Gideon Oteng
Network engineer. Platform builder. Things I run don't fall over.
Five years across Tier-1 ISP backbone at Cogent and enterprise managed services at CDW. CCNP Security. Running a two-node Proxmox cluster as production infrastructure — BGP mesh, zero-trust access, full observability, wildcard TLS. The same standards I'd hold at work, operated solo.
// Selected work
Things I've built
SecureBytes Platform
Self-managed Proxmox cluster running production-style network and security infrastructure — wildcard TLS, public status page, and selective Cloudflare Tunnel exposure.
AWS Detection Engineering Portfolio
Production-quality Sigma rules for AWS IAM privilege escalation, each validated end-to-end against CloudGoat scenarios using Stratus Red Team and CloudTrail.
Network Design Lab
Multi-vendor lab on Cisco Modeling Labs and EVE-NG. Routing, switching, wireless, security, SD-WAN, identity, and observability platforms for design validation, failure testing, and certification work.
// Field notes
Recent writing
SecureCRT Button Command Suite - Full NOC Automation Pack
200+ commands across 13 sections, platform-tagged for IOS/IOS-XE, IOS-XR, NX-OS, ASA, and FTD/FMC — wired into SecureCRT's button bar to cut the time spent typing the same commands during every troubleshooting call.
Why TLS made my homelab actually usable
Running eight internal services without HTTPS is a friction tax you pay every day. Here's how I fixed it with nginx, acme.sh, and a single wildcard cert — no manual renewals, no browser warnings.
When the firewall isn't the edge
Half the lab was misbehaving in unrelated ways. The common cause was one NAT I didn't own.
// /now
What I'm working on
Day job
Operations Analyst at CDW — supporting hundreds of enterprise networks across SD-WAN, firewall, and cloud-connected environments.
Just shipped
SecureCRT Button Command Suite - Full NOC Automation Pack
Building next
AWS detection engineering portfolio — Sigma rules for IAM privilege escalation, each validated end-to-end against real CloudTrail telemetry from CloudGoat attack scenarios.