Open to senior roles in IT infrastructure, platform engineering, and automation
CZ / EN

Antonín Ečer, DiS. Senior Infrastructure Specialist

I build and operate infrastructure as a system.
Enterprise Linux · Architecture · Segmentation · Patch Orchestration · Hardening · Automation
Location: Prague / hybrid
Status: Active / Monitoring

Operational Impact Snapshot

30+ Years in IT
30+ Years in IT
Long-term experience spanning from helpdesk to architecture.
7 000+
7,000+ Servers
Orchestrated patch compliance at enterprise scale.
120+
120+ Components
Critical wireless components integrated into central Zabbix HA.
20+
20+ Locations
Multi-site hospitality and datacenter connectivity.

Professional Philosophy & Values

Tech, People & Processes

Over 30 years in IT, I have worked across all levels from user support to IT management. Having led developers, sysadmins, and helpdesk teams, I understand not only the technical details but also the human dynamics and the necessity of smooth communication.

Pragmatic Frameworks

I do not view ITIL 4, TOGAF, or PRINCE2 certifications as trophies to hang on a wall. I use them as practical toolsets to bring order, auditability, and predictability to real-world operations and change management.

Calmness & Context

I bring operational calm, deep contextual knowledge, and the ability to solve crisis situations with a cool head. I believe in continuous process improvement and that well-designed automation and monitoring eliminate daily fire-fighting.

The Coding Sysadmin

I have coded all my life (Bash, PHP, Python, SQL, Java). My natural mindset is to build and automate - if no suitable tool exists for an operational task, or if it is overengineered, I prefer to design and code my own solution (e.g., PatchMonitor).

Professional Timeline

Profile Perspective:

Fio banka a.s. Banking / Financial Services

April 2026 – present

Senior Infrastructure Specialist - OSSS / Network Security

  • Ensuring secure and stable banking operations in compliance with strict governance and audit standards.
  • Integrating and monitoring 720+ critical wireless components into the central monitoring system.
  • Setting up efficient processes for managing and developing monitoring infrastructures.
  • Designing and implementing high-availability monitoring (Zabbix HA) built on Rocky Linux.
  • Automating deployment and management of monitoring agents and configurations using Ansible.
  • Integrating and monitoring critical network components (720+ components) and managing alert rules.
  • Creating audit-ready operational standards and preparing reporting deliverables.

Komerční banka a.s. Banking / Financial Services

August 2021 – December 2025

Senior Linux / Infrastructure Engineer

  • Co-responsible for operations, automation, and compliance of a fleet of 7,000+ Linux servers.
  • Created the internal tool PatchMonitor for patch tracking, DR validation, and management reporting.
  • Significantly shortened patch cycles and reduced operational risks by introducing automated orchestrations.
  • Managing and patching 7,000+ Linux servers (RHEL, Oracle Linux, CentOS, Ubuntu, Debian).
  • Orchestrating patch compliance and repository lifecycles using Ansible, AWX, Foreman, and Katello.
  • Creating and optimizing dynamic inventories in Ansible AWX for scalable task execution.
  • Developing the PatchMonitor system (PHP, Python, SQL) - patch status visualization, DR check logging, management reporting.
  • Hardening operating systems, preparing compliance audit materials, and implementing remediation steps.

Apollo Software s.r.o. Regulated Online Gaming

February 2021 – August 2021

Infrastructure Transformation Consultant

  • Crisis management and infrastructure transformation for rapid stabilization of critical services.
  • Virtualization consolidation and unification of IP address space across datacenters.
  • Introducing standardized operational processes and centralized access control.
  • Audit and redesign of virtualization clusters built on Proxmox VE.
  • Implementing FreeIPA for centralized identity and access management (LDAP).
  • Restructuring IP address space across multiple geographically separated datacenters.
  • Replacing unmanaged and unstable legacy VPN architecture with secure, segmented connectivity.

Digiteq Automotive s.r.o. / Volkswagen Group Automotive / Software Development

June 2018 – January 2021

IT Systems Specialist / Infrastructure Architect (Acting LISO & Deputy CISO)

  • Design and management of IT infrastructure supporting safety-critical software development for VW Group.
  • Responsible for information security as local LISO and Deputy CISO.
  • Implementing access control standards, VLAN segmentation, and audit trail enforcement.
  • Managing a heterogeneous environment of Linux (RHEL, CentOS) and Windows Server.
  • Virtualization on VMware ESXi and Microsoft Hyper-V platforms.
  • Configuring Cisco and FortiGate network devices, VLAN segmentation, LACP, and trunking.
  • Backup and disaster recovery using Veeam Backup & Replication.
  • Managing and integrating developer tools (GitLab, Jira, Confluence) and AD/DNS directory services.
  • Implementing security audit controls and system hardening according to VW Group standards.

LibraHospitality s.r.o. / OREA HOTELS s.r.o. Hospitality / Multi-site IT Operations

March 2004 – May 2018

IT Manager / Regional IT Manager / IT Specialist

  • Managing IT infrastructure for headquarters and 20+ hotel locations in the Czech Republic.
  • Leading the internal helpdesk and coordinating regional IT administrators.
  • Vendor management, SLA negotiations, and efficient IT budget control.
  • Full management of servers and networks for 20+ geographically separated hotel locations.
  • Virtualization and consolidation of physical hardware on the VMware ESXi platform.
  • Integration and maintenance of property management systems (Epitome / Opera PMS) and interfaces.
  • Implementing backup and disaster recovery standards across branches.
  • Managing and executing hotel system migrations and deployments in the CEE region.

Earlier Career / Začátky kariéry Telecommunications, Logistics, IT Services

1993 – 2004

IT Specialist / Network Administrator / Systems Technician

  • Gaining a broad foundation in IT support, network administration, and database maintenance.
  • Technical support for national GSM network rollouts and monitoring logistics systems.
  • Positions at Ericsson s.r.o., AAA Auto a.s., and Czech Post.
  • Network administration on Novell NetWare and early Windows Server platforms.
  • Supporting the GSM 1800 network rollout in the Czech Republic for Ericsson.
  • Maintenance of automated mail-sorting technologies and SQL databases at Czech Post.
  • Developing internal utilities and scripts (Pascal, PHP, Bash) to automate recurring tasks.

Technical Competencies

Operating Systems

Linux RHEL Oracle Linux Rocky Linux CentOS Ubuntu Debian Windows Server

Automation & Version Control

Ansible Ansible AWX Foreman / Katello Git / GitLab CI/CD pipelines

Monitoring & Observability

Zabbix HA Grafana Prometheus SNMP integration Alerting configurations

Virtualization & Cloud

VMware ESXi Proxmox VE Microsoft Hyper-V KVM Docker / Containers AWS Foundations

Networking & Security

FortiGate Cisco networking VLAN segmentation LACP / Trunking OS hardening Compliance audits

Scripting & Databases

Bash Python PHP SQL (Oracle, MySQL) PowerShell YAML configurations

Key Projects & Presentations

PatchMonitor

An internal enterprise system for managing massive server infrastructure patching in a banking environment. Provides transparent reporting for management, patch compliance monitoring, DR checks, and integration with AWX orchestrations. Reduced operational cycles from weeks to hours.

Ansible Inventory Studio

A utility for visualizing, auditing, and managing complex Ansible inventories. Displays logical relationships between groups, variable inheritance (group_vars, host_vars), and prevents incidents caused by unintentional overrides in large environments.

Zabbix HA Monitoring

Design and implementation of a robust, high-availability monitoring cluster on Rocky Linux. Provides centralized supervision over 120+ critical network components in a high-security banking environment with integrated alerting and reporting.

Linux Security – The Illusion of Safety

A practical presentation on Linux infrastructure operational security: segmentation, IoT risks, lateral movement, patch management, hardening, and disaster recovery. Real-world operations perspective rather than abstract theory.

LM Helper (Offline RAG)

A diagnostic assistant leveraging local LLMs and RAG search over operational and technical documentation. Enables rapid lookup and troubleshooting within a closed environment, preventing any data leaks of logs or configs outside the corporate network.

Quantum Random API

Experimental HTTP service providing high-quality cryptographic randomness. The architecture is ready for future integration with specialized (quantum) hardware.

AWS hands-on (foundation)

Hands-on training focusing on compute, networking, storage, IAM, monitoring, and security. Includes real-world tasks and deployments; practical understanding of basic cloud building blocks.

Homelab Architecture

A private test and development infrastructure running on a 3-node Proxmox VE cluster. Features a virtualized router, network segmentation via VLANs, containers for various services, monitoring, and secure site-to-site/OCI connectivity via Tailscale VPN.

Education & Certifications

Higher Professional School – Institute of Informatics

2008 – 2012
DiS. (Diplomovaný specialista v oboru informatika)

Focused on Linux, SQL (Oracle, MySQL), Java, and networking.

Level Comparison: Tertiary professional education ending with the DiS. degree corresponds to EQF Level 6 (same level as a Bachelor's degree, but with a major emphasis on practical operations in IT and infrastructure).

J. A. Komenský University

2003 – 2004
Human Resources Management (studies)
  • TOGAF 9 Certified (Level 1 & 2)
  • ITIL 4 Foundation
  • PRINCE2 Foundation
  • AWS Cloud Quest: Cloud Practitioner
  • AWS Fundamentals
  • Kubernetes Fundamentals (course)
  • Oracle SQL (course)
  • Cisco CCNA (course)
  • Microsoft Hyper-V Advanced Management (course)
View Certificates Portfolio (PDF)
Certain proprietary architecture details are omitted in compliance with security guidelines.

Contact

Interested in working together? Reach out on LinkedIn, explore my GitHub repositories, or contact me via email.

Email: antoninecer [at] gmail [dot] com