Robert D. Lish

Systems AdministratorSalt Lake City metro, Utah

I am the primary IT contact for a ~200-employee e-commerce company — identity, endpoints, network, and security are mine end to end. Outside of that I run Drecht, a Proxmox lab where I build AI agent infrastructure against local inference: about seventy MCP tools, a self-hosted model server, and a daily agent that checks the whole estate before I wake up.

Ten years across managed services, 24/7 life-safety monitoring, CJIS-regulated public sector, and e-commerce.

years in IT
10+
managed endpoints
100+
MCP tools in production
~70
automated daily checks
13

Professional

Enterprise infrastructure

Sole dedicated IT administrator at a luxury gifting and e-commerce company, with director-level support and a separate development team owning application code.

  • Windows Hello for Business rollout

    Passwordless authentication across the fleet on Cloud Kerberos Trust.

    Root-caused a class of enrollment failures traced to protected-account attribute conflicts that blocked a subset of users, then drove the rollout to completion.

    • Entra ID
    • Cloud Kerberos Trust
    • Conditional Access
  • Global Secure Access deployment

    Replaced legacy remote access with Microsoft Private Access.

    Included constrained delegation on connector infrastructure and service principal name registration to reach backend databases.

    • Global Secure Access
    • Kerberos
    • Entra ID
  • Wazuh SIEM

    Built the security monitoring pipeline from nothing.

    Network appliance syslog ingestion, custom decoders and correlation rules, and chat-based alert routing — plus a recurring vulnerability triage process with documented risk assessment and remediation tracking.

    • Wazuh
    • syslog / CEF
    • FortiGate
  • Intune detection & remediation scripting

    Enforced a weekly reboot cadence across 100+ endpoints.

    Versioned state tracking, an uptime threshold rather than a blunt schedule, and permission hardening so users cannot tamper with the state file.

    • Intune
    • PowerShell
    • Microsoft Graph
  • Storefront failure diagnosis

    Resolved a customer-facing product configuration failure nobody could reproduce.

    HAR-based analysis isolated an interaction between API rate limiting, an active A/B test, and an internal DNS conflict — three systems that were each individually healthy.

    • HAR analysis
    • DNS
    • REST APIs
  • Identity, endpoint & network estate

    The day job underneath the projects.

    Autopilot provisioning, hybrid Entra join troubleshooting across directory sync scoping, high-availability FortiGate perimeter with multi-ISP failover, UniFi switching and wireless, RDS/RemoteApp with broker HA, and Hyper-V migrations including legacy dynamic disk recovery.

    • Intune
    • Autopilot
    • FortiGate
    • UniFi
    • Hyper-V
    • RDS

Drecht

Homelab & applied AI

A self-designed lab built to production patterns: Proxmox VE on 256 GB of RAM, VLAN-segmented storage, media and infrastructure traffic, and external exposure through health-checked Cloudflare tunnels with token authentication.

  • Hermes Agent

    A custom orchestration agent with roughly 70 registered MCP tools.

    Local inference is the default provider, with a hosted frontier model as fallback — so routine work costs nothing and only hard problems reach the paid path. Includes a coding-task delegation tool that hands implementation to an autonomous coding agent, and a deploy tool targeting multiple repositories.

    • Model Context Protocol
    • Python
    • Node.js
  • D-Forge

    Local LLM inference node — a quantized 26B mixture-of-experts model on CPU.

    Running llama-server with a 32k context window. The lab’s discrete GPU was retired, so throughput came from tuning thread count, context and batching rather than hardware.

    • llama.cpp
    • quantization
    • systemd
  • Planner Agent

    A scheduled daily agent running 13 checks across the entire estate.

    Infrastructure, services, security, storage, network, revenue, snapshot integrity and inference health — each result routed to a purpose-specific chat channel so the signal is not buried in one firehose.

    • Python
    • cron / systemd timers
    • webhooks
  • Mission Control

    A Next.js operations dashboard for the lab.

    Its own repository with a key-based deployment pipeline, alongside a cost tracking service that reconciles monthly lab operating expense against side-project revenue.

    • Next.js
    • REST APIs
  • D-Trader

    Retired 2026

    Algorithmic trading platform — crypto scalping and equity swing trading.

    Applied Focal Loss to severe class imbalance in signal labeling, with automated weekly retraining. An unattended research harness for hyperparameter sweeps improved crypto entry-signal F1 from 0.579 to 0.968. It reached partial self-funding against lab operating costs before I wound it down deliberately — positions closed, schedules removed, configuration zeroed.

    crypto entry-signal F10.5790.968

    • Python
    • Focal Loss
    • brokerage API
  • Self-hosted services & operating practice

    The unglamorous half that makes the rest trustworthy.

    Home Assistant migrated from an appliance-style VM to multi-container Docker on the NAS, splitting core, Z-Wave and Matter into independently upgradable services. Least-privilege read-only tokens on every external integration, a full-credential rotation procedure exercised end to end, and snapshot and backup verification built into the daily check suite.

    • Docker
    • Proxmox
    • Cloudflare Tunnel
    • NAS

Background

Where I've worked

Environments with real consequences for downtime — dispatch centres, alarm monitoring, regulated public sector, and revenue-carrying storefronts.

  1. Systems Administrator

    Luxury gifting & e-commerce company

    ~200 employees. Sole dedicated IT administrator.

  2. Systems Administrator → IT Manager

    Regional fire & security integrator

    Enterprise video management, access control, life-safety systems.

  3. Service Desk Lead

    Managed service provider — Portland, OR metro

    Led a 3-person service desk across a mixed client base.

  4. IT Operations

    County Sheriff's Office / Emergency Dispatch

    CJIS-regulated law enforcement environment.

  5. 24/7 Central Station Operations

    Life-safety monitoring provider — Portland, OR metro

    Round-the-clock alarm monitoring and response.

  6. IT Operations

    Accounting services firm

    Generalist IT in a compliance-sensitive environment.

Certifications

  • CompTIA A+
  • CompTIA Network+
  • CompTIA Security+
  • Microsoft 365 Certified: Endpoint Administrator Associate
  • WGU AI Skills Fundamentals

Toolkit

What I work with

Cloud & Identity

  • Microsoft 365
  • Entra ID
  • Conditional Access
  • Intune
  • Autopilot
  • Windows Hello for Business
  • Global Secure Access
  • Hybrid Active Directory
  • Directory synchronization

Infrastructure

  • Proxmox VE
  • Hyper-V
  • Windows Server
  • RDS / RemoteApp
  • Ubuntu / Debian
  • Docker
  • LXC
  • NAS & storage
  • Backup & DR

Networking

  • FortiGate
  • UniFi
  • VLAN design
  • DNS
  • Cloudflare Tunnel
  • VPN & ZTNA

Security

  • SIEM deployment & tuning
  • Vulnerability triage
  • Syslog & CEF pipelines
  • Secrets management
  • CJIS-regulated environments

Automation & Development

  • PowerShell
  • Microsoft Graph API
  • Python
  • Node.js
  • systemd
  • REST APIs
  • Model Context Protocol
  • Local LLM deployment

Physical Systems

  • Enterprise video management
  • Access control
  • Life-safety monitoring