Curriculum Vitae
Infrastructure as Craft | Building calm, reliable systems through Platform Engineering & Site Reliability Engineering
Barendrecht, South Holland, Netherlands
Experience
Senior Linux Engineer – Global Infrastructure — i3D.net
Platform Engineer — Logius
Elasticsearch and ECE, boring in the best way. Coaching, codified patterns, change reviews. Good practice over quick fixes.
- Own platform health across multiple Elasticsearch/ELK environments supporting critical national services; drive consistency in operations.
- Codify cluster deployment & operations patterns in Ansible playbooks used by other teams (reproducible + sane by default).
- Agree reliability targets with product teams and review alerts against those targets.
- Prepare environments for Cross-Cluster Replication (CCR) & multi-tenancy to broaden platform reach.
- Serve as technical conscience / design sparring partner across infra initiatives; influence decisions toward long-term reliability.
- Reduced toil & alert fatigue by strengthening automation and observability signals.
- Unblock teammates & sister teams when needed; keep delivery flow smooth.
Sr. Linux Specialist — Ministerie van Binnenlandse Zaken en Koninkrijksrelaties
Made complex infra predictable and boring; central Elastic Cloud Enterprise, Flask insight tooling, modular Ansible; codified patterns and ran reviews.
- Acting Tech Lead for 6 months: coordinated delivery, represented the team in SAFe ceremonies (ART Syncs, SI syncs, PI Planning), coached engineers; returned to IC to maximise impact as the model became process-heavy, documented recommendations, and handed over cleanly.
- Designed, deployed & operated a central Elastic Cloud Enterprise platform that now serves 10+ teams of varying scale, streamlining Elasticsearch adoption and giving a single point of control and accountability.
- Built a Flask-based infra insight tool (MongoDB, Pandas, Pydantic, Celery + RabbitMQ) aggregating CMDB (TOPdesk), Ansible facts & Grafana data; used by capacity, procurement & platform teams for usage, storage & ECE reporting.
- Re-architected monolithic Ansible repository into modular Galaxy structure; accelerated reuse and lowered maintenance burden.
- Authored & maintained broad Ansible role library to automate deployments and reduce manual ops.
- Championed infra best practices via reviews & mentoring; raised automation maturity.
- Managed and improved production Elasticsearch environments (stability, uptime, predictability).
Sr. Linux Specialist — Nationaal Cyber Security Centrum (NCSC-NL)
Kept infrastructure dependable and future-proof by managing SINA systems and rolling out their next generation.
- Operated and refreshed secure SINA infrastructure (incl. PKI) underpinning NCSC operations; delivered next-gen rollout to replace ageing environment with minimal disruption.
- Managed mixed physical & virtual infrastructure footprint in high-trust environment.
DevOps Engineer — Hoppinger
Puppet 2.7 to modular Puppet 5 with r10k/Hiera; GitLab CI/CD standards; Docker hosting on OpenStack and bare metal; ZFS-backed foundations; coached CLI fluency.
- Transformed Puppet 2.7 legacy into modular Puppet 5 (r10k/Hiera); enabled multi-dev workflows and cleaner environments.
- Established Git Flow & GitLab CI/CD to standardise change across infra repos; enforced quality gates.
- Developed scalable update strategy tied to both server count & team growth.
- Designed Docker-based hosting platform deployable on OpenStack or bare metal; abstracted infra differences.
- Built ZFS-backed Ubuntu building blocks (KVM, Docker, central backup) to lower hosting TCO.
- Modernised network stack with MikroTik CCR/CRS + VLAN segmentation & CAPsMAN Wi-Fi.
Senior Linux Engineer at Stichting Deltares — Snow B.V.
Helped keep the national flood forecast running, replaced fire-fighting with scheduled maintenance, and designed FreeBSD storage that could scale with the tide.
- Maintained mission-critical forecasting clusters (~120 servers) supporting national water infrastructure
- Redesigned server environments for improved robustness, scalability, and maintainability
- Deployed custom-developed forecasting software (Delft-FEWS) into production environments
- Introduced regular maintenance windows to stabilise long-running services
- Designed and planned rollout of a scalable FreeBSD + ZFS-based storage platform (starting at 20TB raw)
Founder — Loeniks
Kept a shoestring VPS platform humming: XenServer to carve up the metal, Bacula to sleep at night, and enough automation to keep click‑ops at bay. Looked after users, comms, and capacity so side‑projects could just run.
- Virtualisation & backups: XenServer + Bacula, with sensible defaults.
- Provisioning automation and base images to keep instances consistent.
- Community support, PR, and incident handling.
Senior UNIX & Linux Engineer at KPN Mobile — Snow B.V.
Kept the Sun boxes purring, brought Linux into the fold, and modernised Nagios before it was cool again.
- Planned and implemented improvements across a 1500+ server Unix/Linux landscape
- Designed and implemented high-availability(ish) environments using Solaris 10 and Red Hat Enterprise Linux
- Upgraded legacy monitoring systems (Nagios 1 → 3) and integrated with Groundwork
- Managed Solaris Zones on Sun SPARC Enterprise M5000 systems
- Performed periodic tooling upgrades on Sun Fire 6900 to support Ericsson OSS operations
- Provided backline support for all Unix infrastructure across multiple data centres
Senior Unix/Linux Consultant (Selected Engagements) — Snow BV
Short, high‑impact automation and platform work for enterprise clients:
- Mirabeau (Jan 2013 - Jul 2014): Automated ov-chipkaart.nl infrastructure with Puppet
- Deltares (Nov 2012 - Dec 2012): Created CentOS 6 VMware baseline
- ASML (Apr 2012 - Oct 2012): Extended Perl tooling to consume the RHEV API
Senior UNIX & Linux systems administrator — ProServe B.V.
Helped scale and modernise a growing ISP by migrating legacy platforms, automating ops, and keeping 600+ servers happy.
- Designed and implemented high-availability server environments for clients with 99.9% SLA commitments
- Led a zero-downtime platform migration from FreeBSD 4.11 to CentOS/RHEL alongside a colleague
- Developed internal tooling (Perl/Bash) to automate updates, manage backups, and visualise backup health
- Acted as third-line support and escalation point for complex technical issues
- Maintained and grew a 600+ server landscape in a rapidly scaling ISP environment
- Served as the department’s go-to engineer for deep-dive problems and technical guidance
Linux systems administrator — Netnation Europe
Built mail and DNS clusters that stayed up, stayed redundant, and stayed out of the pager.
- Designed, implemented, and documented a geographically redundant mail cluster with spam and virus filtering, serving over 60,000 domains
- Built a redundant DNS cluster to provide authoritative name service for the same domain base
- Standardised automation for backups & quotas
- Managed a rapidly growing fleet of ~900 servers (primarily CentOS, with some FreeBSD and Windows)
- Developed internal tools (Perl/Bash) to automate updates, backups, and quota management
- Maintained spam and virus filtering on all mail frontends
- Acted as third-line support for escalated infrastructure issues
Technological mastermind — Digital Storm Technologies
FreeBSD/Linux hosting admin. Automated backups and updates (Bash/Perl), standardised web/DNS/mail configs, and hardened internet‑facing services.
Support Engineer — Sitecom
Technical support.
Junior systems administrator — Wirehub! Internet B.V.
Juggled Apache configs, shell scripts, and the occasional Windows NT box.
- Created and managed virtual hosts on FreeBSD, Linux, and Windows NT web servers
- Maintained and supported client-dedicated servers across multiple platforms
- Developed internal tools and utilities using PHP, Perl, and Bash
- Handled day-to-day web server and database management tasks
- Maintained and updated content on the company’s public-facing website
Skilled frontdesk operative — Wirehub! Internet B.V.
Wirehub! Internet B.V. was an ISP targeted on the business-to-business market. Wirehub! was sold to Easynet in 2002. My tasks included:
- Support by phone
- Support by email
Homelab Engineer — Home.arpa Enterprises
Built a homelab that runs smoother than some prod environments, just to keep my CLI chops sharp and my data safe with ZFS.
- Architect and run an Arch Linux KVM host with OpenBSD guest (DNS for private zones) plus rotating FreeBSD/OpenBSD guests for continuous OS expertise
- Manage container services via Portainer. Services include Nextcloud, Vaultwarden, Ghost CMS, and several static sites
- Operate an OpenBSD and Debian-based Raspberry Pi fleet providing internal services, including LDAP, NTP, privacy-filtered DNS, and CalDAV
- Deploy an off-site OpenBSD guest with WireGuard VPN to expose public projects while isolating the homelab
- Segment networks into Private, Generic Services, IoT, and DMZ VLANs to enforce granular security controls
- Design and maintain off-site, incremental backups with ZFS and Restic, protecting ~35 TB of data
- Serve as a sandbox for patterns I later apply in production; lessons here fed straight into the Logius ELK stack and the ECE platforms at Logius and MinBZK.
Projects
LPIC2 exam prep
Updating internal LPIC2 exam prep documentation to (then) current standards.
APC UPS integration
Preparing, implementing and documenting several APC UPS devices (SURT6000XLI) into the network
Perl programming
Miscellaneous code enhancements to a Perl (CGI) based internal website
PS3 Mersenne
Exploring the alternative uses of the PlayStation3 in a low-cost high performance computing environment.
OpenSSL PKI
Setting up and documenting the new PKI environment
Typo3 CMS
Implementing a new CMS
Creating RHEV interface layer
Expanding existing Perl-based toolset features to interface with the RedHat Enterprise Virtualizatiin (RHEV) API
Publish LPIC2 exam prep to Google Play, Apple iBooks and Scribd
Publish Snow's internal LPIC2 exam prep documentation to the Google Play store, Apple iBooks, and Scribd.
Elastic Cloud Enterprise
Set up an ECE environment to assess the product for use in the organisation.
Elastic Cloud Enterprise
Designed & ran a central ECE platform, onboarding 11 teams and collapsing multiple ad‑hoc clusters into one managed service; docs + SLM/ILM policies cut delivery from weeks to hours. Purpose Replaced, and prevented further growth of, a patch‑work of standalone Elasticsearch clusters spread across several data‑centres. Introduced one centrally managed ECE platform that provides a single point of contact, faster cluster delivery, and easier life‑cycle governance. Scale & Adoption
- 40 nodes overall (18 nodes in production DTAP)
- 11 teams onboarded; additional teams queued (growth limited only by external networking capacity) My Contributions
- Architecture & Roll‑out: designed, deployed, and tuned the 18‑node production ECE platform; migrated initial tenants from legacy clusters.
- Self‑Service Onboarding: authored step‑by‑step docs and scripts; guided each team through its first deployment.
- Life‑Cycle Policies: implemented Snapshot and Index Life‑cycle Management (SLM/ILM) to enforce retention and control costs for teams without Elastic expertise.
- Operational Consolidation: decommissioned multiple ad‑hoc clusters, reducing cross‑DC sprawl and unifying support under one platform queue. Impact
- Cluster provisioning time dropped from weeks to hours for the first wave of teams.
- Support simplified: one platform, one contact channel, consistent monitoring and backups.
Infrastructure Insight & Capacity Tool
Developed an internal Flask-based web application to surface actionable insights from infrastructure data, combining CMDB records, Ansible facts, and monitoring metrics.
- Aggregated data from TopDesk (CMDB), Grafana/MySQL, and Ansible into a unified interface
- Built with Flask, Pandas, Pydantic, and backed by MongoDB
- Enabled reporting on server usage, ECE deployments, and storage consumption
- Used by multiple teams for capacity planning, procurement, and environmental auditing Outcome: Reduced manual reporting overhead and made real-time infra insights accessible across teams.
Education
Hogeschool Rotterdam — (unspecified)
St. Montfort College — HAVO
Thomas More Hogeschool — (unspecified)
Skills
- Skills
- Platform Engineering, Infrastructure as code (IaC), Site Reliability Engineering, Ansible, Elastic Stack (ELK), Hybrid Cloud, Technical Leadership, Elastic Cloud Enterprise, Elasticsearch, Jinja2, Terraform, Configuration Management, Secunet SINA, Perl, Apache, Postfix, Bind, Coaching, Data Visualization, Cloudflare, Puppet (Software), Scalable Web Applications, Extract, Transform, Load (ETL), Telemetry, Reliability, Skill Development, Network Infrastructure, Critical Infrastructure, Scalability, Capacity Planning, Networking, GitOps, OpenBSD, FreeBSD, Platform Architecture, Jenkins, Nginx, Pandas (Software), Gitlab, Flask, Troubleshooting, REST APIs, Automation, Linux System Administration, Virtualization, System Administration, High Availability, Agile Methodologies, Bash, Unix, MySQL, Git, Linux, Debian, Ubuntu, Red Hat Linux, Docker Products, MongoDB, Python (Programming Language), DevOps, Containerization, Continuous Integration and Continuous Delivery (CI/CD), Amazon Web Services (AWS), Cybersecurity
Certifications
- Puppet Professional 2014 Certification — Puppet (2014)
- Red Hat Certified Engineer — Red Hat (2012)
- Red Hat Certified System Administrator — Red Hat (2012)
- SNIA Certified Storage Professional — SNIA (2010)
- LPI-2 — Linux Professional Institute (2008)
- LPI-1 — Linux Professional Institute (2008)
- Novell Certified Linux Administrator — Novell (2011)
- Novell Data Center Technical Specialist — Novell (2011)
- ITIL (v3) Foundations (ITV3F) — itSMF International (2008)
- Sun Certified System Administrator for the Solaris 10 OS part 1 — Sun Microsystems (2008)
- SINA Basics — secunet Security Networks AG (2018)
- [PCEP-30-02] PCEP – Certified Entry-Level Python Programmer — Python Institute (2022)
- Introduction to Terraform on Azure — LinkedIn (2025)
Languages
- English — Native or bilingual proficiency
- Dutch — Native or bilingual proficiency