Work

Arnold Perlas — Enterprise Systems, SecOps & Cloud Engineering

Senior IT Systems Engineer with over 13 years of experience building vulnerability remediation engines, hybrid-cloud architecture, automated zero-touch endpoint systems, and infrastructure-as-code.

13+
Years Engineering Depth

Systems engineering, SecOps, cloud & infrastructure leadership.

96%
Vulnerability Reduction

Cleared 1M+ findings across hybrid enterprise endpoints & VMs within 90 days.

10,000+
Endpoints Automated

Zero-touch Intune MDM, Autopilot, Tanium, and CrowdStrike deployment.

370+
Sites Migrated

Transitioned nationwide enterprise locations to Azure & Entra ID.

Engineering Focus & Career Journey

My technical work spans more than a decade of designing, governing, and automating infrastructure across hybrid cloud and on-premises environments. Throughout my career, I've specialized in transforming complex operational challenges into streamlined, self-healing systems:

  • Enterprise Vulnerability Remediation: Engineered automated Python and PowerShell engines that slashed vulnerability backlogs by up to 96% across more than 1,000,000 endpoint and server findings.
  • Hybrid Cloud Infrastructure: Led site migrations from legacy colocated VMware environments to Microsoft Azure and Entra ID across 370+ nationwide locations.
  • Zero-Touch Endpoint Management: Managed zero-touch Intune MDM, Autopilot V2, Tanium, and CrowdStrike security deployments across 10,000+ endpoints.
  • M&A Integration & Hardening: Standardized baseline security toolkits and NIST CSF 2.0 alignment for 30+ acquired organizations within 90 days.

AI-Assisted SecOps & Workflow Automation

I actively integrate modern AI capabilities into my daily engineering workflows. By pairing agentic AI tools (Codex, Gemini, Claude, Kimi, and local models via Ollama) with automated orchestrators like n8n and REST APIs, I accelerate script generation, automate security feed triaging, and build reproducible validation sandboxes before ring-group deployments.

Technical Stack & Tools

Core platforms, languages, frameworks, and security suites engineered across enterprise and self-hosted production environments.

🛡️

Security, SIEM & Identity

Vulnerability management engines, SIEM/XDR threat detection, endpoint security governance, SAML/OIDC SSO federation, system hardening, and audit compliance.

CrowdStrike Qualys Wazuh SIEM / XDR Authentik SSO & MFA Microsoft Defender Arctic Wolf Tanium NIST CSF 2.0 PCI DSS & SOX Zero-Trust Controls Penetration Testing System Hardening
☁️

Cloud, Hypervisors & Storage

Architecting hybrid cloud workloads, multi-node hypervisor clustering, enterprise ZFS storage tiering, container microservices, and disaster recovery.

Microsoft Azure Proxmox VE Cluster ZFS Storage & Datasets Synology Enterprise NAS AWS (EC2/VPC/S3) VMware ESXi / vCenter Linux (Debian/Ubuntu/RHEL) Windows Server LXC Containers Docker & Compose CIFS / NFS Storage GPU Passthrough (Intel QSV)

Automation, IaC & DevOps

Declarative infrastructure as code, automated rolling update orchestration, API-driven workflows, self-healing deployments, and automated testing.

PowerShell Python Terraform Ansible Playbooks Bash REST APIs n8n Automation Git & GitHub Actions Rolling Updates Snapshot Rollbacks UEFI PXE Netboot Systemd Timers
💻

Endpoint Engineering & MDM

Zero-touch MDM provisioning, centralized fleet patching, SAML/SSO authentication, RBAC, PIM, zero-trust conditional access, and automated migrations.

Microsoft Intune Autopilot / V2 Entra ID (Azure AD) Tanium Automox RBAC & PIM Windows 11 Migration RMM Tooling Rubrik Active Directory & GPO
🌐

Networking, Ingress & Defense

Enterprise firewall policies, 802.1Q VLAN segmentation, zero-inbound edge tunnels, reverse proxy SSL termination, and split-horizon high-availability DNS.

802.1Q VLANs Cloudflare Tunnels UniFi Cloud Gateway Max Nginx Proxy Manager Palo Alto Networks SonicWall Cisco Meraki Split-Horizon DNS (Pi-hole HA) WireGuard / Gluetun Let's Encrypt Wildcard SSL NIC Bonding
🤖

AI Tools & AI Governance

Integrating AI development workflows, local LLM evaluation, prompt engineering, vector database embeddings, and organizational AI security governance.

Codex Gemini Claude Kimi Ollama (Local LLMs) Vector Embeddings (VectorChord/pgvector) OpenClaw Hermes AI Usage Governance

Engineering Capabilities & Systems Architecture

Architectural focus areas and technical solutions designed for scale, resilience, and security.

Vulnerability Automation

Automated Remediation Engine & Vulnerability Slashing

  • Built custom Python and PowerShell workflows consolidating multi-stream security feeds (Qualys, CrowdStrike, Tanium) into actionable remediation tasks.
  • Engineered trigger-based restoration scripts that compare identified issues against automated script libraries before deployment.
  • Implemented automated log-parsing to determine pass/fail outcomes, isolate failure points, and run retry logic in isolated local sandboxes before ring-group rollouts.
  • Successfully reduced over 1,000,000 detected vulnerabilities by 96% and cleared 83% of backlog findings within 90 days.
Python PowerShell Qualys Tanium CrowdStrike Sandbox Testing
Cloud Architecture

Enterprise Cloud & Zero-Touch Endpoint Management

  • Architected the end-to-end transformation from legacy colocated VMware infrastructure to Azure and Entra ID across 370+ nationwide sites.
  • Designed and governed zero-touch Microsoft Intune MDM, Autopilot V2, and automated patching controls across 10,000+ endpoints.
  • Created and managed Entra applications, SAML SSO, SSL certificates, RBAC, PIM, and zero-trust conditional access policies.
  • Engineered over 100 NIST CSF 2.0 aligned security policies and orchestrated enterprise-wide Windows 11 migrations.
Azure Entra ID Intune MDM Autopilot V2 Zero Trust NIST CSF 2.0
IaC & Integration

Infrastructure-as-Code & Integration Hardening

  • Managed version-controlled Terraform configurations for default applications, network parameters, configuration metadata, and parameter-driven infrastructure.
  • Engineered baseline security hardening standards for acquired organizations, standardizing security toolkits across 30+ acquired entities.
  • Integrated API-derived SaaS reporting data directly into deployment validation workflows to automatically test issue resolution.
  • Coordinated cross-functional remediation to clear ~90% of newly identified vulnerabilities within strict compliance windows.
Terraform REST APIs M&A Hardening SOX & PCI DSS Git
Multi-Cloud Engineering

Azure & AWS Server Lifecycle, Maintenance & Migration

  • Provisioned, configured, and maintained enterprise Azure VMs and AWS EC2 instances, managing the full server lifecycle across production environments.
  • Orchestrated zero-downtime server maintenance, automated patch cycles, and OS upgrades using standardized golden images (Azure Compute Gallery / AWS AMIs).
  • Configured cloud networking perimeters including Azure VNets, AWS VPCs, NSGs, Security Groups, site-to-site VPNs, and secure JUMP hosts.
  • Implemented automated snapshot backup vaults, storage lifecycle policies (Blob/S3), and pro-active server monitoring via Azure Monitor and AWS CloudWatch.
Azure VMs AWS EC2 VNets & VPCs Server Maintenance OS Upgrades Azure Monitor & CloudWatch
Virtualization & GitOps

Hypervisor Clustering, ZFS Tiering & Zero-Trust Ingress

  • Engineered a 3-node Proxmox VE hypervisor cluster utilizing active-backup bonded NICs, QEMU/KVM virtual machines, LXC containers, and hardware GPU passthrough (Intel QuickSync).
  • Architected tiered enterprise storage featuring direct-attached 18TB ZFS IronWolf storage pools, RAM transcoding disks, and 23TB Synology NAS shared CIFS/NFS clusters with automated Rsync replication.
  • Orchestrated zero-downtime rolling hypervisor and container maintenance using Ansible automation playbooks with pre-update snapshotting (`pct snapshot`) and automatic rollback triggers.
  • Enforced a defense-in-depth perimeter with 802.1Q VLAN matrix, Authentik SSO/MFA federation, Wazuh SIEM threat monitoring, and zero-inbound Cloudflare Tunnels.
Proxmox Cluster ZFS Storage Pools Ansible Automation Authentik SSO & MFA Wazuh SIEM 802.1Q VLANs

Homelab & R&D Sandbox

Continuous self-driven experimentation, enterprise-grade GitOps architecture, multi-node clustering, and open-source infrastructure testing.

GitOps Architecture Multi-Node Proxmox VE Cluster & Enterprise-Grade R&D Sandbox

A fully modular, sanitized GitOps infrastructure project modeling enterprise infrastructure concepts: multi-node hypervisor clustering, declarative Terraform & Ansible automation, 802.1Q VLAN isolation, split-horizon DNS, machine learning vaults, hardware GPU acceleration, and automated disaster recovery.

🖥️

Multi-Node Proxmox Cluster

3-node clustered Proxmox VE hypervisors with active-backup bonded NICs, LXC microservices, GPU passthrough (Intel QuickSync), and isolated VM workloads.

Proxmox VE Cluster LXC & Docker Stacks NIC Bonding Intel QSV GPU
💾

Tiered Storage & Direct ZFS

Direct-attached 18TB ZFS IronWolf storage arrays, 23TB Synology NAS shared cluster storage (CIFS/NFS), and automated cross-node backup replication.

18TB ZFS Pools Synology CIFS/NFS RAM Transcoding Rsync Replication
🛡️

VLAN Matrix & Zero-Trust Ingress

Standardized 802.1Q VLAN isolation (Management, SecOps, DMZ, Services, IoT), Authentik SSO/MFA, Wazuh SIEM/XDR, and dual zero-inbound Cloudflare Tunnels.

802.1Q VLANs Authentik SSO & MFA Wazuh SIEM Cloudflare Tunnels

GitOps, IaC & Rolling Updates

Declarative Terraform modules, Ansible rolling update playbooks with automated pre-update snapshots & QA rollbacks, and UEFI PXE automated OS deployment.

Ansible Playbooks Terraform Modules Snapshot Rollbacks UEFI PXE Boot
Explore 70+ categorized runbooks, Terraform modules, Ansible playbooks, and architecture blueprints: 📦 View Infrastructure on GitHub ↗

Engineering Philosophy

Process standardization, infrastructure autonomy, defense-in-depth security mindset, decision-making under SLA constraints, thorough technical documentation, AI-assisted SecOps workflow automation, and mission-driven execution.

Beyond the Keyboard

When not configuring server clusters or writing automation scripts, I practice photography (landscape & street photography featured on this site), play tennis, explore classic literature, and contribute to open-source software (FOSS) projects.