Skip to content
gen0ne@zrh:~

$ whoami

Nicolás Damián Sadofschi

Senior Firewall Engineer @ SIX · Zurich

✓ Master in Offensive Security ✓ OSCP ✓ OSCP+

I run firewalls and remote access for Swiss financial infrastructure. Off the clock I hold the OSCP and build my own servers and tools until they work.

  • 20+

    years in IT

  • OSCP

    passed Jan 2026

  • 17

    projects built

  • 4

    languages spoken

§ 01 / about

Twenty years of keeping other people’s systems up. Now I also know how they fall.

Infrastructure taught me how things are meant to work. Offensive security taught me how they actually fail. After twenty years of building and running other people’s platforms I did a master’s in offensive security and passed the OSCP, and now I use both sides every day: I build like someone who knows how it gets broken.

By day that means firewalls at SIX, and before that four years engineering remote access at Julius Baer and almost seven at NTT, where I ended up as the last line of escalation for managed hosting customers.

At home I run a small fleet for real: a hardened VPS, a Raspberry Pi, a site-to-site VPN, Zero Trust access and a pile of services I built myself. I do not hand-write much code any more: I work with AI coding agents, where my part is the design, the review of every change and knowing when to say no. If it is on this page, it is running somewhere.

$ history | head · how it started

  1. 01 · 6th grade

    First website

    Built with FrontPage 97. The follow-up was a Simpsons fan site on free hosting, with a three-level quiz that kept stats and a JavaScript cookie that remembered your name and greeted you with it.

  2. 02 · 6th–7th grade

    First “hacks”

    Sent the Sub7 and PC Invader backdoors to classmates over ICQ. “Hacking”, in very large quotation marks, but it was the first time a machine did what I wanted from somewhere else.

  3. 03 · Early 2000s

    IRC and the easy bugs

    Fell into IRC groups and learned from the Unicode traversal bug and the Code Red era that most of the internet was held together with defaults.

  4. 04 · Teens

    Counter-Strike taught me Linux

    Running game servers meant learning Linux, Apache, IIS and SQL without noticing I was studying.

  5. 05 · 2004

    Cyber-cafés

    My first unofficial job: crimping network cables and setting up every machine in the room. The official career starts right after.

§ 02 / experience

Experience

From a repair bench to the firewalls of Swiss financial infrastructure.

  1. Apr 2026 – Present

    Senior Firewall Engineer · SIX

    Zurich

    Firewall engineering for the company that operates Swiss financial market infrastructure.

    • Working on bringing a Model Context Protocol server for Palo Alto firewalls into the team’s tooling.
    • Palo Alto
    • MCP
  2. May 2022 – Mar 2026

    Security Engineer · Julius Baer

    Zurich

    Operations and engineering for remote access at a Swiss private bank.

    • Improved how tickets flow between the helpdesk and engineering, and ran training and mentoring sessions for the helpdesk every six months.
    • Tightened day-to-day operations of the remote access platform.
    • Onboarded two engineers and took them from zero to fully autonomous.
  3. Aug 2021 – May 2022

    Senior Infrastructure Engineer · SYNLAB International

    Barcelona

    Infrastructure engineering for an international medical diagnostics group.

    • Planned and delivered a datacenter migration from Madrid to Germany, including the network architecture.
    • Kept the original subnets, as required, and scripted traffic analysis to work out which firewall rules the new site needed.
    • Moved the databases with SnapMirror, with no data loss.
    • Network design
    • SnapMirror
    • Traffic analysis
  4. Sep 2019 – Aug 2021

    Solutions Engineer Tier 3 & Deputy Team Lead · NTT Ltd.

    Barcelona

    Last level of escalation for NTT cloud and managed hosting customers, plus installation and QA.

    • Owned customer platforms end to end, from deployment to support, inside agreed SLAs.
    • Built and ran networking, Linux and Windows servers, virtualization, load balancing, firewalls and storage.
    • On-call engineer for maintenance windows and customer projects; deputy lead of the team.
  5. Aug 2017 – Sep 2019

    Service Desk Engineer · NTT Ltd.

    Barcelona

    Escalation point for complex incidents on managed infrastructure; trained and mentored the team.

    • Supported managed hosting for customers such as Decathlon, Canon, Emirates, Etihad, Aviva and Nomura.
    • Led internal and customer-facing projects as one of the most technical members of the desk.
    • FortiGate
    • Juniper
    • Cisco
    • NetScaler
    • Alteon
    • VMware
    • NetApp
  6. Dec 2014 – Aug 2017

    Senior Infrastructure Analyst · NTT Ltd.

    Barcelona

    Networks, firewalls, VPN, storage, load balancing and servers for customer solutions.

    • Resolved incidents and problems and planned production changes, often out of hours.
    • Configured FortiGate firewalls through FortiManager and the CLI.
  7. 2004 – 2014

    Support, freelance and a company of my own · Earlier years

    Catalonia

    Ten years of hands-on IT before the datacenter.

    • Second-level support for Meliá Hotels at Digitex: Active Directory, Exchange, Citrix, VMware.
    • Freelance consultant for small businesses: networks, servers, hosting and websites.
    • Managing partner of Verynice Europa, a company that built, sold and rented ice rinks.
    • Repair bench, field support and a cyber-café, where it all started.

Education

  • 2024 – 2025

    Master’s Degree in Offensive Security

    UCAM, Universidad Católica San Antonio de Murcia

  • 2005 – 2007

    Network Systems Administration

    IES Lacetània, Manresa

§ 03 / credentials

Certifications & skills

  • UCAM

    Master’s Degree in Offensive Security

    Universidad Católica San Antonio de Murcia. A full year of offensive security, built around the OSCP syllabus.

    2024 – 2025

  • OffSec

    OSCP

    OffSec Certified Professional. A 24-hour, hands-on penetration test followed by a written report.

    January 2026

    Verify OSCP
  • OffSec

    OSCP+

    The renewable edition of the OSCP, earned in the same exam.

    January 2026 · valid until January 2029

    Verify OSCP+
Also earned
CredentialIssuerHeld
VMware Certified Professional, Data Center Virtualization 2020VMware2020 – 2022
VMware Certified Professional 6, Data Center VirtualizationVMware2017 – 2019
NSE 7 Network Security ArchitectFortinet2020 – 2022
Network Security Expert 4 (FortiOS 5.4)Fortinet2018 – 2020
Citrix Certified Associate, Networking (CCA-N)Citrix2019 – 2022
ITIL FoundationsITIL—
CyberOps AssociateCisco2022
English CEFR C1 (Aptis ESOL)British Council2025

Skills

Network security

  • Firewall engineering
  • Remote access & VPN
  • IPsec / IKEv2
  • WireGuard
  • Zero Trust access
  • Load balancing

Offensive security

  • Penetration testing
  • Active Directory
  • Privilege escalation
  • Web applications
  • Reporting

Infrastructure

  • Linux
  • Windows Server
  • VMware
  • Storage
  • DNS
  • Hardening
  • Backup & recovery

Building with AI

  • AI coding agents
  • Specs, review and rollback
  • MCP servers
  • OAuth 2.0
  • LLM tooling
  • Bash

Operations

  • Prometheus
  • Grafana
  • systemd
  • nginx
  • Docker
  • Incident analysis

§ 04 / projects

Things I built, and still run

Built for real use, on hardware I pay for and patch. Internal details stay internal; the design is what I can show.

Running today

  • security

    Remote MCP server with its own OAuth 2.0

    A Model Context Protocol server that lets an AI assistant query private data. It has its own authorization server instead of a borrowed one: dynamic client registration, PKCE, redirect allow-list and lockouts, then hardened it after an audit.

    • Python
    • FastAPI
    • OAuth 2.0
    • PKCE
    • Zero Trust tunnel
  • security

    Site-to-site VPN that heals itself

    An IPsec IKEv2 tunnel between home and a VPS, working behind double NAT and a dynamic address. Watchdogs detect a dead tunnel, tell ingress from egress failures and bring it back, with a kill switch so nothing leaks meanwhile.

    • IPsec
    • IKEv2
    • WireGuard
    • Firewalling
    • Bash
  • security

    Daily security review, run by an LLM analyst

    Every day a headless agent reads logs, port diffs and access events from my servers, triages them like a junior analyst would and only pages me when it is serious. Read-only by design.

    • Python
    • LLM agents
    • systemd timers
    • Telegram
  • platform

    gen0ne: a personal data platform on a 1 GB server

    Wearables, training, nutrition and calendar pulled into one API and dashboard, with alerting and an AI layer for logging by text, voice or photo. About ten integrations, no Docker, VPN-only by default.

    • FastAPI
    • SQLite
    • React
    • APScheduler
    • nginx
  • infrastructure

    Home lab with Zero Trust access

    A Raspberry Pi and a NAS that behave like a small datacenter: identity-gated access with short-lived SSH certificates, redundant DNS filtering, Prometheus and Grafana for every host, three tiers of backup and fault-injection tests that I actually run.

    • Raspberry Pi
    • Cloudflare Tunnel
    • Prometheus
    • Grafana
    • Docker
  • tool

    Telegram ChatOps bot

    One chat to run the fleet: wake or hibernate a PC, check servers, approve updates. Each integration gets its own forced-command SSH key limited to an allow-list of verbs, and anything that writes waits for my confirmation.

    • Python
    • Telegram Bot API
    • SSH forced commands
    • Whisper

Also built

  • infrastructure

    Rebuild-the-server kit

    Scripts and a runbook that recreate a whole VPS from Git: services, firewall, users and GPG-encrypted secrets, backed by layered off-site backups with integrity checks.

    • Bash
    • Git
    • GPG
    • rclone
  • security

    VPS hardening and self-audits

    Default-drop firewall, key-only SSH, fail2ban, sandboxed non-root services with memory caps, and periodic audits of my own perimeter with tracked remediation.

    • Debian
    • systemd
    • fail2ban
    • nginx
  • app

    Trip planner: offline-first PWA, bot and MCP

    A planning app that keeps working with no signal, with a Telegram bot and an OAuth-protected MCP server on top. Around 540 tests and a full staging clone with a simulated clock to rehearse days in advance.

    • Python
    • PWA
    • OAuth 2.0
    • Playwright
  • security

    Travel VPN hotspot

    A Raspberry Pi that turns any hotel network into my own: every client is forced through a WireGuard tunnel, with a kill switch checked against DNS and IPv6 leaks.

    • Raspberry Pi
    • WireGuard
    • NetworkManager
  • tool

    claudetrack-tray

    A Windows tray app for Claude Code that keeps session usage in view at all times and, more importantly, resumes sessions by itself when the limits reset. Credentials live in the OS keystore; 129 tests and ten languages.

    Inspired by a browser extension my brother wrote. I built the desktop version and gave it to him; it lives on as UsagePeek.

    • Rust
    • Tauri 2
    • TypeScript
    usagepeek.com
  • app

    AI wardrobe with virtual try-on

    An open-source closet app extended with try-on image generation. It runs on a gaming PC that only wakes when someone asks for it.

    Built on the open-source wardrowbe project.

    • Docker
    • Wake-on-demand
    • Image generation
  • app

    Kery

    A mobile app with an LLM at its core, built with prompt-injection rules and owner-only data access from day one. Paused, not abandoned.

    • Flutter
    • Firebase
    • Gemini
  • app

    A routine tracker for kids

    A small PWA with rewards and a parent approval loop over Telegram, plus a reproducible pipeline for its clay-style artwork.

    • FastAPI
    • PWA
    • Telegram
  • tool

    OSCP Obsidian Tracker

    The templates, dashboard and methodology I used to prepare the OSCP, packaged as an Obsidian vault.

    • Obsidian
    • Dataview
    • Markdown
    GitHub
  • tool

    Tunneleitor

    A Bash script that creates and manages forward and reverse SSH tunnels: port checks, PID tracking, logs and a report of what is up.

    • Bash
    • SSH
    GitHub
  • web

    Afectados MOVES III

    A campaign website for people affected by delays in a public subsidy programme.

    • HTML
    • GitHub Pages
    Website

§ 05 / beyond

Beyond work

Away from the keyboard I am usually moving. I live in Zurich with my partner and our young son, and most weekends end up on a mountain or in a lake.

  • Two wheels

    Motorbikes and mountain bikes. One has an engine, both go downhill faster than they should.

  • Sport

    Gym, swimming, hiking. I train most days and I am not picky about how.

  • On the water

    Licensed for motorboats and jet skis. The entry-level licence, but it floats.

  • Music

    Always something playing while I work.

  • Family

    Playing with my son is the best part of the day. Half of what I build at home is for the three of us.

  • Tinkering

    Raspberry Pis, fan controllers, anything with a serial port. If it can be automated, it will be.

§ 06 / contact

Get in touch

For work, a second opinion on a design, or to tell me something on this page is wrong.

$ cat info.py

# contact details

nick = 'gen0ne'

email = 'contacto' + '@' +'nicodamian.com'

linkedin = 'https://www.linkedin.com/in/nicolas-damian-sadofschi/'

github = 'https://github.com/nicolasdamians'

print(email)

contacto [at] nicodamian [dot] com