root@brion.in:~#

open to fully remote roles · mission-driven and research orgs preferred

I take over infrastructure that arrives with no documentation and no institutional knowledge, map what is actually running, standardize it without breaking production, and write the documentation that should have existed. I would rather do that for an organization trying to move the world forward than for one that only moves money.

resume.pdf say hello

## core focus

proxmox ecosystem
PVE cluster design, deployment, and maintenance · HA and quorum · ZFS-backed and Ceph storage · iSCSI and NFS shared storage · PVE SDN · KVM and LXC guests · GPU passthrough, SR-IOV, and vGPU · Proxmox Backup Server with verified, tested restores · Proxmox Datacenter Manager for multi-site control · rolling upgrades and patch cycles
containerization
Docker, Podman, Compose, Quadlets, LXC · rootless containers · systemd integration · reverse proxy publishing with automated ACME
migration & modernization
P2V/V2V of legacy physical and VMware/Hyper-V/Xen workloads into PVE · end-of-life OS preservation · extracting configuration from aging network appliances and rebuilding on current hardware · cutovers with minimal production downtime
zero trust networking
Netbird and WireGuard (hub-and-spoke, mesh) · identity-scoped application access via Microsoft Entra ID and other IdPs · site-to-site routing and multi-site interconnect

## ai infra

Self-hosted language models and agent tooling, architected so inference and data stay on organization-owned hardware. No third-party model provider in the data path, no egress of client records, full control over retention and access.

  • Local inference stacks with Ollama and Open WebUI: model selection, quantization tradeoffs, sizing against available GPU, CPU, and memory on Proxmox hosts.
  • Hermes Agent (Nous Research, MIT-licensed) as the agent platform, with a multi-model backend across local models, Nous Portal, and Claude. Local by default; hosted models only where the work requires them.
  • GPU-accelerated inference on Proxmox: PCIe passthrough to VMs, device mapping into LXCs, Intel SR-IOV, and NVIDIA vGPU sharing one card across concurrent inference VMs.
  • Legacy systems wired into modern agents through custom and community MCP connectors, so clients can ask conversational questions of data that used to require manual export-and-parse.

## skills

virtualization
Proxmox VE, KVM/QEMU, VMware vSphere/vCenter, Hyper-V, Xen
containers
Docker, Podman, LXC, Compose, Quadlets, Ansible, cloud-init
storage
ZFS (RAIDZ, replication, snapshots), Ceph, iSCSI, NFS, SMB, TrueNAS, Proxmox Backup Server
operating systems
Linux (Debian & RHEL families, desktop since 1999), FreeBSD/OpenBSD, Solaris/Illumos, Windows Server & 11, macOS
networking
UniFi, OPNsense, pfSense, Omada, Meraki, OpenWRT, Mikrotik, iptables/nftables, WireGuard, Netbird, OpenVPN
services
Nginx, Caddy, HAProxy, Traefik, Unbound, DNSCrypt, dnsmasq
monitoring
Prometheus, Grafana, Loki, InfluxDB, syslog, Cockpit
security & identity
Microsoft Entra ID, ACME automation, Wazuh, filesystem/E2EE encryption, Vaultwarden
ai & inference
Ollama, Open WebUI, Hermes Agent, MCP connectors, local model deployment
gpu virtualization
PCIe passthrough, LXC device mapping, Intel SR-IOV, NVIDIA vGPU
scripting
Bash (proficient), Python and Go (working knowledge), Git
hardware
HP/Dell/Supermicro servers, AMD EPYC, iLO/iDRAC/IPMI/OpenBMC, x86_64/ARM64/POWER/SPARC, embedded SBCs

## experience

Systems Engineer · Twin Pines Technology

2024 to present · MSP serving small and medium businesses across Northeast Ohio

  • Operate five production Proxmox VE clusters across three clients, including a three-site, nine-node deployment (~30 guests) and a four-node cluster running close to 50 guests.
  • Lead legacy virtualization migrations: aging physical servers and legacy hypervisor workloads into PVE, including end-of-life operating systems preserved intact rather than rebuilt.
  • Design cluster storage on ZFS, with Ceph, iSCSI, and NFS by workload; run Proxmox Backup Server with retention policy, verification jobs, offsite sync, and documented restore testing.
  • Stood up Proxmox Datacenter Manager across multiple physical sites over a Netbird/WireGuard overlay instead of exposed management interfaces.
  • Built zero trust network and application access with Netbird against Microsoft Entra ID and other IdPs, replacing flat site-to-site trust with identity-scoped access.
  • Migrate configuration off legacy network appliances and recreate it on UniFi, OPNsense, and pfSense, standardizing on hardware without recurring relicensing cycles.
  • Built self-hosted AI agent integrations bridging legacy client systems to conversational access via MCP connectors, keeping inference and data on client-owned hardware.
  • Inherit undocumented infrastructure, audit what is genuinely running, surface hidden dependencies before they become outages, and leave durable documentation behind.

Design & Deployment Engineer · Park 'N Fly

2023 to 2024 · kiosk technology on embedded Linux and Android SBCs

  • Built and maintained Debian images for embedded SBCs in production kiosk hardware.
  • Traveled CONUS upgrading lot entrance/exit kiosks and POS devices, including loop detection relay wiring and digital I/O interfacing.
  • Wrote the installation and configuration documentation field teams used on later deployments.

Freelance IT Consultant · Self Employed

2008 to 2023

  • Administered virtual environments across Linux KVM/Proxmox, VMware, Hyper-V, and Xen for individuals and small businesses.
  • Deployed and supported Windows and Linux servers, workstations, and networks end to end.
  • Built virtual network overlays with WireGuard and OpenVPN, including site-to-site routing and firewall migrations.

## homelab

A self-hosted lab run as a continuous testbed for the same stack I deploy professionally.

compute
six-node Proxmox VE cluster on AMD EPYC 3000 and Ryzen embedded platforms
storage
PVE storage node with 8 × 14 TB RAIDZ2 (~112 TB raw); HP EC200a + drive shelf on TrueNAS as dedicated backup target
services
Docker/Podman stack behind a reverse proxy with automated TLS, DNS, monitoring, WireGuard/Netbird mesh
inference
Ollama + Open WebUI + Hermes Agent; MCP connectors and GPU passthrough configs are proven here before they touch a client environment
edge
5G/LTE, LoRa, and reflashing e-waste routers and APs with OpenWRT to put them back into service

## how i work

Most of my work starts the same way: an environment nobody fully understands anymore, a client who needs it to keep running, and a pile of questions with no owner. The people who built it are gone, the credentials live in someone's head, and the documentation is a sticky note from 2016.

So I hold several of these projects at once, because none of them can move in a straight line. Discovery on one client fills the gaps while another waits on access or answers. I sequence the work so a blocker in one engagement never stalls the rest, and everything I learn goes into documentation durable enough that the next person, or the next me, never has to excavate it again.

The result: legacy systems land in modern, backed-up, monitored infrastructure, and "how does this work?" has a written answer.

## contact

$ echo "hello" | mail -s "let's talk" hansen.brion@gmail.com

Best fit: fully remote Linux/virtualization roles with research, scientific, or genuinely mission-driven organizations. If your infrastructure helps people and your data should stay on your own hardware, we will get along.

Prefer machine-readable? resume.json · prefer a terminal? curl -L brion.in/resume.txt