Morgan Mathis • Systems & Networks Technician — Cybersecurity Master's work-study

Designing, securing and operating systems with discipline.

I am pursuing a Master's degree in IT Security, Cybersecurity and Cyber Threats at CNAM while working at STT INFOPRO / IP INFOPRO, turning technologies into reliable, monitored, backed-up and documented services.

My Home Lab is my main case study: a complete platform I operate over time through audits, reversible changes, SLOs and disaster-recovery planning — without exposing sensitive implementation details.

Professional portrait of Morgan Mathis
Cybersecurity Master's work-study • since Sep. 2026Cybersecurity Master's degree • CNAM
10operated VMsRationalized roles and monitored QGA
44containersAll running without restart loops
24Compose stacksCanonical and reproducible
66/66monitored targetsPrometheus check on 2026-09-08
100%expected backup coverageEligible workloads verified by PBS
24/7observabilityMetrics, logs and alerts

What I deliver

Skills connected to outcomes

Every area is demonstrated by something operated, measured or documented.

Infrastructure & virtualization

Design isolated roles, maintain systems and prepare their reconstruction.

10 VMs, Proxmox VE, PBS and 24 versioned Compose definitions.
ProxmoxDebianDockersystemd

Networking & exposure

Segment usage, control flows and publish only what is required.

Server, DMZ, IoT and administration zones; redundant DNS and a central reverse proxy.
VLANDNSVPNReverse proxy

Operational cybersecurity

Reduce the attack surface while keeping actionable detection signals.

Host hardening, CrowdSec, local filtering, least privilege and independent re-audits.
HardeningCrowdSecLeast privilegeAudit

Observability & SRE

Measure health, capacity and failure without creating false-green states.

66 targets, 27 probes, Grafana, Prometheus, Loki, Blackbox, Alloy and ntfy alerting.
GrafanaPrometheusLokiSLI/SLO

Backups & continuity

Define what must be restored, in what order and within which target time.

Daily PBS, offline USB copy, SHA-256 manifests, a restore validator and UPS orchestration.
PBSDRUPSRTO/RPO

Automation & documentation

Turn manual work into repeatable, auditable controls.

A local Git repository, standalone validation gate, idempotent scripts, evidence and a formal change log.
GitBashPythonRunbooks

Flagship project

An enterprise-minded platform at Home Lab scale

Its value comes from how the platform is designed, operated and recovered — not from the number of tools.

Left front view of the personal home lab rack with Proxmox server, Grafana wallboard, Synology NAS and Eaton UPS.

A complete infrastructure, with evidence and acknowledged limits

Virtualization, segmented networking, DMZ exposure, DNS, observability, backups, administration access, smart home and documentation are treated as one system.

  • Complete audits and independent re-audits retained
  • Docker reproducibility and a Git source of truth
  • DR, RTO/RPO and residual debt documented
Review the architecture and method

Methodology

Change without losing control

A change discipline applied to the platform and to professional work.

  1. 01

    Observe

    Real state, dependencies, metrics and risk before making a decision.

  2. 02

    Back up

    Configuration, data and last known-good state with verified integrity.

  3. 03

    Prepare rollback

    A written, executable return path before the first change.

  4. 04

    Change minimally

    Limited blast radius, one component at a time, without hiding alerts.

  5. 05

    Validate

    Syntax, service, user journey, logs and several monitoring intervals.

  6. 06

    Prove & document

    Change log, hashes, independent re-audit and explicit residual debt.

Concrete outcomes

Three examples of engineering work

Problem, decision, outcome: tools remain secondary.

Reproducible Docker

Challenge
Scattered projects and runtime parameters that were difficult to rebuild.
Outcome
44 services aligned with 24 canonical Compose definitions, pinned images and a Git validation gate.

44/44 running • 42 registry images • 2 controlled builds

High-signal monitoring

Challenge
Remove duplication, structurally false probes and silent alert failures.
Outcome
Rationalized targets, visible Error/NoData states, local Proxy health and capacity reviews.

66/66 targets • 27/27 probes • 0 active alert

Honest disaster recovery

Challenge
Move from existing backups to an ordered, measurable recovery process.
Outcome
PBS, an offline USB copy, integrity checks and an isolated validator complement tiered RTO/RPO and runbooks.

100% PBS coverage • verify confirmed • rollback tested

Power continuity

Challenge
An actual outage had produced neither reliable notification nor controlled orchestration.
Outcome
UPS telemetry now flows through the NAS over SNMP into Prometheus, ntfy and a least-privilege PVE orchestration guard.

Battery/mains simulation validated • notifications received • no destructive action

Experience

From the Home Lab to real operations

A consistent path across education, personal operations and professional assignments.

Sep. 2026 — present

Systems & Networks Technician — Master's work-study

STT INFOPRO / IP INFOPRO • Le Muy

Cybersecurity, infrastructure hardening, systems and network administration, operational maintenance and technical projects.

Sep. 2025 — Aug. 2026

IT Technician — Professional degree work-study

STT INFOPRO / IP INFOPRO • Le Muy

L1/L2 support, deployment, systems and network administration, maintenance and on-site interventions.

Jan. — Feb. 2025

Network & Systems intern

Circet

Network diagnostics on security and switching equipment, troubleshooting and routine Windows Server operations.

2022 & 2024

Technical internships

Local government organizations

Active Directory, GPO, workstation deployment and switching-infrastructure work.

Master's in IT Security, Cybersecurity and Cyber Threats — CNAM • 2026–2028

Following a Professional degree in Network and Telecommunications Engineering at the University of Toulon (2025–2026), awarded with honours.

Let's talk

Looking for someone who structures before acting?

I can walk through my architecture decisions, validation evidence and approach to risk.

Infrastructure, networking, cybersecurity, monitoring or continuity: let's discuss the need and the method, not just the tools.