Marcos Almaguer

Infrastructure & Application Support Engineer

About Me

I’m an Application Support Engineer with experience supporting enterprise web and server based applications in regulated financial environments. My background includes troubleshooting complex multi tier issues across IIS, networking, databases, and mainframe connected systems using log analysis, SQL, and monitoring tools. I’ve worked extensively with proprietary Fiserv platforms to maintain system stability, improve reliability, and resolve high impact production incidents. Outside of work, I run a personal homelab where I build and manage self hosted services, containerized applications, multi terabyte storage arrays, and segmented networks. It’s become both a learning experience and a passion project that lets me explore infrastructure, automation, networking, and security in a hands on environment. I enjoy building reliable systems and services, solving difficult technical problems, and continuously expanding my knowledge across IT and cybersecurity. I currently hold the Google IT Support and CompTIA Network+ certifications and am working toward earning my CompTIA Security+.

Skills

Systems

Networking

Security

Tools

Certifications

Google IT

Google IT Support

Network+

CompTIA Network+

Verification Code: b4085dc1494146e7aee3d5bce67a7514

CompTIA Security+

In Progress

Projects

Self Hosted Media & Application Server (Unraid)

I designed, built, and actively maintain a centralized self hosted server using Unraid, running a variety of containerized services like Plex, Nextcloud, Immich, SearXNG, BookStack, and NGINX, backed by MariaDB and PostgreSQL. It’s set up as a personal homelab that supports multiple users (including friends and family) with a strong focus on reliability, performance, and secure access both locally and over VPN.

Core Services

Plex
Nextcloud
Immich
SearXNG
BookStack
MariaDB / PostgreSQL
NGINX

Storage & Performance

  • 18TB (and counting) across multiple HDDs
  • NVMe cache for improved performance
  • Parity protection for data integrity

Implementation

  • Docker based services
  • Database backends configured
  • Reverse proxy routing
  • Networking & ports managed
  • Monitoring

Impact

  • Reduced reliance on paid services by self hosting
  • Supports multiple active users, including friends and family
  • Production like experience
  • Self Sufficiency & Continuous Learning

Self Hosted Web Server (Ubuntu Server)

I built and maintain a Linux based web server (Ubuntu Server) to host this portfolio, using NGINX to handle routing and delivery. I set it up for secure public access with Cloudflare and a custom domain, handling HTTPS, DNS, and traffic management to keep things fast, reliable, and protected. Along the way, I’ve gained hands on experience with web hosting and what it takes to run a site on the public internet.

Core Services

Ubuntu Server
NGINX
Web Hosting
Cloudflare

Configuration

  • Deployed and configured Ubuntu Server
  • Set up NGINX for web hosting and reverse proxying
  • SSD + HDD separation

Implementation

  • Deployed and host a personal portfolio website
  • Configured DNS and routing for external access
  • Planned and implemented secure exposure to the public internet

Impact

  • Built and maintain a public facing server
  • Gained hands-on experience managing Linux servers
  • Developed a strong understanding of web hosting fundamentals

Network Segmentation & Security

Designed and built a segmented homelab network using VLANs with firewall policies configured in TP-Link Omada to ensure traffic isolation and enhance device security. Deployed a self hosted DNS server (Pi-hole) across all VLANs for centralized traffic filtering and control. Configured VPN access with VLAN specific routing to provide secure, role based remote access to designated network segment.

Core Components

Router
Managed Switch
Access Point
Firewall

Architecture

  • VLAN based network segmentation
  • SSID to VLAN mapping
  • DMZ network design

Implementation

  • Firewall rule configuration
  • Traffic isolation
  • Inter VLAN routing

Impact

  • Enhanced network security
  • Improved network visibility
  • Hands on experience in network design and administration

DNS Filtering & Secure Remote Access

Built a centralized DNS filtering and ad blocking server on a Raspberry Pi 5, running Pi-hole to enhance network security, visibility, and traffic control. Deployed PiVPN on the same host to enable secure remote access with VLAN based access controls.

Core Components

Raspberry Pi
Pi-hole
PiVPN

DNS

  • Centralized DNS management
  • Ad & Tracker blocking (Pi-Hole)

VPN

  • Secure remote access
  • Restricted VLAN routing

Impact

  • Reduced malicious & unwanted traffic
  • Improved network security & remote connectivity

Home Automation Platform (Home Assistant)

Built a centralized smart home system using Home Assistant to control and monitor devices including lighting, thermostats, and cameras. Utilized Zigbee for device connectivity, reducing reliance on Wi-Fi and Bluetooth. Eliminated dependence on cloud based platforms such as Google Home and Amazon Alexa, allowing local control, enhanced privacy, and improved security.

Core Components

Home Assistant
Smart Devices
Cameras

Devices

  • Smart lights, switches, and thermostat integration
  • Local camera feed

Automation

  • Temperature based workflows
  • Custom trigger based automations

Impact

  • Fully local control (no cloud)
  • Improved efficiency & automation reliability