SergioBerruetta

Senior IT Support Engineer & Linux Systems Administrator

I take incidents from the first ticket to the root cause, and keep the Linux systems behind them healthy, hardened and automated.

In IT since
2011
Support
L1 → L3
Certified
CompTIA Security+ SY0-701
Based in
Pamplona, Spain (EU)

About

Self-taught. Trained in Uruguay, based in Pamplona. Fifteen years moving up the stack one layer at a time, from repairing hardware to running Linux support for enterprise monitoring.

From the workbench to L3 Linux.

  1. Learning the machine

    Instituto BIOS, Uruguay · 2005 – 2009

    PC repair and IT first, then Systems Administration & Networked IT Systems. The foundations: hardware, operating systems, networks.

    Hardware

  2. Technical Department Manager

    Composystem · 2011 – 2012

    First team: five technicians

    Ran daily operations, quality control and process improvement, and kept the Windows Server 2008 machines backed up and patched.

    Hardware

  3. Fiber Optics Activation Technician

    Antel · 2012 – 2014

    In the field, at customers' homes

    Installed and configured ONT routers, activated fiber services and verified connectivity on site.

    Networks

  4. IT & Administration Manager

    Local hospitality business · 2015 – 2020

    Owned the whole infrastructure: POS systems, LAN, CCTV cameras, hardening and basic network administration.

    Infrastructure

  5. IT Helpdesk

    Helphone · 2020 – 2022

    Enterprise remote support, L1/L2

    Active Directory users and permissions on Windows Server, remote support over CITRIX and TeamViewer, procedures documented to shorten response times.

    Enterprise support

  6. Senior IT Support Engineer

    Pandora FMS · 2022 – today

    Linux support for enterprise monitoring, L2/L3

    Red Hat and CentOS administration, Apache and custom plugins in Bash and Python, automation, hardening and pentesting audits.

    • 2025 CompTIA Security+
    • PyPI Eight of my own open-source tools published

    Linux & security

Tools I built for problems I kept meeting.

Nine open-source tools, eight of them published on PyPI. Here are three, shown the way they came about: the problem, what I built, and what it produces.

infradrift

  1. The problem

    A server that was fine last week starts misbehaving. Someone opened a port, added a user or changed a cron job, and nobody knows what.

  2. What I built

    A CLI that snapshots packages, listening ports, users and sudo groups, cron jobs and systemd services while the server is healthy, then compares any later state against that baseline.

  3. The result

    A drift report ranked by severity, as terminal output, JSON for CI or Markdown. It exits with code 1 when something drifted, so it can run from cron.

infradrift · drift report

Baseline
2026-09-26T09:52:48
Current
2026-09-26T09:52:50

Users

critical+deploy-test uid=1000 /bin/bash, new user

Privileged Groups

critical+deploy-test added to privileged group sudo

Cron Jobs

warning+New cron job: */5 * * * * root /usr/bin/true

3 changes detected (2 critical, 1 warning)

Real run of infradrift 1.1.0 on 26 Sep 2026, in a throwaway test container, after adding a test user to the sudo group and a cron job.

syslog-postmortem

  1. The problem

    After an outage the timeline is scattered across journalctl, syslog, auth.log and kern.log, full of duplicates, and someone has to rebuild it by hand.

  2. What I built

    A tool that takes the incident window, collects all four sources, removes duplicates and detects patterns: OOM kills, restart loops, auth bursts, cascading failures.

  3. The result

    A postmortem draft in Markdown or HTML, with timeline, contributing factors and action items, ready to edit.

Postmortem: Database outage

Window
14:00 → 16:00
Severity
Critical

Timeline

14:03:22kernelOut of memory: Killed process 2211 (postgres)

14:03:45nginxconnect() failed (111: Connection refused) ×40

Contributing factors

–postgresql triggered restart-loop detection 4 times

–nginx errors began 21s after the first postgresql critical event

Diagram of four log sources merging into one timeline; the report is an excerpt of the example in the project README.

envlock

  1. The problem

    "It works on my machine" is a drift problem: the Python and Node versions, the installed packages and the runtimes diverge between a laptop, staging and production, and nobody notices until something breaks.

  2. What I built

    A tool that snapshots a project's environment across layers — Python and Node packages, language runtimes, OS and environment variables — and compares the current state against that baseline, locally or as a CI gate.

  3. The result

    Every change listed and ranked by severity: a runtime version change is critical, a removed or downgraded package is a warning. The exit code fails the pipeline, so drift is caught before it reaches production.

envlock check

Python packages

  • +httpx added ==0.27.0info
  • −urllib3 removed was ==2.0.7warning
  • ~requests ==2.31.0 → ==2.32.3warning

3 changes · 2 warnings · 1 info exit 1

Diagram of the layers envlock locks in its baseline; the report is real output of envlock 1.1.0 on 2 Oct 2026, hostname and path shortened. A changed Python or Node version would show as critical.

What I work with, every week.

Linux systems

Red Hat, CentOS, Debian and Ubuntu. Services with systemd, cron, logrotate and journalctl; performance tuning of critical environments; Apache, MySQL, OpenVPN, OpenSearch / Elasticsearch.

Automation

Advanced Bash, Python plugins and CLI tools, hands-on Ansible. JSON, XML, SQL and PHP where an integration needs them.

Monitoring & platforms

Pandora FMS with custom plugins, Docker and LXC containers, Proxmox, VMware and VirtualBox.

Networks & support

LAN, firewalls, VLANs, VPNs, DNS, DHCP and LDAP. Active Directory, CITRIX, TeamViewer and Google Workspace. L1 to L3.

CompTIA Security+ SY0-701

Issued 24 Jun 2025 · valid until 24 Jun 2028

Security runs through the daily work: Linux hardening, log analysis, pentesting audits for clients and incident response. Wazuh, OSSEC, Pandora SIEM, ESET EDR and Nessus; CVE analysis and disclosure through Vulnogram; Red Team labs on Hack The Box.

Languages
Spanish (native), English (C1), French (A1, learning)
Education
Systems Administration & Networked IT Systems, Instituto BIOS, Uruguay (2007–2009)

Hiring a senior Linux or IT support engineer?

Tell me about the team and the systems behind it. Write to me here; my CV is available on request.

I only use your details to reply to you. Spam protection by Cloudflare Turnstile.