Antonín Ečer, DiS. Senior Infrastructure Specialist
Operational Impact Snapshot
Professional Philosophy & Values
Tech, People & Processes
Over 30 years in IT, I have worked across all levels from user support to IT management. Having led developers, sysadmins, and helpdesk teams, I understand not only the technical details but also the human dynamics and the necessity of smooth communication.
Pragmatic Frameworks
I do not view ITIL 4, TOGAF, or PRINCE2 certifications as trophies to hang on a wall. I use them as practical toolsets to bring order, auditability, and predictability to real-world operations and change management.
Calmness & Context
I bring operational calm, deep contextual knowledge, and the ability to solve crisis situations with a cool head. I believe in continuous process improvement and that well-designed automation and monitoring eliminate daily fire-fighting.
The Coding Sysadmin
I have coded all my life (Bash, PHP, Python, SQL, Java). My natural mindset is to build and automate - if no suitable tool exists for an operational task, or if it is overengineered, I prefer to design and code my own solution (e.g., PatchMonitor).
Professional Timeline
Fio banka a.s. Banking / Financial Services
April 2026 – presentSenior Infrastructure Specialist - OSSS / Network Security
- Ensuring secure and stable banking operations in compliance with strict governance and audit standards.
- Integrating and monitoring 720+ critical wireless components into the central monitoring system.
- Setting up efficient processes for managing and developing monitoring infrastructures.
- Designing and implementing high-availability monitoring (Zabbix HA) built on Rocky Linux.
- Automating deployment and management of monitoring agents and configurations using Ansible.
- Integrating and monitoring critical network components (720+ components) and managing alert rules.
- Creating audit-ready operational standards and preparing reporting deliverables.
Komerční banka a.s. Banking / Financial Services
August 2021 – December 2025Senior Linux / Infrastructure Engineer
- Co-responsible for operations, automation, and compliance of a fleet of 7,000+ Linux servers.
- Created the internal tool PatchMonitor for patch tracking, DR validation, and management reporting.
- Significantly shortened patch cycles and reduced operational risks by introducing automated orchestrations.
- Managing and patching 7,000+ Linux servers (RHEL, Oracle Linux, CentOS, Ubuntu, Debian).
- Orchestrating patch compliance and repository lifecycles using Ansible, AWX, Foreman, and Katello.
- Creating and optimizing dynamic inventories in Ansible AWX for scalable task execution.
- Developing the PatchMonitor system (PHP, Python, SQL) - patch status visualization, DR check logging, management reporting.
- Hardening operating systems, preparing compliance audit materials, and implementing remediation steps.
Apollo Software s.r.o. Regulated Online Gaming
February 2021 – August 2021Infrastructure Transformation Consultant
- Crisis management and infrastructure transformation for rapid stabilization of critical services.
- Virtualization consolidation and unification of IP address space across datacenters.
- Introducing standardized operational processes and centralized access control.
- Audit and redesign of virtualization clusters built on Proxmox VE.
- Implementing FreeIPA for centralized identity and access management (LDAP).
- Restructuring IP address space across multiple geographically separated datacenters.
- Replacing unmanaged and unstable legacy VPN architecture with secure, segmented connectivity.
Digiteq Automotive s.r.o. / Volkswagen Group Automotive / Software Development
June 2018 – January 2021IT Systems Specialist / Infrastructure Architect (Acting LISO & Deputy CISO)
- Design and management of IT infrastructure supporting safety-critical software development for VW Group.
- Responsible for information security as local LISO and Deputy CISO.
- Implementing access control standards, VLAN segmentation, and audit trail enforcement.
- Managing a heterogeneous environment of Linux (RHEL, CentOS) and Windows Server.
- Virtualization on VMware ESXi and Microsoft Hyper-V platforms.
- Configuring Cisco and FortiGate network devices, VLAN segmentation, LACP, and trunking.
- Backup and disaster recovery using Veeam Backup & Replication.
- Managing and integrating developer tools (GitLab, Jira, Confluence) and AD/DNS directory services.
- Implementing security audit controls and system hardening according to VW Group standards.
LibraHospitality s.r.o. / OREA HOTELS s.r.o. Hospitality / Multi-site IT Operations
March 2004 – May 2018IT Manager / Regional IT Manager / IT Specialist
- Managing IT infrastructure for headquarters and 20+ hotel locations in the Czech Republic.
- Leading the internal helpdesk and coordinating regional IT administrators.
- Vendor management, SLA negotiations, and efficient IT budget control.
- Full management of servers and networks for 20+ geographically separated hotel locations.
- Virtualization and consolidation of physical hardware on the VMware ESXi platform.
- Integration and maintenance of property management systems (Epitome / Opera PMS) and interfaces.
- Implementing backup and disaster recovery standards across branches.
- Managing and executing hotel system migrations and deployments in the CEE region.
Earlier Career / Začátky kariéry Telecommunications, Logistics, IT Services
1993 – 2004IT Specialist / Network Administrator / Systems Technician
- Gaining a broad foundation in IT support, network administration, and database maintenance.
- Technical support for national GSM network rollouts and monitoring logistics systems.
- Positions at Ericsson s.r.o., AAA Auto a.s., and Czech Post.
- Network administration on Novell NetWare and early Windows Server platforms.
- Supporting the GSM 1800 network rollout in the Czech Republic for Ericsson.
- Maintenance of automated mail-sorting technologies and SQL databases at Czech Post.
- Developing internal utilities and scripts (Pascal, PHP, Bash) to automate recurring tasks.
Technical Competencies
Operating Systems
Automation & Version Control
Monitoring & Observability
Virtualization & Cloud
Networking & Security
Scripting & Databases
Key Projects & Presentations
PatchMonitor
An internal enterprise system for managing massive server infrastructure patching in a banking environment. Provides transparent reporting for management, patch compliance monitoring, DR checks, and integration with AWX orchestrations. Reduced operational cycles from weeks to hours.
Ansible Inventory Studio
A utility for visualizing, auditing, and managing complex Ansible inventories. Displays logical relationships between groups, variable inheritance (group_vars, host_vars), and prevents incidents caused by unintentional overrides in large environments.
Zabbix HA Monitoring
Design and implementation of a robust, high-availability monitoring cluster on Rocky Linux. Provides centralized supervision over 120+ critical network components in a high-security banking environment with integrated alerting and reporting.
Linux Security – The Illusion of Safety
A practical presentation on Linux infrastructure operational security: segmentation, IoT risks, lateral movement, patch management, hardening, and disaster recovery. Real-world operations perspective rather than abstract theory.
LM Helper (Offline RAG)
A diagnostic assistant leveraging local LLMs and RAG search over operational and technical documentation. Enables rapid lookup and troubleshooting within a closed environment, preventing any data leaks of logs or configs outside the corporate network.
Quantum Random API
Experimental HTTP service providing high-quality cryptographic randomness. The architecture is ready for future integration with specialized (quantum) hardware.
AWS hands-on (foundation)
Hands-on training focusing on compute, networking, storage, IAM, monitoring, and security. Includes real-world tasks and deployments; practical understanding of basic cloud building blocks.
Homelab Architecture
A private test and development infrastructure running on a 3-node Proxmox VE cluster. Features a virtualized router, network segmentation via VLANs, containers for various services, monitoring, and secure site-to-site/OCI connectivity via Tailscale VPN.
Education & Certifications
Higher Professional School – Institute of Informatics
2008 – 2012Focused on Linux, SQL (Oracle, MySQL), Java, and networking.
J. A. Komenský University
2003 – 2004- TOGAF 9 Certified (Level 1 & 2)
- ITIL 4 Foundation
- PRINCE2 Foundation
- AWS Cloud Quest: Cloud Practitioner
- AWS Fundamentals
- Kubernetes Fundamentals (course)
- Oracle SQL (course)
- Cisco CCNA (course)
- Microsoft Hyper-V Advanced Management (course)