Infrastructure and security, run on real hardware.
Infrastructure and security engineer. Production owner of a 38-service self-hosted platform across VLAN-segmented networks, ZFS storage, GPU passthrough, and a zero-trust mesh. National Science Foundation I-Corps Entrepreneurial Lead. IEEE SmartNets 2024 co-author.
- Services on the box
- 38
- Customer interviews
- 100+
- Containers / VMs
- 38 / 4
- Years self-hosting
- 2+
Work
Two roles, ongoing. The first is interview-led customer discovery; the second is the platform I run end-to-end.
- 01
Entrepreneurial Lead, National Science Foundation I-Corps
Apr 2024 - Nov 2024 · New York, NY
- Conducted 100+ customer-discovery interviews with industry and academic stakeholders as the team's principal interviewer alongside a co-Entrepreneurial Lead, under faculty PI (P. Ghazizadeh, PhD) and one industry mentor; completed both Regional and National Teams cohorts.
- Ran problem-solution fit validation for decentralized edge computing in vehicular cloud environments; findings drove the team's pivot to a vehicular-cloud market focus.
- Co-authored peer-reviewed IEEE SmartNets 2024 paper with faculty PI P. Ghazizadeh.
- 02
Solo Systems and Network Operator, Independent Infrastructure
Jan 2023 - Present · New York, NY
- Run a production self-hosted platform (i5-12400, RTX 3050, 64 GB RAM, 11 TB ZFS) hosting 38 containerized services across Nextcloud, Matrix, and local LLM inference; VLAN-segmented, exposed through Caddy with TLS across 6 public domains. GPU passthrough via IOMMU/VFIO for Ollama LLMs, 4 KVM/QEMU VMs, Tailscale zero-trust mesh, Prometheus and Grafana observability.
- Operate a personal and tenant stack that replaced third-party SaaS for primary users; managed zero-downtime migrations from Google Drive, Slack, and Dropbox over 2-week cutovers.
- Migrate the platform stack between bare-metal and VM substrates as system needs evolve; current configuration runs NixOS on bare-metal with ZFS mirrors, GPU passthrough for LLM inference, and a Tailscale zero-trust mesh.
- Maintain an Obsidian vault synced to iPhone via Syncthing; built a nightly cron with an LLM-Wiki skill that auto-folds session output into approximately 50 pages across chat, web, and mobile surfaces.
Projects
Things I built and run. Each lives on the platform in Work as a deployable artifact.
- 01
Relay - Self-Hosted Live Streaming
Solo Builder
Jan 2024 - Present
- Built Relay, a Go-based self-hosted SRT live-streaming server with HLS transcoding, rate-limited moderated live chat, and admin panel; single binary, no database, multi-architecture Docker image auto-built via GitHub Actions.
- Designed for OBS-over-SRT ingest with a separate producer monitoring feed; adaptive 1080p / 720p / 480p / 360p output via FFmpeg.
- 02
Hermes Agent Deployment
Operator and Configurator - Hermes Agent (Nous Research)
Jan 2024 - Present
- Deployed and operated a Hermes Agent (Nous Research) instance across Discord, Telegram, and iMessage (Photon); built a 25-plus-tool MCP layer (Firecrawl, SearXNG, Playwright, smart-home) with execution-approval policies and webhook ingress.
Publication
Singh, B., Ghazizadeh, P., Choudhury, P., and Ebrahimi, A. (2024). Assessing Cooperative Trust-Based Authentication within Micro Vehicular Clouds. IEEE SmartNets 2024.
Read on IEEE Xplore
Stack
The things I reach for daily. The order is roughly: Linux on the box, Go or Python for new services, NixOS where the system has to survive a cutover.
Infrastructure and Networking
Linux server administration (NixOS, Ubuntu Server, Fedora), VLAN segmentation, TCP/IP networking (L2/L3 fundamentals, routing, firewalling), WireGuard, Tailscale, Caddy, Nginx, DNS, DHCP, network monitoring.
Systems and Virtualization
KVM/QEMU virtualization, GPU passthrough (IOMMU/VFIO), Docker, Docker Compose, ZFS storage, systemd, journald, GNS3 lab, bare-metal provisioning.
Security
Network security architecture, threat modeling, deny-list and allow-list patterns, secure-by-default configuration, MCP tool-call security, OAuth 2.0, OIDC, cryptography fundamentals, digital forensics, reverse engineering.
Observability and Operations
Prometheus, Grafana, Wireshark, log analysis, incident response patterns, capacity planning, multi-week zero-downtime migration cutovers.
Languages
Go, Python, Bash, Kotlin, TypeScript, SQL, C/C++ (Android NDK).
Education
M.S., Cyber & Information Security
2023 - 2025St. John's University · New York, NY
GPA 4.0 / 4.0
NSA- and ABET-accredited program. Coursework: Network Security, Cryptography, Digital Forensics, Secure Software Engineering.
B.S., Computer Science (Cyber Security Systems)
2018 - 2022St. John's University · New York, NY
GPA 3.32 / 4.0