Ahmed Hanafy

Systems & Infrastructure Engineer
Systems Administrator · Infrastructure · Cloud · Automation
Fully Remote · Open Worldwide
14+ years in hybrid Windows / Linux / macOS Virtualization & cloud at enterprise scale Builds & automates with containers
14+
Years in IT infrastructure
27,000
Users supported at peak
250+
Servers administered
Zero
Data loss across migrations

#About

Hands-on across systems, infrastructure, cloud, and automation, owning environments end to end from the hypervisor to the firewall.

I'm a systems administrator and infrastructure engineer with 14+ years building, securing, and operating hybrid Windows, Linux, and macOS environments at enterprise scale. I've repeatedly been the sole and/or lead engineer responsible for virtualization, identity, cloud, and backup/DR across organizations serving up to 27,000 users.

I migrated an entire virtual environment from VMware to Nutanix AHV, customized an identity management platform and built the supporting scripts to automate the user lifecycle for tens of thousands of accounts, modernized remote access with a zero-trust model and multi-factor authentication, and protected the business with cloud-based backup and disaster recovery. I am a strong automator at heart. I use whatever scripting or tooling gets the job done and clears away the manual, repetitive work.

Currently seeking a fully remote role in systems administration, infrastructure, cloud, or IT operations. Currently working toward a cloud administration certification.

#The Homelab

An advanced, self-hosted environment run as a near-enterprise stack. It is my proving ground for everything before it reaches production. (This very site is served externally for reliability, while the lab hosts the live demos.)

Internet public traffic Cloudflare DNS · Tunnel · ZTNA Omada SDN Gateway VLANs · firewall · controller Azure / AWS site-to-cloud VPN (HA/DR) Core Switch · VLANs Proxmox Cluster VMs & LXC containers Docker Swarm / K8s self-hosted services AI / LLM Server self-hosted Monitoring metrics + alerts NAS tiered backup
Proxmox virtualization cluster running VMs and LXC containers with full VLAN network segmentation.
Container orchestration with Docker Swarm and Kubernetes, hosting self-managed services and AI-assisted tools I build and deploy.
TP-Link Omada SDN network with a gateway, managed switches, and access points, providing VLAN segmentation, firewall rules, and a site-to-cloud VPN for hybrid integration.
Self-hosted AI / LLM server I use to experiment and build containerized, AI-powered tools.
Full monitoring and observability stack covering metrics collection, alerting, and dashboards.
NAS-based tiered backup and recovery mirroring enterprise disaster-recovery practices.

#Projects

Self-hosted services I designed, containerized, and deployed using modern, AI-assisted workflows. Source on github.com/hanafytech.

Self-hosted · AI

SearXNG AI Search Stack

A privacy-respecting, AI-powered search stack. SearXNG aggregates results privately and feeds them to a local LLM, fully containerized with Docker Compose.

Docker ComposeSearXNGLLMReverse proxy
Self-hosted · Python

Internet Clipboard

A lightweight, “burn-after-reading” pastebin for sharing text, secrets, and files. Data lives in memory and is destroyed on read; a companion build handles secure transfers up to 10 GB.

PythonIn-memoryDockerReverse proxy
Self-hosted · Privacy

Custom Tor (Dockerized)

A fully isolated Tor Browser running inside a Docker container and accessible from any web browser. It is an exercise in container isolation and secure networking.

DockerIsolationNetworking

#Skills

Broad, hands-on depth across the modern infrastructure stack.

Virtualization & HCI
VMware vSphere/ESXi, Nutanix AHV, Hyper-V, Proxmox, Linux KVM, Citrix Virtual Apps and Desktops
Cloud
Microsoft Azure (IaaS, hybrid HA/DR, Entra ID), AWS (EC2, WorkSpaces), GCP, Linode
Operating Systems
Windows Server 2008–2025, RHEL / Ubuntu / Debian / Fedora Linux, Unix, macOS
Identity & Access
Active Directory, Group Policy, Entra ID, Google Workspace, Duo MFA, Cloudflare ZTNA, SSO
Automation & Scripting
Scripting & process automation, containerization (Docker, Kubernetes), AI-assisted development and tooling
Backup & DR
Veeam Backup & Replication, Wasabi, Synology, Barracuda, Datto, Carbonite
Networking
TCP/IP, DNS, DHCP, VLANs, VPN, Palo Alto, Fortigate, Cisco/Meraki, TP-Link Omada SDN, pfSense/OPNsense, Cloudflare
Monitoring & ITSM
Netdata, Uptime Kuma, Zabbix, Nagios, SolarWinds Orion, Lansweeper, ManageEngine, ConnectWise
Security & Compliance
Cortex XDR, Sophos, Wazuh (SIEM), Greenbone, 1Password, DKIM/DMARC/SPF

#Experience

A clean upward arc from IT Support to Senior Systems Engineer.

Nov 2023 – May 2026

Senior Systems Engineer

Paterson Public Schools: 43 schools, 25,000+ students, 2,000+ staff, ~70 servers

Migrated the entire virtual estate (50+ VMs) from VMware to Nutanix AHV, deployed Cloudflare ZTNA and Duo MFA, added centralized security monitoring and vulnerability scanning, containerized apps on Docker Swarm, and implemented Veeam-to-Wasabi cloud DR.

Aug 2022 – Nov 2023

Senior Systems Engineer

Millburn Public Schools: sole engineer, Nutanix and HyperFlex/VMware

Engineered Jamf Pro zero-touch deployment, rebuilt the Active Directory OU structure, consolidated Azure and Microsoft 365 tenants, automated SIS-driven account lifecycle, and implemented Veeam and Synology backup.

Jul 2019 – Aug 2022

Systems Engineer

Teaneck Public Schools: 65+ servers, Palo Alto, Meraki, dark-fiber WAN

Migrated the district's virtual environment from VMware to Hyper-V, built failover clustering and failover internet, configured L3 Palo Alto routing, hardened email (DKIM/DMARC/SPF), deployed Entra ID sync and SSPR, and automated account provisioning.

Oct 2014 – Feb 2018

Systems Administrator

GalaxE.Solutions: 2,000 employees, 250+ servers, two data centers

Maintained a 16-host VMware environment with 200+ VMs including Citrix Virtual Apps and Desktops, automated routine administration through scripting, delivered a 3-tier unified communications platform for 2,000 users, and migrated 1,500+ accounts to a single domain.

2012 – 2019

Earlier roles

Chefman (Manager of IT) · Olmec Systems (MSP) · TEAM/KIPP · Staples

Designed a 50,400 sq ft warehouse network; managed multi-client MSP infrastructure (VMware/Hyper-V, ConnectWise); supported and built school IT from the ground up.

Let's talk

Open to fully remote Systems Administration, Infrastructure, Cloud, and Operations roles. Based in the U.S., open to international teams, and flexible across time zones.