Michael Horwath

2033 127th Lane NW                                                                       [email protected]

Coon Rapids, MN 55448                                                                https://www.linkedin.com/in/geekandi

Cell: 612-229-5878

 

Download my resume: Word or PDF formats


 

Profile

·       More than 30 years of experience successfully leading companies, teams, departments, and projects.

·       Detail-oriented IT professional with experience as a systems architect, administrator of hundreds of servers, mid-to-large sized networks, and managing the teams that manage the infrastructure.

·       Highly skilled at managing large, complicated projects on a range of platforms, both in the cloud and on-premises.

·       Able to quickly adapt to any IT environment and exercise independent judgement within management guidance and project goals.

·       Excellent written and oral communication skills.

·       Capable of breaking down complex issues into easy-to-understand terms based on target audience.

·       SecOps, DevOps, and Agile methods used in daily workflows.

 

Notable Achievements

·       Accomplished technical blogger via my website since 2006.

·       Operated one of the largest UseNet server clusters in the world in the late 1990s and mid-2000s.

·       CTO of VISI, helping drive growth to $8.5MM per year revenue and eventual sale for 3x revenue.

·       Started first ISP for regular people in MN in 1993.

                                                                                          

Employment & Business History

 

Trility Consulting

Cloud Security Engineer, Senior Cloud/SecOps/DevOps Engineer March 2018 – July 2023

 

Duties

Work with customers on multiple statement of work contracts implementing deliverables.

 

Experience

·       Deploying AWS cloud infrastructure keeping an eye on that elusive goal of zero downtime while using secure infrastructure patterns.

·       Jenkins as the CI/CD across multiple projects and customers.

·       Writing Terraform modules, code review for others (Terraform, Python, shell scripts), playing mentor and teacher (mostly Terraform but general UNIX things as well), and sometimes acting as the person you call when diagnosing problems that are difficult.

·        

·       Terraform and security infrastructure with HashiCorp Vault Enterprise

·       Jenkins CI/CD across multiple projects including writing modules, code review for others.

·       Mentor and train clients and co-workers on the technology used.

·       Involved with more than 40 accounts and 40 security & cloud engineers helping to make everything right.

 

Achievements

·       Creation of both secure AMI and container images for open-source applications following ‘gold image’ standards for patching and security.

·       Implement dashboards from centralized logging of VPC Flow Logs, CloudTrail, and S3 access logs in AWS.

·       Deep dive presentations across multiple processes from building AMIs in a repeatable fashion using Terraform to diagnosing performance issues of AWS instances, networking, and security group configurations.

·       Deployment to multiple environments and accounts using a single source repository.

·       Wrote Terraform modules to create repeatable, consistent infrastructure resources.

 

TEKsystems

Contractor, Security Automation Developer October 2017 – February 2018

 

Duties

Implement best common practice security controls within AWS for a large agriculture company.

 

Experience

·       Implement CIS AWS Foundations Benchmark controls across all AWS accounts and business units.

·       Create a framework that operates in a pipeline to create common elements across all accounts.

·       Work as a conduit to other teams to create better security practices.

·       Involved with design/architecture of new centralized logging for VPC Flow Logs and S3 access logs.

·       Code review of Terraform within the cloud platform team repositories including optimization.

·       Mentored developers on the team on Terraform best practices and sharing what I have learned along the way.

 

Achievements

·       Create new bootstrap for the security team that instantiates a pipeline per account and uses the attached framework to implement security controls and consistency in the business unit accounts.

·       Work with other teams to streamline bootstrap code for new AWS accounts and VPC configuration.

·       Implement AWS GuardDuty across any account tied to the framework via master/member account relationships.

·       Implement centralized logging of VPC Flow Logs, CloudTrail, and S3 access logs to master account.

·       Stand up and configure Palo Alto Networks firewalls in AWS for both ingress and egress in a multi-account configuration using VPC peering and direct-connect.

·       Configure external load balancers on ingress in security account that use the Palo Alto Networks firewalls which then send connections cross-account to auto-scaling group (AWS ASG) built nginx instances that talk to internal ELB/ALB in the target account.

·       Write Terraform modules to create repeatable, consistent infrastructure resources.

 

 

RAZR Marketing

Ad hoc consultant October 2015 - July 2016

Senior Site Reliability Engineer and Senior Security & Compliance Engineer - August 2016 - October 2017

 

Duties

Originally worked with RAZR Marketing as an ad hoc consultant helping them with their office networking, initial AWS implementation, firewall upgrades, and work on PCI DSS.

 

DevOps: Develop and maintain infrastructure as repeatable routines via Terraform (AWS) and Ansible (instance configuration). Monitor and maintain CI/CD tasks with Jenkins, and the migration away from Bamboo. Engage with development and project management to architect, scale, and improve the security, compliance, and uptime of our production systems.

 

Security/Compliance: review, implement, and remediate our policies, procedures, systems, and networks. Deep interaction in our PCI/SOC2 compliance certifications as the subject matter expert. Implement HIPAA supported architecture in AWS for a large medical device company solution.

 

Experience

·       Architect and implement self-hosted Atlassian products (Jira, Confluence, Crucible).

·       Terraform has taken over for approximately 90% of my automation work within AWS.

·       Written many Ansible playbooks to maintain our Linux instances, from patching to compliance.

·       AWS infrastructure design, architecture, and implementation.

·       Some VMware work within legacy data-center installation as production infrastructure moves to AWS.

·       Review and Rewrite sections of our compliance standards and procedures.

 

Achievements

·       Redesign network infrastructure and architecture to fully comply with PCI DSS and HIPAA.

·       Remove Bamboo from production environment.

·       Migrate legacy Tomcat/Java based applications to AWS in a repeatable fashion.

·       Worked with development and other SRE to implement micro-services architecture for a new class of services offered by RAZR in AWS.

·       Achieve over 99.9% uptime, including planned downtime, for our customer offerings via improved architecture and automation.

                                                                                       

 

SPS Commerce

Principal Systems Engineer - July 2014 – August 2015

Lead Systems Engineer - September 2013 – August 2015

 

Duties

Transitioned to a full-time employee. Responsible for architecting, building and implementation of technologies to offer a world-class SaaS platform. Collaborated closely with development and other technology staff to develop, migrate, and manage services both in our private datacenters and in the Amazon Web Services (AWS) cloud environment. Advocate and agent of change by actively researching and developing strategies, tools, and technologies that can be used within the company. Continued implementation of Fortigate solutions within AWS to secure data operations. Worked with the network team to implement Fortigate firewalls into HQ replacing the current ASA solution that was underperforming.

 

As a mentor, I took on the responsibility of delivering training and invaluable supplementary support to fellow technology staff whenever required. This role demanded a high level of self-sufficiency and initiative, along with exceptional communication skills and a knack for collaborating seamlessly across departments and with upper management.

 

Experience

·       Continuation of the projects I had as a consultant.

·       DevOps

·       Implementation of Ansible as our go-to automation solution.

·       Continued support of Chef and Puppet for legacy applications.

·       Work on special projects with many operation and development teams.

·       Continued involvement with the network team as needed.

·       Helped with implementation of ElasticSearch+Logstash+Kibana (ELK) for centralized logging during 2014. With over 90 applications in SPS we had a lot of logging to deploy. In early 2015 we brought in Sumo Logic as our centralized logging destination. I built out many of the production dashboards for different operations groups and a few scheduled searches for nightly reporting including security and performance reports.

·       Continued implementation of LogicMonitor throughout 2014. We really pushed LM datasources to the limit with scripts and SQL queries generating a lot of data for us to graph and alert on.

 

Achievements

·       Brought backups to the forefront as an important service provided internally for SPS for the continued operation and recovery in case of disaster.

·       Decommissioned VMware backups in CommVault (wrong solution).

·       Implemented Veeam Backup & Recovery for production and development workloads (right solution).

·       Involved in the implementation of Veeam Backup & Recovery within the corporate ‘office pattern’ used in all offices (new solution).

·       Designed and architected ActiveMQ in scalable, cluster of cluster configuration to replace Oracle WebLogic queuing infrastructure, was one of the most memorable projects that I worked on during 2014 though in the end it was not chosen.

·       Ansible as the primary automation system for new production and development deployments replacing puppet (local) via attrition and replacing Chef as the automation system for AWS. While discussed earlier in 2014 it really didn’t get a foothold until the end of the year.

 

SPS Commerce

Consultant - September 2013 – July 2014

Lead Systems Engineer - September 2013 – August 2015

 

Duties

Hired by SPS to help figure out why the operations team seemed to be doing more firefighting than operating.

 

As a teammate of the systems engineering group, I helped build morale, increase efficiencies, and improve workplace enjoyment.

 

Network team was understaffed so I split some of my time with them helping get projects to a completed state.

 

Experience

·       Introduced LogicMonitor into SPS to handle monitoring activities of the network and servers replacing Nagios and the deprecation Sitescope and Nagios.

·       Wrote many of the initial base Chef cookbooks/recipes for AWS deployment.

·       Solidified systems engineering team into a tight-knit group supporting Cisco UCS, VMware, and almost 900 servers initially then growing to over 1400 over 18 months.

·       Worked with the understaffed networking team to solve issues, finish projects, and day-to-day management.

·       Implemented Amazon Web Services (AWS) services (see below).

 

Achievements                                       

·       Initial design work on ElasticSearch+Logstash+Kibana (ELK) for centralized logging of over 90 applications.

·       Cleanup of F5 load balancer configurations.

·       Created first Reason for Outage (RFO) documentation and policies for ongoing internal notifications.

·       Segregated customer-facing infrastructure from internal infrastructure to create logical boundary for measurement and monitoring of service delivery.

·       Initial architecture and implementation of AWS for SPS:

o    Implemented production and development AWS Virtual Private Cloud configurations.

o    Designed and implemented initial subnet and security group designations.

o    Implemented (physical) HA Fortigate firewalls in both (current) production and development environments.

o    Initial implementation of VPN connectivity between AWS VPC to new (physical) HA firewalls in the two datacenters.

o    BGP configuration for new AS.

o    Helped networking team with new policies to support AWS connectivity, failover, and security.

o    Instrumental in the set-up of the first direct-connect from AWS to SPS (New Jersey datacenter).

o    Implementation of direct-connect from AWS to SPS (St. Paul datacenter).

                                                                                                  

Atomic Data, LLC

Director of Network Engineering December 2012 – August 2013

 

Duties

Manage Systems Engineering and Network Engineering teams to fulfil a common goal.  Deeply involved in design and implementation of server and network projects base on business and customer requirements.

 

Experience

·       Defined VMware cluster architecture based on business requirements and growing customer demands.

·       Integral member of Compliance Advisory Board that defined products, services, and general policies for secure operation of the business and our customers.

·       Defined scope of security compliance, definition of access, policies, and implementation of security measures used in the day-to-day operations of the business regarding SOC3 compliance as part of Security Advisory Board.

 

Achievements

·       Designed, implemented, tested, and delivered new VMware cluster in record time including NetApp storage configuration and deployment.

·       Used my strong knowledge of VMware technologies, NetApp storage appliances, F5 load balancers, and IPv4/IPv6 networking protocols and design.

·       Created first Reason for Outage (RFO) documentation and policies for ongoing internal notifications.

·       Segregated customer-facing infrastructure from internal infrastructure to create logical boundary for measurement and monitoring of service delivery.

 

ipHouse

Founder, CTO May 2004 – November 2012

 

Duties

Designed, implementation, delivery of high-tech infrastructure for the service provider industry. Managed the day-to-day operation of the business including employees, purchasing, scheduling, and customer interactions. Deeply involved with purchases and mergers and their integration into the ipHouse infrastructure.

 

Experience

·       Managed all day-to-day operations of sales, marketing, and technical employees.

·       Designed and built complete network and server infrastructure for launch of business.

·       Documented customer services for purchased companies. Managed transition of services into ipHouse.

·       Advised customers and designed platform plans to meet their short-term needs and positioned the customer for future growth.

 

Achievements

·       Instrumental in refocusing corporate mission from home Internet access to managed hosting services for businesses.

·       Designed and launched fastest growing product lines in company history.

·       Added security focused solutions built using Fortigate firewalls.

·       Integrated 3 service providers into the ipHouse infrastructure preserving over 95% of customer base while streamlining product offerings to decrease support burden and increase profitability. In the case of one ISP - increased received revenue by almost 40% after technical audits.

·       Implemented new billing procedures resulting in decreased billing support and measurable increase in revenues.

 

VISI.com

CTO July 1996 – May 2000

Director of Network Engineering May 2000 – May 2004

 

Duties

·       Handled day to day management of roughly 55% of the employees dealing with support, engineering, and customer service.

·       Design and managed internal and external servers, network, and physical infrastructure.

·       Created disaster recovery plans and led engineering teams during both scheduled and unanticipated downtimes.

·       Day-to-day management of all engineering and support staff.

 

Experience

·       Instrumental in business growth from $200K in 1995 to $8.5M in 2000.

·       Directly managed 35 of 65 employees.

·       Proactively managed servers and network to achieve near 100% uptime.

·       Designed and supervised building of new datacenter in Minneapolis.

·       Retrofitted an old datacenter in St. Paul to modern infrastructure.

·       Redesigned network/server infrastructure to improve reliability during rapid growth.

·       Primary vendor contact and manager of relationships of multiple telecommunications providers including US West/Qwest, Level3, BBN Planet/Genuity Networks, Sprint, AT&T, and UUNET/MCI to support the growing network.

 

Achievements

·       Deployed and managed the largest 3rd party DSL network in the US West/Qwest ILEC states with over 6000 direct customers as of February 2000.

·       Instrumental in company growth from a fledgling ISP to the largest ISP in Minnesota with $8.5M in revenue in under 4 years.

·       Operated and managed Minnesota peering point, growing it to 25+ peers in the state.

·       Operated and managed top 10 UseNet service with over 100 peers.

·       Deeply involved with the sale of VISI.com to DSLN for $25M.

·       Managed growth of network from single T1s to multiple BGP OC3 connections.

Winternet

Founder, President November 1993 – July 1996

 

·       Launched first Internet Service Provider in Minnesota from zero revenue to $2M in less than 18 months.

·       First ISP in Minnesota to deliver and support PPP in Minnesota.

·       First ISP in Minnesota to utilize BGP in a multiple Tier 1 provider implementation.

·       Worked with multiple telecommunications providers to support the growing network including USWest and UUNET, and MRNet (regional provider).

·       Operated large UseNet news hub with over 80 peers.

·       Creating and operating Minnesota’s first public peering point exchange.

 

US Army

Truck Driver, Ammunition Handler May 1985 thru May 1993

                                                                                      

Duties

 

·       Lead teams of non-commissioned personnel including higher ranked individuals in day-to-day operations.

·       Review rules, laws, policies, and regulations for both US and German government statutes in the handling and movement of ammunition.

·       Manage and coordinate storage in active ammunition supply points in 3 regions of West Germany.

·       Support E6 management by organizing, filling out, and reviewing required paperwork.

 

Experience                                                                      

·       Determined correct procedures to follow when government ammunitions regulations conflicted.

·       Supported ammunition teams by organizing schedules, duty rosters, and layout of temporary supply points while on manoeuvres.

 

Achievements

·       Perfect marksmanship throughout active duty with commendations.

·       Zero issues/faults in audits of ammunition supply points during my deployment and management of the ASPs.

 

Redundant Networking Corporation

Founder, Principal June 1997 - present

 

Duties

I have operated a couple of businesses under this umbrella, including Octanews (2003-2012) and Minnesota Tau (mtau).

 

Note: This business is currently inactive

 

mtau Experience

·       Manage engineering teams on projects from planning to completion.

·       Cloud infrastructure design, architecture, and implementation within AWS (preferred), GCP, and Azure.

·       VMware design, architecture, implementation, and maintenance.

·       Network infrastructure design and architecture, implementation via Juniper, Cisco, and Fortigate platforms.

·       Automation architecture, implementation, and maintenance via Terraform and Ansible.

·       General IT consultancy duties.

·       Security focused approach in all levels of planning and implementation.