root@bengomez:~$ whoami

Ben Gomez

// Systems Administration & Cybersecurity

Aspiring systems administrator with hands-on experience managing Linux servers, virtualization, networking, and enterprise-style home lab environments โ€” from firewall configuration and containerization to automated backups and security monitoring.

// live production server

Security Stack

This portfolio is self-hosted on an Ubuntu Server, secured and hardened end-to-end. Every layer below is actively running in production.

๐Ÿ”’
Let's Encrypt / Certbot
Trusted HTTPS certificate via DNS-01 challenge. Auto-renews every 90 days using GoDaddy DNS API hooks.
ACTIVE โ€” TLS_AES_256_GCM_SHA384
๐ŸŒ
Apache2 + Security Headers
Version info hidden. X-Frame-Options, X-Content-Type-Options, and X-XSS-Protection headers enforced on all responses.
ACTIVE โ€” Apache httpd
๐Ÿ›ก๏ธ
ModSecurity + OWASP CRS
Web Application Firewall blocking SQL injection, XSS, and other OWASP Top 10 attacks in real time.
ACTIVE โ€” Engine: ON, CRS 4.x
๐Ÿšซ
Fail2ban
4 active jails monitoring SSH and Apache logs. Bans IPs after 3 failed attempts for 1 hour.
ACTIVE โ€” 4 jails running
๐Ÿ”ฅ
UFW Firewall
Default deny all incoming. Only ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) are explicitly allowed.
ACTIVE โ€” Default deny incoming
๐Ÿ‘ฅ
CrowdSec
Community-powered threat intelligence. Shares and receives blocklists from thousands of global servers.
ACTIVE โ€” Firewall bouncer enabled
๐ŸŒ
GoDaddy DNS + Auto IP Update
Custom domain hosted on GoDaddy DNS with a cron job that automatically updates the A record when the public IP changes.
ACTIVE โ€” Monitored via cron
๐Ÿ”„
Auto Cert Renewal
Certbot renewal hook scripts automatically update GoDaddy DNS TXT records and reload Apache on renewal.
ACTIVE โ€” Runs nightly at 03:00
๐Ÿ“ก
Security Monitor (Python)
Custom Python daemon that tails Apache, Fail2ban, ModSecurity, and auth logs in real time and sends email alerts on new bans, WAF blocks, failed SSH logins, and 404 scan spikes. Runs continuously as a systemd service.
ACTIVE โ€” systemd service, 60s poll interval
// nikto scan comparison

Before vs After Hardening

BEFORE โ€” baseline scan
โœ— Apache/2.4.66 version exposed
โœ— X-Frame-Options header missing
โœ— X-Content-Type-Options missing
โœ— X-XSS-Protection missing
โœ— ETags leaking inode data
โœ— 997 ports closed (visible)
โœ— 3 issues reported by Nikto
AFTER โ€” hardened scan
โœ“ Version hidden โ€” "Apache" only
โœ“ X-Frame-Options: SAMEORIGIN
โœ“ X-Content-Type-Options: nosniff
โœ“ X-XSS-Protection: 1; mode=block
โœ“ ETags leaking fixed
โœ“ 997 ports filtered by UFW
โœ“ 0 errors reported by Nikto
// what I work with

Technical Skills

Systems Administration

Linux Server Admin KVM/QEMU systemd Docker

Operating Systems

Windows Linux Ubuntu Server Debian BIOS/UEFI

IT Support

OS Installation Factory Resets Antivirus Hardware Remote Support JSM Ticketing

Networking

TCP/IP DNS DHCP OPNsense Port Forwarding SSH

Cybersecurity

Python Scripting Threat Analysis Log Analysis WAF IDS

Server Tools

Apache2 ModSecurity Fail2ban UFW CrowdSec Certbot

Backup

Restic systemd Timers

Tools

CLI nmap nikto Git Firmware Updates
// where I've worked

Work Experience

Print Dept. / Onsite Helpdesk IT Associate
OfficeMax
2 Years
  • In-store technical support and troubleshooting for customer devices
  • Utilized Jira Service Management (JSM) for ticket triage and escalation coordination
  • Performed factory resets, OS installations, and full system setup
  • Updated BIOS and firmware on supported devices
  • Installed and activated antivirus software using license keys
  • Assisted with printing, copying, and document services
Enrollment Advisor
Primavera Online School
Oct 2025 โ€“ Present
  • Handle high-volume calls with ticket triage and escalation coordination
  • Assisted students with enrollment and system navigation
  • Maintained accurate digital records and ensured compliance
  • Technical and administrative support via phone and email
  • Resolved issues efficiently using structured problem-solving
Assistant Manager
Circle K
1 Year
  • Managed daily operations, inventory, and cash handling
  • Supervised and trained staff members
  • Maintained organized workflows and delivered strong customer service
// things I've built

Projects

๐Ÿ–ฅ๏ธ
Self-Hosted Hardened Web Server
Administer a production Linux server (Dell Precision Tower 5810, Ubuntu Server) running Apache2, HTTPS, ModSecurity WAF, Fail2ban, UFW, and CrowdSec. This site runs on it.
๐Ÿณ
Dockerized Media Application
Containerized a self-built Flask application (medialib) with Docker, moving a previously bare-metal service to a portable, isolated deployment.
๐Ÿ’พ
Automated Backup Management
Implemented nightly Restic snapshot backups to a dedicated backup drive, scheduled and managed with systemd timers for reliable, unattended recovery points.
๐Ÿ“ก
Python Security Monitor
A Python daemon that tails Apache, Fail2ban, ModSecurity, and SSH auth logs in real time, then emails alerts on new IP bans, WAF blocks, failed logins, and 404 scan spikes. Deployed as a systemd service on this server.
► View source on GitHub
// credentials

Certifications

๐ŸŽ“
Google IT Support Professional Certificate
Coursera ยท Google
๐Ÿ”ง
Technical Support Fundamentals
Coursera ยท Google
๐Ÿ
Introduction to Python for Cybersecurity
Coursera
๐Ÿง
Linux Fundamentals
Coursera

Education

Bachelor's Degree in Cybersecurity
Central Arizona College
IN PROGRESS
General Educational Development (GED)
Rio Salado College
COMPLETED
// let's connect

Open to Opportunities

Currently seeking systems administration, IT support, or entry-level cybersecurity roles. Feel free to reach out โ€” I respond promptly.

Send an Email