The following references describe selected projects and tasks from professional practice as well as personal infrastructure and development projects.
01 · Professional practice · Distributed IT infrastructure · Network & security engineering
Firewall automation & central network management
Standardised recurring firewall tasks and built a central management system for inventory, health checks, event assessment, and alerting. Automated recurring verification, documentation, and policy workflows; structured access rules around required communication paths and system groups under least privilege; and used controlled changes with functional, negative, and rollback testing.
02 · Professional practice · Decentralised IT environment · IT & security engineering
Secure remote access & network segmentation
Provided internal applications to distributed users with targeted access rights. Analysed necessary communication paths and assigned access to user, device, and system groups; traced issues end to end across identity, certificates, name resolution, access policy, and the target application; and documented dependencies, impacts, maintenance windows, and rollback options.
03 · Professional practice · Clients, servers & network · Infrastructure engineering
Operations & monitoring of distributed IT systems
Detected critical conditions early and sustainably stabilised network, server, storage, client, and power components in daily operations. Supported client and server environments during incidents; assessed monitoring alerts by cause, scope, and service impact; and documented dependencies, configurations, and proven solutions for maintenance, support, and handover.
04 · Professional practice · Windows endpoints · IT & security engineering
Endpoint security & security-event handling
Technically assessed and handled endpoint-security events by investigating affected processes, users, and system context. Distinguished false positives, unwanted software, and security-relevant incidents; carried out or coordinated containment and remediation; checked effectiveness afterwards; and documented outcomes to improve policies and configurations.
05 · Professional practice · International industrial environment · IT security officer · 2023 — 2025
Enterprise security & technical risk analysis
Identified, technically validated, and followed up security, software, and compliance deviations across a large system landscape. Assessed version status, known vulnerabilities, usage context, prevalence, and operational impact; created structured work items with technical recommendations; checked the effectiveness of completed measures; and reported causes, trends, status, and remaining risks.
Personal project · Homelab & self-hosting · Platform & infrastructure engineering
Self-hosted infrastructure & AI platform
Built a self-hosted platform for virtualisation, logically separated services, secure remote connectivity, automated deployments, and local AI workloads. Operated virtualised Linux and container services with DNS, segmentation, backups, service isolation, and controlled service publication.
Personal product project · Quran learning application · Software development
Tilawi.ai as a web & app project
Designed and further developed a Quran application with reading and learning features. The project combines product development, application implementation, APIs and data storage, AI-supported learning features, testing, version control, privacy-aware design, deployment, and day-to-day operations.