Resume

Nir Livshin · IT Infrastructure & Systems Specialist · nir2010@gmail.com · LinkedIn

9+ years of experience in IT infrastructure, system administration, and cybersecurity across on-site, hybrid, and remote environments.


Experience

IT Manager
Helfy
Aug 2025 – Present
Herzliya · On-site
IT Manager
PROMAI LTD
Jan 2023 – May 2025
Tel Aviv · Hybrid
IT Manager
Optimum Group
May 2021 – Jan 2023
Herzliya · Remote
Custom PC Specialist
K.S.P Group
Jun 2019 – May 2021
Tirat Karmel · On-site
Cyber Security Analyst
Isracard
Jun 2018 – May 2019
Tel Aviv · On-site
Help Desk Technician
e-shop Ltd.
Jan 2017 – Jan 2018
Rehovot · On-site

Technical Projects

Zero-Trust Remote Access & Multi-Cloud DNS Architecture 🔒🌐

Architected and deployed secure enterprise remote access solutions using Cloudflare Zero Trust (Access & Tunnels), Twingate, Tailscale, OpenVPN, and WireGuard. Integrated global DNS routing and domain management via AWS Route 53, enforcing identity-based access policies and micro-segmentation across multi-cloud and on-premise environments.

Stack
Cloudflare Zero TrustAWS Route 53TwingateTailscaleOpenVPNWireGuardIdentity Access ManagementGlobal DNS

Docker Swarm & OCI Kubernetes Testing Platform with Terraform 🐳☁️

Engineered a container orchestration testing platform providing ephemeral Kubernetes/Docker Swarm test environments for product team version validation. Provisioned Oracle Cloud Infrastructure (OCI) via Terraform / OpenTofu, including custom Docker registries (OCIR) and automated Bitbucket Pipelines CI/CD. The pipeline builds, tags, and deploys dynamic feature branches and version variants, running automated Python test suites and gating releases on pass verification.

Stack
Docker SwarmOracle Cloud (OCI)TerraformOpenTofuBitbucket PipelinesOCIRKubernetes TestingPython Test AutomationCI/CD

Full-Stack Enterprise Observability & RMM Agent Infrastructure 📊🔔

Designed and deployed an end-to-end telemetry and monitoring stack utilizing OpenTelemetry, Prometheus, PromQL, Grafana, and Netdata for high-density metrics and log aggregation across cloud and on-premise environments. Configured automated alert triggers with email and webhook notifications for real-time incident routing. Deployed lightweight Remote Monitoring and Management (RMM) system agents embedded directly inside target endpoints and container hosts to ensure proactive health monitoring, metric extraction, and centralized node governance.

Stack
OpenTelemetryPrometheusPromQLGrafanaNetdataRMM Endpoint AgentsAutomated AlertingEmail & Webhook TriggersMetric & Log AggregationInfrastructure Observability

Global Cloud AV / EDR Integration & On-Prem Hybrid Security (Bitdefender GravityZone, SentinelOne & Ubiquiti) 🛡️🏰

Architected and deployed enterprise-wide Endpoint Detection & Response (EDR) and Antivirus platforms featuring centralized cloud security management with Bitdefender GravityZone and SentinelOne Cloud across international endpoints. For legacy and air-gapped environments, engineered strict on-premise security architectures utilizing local Bitdefender On-Premise Virtual Appliances and localized Ubiquiti UniFi network security gateways/firewalls, ensuring total isolation and zero-cloud dependency for older infrastructure.

Stack
Bitdefender GravityZone Cloud & On-PremSentinelOne EDRUbiquiti UniFi SecurityOn-Premise AV ManagementAir-Gapped SecurityLegacy Infrastructure IsolationEndpoint Protection

Global Fortinet Site-to-Site SD-WAN & Branch Security Architecture 🛡️🌐

Architected and deployed a multi-branch Site-to-Site IPsec VPN mesh connecting international corporate offices using FortiGate appliances and FortiManager / FortiCloud. Configured strict Zero-Trust network guardrails and VLAN segmentation on-premise at each branch location to isolate local IT services, maintaining local maintenance autonomy while keeping security policy enforcement uniform across all global sites.

Stack
FortiGateFortiCloudFortiManagerSite-to-Site IPsec VPNSD-WANGlobal Multi-BranchNetwork GuardrailsVLAN Segmentation

Defense-Grade On-Prem to GCP Datacenter Migration 🛡️☁️

Led the large-scale cloud migration for a defense cybersecurity firm, lifting and shifting full physical server racks running legacy VMware ESXi 6.x infrastructure directly into Google Cloud Platform (GCP). Replicated on-premise network segmentation with GCP VPCs, subnet topology, and strict firewall policies while modernizing workload delivery. Successfully executed secure physical rack hardware decommissioning following migration validation.

Stack
Google Cloud Platform (GCP)VMware ESXi 6.xLift & Shift MigrationVPC Network SegmentationDatacenter DecommissioningDefense Security Standards

AI LLM Router & Budget Observability Gateway 🤖📊

Designed and deployed an enterprise AI proxy gateway for multi-provider routing (Anthropic, AWS Bedrock, GCP Vertex AI, Azure OpenAI) behind an encrypted end-to-end VPN. Integrated full budget observability featuring daily spend caps, token consumption tracking, and cost per branch/mission mapped directly to Jira tasks. Backed by an AWS RDS managed database and a WebGUI dashboard for real-time limit management and metrics.

Stack
AWS RDSAWS BedrockAnthropic APIAzure OpenAIGCP Vertex AIJira APIEncrypted VPNWebGUIToken Metrics

Jira Asset Management Agent with OCR 📦🤖

Built an intelligent conversational Jira Asset Agent that interacts via chat to catalog and track IT hardware globally. Features OCR document scanning to automatically ingest equipment receipts/serial numbers and matches items against the global company Jira asset database for employee and hardware tracking.

Stack
Jira Assets APIOCR ParsingPythonAI AgentChat IntegrationAsset Management

Self-Hosted Enterprise Asset Management & Inventory System (Odoo & MSSQL / IIS) 📦🏢

Designed and deployed a self-hosted enterprise asset and inventory management ecosystem based on Odoo integrated with Microsoft SQL Server (MSSQL) databases and IIS-hosted corporate web portals. Provides centralized tracking, custom asset workflows, barcode/RFID integration, and automated database sync between ERP modules and legacy Microsoft infrastructure.

Stack
Odoo ERPMicrosoft SQL Server (MSSQL)IIS Web ServerSelf-Hosted InventoryAsset ManagementEnterprise Web PortalsDatabase Synchronization

Enterprise Service Aggregation & Centralized Portal Architecture (Dashy & Homer) 🌐🧭

Architected and repeatedly deployed centralized company service portals and dashboard hubs using Dashy and Homer across various organizational branches and clients. Centralizes all corporate tools, internal/external links, monitoring feeds, and web applications into unified, role-based single-sign-on access portals with health monitoring, full-text link indexing, and custom company branding.

Stack
DashyHomerCentralized Service PortalDashboardsApplication AggregationRole-Based AccessEnterprise NavigationLink Indexing

Enterprise SaaS & Workspace Administration (Atlassian, M365, Google Workspace, Exchange Cloud, Slack & Teams) ☁️💼

Architected, configured, and managed tenant-wide identity, messaging, and productivity platforms across Atlassian (Jira/Confluence), Microsoft 365, and Google Workspace. Enforced security baselines, DLP policies, conditional access, and MDM settings. Managed cloud email infrastructure across Microsoft Exchange Cloud and Google Workspace Mail, alongside enterprise collaboration platforms including Slack and Microsoft Teams.

Stack
Microsoft 365Google WorkspaceAtlassian SuiteExchange CloudGoogle Workspace MailSlack AdministrationMicrosoft TeamsDLP & Security Policies

Fully Managed Enterprise VoIP & Cloud PBX Infrastructure 📞⚙️

Designed and deployed an enterprise VoIP telephony system featuring virtual phone numbers, multi-department extension routing, and automated IVR trees. Configured official company verification integrations for carrier/access providers, agent call recording compliance, call queue distribution, and real-time PBX analytics in a fully managed infrastructure.

Stack
Cloud PBXVoIP TelephonyVirtual Numbers & ExtensionsAgent Call RecordingProvider VerificationIVR & Call QueuesSIP TrunkingPBX Analytics

Enterprise Conference Room Systems & Hybrid Workspace Audio/Visual (Zoom Rooms & Microsoft Teams Rooms) 🎥🎙️

Architected and deployed enterprise-grade Zoom Rooms and Microsoft Teams Rooms across corporate meeting spaces, integrated directly with Microsoft 365 Exchange and Google Workspace calendars for one-touch join capabilities and automated room scheduling displays. Configured official certified AV hardware from Logitech (Rally Bar, Tap IP, MeetUp), Jabra (PanaCast 50, Speak 810), and Neat (Neat Bar, Neat Pad, Neat Board), tailoring system specs, acoustic tuning, dual-display output, and wireless content sharing to room dimensions and company requirements.

Stack
Zoom RoomsMicrosoft Teams RoomsExchange / Workspace Calendar IntegrationLogitech Rally / TapJabra PanaCastNeat Bar & PadEnterprise AV & AcousticsSmart Meeting Hardware

Enterprise Hybrid Cloud Infrastructure & Backup Solution ☁️🏰

Engineered a resilient hybrid environment connecting on-premise Dell PowerEdge servers running Hyper-V clusters (Windows Server 2019–2022) with Azure Cloud. Protected by FortiGate firewalls and FortiSwitches. Implemented a dual-tier backup architecture combining local on-premise backup servers with Synology C2 Cloud storage for off-site disaster recovery and split-resource operational continuity.

Stack
Azure Hybrid CloudWindows Server 2019/2022Hyper-V ClusterFortiGateFortiSwitchSynology C2On-Prem Backup

GPU Cluster for Research, SolidWorks & SageMaker ML Pipeline 🖥️⚡

Architected a high-performance Windows Server GPU cluster supporting remote engineering research sessions. Configured multi-user isolated solidWorks virtual desktops for concurrent remote engineering workflows with encrypted disk environments. Synchronized research storage directly with AWS SageMaker pipelines for distributed model training and ML acceleration.

Stack
Windows Server GPU ClusterRemote SolidWorksAWS SageMakerGPU VirtualizationEncrypted StorageML Workflows

Automated Linux Testing Environment with Ansible & Jenkins 🐧⚙️

Constructed an automated on-premise Linux testing infrastructure managed via Ansible for continuous patching, system updates, and dependency management. Integrated Jenkins pipelines to automatically spin up fully configured test environments upon code commits. Enforced strict Zero-Trust VPN network segmentation and automated developer SSH key lifecycle management.

Stack
AnsibleJenkins CI/CDLinuxAutomated PatchingStrict VPN AccessSSH Key ManagementTest Automation

Containerized Learning & Examination Platform 🎓🐳

Architected a secure, containerized WordPress e-learning platform running on Oracle Cloud Infrastructure (OCI). Automated the provision of isolated container environments for engineering exams, complete with progress tracking, image evaluation, and automated review passes. Enforced full CI/CD deployment pipelines, code branch mocking for study purposes, WAF security, and container isolation.

Stack
Oracle Cloud Infrastructure (OCI)Docker ContainersWordPress LMSCI/CD PipelinesWAF SecurityAutomated Testing

Skills

Skills
Cloudflare Zero TrustAWS Route 53TwingateTailscaleOpenVPNWireGuardGitHub ActionsBitbucket PipelinesTerraformOpenTofuAWSAzureGCPOracle Cloud (OCI)Akamai / LinodeDigitalOceanCloudwaysProxmox VEHyper-VUnraidQEMU/KVMLXCVMwareOdoo ERPMicrosoft SQL Server (MSSQL)IISDashyHomerJira Assets APIOCRMicrosoft 365Google WorkspaceExchange CloudAtlassianSlackMicrosoft TeamsVoIP / Cloud PBXSIPZoom RoomsMicrosoft Teams RoomsLogitech AVJabra AVNeat SystemsNginx Proxy ManagerVLANsVPNSSL/TLSDNSLinuxWindows ServerActive DirectoryDockerBashPowerShellOpenTelemetryPrometheusPromQLGrafanaNetdataRMM AgentsBitdefender GravityZoneSentinelOneUbiquiti UniFiAir-Gapped SecuritycAdvisorNode ExporterTelegram APIGit

Certifications

🛡️
CISSP
(ISC)²
☁️
Oracle Cloud Infrastructure
Oracle · 2025
🔒
CompTIA Security+
Udemy · 2024
🌐
CompTIA Network+
CompTIA
🖥️
CompTIA A+ 1002
Udemy · 2023
💻
CompTIA A+
Udemy · 2023