shown the way they came about: the problem, what I built, and what it produces.
infradrift
The problem
A server that was fine last week starts misbehaving. Someone opened a port, added a user or changed a cron job, and nobody knows what.
What I built
A CLI that snapshots packages, listening ports, users and sudo groups, cron jobs and systemd services while the server is healthy, then compares any later state against that baseline.
The result
A drift report ranked by severity, as terminal output, JSON for CI or Markdown. It exits with code 1 when something drifted, so it can run from cron.
Real run of infradrift 1.1.0 on 26 Sep 2026, in a throwaway test container, after adding a test user to the sudo group and a cron job.
syslog-postmortem
The problem
After an outage the timeline is scattered across journalctl, syslog, auth.log and kern.log, full of duplicates, and someone has to rebuild it by hand.
What I built
A tool that takes the incident window, collects all four sources, removes duplicates and detects patterns: OOM kills, restart loops, auth bursts, cascading failures.
The result
A postmortem draft in Markdown or HTML, with timeline, contributing factors and action items, ready to edit.
Python · PyPIpip install syslog-postmortemView on GitHub
journalctl
syslog
auth.log
kern.log
timeline
Postmortem: Database outage
Window
14:00 → 16:00
Severity
Critical
Timeline
14:03:22kernelOut of memory: Killed process 2211 (postgres)
–postgresql triggered restart-loop detection 4 times
–nginx errors began 21s after the first postgresql critical event
Diagram of four log sources merging into one timeline; the report is an excerpt of the example in the project README.
envlock
The problem
"It works on my machine" is a drift problem: the Python and Node versions, the installed packages and the runtimes diverge between a laptop, staging and production, and nobody notices until something breaks.
What I built
A tool that snapshots a project's environment across layers — Python and Node packages, language runtimes, OS and environment variables — and compares the current state against that baseline, locally or as a CI gate.
The result
Every change listed and ranked by severity: a runtime version change is critical, a removed or downgraded package is a warning. The exit code fails the pipeline, so drift is caught before it reaches production.
Diagram of the layers envlock locks in its baseline; the report is real output of envlock 1.1.0 on 2 Oct 2026, hostname and path shortened. A changed Python or Node version would show as critical.
WazuhOSSECPandora SIEMESET EDRNessusVulnogramHack The BoxActive DirectoryLDAPCitrix
What I work with, every week.
Linux systems
Red Hat, CentOS, Debian and Ubuntu. Services with systemd, cron, logrotate and journalctl; performance tuning of critical environments; Apache, MySQL, OpenVPN, OpenSearch / Elasticsearch.
Automation
Advanced Bash, Python plugins and CLI tools, hands-on Ansible. JSON, XML, SQL and PHP where an integration needs them.
Monitoring & platforms
Pandora FMS with custom plugins, Docker and LXC containers, Proxmox, VMware and VirtualBox.
Networks & support
LAN, firewalls, VLANs, VPNs, DNS, DHCP and LDAP. Active Directory, CITRIX, TeamViewer and Google Workspace. L1 to L3.
CompTIA Security+ SY0-701
Issued 24 Jun 2025 · valid until 24 Jun 2028
Security runs through the daily work: Linux hardening, log analysis, pentesting audits for clients and incident response. Wazuh, OSSEC, Pandora SIEM, ESET EDR and Nessus; CVE analysis and disclosure through Vulnogram; Red Team labs on Hack The Box.