IT Consultant - Infrastructure Manager
RILC QualServ SRL
octobre 2010 - février 2019
City: Brussels
Rubén ********
Nationality: Spanish Date of birth: 12/10/1966 Gender: Male Phone number: (+32) 476681899
Email address: ********
Home: ********
Country: Belgium
Customer: subcontractor of Televic and Videlio for the final customer European Parliament.
Environment: conference and meeting rooms managed by DG LINC CIIU.
Job overview:
• Concept-Design
• Installation
• Configuration
• Maintenance
• Programmation - Programming
Technical aspects:
• DG Linc IT infrastructure migration from current HP to Cisco switches by migrating rooms to DG ITEC
infrastructure, re-configuration of all audio and video equipment.
• Installation, configuration, maintenance, and monitoring of the new CTULAN central management
infrastructure based on VMWare ESXi servers and Synology NAS appliances.
• Installation, configuration, and maintenance of the new DANTE networks.
• Installation, configuration, and maintenance of the central monitoring solution based on PRTG using mainly
SNMP.
• Installation, configuration, and maintenance of central SYSLOG server based on Kiwi Syslog.
• Installation, configuration, and maintenance of the central backup solution based on Acronis and local
scripting.
• Installation, configuration, maintenance, and monitoring of the Active directory and DNS for central user
management and GPO policies.
• Monitoring of the new central audio recording solution based on SoundEyes for CRE and MRS projects.
• Maintenance of the central CA to distribute proper X509 certificates on the CTULAN network.
• PoC installation, configuration, and maintenance of Digital signage, global anti-virus solution, etc.
Technologies:
• IT: Cisco and HP switches, PRTG Network Monitor, Kiwi Syslog Server, VMware ESXi, Active Directory,
Windows 7/10/2012R2.
• Audio/Video: Axis, Crestron, DANTE, Alias SoundEyes.
IT Consultant - Infrastructure Manager
RILC QualServ SRL [
octobre 2010 - aujourd'hui
Business or sector: Financial and insurance activities
Customer: High-SEA SRL
Environment:
Dedicated physical servers hosted in a 3rd-party datacentre and each hosting virtual servers and appliances, and
interconnected with VPN IPSec.
Servers side:
- Physical servers interconnected with VPN IPSec.
- Virtual environment design, installation, and maintenance.
- Security design and implementation.
- Windows-based SAP and Active Directory/DNS, and Ubuntu-based Web services such as bug tracker, IMPEX,
DNS, syslog, Wiki, IDS/IPS, VPN server, PKI.
- Lock-down and audit/pentest of servers.
- WAF based on pfSense/Squid. ModSecurity in PoC.
- Backups and Imaging.
Clients side:
- Windows-based laptops.
- Remote access via VPN and client-based authentication (Smart-card, Client/Machine Certificate, RADIUS)
- Microsoft Office365 (former MS Online Services): setup, maintenance, and end-user support.
- Backups and Imaging.
Technologies used:
VMware ESXi/Proxmox, pfSense, OpenVPN, VPN IPSec, PKI, Kali (PenTest), Suricata (IDS/IPS), Squid forward/
reverse proxy/Artica Reverse Proxy, PKCS11/eID, FreeRADIUS, SFTP, NextCloud, Windows 2012R2/10, Active
Directory, osTicket, BIND9, PRTG/Kiwi/Graylog, DokuWiki, MS Office365, Altaro VM Backup/Proxmox Backup,
ModSecurity.
Practices:
• ITIL-based practices: change, incident, and problem management. Troubleshooting.
• Documentation of installation and procedures.
• Training an
Network Security Engineer
RILC QualServ sprl
juillet 2010 - février 2017
Customer: subcontractor of Prodata Systems (Zaventem – Belgium) for the final customer General Secretariat of
the Council of the European Union
Environment:
- BCP-compliant non-classified and classified (Restreint and Secret) networks with VPN-based WAN access for
remote sites.
- Production servers and end-user computers: Windows 2008R2/7, RPM-based Linux servers.
Job overview:
- Implementation, configuration, administration, and maintenance of GSC's security environment.
- First easy-to-understand advices on security architecture and test scenarii before handover to engineering team.
- Technical analysis and specification in order to integrate IT security solutions with reference to GSC's security
policies.
- Technical assessment of security technologies and products.
- Installation and configuration of security appliances and software.
- Rollback plans.
- Training to newcomers.
Technical aspects:
- Segmentation of the environment in zones designed for less impact on production and layering of protection.
Access of the end-users based on Check Point IA.
- Isolation of the administrators in a parallel environment known as Management Domain.
- Maintenance of Check Point IDS/IPS, help on SIEM integration with the security appliances.
- Remote access management to GSC internal resources based on one- and two-factor authentication: SSL VPN,
VPN IPSec for remote sites across sTESTA, SecurID with or without SMS OTP, Client certificate.
- Virtual lab with security appliances and servers.
- Forward and Reverse proxies design, implementation, and support for Internet access and access from sTESTA
partners.
- Firewalls configurations for projects such as UCC and VTC.
- Development of scripts for certificate expiration monitoring and alert, web access alert, SNMP-based firewall
inventory and routing discrepancies, SNMP-based monitoring, and standalone certificates analysis and
decryption.
- Configuration of HP IMC for security appliances monitoring.
PoC implementation and follow-up with the GSC and third-parties contractors.
- Steria's PKI security help and support for integration non-classified and classified environments.
- Support on ConferenceNet firewall and Wi-Fi.
Technologies used:
Check Point Splat/Gaia firewall and IDS/IPS, Stonesoft firewall, NetASQ/Stormshield firewall and VPN IPSec, SINA,
Blue Coat ProxySG and SSL Visibility, Juniper PulseSecure and firewall SSG, Nagios/Shinken/SNMP, RSA SecurID,
Infoblox, HP IMC, Check Point/SINA VPN IPSec, Safenet client certificate authentication, VBScript, Python, Bash,
dotNET C#, Wireshark/tcpdump, Wi-Fi IAC-BOX, MS Office, ROLAN PKI.
Practices:
- ITIL-based practices: change, incident, and problem management. Troubleshooting. OASIS.
- Writing of documentation, operational guidelines, troubleshooting guides, and procedures.
- Meetings animation.
- Reporting.
- Assets inventory lists.
IT Infrastructure Manager
Syncada Europe sprl [
janvier 2004 - juillet 2010
Address: Brussels (Belgium)
Business or sector: Financial and insurance activities
Evolution of the job position:
- Network/Systems Administrator and BDA (FEB2004-MAY2008)
- Senior Systems Engineer / IT Infrastructure Manager (MAY2008-JUL2010)
Team supervised: 1
Environment:
- Windows-based internal and public servers, Windows clients, three plants interconnected.
Job overview:
- Design, deployment, standardization, and maintenance of more than 100 machines, and international support
to USA and India.
- Network and security topology design, implementation, and deployment with DRP.
- Global backups procedures, imaging, and SAN implementation.
- Hardware & Software purchases. Roles: recommend and/or decide.
- Licenses management.
- Procedures implementation and documentation.
- IT CapEx establishments.
- Responsible of the voice switching/IP system with its physical and logical isolations.
- Explain in understandable words the technical aspects and impacts of the projects.
Technical aspects:
- Firewall migration from Check Point to Fortinet.
- URL filtering, routing policies, MAC/IP filtering , Iptables/Netfilter, Snort IDS/IPS.
- Sites interconnection with VPN IPSec.
- Secure exchange of EDI files with PGP/GnuPG, SFTP, and OFTP.
- Virtualized infrastructure protected by reverse proxy.
- MySQL design, installation, and security.
- Desktops security enforcement: IAM, PKI-based accesses to dedicated servers, and Active Directory GPOs.
- Active Directory design, implementation, and security on Windows Server 2003 R2: GPOs, PKI, NTFS/S.
- Share permissions, DFS, and Access-Based Enumeration. Core services started by "nobody"-like user account.
Encrypted replication.
- Novell Netware 5.x upgrade to Novell OES Netware/Linux with complete NDS and security re-design and
implementation. Active Directory cohabitation.
- Development and scripting.
- Unattended OS installs and users maintenance.
- Load-balancing of public servers.
- Management of the central telephony system.
Main projects:
- Standardization of the client computers and migration to Active Directory.
- Setup of the network and security infrastructures.
- Office relocation. This mainly involves LAN, WAN/Telecommunication, security access, design and dimensioning
of the datacentre, and coverage of the whole project.
- Secure and automated data exchange with customers and their carriers through SSH and OFTP, and parsing of
data before injection into production databases.
Technologies used:
Check Point, Fortinet, Windows 2000/XP/2003R2/2008R2, FoxPro, VBScript, Visual FoxPro, dotNET, VMWare
Workstation, MySQL with Master/Slave redundancy, PKI MS CA/GnuPG, Cisco VPN IPSec, C#, MS Office 2000/2003,
MS Project, MS Visio, Wireshark/tcpdump, Snort (IDS/IPS), Heartbeat, Windows LB, Odette FTP, ADSL/ISDN/PDH,
VoIP, Nagios, OpenSUSE/Ubuntu/CentOS, MS Office, Wi-Fi LinkSys DDWRT54L, Ericsson switching/VoIP system.
Practices:
- Change, incident, and problem management. Troubleshooting.
- Reporting.
- Meetings animation.
- Documentation
Network and Systems Consultant
Dow Corning Coordination Centre
octobre 2003 - janvier 2004
Address: Sene...