// Senior Cyber Systems Engineer

Jeremy

polymanian.com

Security Automation · STIG Compliance · Enterprise Infrastructure

CISSP Security Clearance Programming Scripting Compliance
jack@pds-lab ~
$ ansible-playbook site.yml --tags stig PLAY [Apply STIG Baselines] **************** TASK [esxi_stig : Check SSH timeout] ... ok: [esxi-01.pds.local] ok: [esxi-02.pds.local] TASK [windows_stig : Enforce audit policy] changed: [dc01.pds.local] changed: [ws11-001.pds.local] TASK [wazuh : Validate agent heartbeat] ... ok: [all 14 hosts] PLAY RECAP ******************************** ok=47 changed=6 failed=0 skipped=2 $

Enterprise-Grade Homelab Environment

A full simulation of a defense contractor security environment, running 24/7 on a Dell R730XD. Every component mirrors production systems I engineer at scale.

NET // PERIMETER

pfSense Firewall

Netgate 8100 running pfSense with 10 VLANs, HAProxy reverse proxy, pfBlockerNG threat intel feeds, and Suricata IDS/IPS on WAN.

VLAN SegmentationIDS/IPSDNS FilteringDHCP

VIRT // HYPERVISOR

Proxmox VE

Dell R730XD hosting 15+ VMs and LXC containers. Terraform + cloud-init provisioning with a FastAPI VM registry for dynamic Ansible inventory.

Terraformcloud-initLXCKVM

SEC // SIEM + IDS

Security Onion

Full-stack network security monitoring with Zeek, Suricata, and the Elastic stack. Ingests traffic from pfSense span ports across all VLANs.

ZeekSuricataElasticPCAP

SEC // HIDS

Wazuh

Host-based intrusion detection, file integrity monitoring, and log aggregation across all endpoints. Integrated with Active Directory for auth event correlation.

HIDSFIMSIEMCompliance

IAM // DIRECTORY

Active Directory

Two Server 2022 domain controllers with WSUS, GPO hardening, and Windows 11 endpoints. Simulates a full enterprise AD environment with tiered accounts.

GPOWSUSDNSPKI

MAIL // MTA

Mailcow

Self-hosted mail stack with Postfix, Dovecot, SOGo, and Rspamd. Deployed in an isolated VLAN with pfSense policy enforcement and TLS everywhere.

PostfixDKIM/DMARCRspamdTLS

ITSM // HELPDESK

Faveo Helpdesk

Self-hosted ITSM and service desk for ticketed workflows, change requests, and operational SOPs across the lab environment.

ITSMTicketingService Desk

HR // WORKFORCE

OrangeHRM

HR management and employee lifecycle — onboarding workflows that integrate with AD account provisioning and IT ticketing.

HROnboardingUser Lifecycle

DEV // SCM

Self-Hosted GitLab

gitlab.polymanian.com with container registry, CI/CD runners, and pipelines for AD inventory automation and STIG toolchain deployment.

CI/CDContainer RegistryPowerShell Runners

STORE // NAS

TrueNAS

Centralized storage with ZFS, SMB/NFS shares, and snapshot-based backup for VM data, security logs, and tool artifacts.

ZFSSMB/NFSSnapshots

Multi-VLAN Segmented Design

Defense-in-depth network layout modeled after NIST 800-53 and DISA RMF principles. All inter-VLAN traffic is firewall-inspected.

INTERNET

Netgate 8100 · pfSense

Perimeter firewall / inter-VLAN inspection

Suricata IPSpfBlockerNGHAProxy
802.1Q VLAN Trunk

VLAN 10

Management

  • Proxmox VE
  • TrueNAS
  • pfSense GUI

VLAN 20

Servers

  • Active Directory
  • GitLab
  • WSUS
  • FastAPI Registry

VLAN 30

Security

  • Security Onion
  • Wazuh
  • T-Pot Honeypot

VLAN 40

Clients

  • Windows 11
  • Managed Endpoints

VLAN 50

DMZ

  • Mailcow
  • OrangeHRM
  • Ticketing

Security Onion

SPAN port mirrors all VLAN traffic

Zeek · Suricata · Elastic

Wazuh Manager

HIDS telemetry + file integrity

AD auth event correlation

GitLab CI/CD

Config + infrastructure automation

Ansible · PowerShell · Terraform

Project Write-ups

Deep dives into what I have built, why I built it, and the problems I solved along the way. Written for security engineers, not marketing.

Solution Architecture~10 min read

Building a Small-Business Stack with Open Source

Four open-source tools on a single Proxmox host -- Active Directory, Faveo, OrangeHRM, and Mailcow -- cover identity, ITSM, HR, and email: nearly everything a small company needs to operate.

ArchitectureOpen SourceSelf-Hosting
Mail Server~12 min read

Mailcow: A Self-Hosted Mail Server

Running your own mail server with mailcow-dockerized on a Proxmox VM -- full email plus groupware for a small business, and an honest look at the deliverability and security work it demands.

MailcowDockerEmail
ITSM~9 min read

Faveo Helpdesk: Self-Hosted ITSM

Deploying Faveo Helpdesk as a TurnKey Linux appliance on Proxmox to give a small business real ITSM -- ticketing, SLAs, and a knowledge base -- without per-agent SaaS fees.

FaveoTurnKeyITSM
Identity Management~11 min read

Active Directory: The Identity Backbone

Standing up Windows Server 2022 Active Directory on Proxmox as the identity backbone for a small-business stack -- and why centralized identity is the first problem to solve.

Windows ServerAD DSIdentity
Self-Hosting~10 min read

Self-Hosting OrangeHRM

Evaluating OrangeHRM as an open-source solution to a real business problem -- deployed as a TurnKey Linux appliance on Proxmox -- through both an architecture-and-solutions and a security lens.

OrangeHRMTurnKeyProxmox
PowerShell Module~9 min read

CSVActiveDirectory

A PowerShell module that simulates Active Directory using CSV files as the backend -- real AD cmdlets, password validation, and backups, with no domain controller required.

PowerShellActive DirectoryCSV
Compliance Automation~10 min read

ESXiManScan

An Ansible + PowerCLI tool that runs DISA STIG compliance scans against VMware ESXi hosts and outputs ready-to-submit STIG Viewer (.ckl) checklists.

AnsiblePowerCLISTIG
Security Tooling~12 min read

Trivy Security Center

A self-hosted vulnerability management platform that ingests Trivy and CycloneDX scans, with RBAC, audit logging, waivers, and one-command RPM deployment.

DjangoTrivyCycloneDX
Virtualization~13 min read

VM Provisioning With Proxmox

Build one VM the right way, get it fully updated and stable, generalize it, and convert it to a Proxmox template -- then clone ready-to-go machines in seconds.

ProxmoxtemplatesKVM

Security Engineer. Builder. Veteran.

  • CISSP — Certified Information Systems Security Professional
  • Bachelor's Degree in Cybersecurity & Information Assurance
  • Active DoD Security Clearance
  • 10+ years cybersecurity engineering experience
  • United States Marine Corps Veteran

Automation & Scripting

PowerShellPythonBashAnsible

Security Platforms

Security OnionWazuhpfSenseSplunkTenable.SC

Compliance & Frameworks

DISA STIGsNIST 800-53RMFCMMCCIS Benchmarks

Infrastructure

VMware/ESXiProxmoxRHELWindows ServerActive DirectoryKubernetes

Development

DjangoFastAPIPowerShell WPFGitLab CI/CDDocker/Podman

Let's Connect