mrdtech

Michael Dziegiel

Senior Network & Systems Administrator | Cloud, Security & Automation

Senior Network & Systems Administrator with 20+ years of experience managing, securing, and maintaining enterprise infrastructure. Skilled in hybrid AD/Entra ID, Intune/Autopilot, Meraki/UniFi/pfSense, virtualization, and cloud security. Known for automation, troubleshooting, and securing critical systems.

Michael Dziegiel

Projects

Enterprise achievements and homelab builds.

Enterprise & Automation

AD & M365 Onboarding Automation

WPF-based PowerShell GUI automating AD and Microsoft 365 user onboarding — account creation, license assignment, and manager mapping.

SCCM to Intune & Autopilot Migration

Enterprise migration from SCCM to Intune with Autopilot provisioning, Entra ID modernization, and zero-touch deployment.

ConnectWise RMM & Helpdesk Buildout

End-to-end RMM and helpdesk implementation — PSA, patch management, endpoint management, Auvik network monitoring, ScreenConnect, and BrightGauge dashboards.

Enterprise Infrastructure Management

End-to-end ownership of a hybrid enterprise environment — pfSense, UniFi, Hyper-V, Ubuntu servers, Microsoft 365, Exchange Online, Entra ID, Intune, VLANs, VPN, and DNS/DHCP across the full stack.

Homelab & Infrastructure

NOC Dashboard

Self-hosted Network Operations Center dashboard with real-time visibility into Proxmox VMs, Docker containers, UPS status, backup coverage, security posture, and certificate expiry. Multi-user auth, TOTP 2FA, FastAPI + React.

SIEM + CrowdSec Detection

Wazuh SIEM custom detection rules and CrowdSec bouncer configs across a multi-host homelab, with OpenCanary honeypot integration.

Wazuh CrowdSec Security

Prometheus + Grafana Alerting (n8n)

Self-hosted homelab observability — Prometheus + Grafana + node_exporter + cAdvisor across multiple Docker hosts, with alerting via n8n polling the Prometheus API into Telegram (no Alertmanager required).

Prometheus Grafana n8n

UniFi VLAN Segmentation & Firewalls

Zone-based rules, IoT isolation, DNS control, and hardened routing.

AI, Automation & Integrations

Vault RAG Pipeline

Self-hosted RAG pipeline for an AI homelab agent — semantic search over an Obsidian vault with automated secrets/IP redaction before embedding, Qdrant + Ollama (nomic-embed-text) + gitleaks.

Qdrant Ollama RAG Python

Multi-Server MCP Gateway

Hardened, read-only MCP gateway exposing Portainer, GitHub, Filesystem, Proxmox, PBS, and Vault RAG visibility to an AI agent — loopback-only, SSH-tunneled, zero client-side credentials.

MCP Docker Security Python

n8n Self-Healing Infrastructure

Automated VM/container recovery, backup-failure alerting, and SIEM event routing to Telegram.

n8n Proxmox CrowdSec

Obsidian Vault Setup

Personal knowledge base built on Obsidian, structured as long-term memory for a self-hosted AI agent — RAG-indexed, auto-logged, secrets-redacted before embedding.

Obsidian Knowledge Base

Experience

Systems Administrator — Jeanne D'Arc Credit Union

July 2026 – Present

  • Administer hybrid enterprise infrastructure spanning on-premises and cloud environments, ensuring high availability, security, and performance across critical business systems.
  • Manage Windows Server and Linux environments, including Active Directory and Group Policy administration for enterprise-wide identity and access control.
  • Administer VMware virtualization infrastructure supporting core business applications and services.
  • Maintain enterprise networking infrastructure including VPNs, firewalls, switches, and wireless systems across the organization.
  • Monitor network performance and troubleshoot complex infrastructure issues, implementing improvements to increase reliability and operational efficiency.
  • Lead infrastructure projects, system upgrades, and business continuity initiatives, maintaining detailed technical documentation throughout.
  • Automate administrative tasks using PowerShell to streamline operations and reduce manual overhead.
  • Provide Tier 3 support for critical systems and collaborate with vendors and cross-functional teams, participating in an on-call rotation.

Senior Network Administrator — Hans Kissle

Feb 2025 – Apr 2026 · Haverhill, MA

  • Own end-to-end hybrid infrastructure — pfSense firewalls, UniFi switching/wireless, Hyper-V, Ubuntu Server, and full Microsoft 365 stack.
  • Migrated endpoint management from SCCM to Intune with zero-touch Autopilot provisioning and Entra ID-only device identity.
  • Administered Entra ID, Conditional Access, MFA, and AD Connect sync across a hybrid identity environment.
  • Automated user provisioning, licensing, and compliance reporting via PowerShell, Power Automate, and Microsoft Graph API.
  • Onboarded ConnectWise RMM, PSA, ScreenConnect, Auvik, and BrightGauge — building the helpdesk infrastructure from scratch.
  • Managed co-managed SCCM/MECM and Intune environment for imaging, application packaging, and policy enforcement.
  • Administered Apple Business Manager integration and Autopilot provisioning for Windows 365 Cloud PCs and mobile endpoints.
  • Monitored and improved infrastructure performance through proactive troubleshooting, upgrades, and project execution aligned with business goals.

Systems Analyst — Skyterra

Sep 2021 – Feb 2025 · Nashua, NH

  • Managed Intune, Azure, MFA, and Autopilot provisioning.
  • Delivered AD/GPO administration, packaging, and PowerShell automation.
  • Strengthened physical and digital security via conditional access, PIN-based access, and FOB/camera system management.
  • Designed and implemented Intune configuration policies to enforce security measures, including application blocking, browser restrictions, and long-path support.
  • Led software packaging and deployment via Intune for Zscaler, CrowdStrike, Keeper, and custom RMM tooling.
  • Deployed Microsoft LAPS tenant-wide for credential management and audit improvement.
  • Administered Mimecast and Cisco Umbrella for email and DNS-layer threat protection.
  • Delivered Tier 2/3 support across Azure, Intune, MFA, Office 365, Teams, SharePoint, and OneDrive.

Network Technician — GID

Apr 2011 – Aug 2021 · Boston, MA

  • Supported Cisco/Meraki networks for VPN, Wi-Fi, and VoIP.
  • Supported Meraki hardware models across switching, wireless, and security appliance deployments.
  • Performed Active Directory administration for users, groups, workstations, permissions, and policy support.
  • Built Windows images, kiosk systems, and kiosk GPO configurations for controlled-use endpoints.
  • Provided Tier 2/3 support and remote site installations.
  • Monitored Meraki networks for outages and performance issues.
  • Coordinated VeraCrypt encryption and tablet rollout efforts for secure field endpoint deployments.
  • Managed IT asset inventory and procurement, tracking hardware lifecycle from acquisition through deployment and retirement across multiple properties.

Skills & Stack

Platforms

Windows Server, Azure, Entra ID, Intune, Autopilot, Active Directory / Group Policy, Windows 365 Cloud PCs, Apple Business Manager, Exchange Online, SharePoint, Teams, VMware, Hyper-V, Proxmox, pfSense, UniFi, Linux

Networking & Security

Routing, Switching, VPN, VLANs, DNS/DHCP, Meraki, MFA, Conditional Access, Intune Compliance & Configuration Policies, LAPS, BitLocker, IDS/IPS, Firewall/WAF Management, Network Segmentation, Wireless, Zero Trust (Cloudflare Access/Tunnel), DNS Filtering, Wazuh, CrowdSec, LimaCharlie, Cloudflare

Tools & Tech

Sophos, Proofpoint, ConnectWise RMM, ConnectWise Manage, Auvik, ScreenConnect, Cisco Umbrella, CrowdStrike, Mimecast, Veeam, ManageEngine, PowerShell, Power Automate, Microsoft Graph API, Git, Docker, KnowBe4, Portainer, GitHub

Automation & Monitoring

AI Agents, MCP, RAG, n8n, Telegram Alerting, Grafana, Prometheus, Automated Alerting, Self-Healing Workflows

Get in touch

Best reached via email.