Infrastructure and security, run on real hardware.

Infrastructure and security engineer. Production owner of a 38-service self-hosted platform across VLAN-segmented networks, ZFS storage, GPU passthrough, and a zero-trust mesh. National Science Foundation I-Corps Entrepreneurial Lead. IEEE SmartNets 2024 co-author.

Services on the box
38
Customer interviews
100+
Containers / VMs
38 / 4
Years self-hosting
2+

Work

Two roles, ongoing. The first is interview-led customer discovery; the second is the platform I run end-to-end.

  1. 01

    Entrepreneurial Lead, National Science Foundation I-Corps

    Apr 2024 - Nov 2024 · New York, NY

    • Conducted 100+ customer-discovery interviews with industry and academic stakeholders as the team's principal interviewer alongside a co-Entrepreneurial Lead, under faculty PI (P. Ghazizadeh, PhD) and one industry mentor; completed both Regional and National Teams cohorts.
    • Ran problem-solution fit validation for decentralized edge computing in vehicular cloud environments; findings drove the team's pivot to a vehicular-cloud market focus.
    • Co-authored peer-reviewed IEEE SmartNets 2024 paper with faculty PI P. Ghazizadeh.
  2. 02

    Solo Systems and Network Operator, Independent Infrastructure

    Jan 2023 - Present · New York, NY

    • Run a production self-hosted platform (i5-12400, RTX 3050, 64 GB RAM, 11 TB ZFS) hosting 38 containerized services across Nextcloud, Matrix, and local LLM inference; VLAN-segmented, exposed through Caddy with TLS across 6 public domains. GPU passthrough via IOMMU/VFIO for Ollama LLMs, 4 KVM/QEMU VMs, Tailscale zero-trust mesh, Prometheus and Grafana observability.
    • Operate a personal and tenant stack that replaced third-party SaaS for primary users; managed zero-downtime migrations from Google Drive, Slack, and Dropbox over 2-week cutovers.
    • Migrate the platform stack between bare-metal and VM substrates as system needs evolve; current configuration runs NixOS on bare-metal with ZFS mirrors, GPU passthrough for LLM inference, and a Tailscale zero-trust mesh.
    • Maintain an Obsidian vault synced to iPhone via Syncthing; built a nightly cron with an LLM-Wiki skill that auto-folds session output into approximately 50 pages across chat, web, and mobile surfaces.

Projects

Things I built and run. Each lives on the platform in Work as a deployable artifact.

  1. 01

    Relay - Self-Hosted Live Streaming

    Solo Builder

    Jan 2024 - Present

    • Built Relay, a Go-based self-hosted SRT live-streaming server with HLS transcoding, rate-limited moderated live chat, and admin panel; single binary, no database, multi-architecture Docker image auto-built via GitHub Actions.
    • Designed for OBS-over-SRT ingest with a separate producer monitoring feed; adaptive 1080p / 720p / 480p / 360p output via FFmpeg.
  2. 02

    Hermes Agent Deployment

    Operator and Configurator - Hermes Agent (Nous Research)

    Jan 2024 - Present

    • Deployed and operated a Hermes Agent (Nous Research) instance across Discord, Telegram, and iMessage (Photon); built a 25-plus-tool MCP layer (Firecrawl, SearXNG, Playwright, smart-home) with execution-approval policies and webhook ingress.

Publication

Singh, B., Ghazizadeh, P., Choudhury, P., and Ebrahimi, A. (2024). Assessing Cooperative Trust-Based Authentication within Micro Vehicular Clouds. IEEE SmartNets 2024.

Read on IEEE Xplore

Stack

The things I reach for daily. The order is roughly: Linux on the box, Go or Python for new services, NixOS where the system has to survive a cutover.

Infrastructure and Networking

Linux server administration (NixOS, Ubuntu Server, Fedora), VLAN segmentation, TCP/IP networking (L2/L3 fundamentals, routing, firewalling), WireGuard, Tailscale, Caddy, Nginx, DNS, DHCP, network monitoring.

Systems and Virtualization

KVM/QEMU virtualization, GPU passthrough (IOMMU/VFIO), Docker, Docker Compose, ZFS storage, systemd, journald, GNS3 lab, bare-metal provisioning.

Security

Network security architecture, threat modeling, deny-list and allow-list patterns, secure-by-default configuration, MCP tool-call security, OAuth 2.0, OIDC, cryptography fundamentals, digital forensics, reverse engineering.

Observability and Operations

Prometheus, Grafana, Wireshark, log analysis, incident response patterns, capacity planning, multi-week zero-downtime migration cutovers.

Languages

Go, Python, Bash, Kotlin, TypeScript, SQL, C/C++ (Android NDK).

Education

M.S., Cyber & Information Security

2023 - 2025

St. John's University · New York, NY

GPA 4.0 / 4.0

NSA- and ABET-accredited program. Coursework: Network Security, Cryptography, Digital Forensics, Secure Software Engineering.

B.S., Computer Science (Cyber Security Systems)

2018 - 2022

St. John's University · New York, NY

GPA 3.32 / 4.0

Get in touch.

Location

New York, NY