• Файл

Ігор

Програміст PHP

Розглядає посади:
Програміст PHP, Системний адміністратор, DevOps engineer, Інженер систем безпеки, Адміністратор, Спеціаліст технічної підтримки, Сервісний інженер, Інженер телекомунікаційної мережі
Місто:
Київ

Контактна інформація

Шукач вказав телефон .

Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.

Завантажений файл

Версія для швидкого перегляду

Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.

Ihor Radetskyi
Network & GNU/Linux Systems Engineer — ISP Infrastructure | Virtualization | Networking | Sysadm
Kyiv, Ukraine (open to remote / office) • [відкрити контакти](див. вище в блоці «контактна інформація»)[відкрити контакти](див. вище в блоці «контактна інформація»)github.com/blindone0

PROFESSIONAL SUMMARY
Network and systems engineer with 8+ years of continuous experience at a Kyiv internet service provider, progressing through five roles from last-mile installation
and call-centre support to core network and systems engineering on AS39027 — single-handedly operating 350+ network devices and personally serving the
entire subscriber base of 6,000+ — every one of them handled by me, as client manager, as L3 systems engineer, and face to face at their homes. Equally
comfortable with carrier networking — Juniper MX routing, BGP peering, D-Link and Cisco L2 design, GPON access — and with the GNU/Linux, virtualisation,
storage and automation layers behind it. Led four full hardware-generation migrations and repeated cross-hypervisor workload moves with no service loss. CCNA-
certified, with a recent focus on infrastructure security and system hardening.

KEY STRENGTHS
Sole operator of a 6,000-subscriber network — single-handedly ran 350+ network devices and personally served every one of 6,000+ subscribers: as
client manager on the phone, as L3 engineer on the core, and in person at their homes — covering BGP routing, RIPE/LIR administration, GPON access and high-
availability L2 design without a team to escalate to
Migration specialist — four complete hardware-generation migrations, repeated cross-hypervisor workload moves (Hyper-V, KVM/QEMU, VMware, Proxmox) a
network-wide PPPoE to DHCP/IPoE subscriber access migration, and full billing/CRM platform migrations, all without service loss
Full-stack infrastructure — bare metal, LVM and RAID storage, Proxmox and Hyper-V virtualisation clusters, Docker and Kubernetes workloads
Multi-distribution GNU/Linux depth — Debian, Ubuntu LTS, RHEL/CentOS, Fedora, Arch and source-based Gentoo, including cross-major-version migrations
Security hardening — production GNU/Linux hardening with AppArmor, auditd, PAM policy, nftables/pf firewalling and Lynis auditing
Automation and shell mastery — deep Bash and POSIX shell expertise alongside Python, Perl and PowerShell, applied to provisioning, monitoring, bulk
configuration, interactive operator tooling and certificate lifecycle management
Multi-vendor interoperability — building working communication between equipment from different manufacturers (Juniper, Cisco, Huawei, D-Link, Edge-
Core, FoxGate, Eltex, TP-Link) — deploying QinQ and DHCP option 82 consistently across every platform — plus direct technical work with vendors on firmware,
interoperability and redundant network design

TECHNICAL SKILLS
Networking D-Link (core competency): VLAN design, QinQ / 802.1ad VLAN stacking and service-provider tagging, DHCP option 82 relay and subscriber-
port identification, STP/RSTP, LACP, IGMP snooping, ACLs, port security, QoS, firmware and bulk configuration across a large switch estate •
Juniper MX • Cisco IOS / NX-OS • Huawei MA5xxx GPON OLTs • Edge-Core • FoxGate • Eltex • TP-Link • BGP (eBGP transit and IX peering,
prefix filtering, route policy, communities) • RIPE/LIR and IRR objects • TCP/IP, UDP, ICMP • GRE tunnels and tunnelled transport • PPPoE and
DHCP/IPoE subscriber access • CGNAT, IPv6 planning • FreeRADIUS (AAA) • OpenVPN • Asterisk (VoIP) • TR-069/CWMP via TP-Link Agile ACS •
DDoS mitigation (RTBH) • FTTx/GPON splicing and OTDR fault localisation
Systems GNU/Linux — Debian, Ubuntu LTS, CentOS/RHEL, Fedora, Arch, Manjaro, Gentoo • FreeBSD • Windows Server 2019 (Active Directory, Group
Policy, Remote Desktop Services and RemoteApp publishing) • cross-major-version and end-of-life migrations • source-based builds and toolchain
management
Virtualisation KVM/QEMU and Proxmox VE (core competency) • Proxmox Backup Server • Hyper-V (production host) • VMware • cross-hypervisor
workload and data migration — disk-format conversion, virtual network remapping, driver and boot reconfiguration, cutover planning and
rollback • Docker • Kubernetes
Cloud Microsoft Azure, Google Cloud Platform and AWS — VM and virtual-network provisioning, IAM, storage services and hybrid connectivity to on-
premises infrastructure • hands-on server provisioning and administration across DigitalOcean, Vultr, Akamai/Linode, UpCloud and LunaNode
(see below)
Security GNU/Linux system hardening • AppArmor • auditd • PAM policy and faillock • nftables/iptables/pf • Lynis auditing and remediation tracking • SSH
and service hardening • ACME/SSL automation • certificate lifecycle management
Storage LVM — physical/volume group management, logical volume resizing, snapshots for backup and safe upgrades, live migration of storage between
devices • RAID 0/1/5/6/10 and nested arrays, hardware vs. software trade-offs, mdadm and ZFS, controller and BBU management, hot-spare and
degraded-array recovery • enterprise server assembly, component selection, thermal and power budgeting, IPMI/iDRAC/iLO, component-level
fault isolation
Telephony Asterisk administration — SIP trunking and registration, dial plan design and call routing, extensions and IVR, codec negotiation and transcoding,
NAT traversal for SIP/RTP, CDR collection and call-quality troubleshooting; subscriber and internal corporate telephony in production
Multi-vendor Configuring the same service consistently across hardware from every major manufacturer — Juniper, Cisco, Huawei, D-Link, Edge-Core,
FoxGate, Eltex, TP-Link and MikroTik-class equipment — including QinQ VLAN stacking and DHCP option 82 on each platform, and reconciling
vendor-specific implementations of the same standards (STP variants, LACP, VLAN tagging, SNMP MIBs, LLDP) to build stable links across mixed
estates rather than standardising on one vendor
Monitoring Zabbix • Grafana • Loki • Prometheus • RRDtool (round-robin time-series collection and custom traffic graphing) • SNMP • NetFlow • centralised
syslog
ISP OSS/BSS ABillS (Perl/MySQL ISP billing platform) — administration, tariff and service logic, module customisation, RADIUS and network-equipment
integration, data migration and upgrades • Userside (administrator and daily operator) — subscriber and technical accounting, network topology
and cable documentation, equipment inventory, ticket and task workflow, switch-port mapping, SNMP integration, permissions, API automation;
billing and RADIUS integration; PHP/MySQL server maintenance
Shell Bash and POSIX shell (core competency) — production scripting and automation: parameter expansion, arrays, process substitution, traps
and signal handling, strict error handling (set -euo pipefail), here-documents, subshells, pipelines and file-descriptor redirection • text processing
with awk, sed, grep, sort, cut, xargs and find • whiptail/ncurses interactive operator tooling • cron, systemd timers and unit files • sh/dash-
portable scripting for FreeBSD and minimal container images
Programming Python • Perl 5 (production billing-platform development and maintenance) • SQL • Bash • PowerShell • PHP • Java • C++ • C • object-
oriented programming (classes, inheritance, polymorphism, encapsulation, interfaces and design patterns) • JavaScript/ES6 • TypeScript •
React • Vue.js • HTML5 and modern CSS (Flexbox, Grid, responsive) • Make • gcc • Git
Databases Relational design and normalisation • SQL across MySQL, MariaDB, PostgreSQL and SQLite • FreeRADIUS with SQL backend — subscriber
authentication, authorisation and session accounting, attribute and policy schema design, accounting-table maintenance and reporting • query
optimisation and indexing • enterprise Oracle RDBMS (academic)
Architecture CPU architecture and instruction sets, memory hierarchy and caching, I/O and bus architecture, x86-64 and ARM, compilation and linking,
kernel/user-space boundary — applied in source-based builds, toolchain tuning and low-level performance troubleshooting
Any platform Able to bring up, manage and troubleshoot any system exposing a standard management interface — CLI/SSH, serial console, SNMP, web UI,
IPMI/iDRAC/iLO or REST API — regardless of vendor or operating system
AI tooling Anthropic Claude (CLI and API) • Google Gemini • ChatGPT/Codex • Microsoft Copilot — applied daily to scripting, code review, troubleshooting
and infrastructure automation
Support L1/L2/L3 technical support • NOC incident management • client relationship management • cross-department and vendor coordination • technical
documentation and runbooks
Languages Ukrainian (native) • Russian (native) • English (Upper-Intermediate, B2) • Polish (Beginner)
PROFESSIONAL EXPERIENCE

ISP Batyevka.NET (AS39027) — Kyiv, Ukraine 2018 – 2026
Regional fixed-line broadband operator. Single-handedly operated 350+ network devices and personally served the full subscriber base of 6,000+ — covering
every tier alone, from call centre and on-site visits through NOC support to core network and systems engineering. Progressed across five roles over eight years,
from last-mile installation and subscriber-facing support to core network and systems engineering.

Network Engineer & Systems Administrator (L3) 2023 – 2026
Single-handedly operated 350+ network devices carrying service for the full base of 6,000+ subscribers, administering core routing on AS39027: Juniper MX
platforms, eBGP sessions with upstream transit providers and IX peers, prefix filtering, route policy and community-based traffic engineering
Managed RIPE/LIR records — IPv4 allocation and block transfers, route objects, IRR/whois maintenance, reverse DNS delegation, sponsoring-LIR administration
Administered Huawei MA5xxx GPON OLTs (service profiles, VLAN and service-port mapping, ONU provisioning, firmware lifecycle) and L2 aggregation across D-
Link, Cisco IOS/NX-OS, Edge-Core, FoxGate and Eltex switching (VLAN design, QinQ service tagging, DHCP option 82 relay, spanning-tree topology, LACP, IGMP
snooping, QoS)
Deployed and operated TP-Link Agile ACS for centralised TR-069/CWMP CPE management — zero-touch provisioning, remote diagnostics, bulk firmware rollout
and configuration templating across the subscriber CPE estate
Established stable interoperability across a mixed-vendor estate (Juniper, Cisco, Huawei, D-Link, Edge-Core, FoxGate, Eltex, TP-Link), implementing QinQ and
DHCP option 82 consistently on each vendor despite differing syntax and behaviour, and reconciling vendor-specific implementations of STP variants, LACP,
VLAN tagging, SNMP MIBs and LLDP; coordinated directly with manufacturers on firmware defects, feature requests, RMA and interoperability testing to build
redundant, high-availability L2 access and aggregation topologies
Migrated the subscriber access model from PPPoE to DHCP/IPoE across the network — addressing and option-82 design, RADIUS accounting rework, CPE
reconfiguration and phased subscriber cutover with parallel operation of both models during transition
Built and maintained GRE tunnels for inter-site transport, partner interconnects and management overlays
Handled CGNAT under IPv4 exhaustion, planned IPv6 rollout, and performed DDoS mitigation via RTBH/blackhole community signalling with upstream
coordination
Hardened production GNU/Linux infrastructure — AppArmor profiles, auditd rules, PAM policy and nftables/pf filtering, with Lynis auditing and remediation
tracked to closure
Planned and executed cross-hypervisor migration of production workloads from Hyper-V to KVM/QEMU — disk-format conversion, virtual network remapping,
driver and boot reconfiguration, staged cutover and rollback planning — with no unplanned service interruption
Ran containerised internal services on Docker and Kubernetes
Administered and extended the ABillS billing platform (Perl/MySQL): tariff and service logic, module customisation, RADIUS and network-equipment integration,
schema-level data work and version upgrades
Administered the company-wide Userside OSS instance: permission model, billing and FreeRADIUS integration, SNMP device polling, network topology and port-
level documentation, API-driven automation
Implemented regulatory domain-blocking obligations per NKEK and court-ordered blocklists; maintained the corporate web platform (Next.js/TypeScript)
including deployment and CI
Mentored L1/L2 staff; authored runbooks, escalation procedures and internal documentation

System Administrator (L2/L3) 2021 – 2023
Administered GNU/Linux, FreeBSD and Windows Server production systems: DNS, DHCP, web, mail and file services
Ran Windows Server 2019 as a production Hyper-V host — VM provisioning, virtual switch configuration, checkpoints, resource allocation and backup
integration
Deployed and administered Remote Desktop Services with RemoteApp publishing: application delivery to end users, session host and collection configuration,
access policy, Group Policy control, licensing and permissions
Delivered four complete hardware-generation migrations of production infrastructure — capacity planning, procurement specification, staged data and workload
transfer across hypervisor platforms, validation and cutover — each completed without service loss
Built and maintained a Proxmox VE virtualisation cluster with Proxmox Backup Server; ran scheduled restore drills
Designed and administered LVM and RAID storage across production servers — volume group and logical volume management, snapshots for safe upgrades
and backup, online resizing, array planning against workload and capacity, controller configuration, health monitoring and recovery of degraded arrays
including live disk replacement and rebuild under load
Operated FreeRADIUS AAA against a MySQL/MariaDB backend — subscriber authentication and authorisation, session accounting, policy attribute assignment,
accounting-table maintenance and usage reporting
Deployed monitoring and alerting: Zabbix, Grafana, Loki, RRDtool time-series collection with custom per-link traffic graphing, SNMP polling of OLTs, switches
and routers, centralised syslog and NetFlow collection
Compiled, configured and maintained a wide range of open-source services from source and package, tuning build options and dependencies for production
requirements
Executed cross-major-version OS migrations and end-of-life transitions across the Debian/Ubuntu and RHEL/CentOS estates, including dependency resolution,
config-format changes and staged rollback planning
Automated provisioning, bulk configuration, user management, log parsing and reporting in Python, Perl, Bash and PowerShell, with SQL-driven reporting over
subscriber and billing data; automated SSL issuance and renewal (ACME) across all production service domains
Ran the ABillS billing platform (Perl 5 / MySQL): module development and customisation, tariff and service logic, RADIUS integration, query optimisation and
schema-level maintenance
Executed full billing and CRM platform migrations — schema mapping, subscriber and financial data transfer, reconciliation and verification against live records,
and staff transition to the new system
Maintained and optimised MySQL/PostgreSQL databases and the Userside PHP/MySQL stack end to end — upgrades, schema migrations, backups and restore
testing
Administered Asterisk telephony for subscriber and internal corporate use: SIP trunking and registration, dial plan and call routing design, extensions and IVR,
codec negotiation, NAT traversal for SIP/RTP, CDR collection and call-quality troubleshooting

Technical Support Engineer, L1/L2 — NOC 2019 – 2021
Personally delivered first and second line support to the entire subscriber base of 6,000+ across phone, chat and ticketing — diagnosing and resolving every
fault myself, remotely and on site at subscriber premises
Diagnosed PPPoE/IPoE session failures, DHCP, NAT, DNS, MTU/MSS mismatches, packet loss and latency complaints
Traced subscriber sessions through RADIUS and system logs; verified ONU optical levels remotely from the OLT
Ran incident triage and subscriber communication during mass outages and planned maintenance windows
Managed the full incident lifecycle in Userside — subscriber lookup, service and equipment history, ticket workflow, field-crew task assignment and escalation
tracking
Executed billing operations (tariff changes, suspension and restoration, credits, service relocations) and authored knowledge-base articles and diagnostic scripts
that reduced repeat-issue handling time

Client Manager & L1 Call Centre Support 2018 – 2019
Handled inbound subscriber contact in a call-centre environment serving 6,000+ subscribers: fault intake, first-line diagnosis, guided CPE troubleshooting and
resolution within SLA
Managed ongoing client relationships — onboarding, tariff consultation, retention conversations, complaint resolution and escalation ownership through to
closure
Coordinated between commercial, technical and field-installation departments to schedule work and keep subscribers informed during multi-team incidents
Maintained subscriber records, contracts, service changes and communication history in the Userside CRM and billing systems
Translated technical constraints into plain language for subscribers, and subscriber symptoms into actionable detail for engineering

Installation & Field Technician 2018 – 2019
Performed FTTx/GPON last-mile installations across multi-dwelling and private-sector premises: drop cable routing, fusion splicing, connectorisation, ONT/ONU
commissioning
Localised optical faults using power meter and OTDR; worked splitters and cross-connects in distribution cabinets
Built and terminated twisted-pair LAN runs; mounted and cabled switches across a distribution network of 350+ building nodes; provisioned CPE and tuned Wi-
Fi channel plans in dense RF environments
Built, commissioned and diagnosed server and workstation hardware — component selection and compatibility, assembly, RAID configuration, BIOS/firmware
setup, burn-in testing and component-level fault isolation
Responded to emergency callouts after storms, power failures and cable damage, including night shifts
Registered installations in Userside — equipment serials, port assignments, cable routes and node documentation

SELECTED TECHNICAL PROJECTS
ABillS billing platform ownership — Took operational and development ownership of the ABillS ISP billing system (Perl 5 / MySQL) for a 6,000+ subscriber
base: tariff and service logic, module customisation, RADIUS and network-equipment integration, reporting queries, schema maintenance and version upgrades.
Extended it to fit operational requirements rather than working around its defaults.
Cross-hypervisor and hardware-generation migrations — Delivered four full hardware migrations and repeated virtualisation platform moves (Hyper-V →
KVM/QEMU, VMware, Proxmox VE): disk-format conversion, virtual network remapping, driver and boot reconfiguration, LVM storage transfer, staged cutover with
rollback planning. Every migration completed without unplanned subscriber-facing downtime.
Operator network labs — Extensive hands-on lab work replicating carrier and enterprise topologies before production rollout: BGP peering and route-policy
scenarios, PPPoE and DHCP/IPoE access models, GRE tunnelling, VLAN and spanning-tree designs, LACP aggregation, RADIUS authentication chains, and QinQ and
DHCP option 82 configurations, and multi-vendor interoperability testing across Juniper, Cisco, Huawei, D-Link, Edge-Core, FoxGate and Eltex equipment. Every
significant network change was proven in lab before it touched subscribers.
RRDtool network graphing — Built round-robin time-series collection and custom per-link traffic graphing for network capacity monitoring and subscriber
troubleshooting.
Gentoo source-based system administration — Maintained Gentoo systems built entirely from source: Portage USE-flag dependency management, custom
CFLAGS optimisation, kernel configuration and toolchain upgrades. The work that most sharpened my understanding of how a GNU/Linux system fits together, and
it changed how I debug every other distribution.
Arch Linux — Long-term daily-driver experience with rolling-release maintenance and manual intervention on upgrades. Reference point for high-quality technical
documentation; the Arch Wiki set the standard I write my own runbooks against.
Network automation tooling — Custom scripts for network monitoring, bulk device configuration, user management and automated bandwidth shaping for VPN
clients.
ISP web platform (newsite.batyevka.net) — Next.js/TypeScript subscriber-facing site: tariff pages, TV subscription ordering flow, build and deployment
pipeline, collaborative Git workflow with an external developer.

EDUCATION

Polish-Japanese Academy of Information Technology (PJATK) — Warsaw, Poland 2016 – 2018
Computer Science, undergraduate — two semesters completed
One of Poland's leading specialist computer science institutions; studied abroad in an international, English-language programme. Core coursework: computer
architecture and organisation, algorithms and data structures, operating systems, computer networks, procedural and object-oriented programming in Java
and C++ — class design, inheritance and polymorphism, encapsulation, interfaces and standard design patterns — software engineering, and database systems
— relational theory, normalisation and schema design with practical work on enterprise Oracle RDBMS.
FoxMinded Academy (foxminded.ua) — Web Frontend Development 2022
HTML5, modern CSS (Flexbox, Grid, responsive layout), JavaScript and contemporary design principles

CERTIFICATIONS & TRAINING

Cisco Networking Academy — SEDICOMM University (authorised Cisco partner) 2019
Cisco Certified Network Associate (CCNA) — Routing & Switching (proctored paid examination)
Interconnecting Cisco Networking Devices (ICND) (proctored paid examination)
Introduction to Cybersecurity
Introduction to the Internet of Things (IoT) • Introduction to the Internet of Everything (IoE)
Continuing professional development — daily follower of the academy's technical channel Cisco Ne Slabo / SEDICOMM TV (youtube.com/@cisconeslabo):
ongoing self-study in networking, GNU/Linux administration and cybersecurity since completing the certification track

LPIC-2 — Linux Engineer, Linux Professional Institute

COMMUNITY & OPEN SOURCE
FreeBSD Forums — active member since 2020
GitHub — github.com/blindone0
Long-standing user and contributor within the open-source ecosystem; strong preference for open tooling in production infrastructure

CLOUD & HOSTING PLATFORMS
Hands-on provisioning and administration of production and test servers across multiple IaaS and VPS platforms — instance deployment and sizing, image and
snapshot management, block storage and volumes, private networking and floating IPs, firewall and security-group rules, DNS, SSH key and access management,
backups and monitoring, cost control across providers:
DigitalOcean • Vultr • Akamai Connected Cloud (Linode) • Google Cloud Platform • UpCloud • LunaNode

Схожі кандидати

Усі схожі кандидати


Порівняйте свої вимоги та зарплату з вакансіями інших підприємств: