$ whoami
Nicolás Damián Sadofschi
Senior Firewall Engineer @ SIX · Zurich
✓ Master in Offensive Security ✓ OSCP ✓ OSCP+
I run firewalls and remote access for Swiss financial infrastructure. Off the clock I hold the OSCP and build my own servers and tools until they work.
20+
years in IT
OSCP
passed Jan 2026
17
projects built
4
languages spoken
§ 01 / about
Twenty years of keeping other people’s systems up. Now I also know how they fall.
Infrastructure taught me how things are meant to work. Offensive security taught me how they actually fail. After twenty years of building and running other people’s platforms I did a master’s in offensive security and passed the OSCP, and now I use both sides every day: I build like someone who knows how it gets broken.
By day that means firewalls at SIX, and before that four years engineering remote access at Julius Baer and almost seven at NTT, where I ended up as the last line of escalation for managed hosting customers.
At home I run a small fleet for real: a hardened VPS, a Raspberry Pi, a site-to-site VPN, Zero Trust access and a pile of services I built myself. I do not hand-write much code any more: I work with AI coding agents, where my part is the design, the review of every change and knowing when to say no. If it is on this page, it is running somewhere.
$ history | head · how it started
First website
Built with FrontPage 97. The follow-up was a Simpsons fan site on free hosting, with a three-level quiz that kept stats and a JavaScript cookie that remembered your name and greeted you with it.
First “hacks”
Sent the Sub7 and PC Invader backdoors to classmates over ICQ. “Hacking”, in very large quotation marks, but it was the first time a machine did what I wanted from somewhere else.
IRC and the easy bugs
Fell into IRC groups and learned from the Unicode traversal bug and the Code Red era that most of the internet was held together with defaults.
Counter-Strike taught me Linux
Running game servers meant learning Linux, Apache, IIS and SQL without noticing I was studying.
Cyber-cafés
My first unofficial job: crimping network cables and setting up every machine in the room. The official career starts right after.
§ 02 / experience
Experience
From a repair bench to the firewalls of Swiss financial infrastructure.
Senior Firewall Engineer · SIX
Firewall engineering for the company that operates Swiss financial market infrastructure.
- Working on bringing a Model Context Protocol server for Palo Alto firewalls into the team’s tooling.
- Palo Alto
- MCP
Security Engineer · Julius Baer
Operations and engineering for remote access at a Swiss private bank.
- Improved how tickets flow between the helpdesk and engineering, and ran training and mentoring sessions for the helpdesk every six months.
- Tightened day-to-day operations of the remote access platform.
- Onboarded two engineers and took them from zero to fully autonomous.
Senior Infrastructure Engineer · SYNLAB International
Infrastructure engineering for an international medical diagnostics group.
- Planned and delivered a datacenter migration from Madrid to Germany, including the network architecture.
- Kept the original subnets, as required, and scripted traffic analysis to work out which firewall rules the new site needed.
- Moved the databases with SnapMirror, with no data loss.
- Network design
- SnapMirror
- Traffic analysis
Solutions Engineer Tier 3 & Deputy Team Lead · NTT Ltd.
Last level of escalation for NTT cloud and managed hosting customers, plus installation and QA.
- Owned customer platforms end to end, from deployment to support, inside agreed SLAs.
- Built and ran networking, Linux and Windows servers, virtualization, load balancing, firewalls and storage.
- On-call engineer for maintenance windows and customer projects; deputy lead of the team.
Service Desk Engineer · NTT Ltd.
Escalation point for complex incidents on managed infrastructure; trained and mentored the team.
- Supported managed hosting for customers such as Decathlon, Canon, Emirates, Etihad, Aviva and Nomura.
- Led internal and customer-facing projects as one of the most technical members of the desk.
- FortiGate
- Juniper
- Cisco
- NetScaler
- Alteon
- VMware
- NetApp
Senior Infrastructure Analyst · NTT Ltd.
Networks, firewalls, VPN, storage, load balancing and servers for customer solutions.
- Resolved incidents and problems and planned production changes, often out of hours.
- Configured FortiGate firewalls through FortiManager and the CLI.
Support, freelance and a company of my own · Earlier years
Ten years of hands-on IT before the datacenter.
- Second-level support for Meliá Hotels at Digitex: Active Directory, Exchange, Citrix, VMware.
- Freelance consultant for small businesses: networks, servers, hosting and websites.
- Managing partner of Verynice Europa, a company that built, sold and rented ice rinks.
- Repair bench, field support and a cyber-café, where it all started.
Education
Master’s Degree in Offensive Security
UCAM, Universidad Católica San Antonio de Murcia
Network Systems Administration
IES Lacetània, Manresa
§ 03 / credentials
Certifications & skills
UCAM
Master’s Degree in Offensive Security
Universidad Católica San Antonio de Murcia. A full year of offensive security, built around the OSCP syllabus.
OffSec
OSCP
OffSec Certified Professional. A 24-hour, hands-on penetration test followed by a written report.
Verify OSCPOffSec
OSCP+
The renewable edition of the OSCP, earned in the same exam.
Verify OSCP+
| Credential | Issuer | Held |
|---|---|---|
| VMware Certified Professional, Data Center Virtualization 2020 | VMware | 2020 – 2022 |
| VMware Certified Professional 6, Data Center Virtualization | VMware | 2017 – 2019 |
| NSE 7 Network Security Architect | Fortinet | 2020 – 2022 |
| Network Security Expert 4 (FortiOS 5.4) | Fortinet | 2018 – 2020 |
| Citrix Certified Associate, Networking (CCA-N) | Citrix | 2019 – 2022 |
| ITIL Foundations | ITIL | — |
| CyberOps Associate | Cisco | 2022 |
| English CEFR C1 (Aptis ESOL) | British Council | 2025 |
Skills
Network security
- Firewall engineering
- Remote access & VPN
- IPsec / IKEv2
- WireGuard
- Zero Trust access
- Load balancing
Offensive security
- Penetration testing
- Active Directory
- Privilege escalation
- Web applications
- Reporting
Infrastructure
- Linux
- Windows Server
- VMware
- Storage
- DNS
- Hardening
- Backup & recovery
Building with AI
- AI coding agents
- Specs, review and rollback
- MCP servers
- OAuth 2.0
- LLM tooling
- Bash
Operations
- Prometheus
- Grafana
- systemd
- nginx
- Docker
- Incident analysis
§ 04 / projects
Things I built, and still run
Built for real use, on hardware I pay for and patch. Internal details stay internal; the design is what I can show.
Running today
security
Remote MCP server with its own OAuth 2.0
A Model Context Protocol server that lets an AI assistant query private data. It has its own authorization server instead of a borrowed one: dynamic client registration, PKCE, redirect allow-list and lockouts, then hardened it after an audit.
- Python
- FastAPI
- OAuth 2.0
- PKCE
- Zero Trust tunnel
security
Site-to-site VPN that heals itself
An IPsec IKEv2 tunnel between home and a VPS, working behind double NAT and a dynamic address. Watchdogs detect a dead tunnel, tell ingress from egress failures and bring it back, with a kill switch so nothing leaks meanwhile.
- IPsec
- IKEv2
- WireGuard
- Firewalling
- Bash
security
Daily security review, run by an LLM analyst
Every day a headless agent reads logs, port diffs and access events from my servers, triages them like a junior analyst would and only pages me when it is serious. Read-only by design.
- Python
- LLM agents
- systemd timers
- Telegram
platform
gen0ne: a personal data platform on a 1 GB server
Wearables, training, nutrition and calendar pulled into one API and dashboard, with alerting and an AI layer for logging by text, voice or photo. About ten integrations, no Docker, VPN-only by default.
- FastAPI
- SQLite
- React
- APScheduler
- nginx
infrastructure
Home lab with Zero Trust access
A Raspberry Pi and a NAS that behave like a small datacenter: identity-gated access with short-lived SSH certificates, redundant DNS filtering, Prometheus and Grafana for every host, three tiers of backup and fault-injection tests that I actually run.
- Raspberry Pi
- Cloudflare Tunnel
- Prometheus
- Grafana
- Docker
tool
Telegram ChatOps bot
One chat to run the fleet: wake or hibernate a PC, check servers, approve updates. Each integration gets its own forced-command SSH key limited to an allow-list of verbs, and anything that writes waits for my confirmation.
- Python
- Telegram Bot API
- SSH forced commands
- Whisper
Also built
infrastructure
Rebuild-the-server kit
Scripts and a runbook that recreate a whole VPS from Git: services, firewall, users and GPG-encrypted secrets, backed by layered off-site backups with integrity checks.
- Bash
- Git
- GPG
- rclone
security
VPS hardening and self-audits
Default-drop firewall, key-only SSH, fail2ban, sandboxed non-root services with memory caps, and periodic audits of my own perimeter with tracked remediation.
- Debian
- systemd
- fail2ban
- nginx
app
Trip planner: offline-first PWA, bot and MCP
A planning app that keeps working with no signal, with a Telegram bot and an OAuth-protected MCP server on top. Around 540 tests and a full staging clone with a simulated clock to rehearse days in advance.
- Python
- PWA
- OAuth 2.0
- Playwright
security
Travel VPN hotspot
A Raspberry Pi that turns any hotel network into my own: every client is forced through a WireGuard tunnel, with a kill switch checked against DNS and IPv6 leaks.
- Raspberry Pi
- WireGuard
- NetworkManager
tool
claudetrack-tray
A Windows tray app for Claude Code that keeps session usage in view at all times and, more importantly, resumes sessions by itself when the limits reset. Credentials live in the OS keystore; 129 tests and ten languages.
Inspired by a browser extension my brother wrote. I built the desktop version and gave it to him; it lives on as UsagePeek.
- Rust
- Tauri 2
- TypeScript
app
AI wardrobe with virtual try-on
An open-source closet app extended with try-on image generation. It runs on a gaming PC that only wakes when someone asks for it.
Built on the open-source wardrowbe project.
- Docker
- Wake-on-demand
- Image generation
app
Kery
A mobile app with an LLM at its core, built with prompt-injection rules and owner-only data access from day one. Paused, not abandoned.
- Flutter
- Firebase
- Gemini
app
A routine tracker for kids
A small PWA with rewards and a parent approval loop over Telegram, plus a reproducible pipeline for its clay-style artwork.
- FastAPI
- PWA
- Telegram
tool
OSCP Obsidian Tracker
The templates, dashboard and methodology I used to prepare the OSCP, packaged as an Obsidian vault.
- Obsidian
- Dataview
- Markdown
tool
Tunneleitor
A Bash script that creates and manages forward and reverse SSH tunnels: port checks, PID tracking, logs and a report of what is up.
- Bash
- SSH
web
Afectados MOVES III
A campaign website for people affected by delays in a public subsidy programme.
- HTML
- GitHub Pages
§ 05 / beyond
Beyond work
Away from the keyboard I am usually moving. I live in Zurich with my partner and our young son, and most weekends end up on a mountain or in a lake.
Two wheels
Motorbikes and mountain bikes. One has an engine, both go downhill faster than they should.
Sport
Gym, swimming, hiking. I train most days and I am not picky about how.
On the water
Licensed for motorboats and jet skis. The entry-level licence, but it floats.
Music
Always something playing while I work.
Family
Playing with my son is the best part of the day. Half of what I build at home is for the three of us.
Tinkering
Raspberry Pis, fan controllers, anything with a serial port. If it can be automated, it will be.
§ 06 / contact
Get in touch
For work, a second opinion on a design, or to tell me something on this page is wrong.
$ cat info.py
# contact details
nick = 'gen0ne'
email = 'contacto' + '@' +'nicodamian.com'
linkedin = 'https://www.linkedin.com/in/nicolas-damian-sadofschi/'
github = 'https://github.com/nicolasdamians'
print(email)
contacto [at] nicodamian [dot] com