Penetration testing & security assessment
SYN/FIN/Xmas/NULL scanning, OS fingerprinting, UFW bypass via conntrack INVALID, hping3, infrastructure recon, hardening recommendations.
I'm Nerses Antonyan, a DevOps engineer and system administrator. After 13 years keeping regulated banking systems accurate and online, I now design, automate and operate production infrastructure across Linux and Windows — with monitoring, CI/CD and infrastructure-as-code built in from day one.
A rare combination: someone who has lived inside systems where an error or an hour of downtime has real consequences — and who now builds the automation and observability that prevent both.
Hardened servers, least-privilege access and hands-on penetration testing — finding weaknesses before attackers do.
13+ years in banking, where downtime and inaccuracy weren't options — now built into how every system runs.
Prometheus, Grafana and Zabbix wired in from the start, so incidents surface — and get resolved — before users notice.
Terraform, Ansible and Bash turn manual, error-prone work into reproducible, version-controlled infrastructure.
A career built on operational accountability — carried from financial institutions into modern infrastructure.
Designing, provisioning and operating production infrastructure for clients — Linux and Windows servers, containerized workloads, CI/CD pipelines and infrastructure-as-code, with monitoring and alerting in place from the first deploy. Everything built to be secure, reliable and observable — now expanding into penetration testing and security assessments.
// case-study links coming in a future update
SYN/FIN/Xmas/NULL scanning, OS fingerprinting, UFW bypass via conntrack INVALID, hping3, infrastructure recon, hardening recommendations.
GitLab CI: test (go test) → build (Docker + GitLab Container Registry) → deploy (ssh + docker pull). Three stages, zero-downtime, deploy to test and prod from a single pipeline.
Prometheus (node_exporter + textfile collector), Grafana (dashboards), Loki + Promtail (container logs + syslog), Alertmanager (8 alerts: CPU, RAM, disk, WireGuard, Nginx, SSH brute force).
Terraform: VPC, subnet, Cloud NAT, MIG, HTTP LB, two environments (test/prod) with VPC peering. Ansible: 7 roles (common, docker, firewall, wireguard, monitoring, nginx, totp). CI validates terraform + ansible-lint.
ZeroTalk: Go WebSocket server with TLS 1.3, Ed25519 challenge-response, pre-key store (24h), file sharing (5min + secure overwrite). HTML client embedded in binary, XSS-protection, rate limiter, 6 security headers.
Multi-layered defense: GCP firewall + UFW + iptables. Zeek IDS (protocol analysis, JA3), Suricata IPS (30,000+ Emerging Threats rules), ntopng (visualization), fail2ban (SSH), egress filtering with alerts.
I'm available now for remote or on-site roles and infrastructure consulting. Bring me your servers, pipelines and uptime targets — I'll bring the discipline to keep them running.