Caleb Sargeant
Platform, Network & Security Engineer
- contact@calebsargeant.com
- +31 68 201 6886
- Eindhoven, Netherlands
- calebsargeant.com
- github.com/CalebSargeant
- linkedin.com/in/calebsargeant
EU work-authorised (living and working in the Netherlands)
Profile
I have worked in IT since 2012, specialising in platform engineering, automation, infrastructure as code, networking and security. I have run everything from bare-metal server rooms to virtualised platforms and cloud-native architectures, and I care about systems that are reliable, maintainable and boring in production. I take ownership of complex technical problems, whether that is optimising CI/CD, designing infrastructure as code, or securing networks and workloads, and I value clear, pragmatic communication.
Core skills
- Kubernetes & Docker 6 yr
- Terraform 6 yr
- Ansible 8 yr
- CI/CD (GitHub Actions, Jenkins, TeamCity, GitLab, Bitbucket) 9 yr
- Git 12 yr
- Azure (AKS, ACR, APIM, Entra ID) 4 yr
- AWS (EKS, VPC, IAM, S3, WAF) 7 yr
- GCP 3 yr
- Routing & switching (Cisco, MikroTik) 11 yr
- Firewalling (Cisco FTD/ASA, FortiGate, MikroTik, SonicWall) 10 yr
- VPN (remote access and site-to-site) 10 yr
- TCP/IP, DNS, DHCP, LDAP, PKI 12 yr
- Wireless (Ubiquiti, Meraki, MikroTik) 9 yr
- Network & workload hardening 10 yr
- Identity & SSO (Entra ID, SAML, Duo, JumpCloud) 6 yr
- AppSec toolchain (Dependency-Track, DefectDojo, SonarQube, Trivy, ZAP) 4 yr
- Pentesting & vulnerability response 6 yr
- Prometheus, Grafana, Alertmanager 6 yr
- Zabbix & Nagios 8 yr
- ELK / Graylog / Datadog 6 yr
- Linux (Ubuntu, CentOS, RHEL) 12 yr
- Bash 12 yr
- Python 6 yr
- Windows Server (2003 onwards) 12 yr
Also
Experience
13 roles since 2012. Highlights here, the full duty list for every role is on the experience page and in the job descriptions PDF.
Cloud Engineer, PinkRoccade
Jun 2025 – Present 1 yr 3 mo Current
Cloud and platform engineering for local-government software: Kubernetes platforms, infrastructure as code and the migration path off legacy application stacks.
- Cloud and Kubernetes platform engineering for government-sector workloads.
- Infrastructure as code and CI/CD for application teams.
- Migration and modernisation of legacy application platforms.
Platform Engineer, Budget Thuis
Jan 2024 – May 2025 1 yr 4 mo
Azure platform engineering for a Dutch energy and telecoms provider: AKS, Terraform, the internal developer platform, and the CI/CD that hundreds of .NET services ship through.
- Designed, built and ran Azure infrastructure as code with Terraform: AKS clusters, ACR, VNets, NSGs and identity integrations.
- Led the migration of legacy Linux VMs to microservices on AKS.
- Built the internal developer platform: reusable DRY infrastructure modules that bootstrap a new team's environments and repos.
- Rolled out observability (Prometheus, Grafana, Blackbox Exporter) across dev, test, acceptance and production.
- Integrated Microsoft Entra ID with Kubernetes RBAC, and audited IP whitelisting, SSO and certificate management.
- Stood in as Scrum Master for the platform team, running retrospectives and turning actions into prioritised engineering work.
- Started the role remotely from Cape Town and relocated to Amsterdam after five months.
Co-Founder, Magma Moose
Mar 2023 – Present 3 yr 6 mo Current
Co-founded a development studio built around platform, cloud, network and security engineering, and its own developer tooling. I run the engineering: the shared infrastructure everything sits on, and most of the products on top of it.
- Built the studio's infrastructure as code: Terraform and Terragrunt across Cloudflare, Kubernetes, Oracle Cloud, AWS and GCP, including Zero Trust access and IPsec/BGP tunnels into the OCI DRG.
- Shipped Diatreme, a release-orchestration GitHub Action and Cloudflare Worker that unifies four semantic-versioning tools and does Docker build, scan, SBOM to Dependency-Track and registry promotion by digest.
- Shipped Chargate and Brimyr, which gate a pull request on net-new findings and on the coverage of the lines it actually changed rather than on a whole-repo number.
- Built Dün Mir, a fleet-assurance platform: agents on routers push heartbeats to a control plane that runs a dead-man sweep and alerts, with a licensed operator console composed in-process against a frozen agent API.
- Run the studio's security posture: DefectDojo as the finding hub, Dependency-Track as the SBOM sink, and a scheduled job that syncs between them and opens issues for new high-severity findings.
- Built Caldrith, a multi-tenant GitHub App that reconciles organisation and repository settings from configuration as code, and uses it to provision shared security and release workflows into every repository.
DevOps Engineer, tengen
Feb 2023 – Present 3 yr 7 mo Current
Sole DevOps engineer for a multi-cloud estate: GitOps Kubernetes, Terraform modules, WireGuard/MikroTik networking, and the monitoring that keeps a production camera fleet honest.
- Ran fully declarative Kubernetes clusters on FluxCD, with Kustomize and Helm templates per environment.
- Wrote and maintained Terraform modules for EKS, VPCs, subnets, IAM, databases and VPNs across AWS, Azure and GCP.
- Secured infrastructure secrets with SOPS (GPG/AGE) stored in Git and decrypted in CI.
- Upgraded production MongoDB from 4.4 to 7 with replica sets, staging/prod separation and offsite backups.
- Cut long-term storage cost by automating disk cleanup and moving backups to S3 Glacier with lifecycle rules.
- Built and ran the production camera platform for live plate recognition, with remote HTTPS, NTP/DNS sync and reverse proxies.
DevSecOps Engineer, Byte Orbit
Nov 2022 – Dec 2023 1 yr 1 mo
The security half of a product engineering org: AWS WAF and Cisco FTD in Terraform, the application-security toolchain (Dependency-Track, DefectDojo, SonarQube), and ZTNA evaluations.
- Wrote the Terraform for AWS WAF, a Cisco FTD Geneve/GWLB transit gateway, Dependency-Track, DefectDojo and SonarQube across environments.
- Stood up the application-security toolchain end to end and wired it into GitLab CI with Sonar, dependency checks, Trivy and ZAP.
- Ran the vulnerability response loop, monitoring alerts, risk-assessing new findings and driving them to closure as tickets.
- Delivered ZTNA proof-of-concepts (Duo Network Gateway, ZScaler, Cisco Umbrella SIG) and the SSO/SAML integrations behind them.
- Contributed the ISO 27001 documentation and reported weekly on security industry trends to the Information Security Council.
DevOps Engineer, Mindspring Computing
Sep 2021 – Nov 2022 1 yr 2 mo
The generalist DevOps seat at an MSP: GCP/Azure/AWS administration, Jenkins and Bamboo, Ansible-managed infrastructure, and the monitoring and backup estate for a book of clients.
- Migrated the organisation from Bitbucket to GitHub, and deployed applications to GCP App Engine.
- Installed and ran Prometheus, Alertmanager and Grafana via Docker and Ansible, with granular alerting into Slack.
- Wrote the automation that starts and stops cloud instances overnight to cut spend.
- Configured MikroTik route failover for fibre outages, with notification, and ran a zero-trust IPTables policy via Ansible.
- Built the backup estate: Veeam on Hyper-V, scripted FTP and cloud backups, and Hyper-V replication.
Senior Security Engineer, Thinkst Applied Research
Oct 2020 – Sep 2021 11 mo
Deep technical support and research for Canary, the deception platform: deployments across every major cloud and hypervisor, protocol-level troubleshooting, and published security write-ups.
- Supported Canary and Canarytoken deployments across AWS, GCP, Azure, on-prem and VMware, including DNS-tunnelling and HTTP channel configuration.
- Found a way to get Canary running on OpenStack.
- Wrote Canarytoken deployments and console configuration in Python, PowerShell and Bash, and assisted customers with API deployments.
- Researched security vulnerabilities and exploits and published write-ups (pass-the-hash and others) on the security blog.
- Ran SAML/SSO configuration, webhooks and syslog integrations for enterprise customers.
Senior Network Security Engineer, Kurtosys Systems
Jul 2020 – Oct 2020 3 mo
Promotion into the senior seat on the same global network, with design and architecture input, Azure migration and the PKI and MFA rollouts.
- Implemented MFA for remote-access VPN and network device management access (Duo, Google Authenticator).
- Implemented Microsoft PKI: a standalone root and enterprise subordinate CA environment.
- Migrated virtualised and physical servers to Azure, and migrated Windows NPS to cloud-based FreeRADIUS.
- Built VPN tunnels between ASA, Azure and AWS, and scripted the DR procedure with Azure.
- Implemented network L2 and L3 redundancy and failover, and Syslog into Azure Sentinel.
Network Security Engineer, Kurtosys Systems
Dec 2017 – Jul 2020 2 yr 7 mo
Two and a half years on a global, multi-datacentre financial-services network: Cisco ASA and FirePOWER, high availability across layers, and packet-level diagnostics.
- Ran network security on Cisco ASA (ACLs, stateful inspection and threat detection) across a global estate.
- Implemented high availability across multiple layers (HSRP and others) and dynamic routing with BGP, OSPF and EIGRP.
- Diagnosed at packet level on Linux and Cisco, including decrypting TLS 1.2 in Wireshark with ephemeral keys.
- Automated network configuration with Ansible and RANCID under Git-based configuration management.
- Ran 802.1x and RADIUS in a mixed FreeRADIUS/Windows NPS environment, and Cisco ISE BYOD.
Security Engineer, Dimension Data
Nov 2016 – Dec 2017 1 yr 1 mo
Managed-security engineering across a book of enterprise clients: Cisco ASA, FortiGate and Juniper firewalls, site-to-site VPNs and ACL reviews.
- Configured and troubleshot site-to-site VPNs, ACLs and firewalls (Cisco ASA, FortiGate, Juniper) for enterprise clients.
- Ran zero-hit ACL reviews across all clients, and firewall upgrades on ASA and FortiGate.
- Owned incidents end to end, from first-line call through to closure and client reporting.
Customer Support Engineer, Dimension Data
Mar 2015 – Nov 2016 1 yr 8 mo
End-to-end customer support for an enterprise client base, including a VIP user group, plus the AD, Exchange and infrastructure administration behind it.
- Provided 1st, 2nd and 3rd line support (telephonic, remote and onsite) across the client base, with a dedicated VIP support focus.
- Administered Active Directory, Group Policy, print, DNS and DHCP servers.
- Managed third-party vendors for cabling, boardrooms, printers and hardware call logging.
Desktop Support Engineer, MMI Holdings (Carecross Health)
Mar 2014 – Mar 2015 1 yr
The whole IT department for a health business: desktops, servers, the switched network, access control and everything in between.
- Ran service and IT support for the entire IT department, from workstation builds to Terminal Servers.
- Monitored, installed and maintained the HP switched network, and implemented and neatened network cabling.
- Administered the ImproNet security access-control system.
IT Support Engineer, Mindspring Computing
Nov 2012 – Feb 2014 1 yr 3 mo
Where it started. MSP helpdesk covering client-side and server-side, on-site work, and the self-taught programming that turned into everything after.
- Ran helpdesk across client-side (Windows, Mac, Office, ADSL) and server-side (CentOS/RHEL 5+, Windows Server 2003+).
- Administered Linux mail (domains, forwards, relays, queues and DNS records) and ADSL/server monitoring with Nagios XI.
- Tested and set up a Git server and a ThinStation server for the business.
- Taught myself PHP, HTML, CSS, VBS, batch and Bash in quiet hours, and built an app that auto-logs into servers using KeePass and PHP.
- Built and shipped two client websites (kaytrad.co.za, saasie.co.za).
Education & certifications
-
AWS Certified Cloud Practitioner
-
CCNP Security
-
ITIL Foundation
-
CCNP Routing & Switching
-
MCSE: Server Infrastructure
National qualification: IT Database Administration (SAQA 71869)
In progress
Everything else (3)
-
CCNA Security
-
MCSA / MCITP: Server Infrastructure
National qualification: IT System Support (SAQA 48573)
-
National Senior Certificate (Grade 12)
Courses & training
-
AWS Certified Cloud Practitioner
-
Kubernetes
-
Ethical Hacking
-
Linux
-
MikroTik MTCNA
-
Cisco WSA
-
F5 Networks
Everything else (4)
-
Docker, Swarm, Kubernetes
-
Net DevOps: Cisco Python, Automation, NETCONF, SDN, Docker
-
ITIL Foundation
-
Work Readiness Programme