Hi, my name is

Sergio Shmyhelskyy.

Network Engineer.

Open to opportunities 📍 Barcelona, Spain 🎓 UPC-FIB

Computer Engineering student at UPC-FIB (Barcelona) focused on cybersecurity, cloud & network engineering and backend/AI development. Currently working on hybrid Azure networking with Infrastructure as Code, SDN governance and Zero Trust.

scroll

0x01 :: About Me

I'm Sergio Shmyhelskyy Yaskevych, a Computer Engineering student at UPC-FIB in Barcelona. I got into technology by taking things apart — now I build and secure the infrastructure that keeps them together.

My core focus is where networking, cloud and security meet: I've designed and implemented a secure hybrid network architecture (on-premises datacenters + Azure) for a regulated enterprise, turning manual network operations into reproducible Infrastructure as Code with Terraform, centralized SDN governance with Azure Virtual Network Manager, GitOps pipelines and a Zero Trust access model. Day to day that also means operating the hybrid perimeter (Check Point on-prem + Azure Firewall Premium), enterprise DNS (Windows Server ↔ Azure Private DNS), dynamic routing with BGP over ExpressRoute/VPN and app publishing with Front Door and Application Gateway.

When I'm not doing infrastructure, I'm breaking things on purpose: solving CTFs on HackTheBox and TryHackMe, experimenting with AI backends in Python, or tinkering with IoT and homelab setups. Currently expanding my systems toolbox with Rust and Go.

  • Based in Barcelona, Spain
  • Languages: Spanish, Catalan, English, Ukrainian
  • Interests: network security, cloud architecture, automation
0hours on enterprise cloud networking (thesis)
0networks governed with IaC & SDN
0isolated environments (dev / pre / prod)
0programming languages used

0x02 :: Experience

Curated highlights — see the full, always up-to-date history on LinkedIn →

Cloud & Network Engineering Intern

Occident (Grupo Catalana Occidente) · Cloud & Networks Team

2025 — 2026

Worked within the team responsible for hybrid connectivity and network security policies of a regulated insurance company (on-prem CPDs + Azure, ~50 networks across dev/pre/prod and 2 tenants).

  • Migrated manually-managed cloud networking (VNets, peerings, routes, firewall rules, DNS) to reproducible Terraform modules with remote state and locking.
  • Implemented SDN governance with Azure Virtual Network Manager: network groups, centralized connectivity, routing and security admin rules, IPAM.
  • Operated hybrid perimeter security: Check Point firewalls on-premises (SmartConsole) alongside Azure Firewall Premium for centralized traffic inspection.
  • Managed enterprise DNS end to end: Windows Server DNS on-premises integrated with Azure Private DNS zones and conditional forwarding for hybrid name resolution.
  • Built GitOps workflows for network changes: plan review, controlled apply, drift detection and post-change verification.
  • Contributed to the Zero Trust access architecture (identity- and context-based access, private endpoints, private DNS, Global Secure Access).
  • Designed and validated Hub & Spoke topologies per environment, hybrid connectivity (VPN/ExpressRoute), app publishing with Front Door, AKS private networking and observability.
  • Azure
  • Terraform
  • AVNM
  • GitOps
  • Zero Trust
  • Check Point
  • Azure Firewall
  • Windows Server DNS
  • ExpressRoute
  • Front Door
  • AKS

Security & Systems — Self-directed Training

HackTheBox · TryHackMe · Homelab

Ongoing

Continuous hands-on practice in offensive and defensive security, Linux system administration and network analysis.

  • CTF challenges and vulnerable machines: enumeration, exploitation, privilege escalation and reporting.
  • Homelab with virtualization, network segmentation, monitoring and self-hosted services.
  • Traffic analysis and hardening with Wireshark, nmap, iptables/nftables.
  • Linux
  • Networking
  • Pentesting
  • Virtualization
  • Bash

0x03 :: Projects

Things I've designed, built or broken — from enterprise cloud networks to weekend experiments.

~/github/pinned fetching…

View all on GitHub →

CTF Write-ups & Security Tooling

Notes, custom scripts and methodology from HackTheBox and TryHackMe machines: recon, web exploitation, privilege escalation and post-exploitation.

  • Python
  • Bash
  • nmap
  • Burp
  • Linux

AI Backend Experiments

Python backends around ML/LLM workflows: REST APIs, task automation and model serving, containerized for reproducible deployments.

  • Python
  • FastAPI
  • Docker
  • LLMs

IoT & Homelab

Arduino/Raspberry Pi projects and a segmented homelab network used as a sandbox for virtualization, monitoring and self-hosted services.

  • Arduino
  • Raspberry Pi
  • IoT
  • Networking

Web Development

Modern web projects with Astro and React — including this portfolio: a dependency-free static site with a canvas network animation and theme system.

  • Astro
  • React
  • Node.js
  • HTML/CSS/JS

0x04 :: Skills

# Cybersecurity

  • Network Security
  • Zero Trust
  • Check Point (SmartConsole)
  • Azure Firewall Premium
  • IDS / IPS
  • Pentesting (CTFs)
  • Wireshark
  • nmap
  • Hardening
  • IAM / RBAC

# Cloud & DevOps

  • Azure
  • Terraform
  • AVNM (SDN)
  • GitOps
  • Landing Zones
  • Azure Policy
  • Entra ID / Global Secure Access
  • Docker
  • Kubernetes / AKS
  • CI/CD
  • Azure Monitor / Network Watcher

# Networking

  • TCP/IP
  • Hub & Spoke
  • VPN (IPsec) / ExpressRoute
  • BGP · OSPF
  • VLANs & Segmentation
  • NAT
  • DNS (Windows Server · Azure Private DNS)
  • DHCP
  • Routing (UDRs)
  • NSG / Firewall Policies
  • Load Balancing (App Gateway · Front Door)
  • Private Endpoints
  • IPAM
  • SD-WAN

# Programming

  • Python
  • Java
  • C / C++
  • Rust
  • Go
  • TypeScript / JS
  • SQL
  • Bash

# Systems

  • Linux (Debian/Ubuntu)
  • Windows Server (DNS · DHCP · AD DS)
  • Virtualization
  • System Administration
  • PowerShell
  • Git

# Web & Backend

  • Astro
  • React
  • Node.js / Express
  • FastAPI
  • REST APIs
  • nginx

# Testing & Quality

  • Unit Testing
  • Integration Testing
  • IaC Module Testing
  • Test Automation
  • Code Review
  • OpenAPI / Swagger
  • Technical Documentation

# Project & Solution Delivery

  • Agile / Scrum
  • Requirements Gathering
  • Solution Design
  • Stakeholder Communication
  • Technical Decision-Making
  • Delivery Coordination
  • Change Management

# Engineering Practices

  • Clean, Maintainable Code
  • GitFlow
  • Full SDLC Ownership
  • Observability & Monitoring
  • Drift Detection
  • Process Improvement
  • Problem Solving

0x05 :: Education

Bachelor's Degree in Computer Engineering

UPC-FIB — Universitat Politècnica de Catalunya, Barcelona

2021 — 2026

Strong foundation in algorithms, data structures, operating systems, networking and computer architecture, with a focus on information technologies: system administration, network engineering and security.

  • Bachelor's thesis: "Design and implementation of a secure hybrid network architecture using Infrastructure as Code and SDN orchestration" — developed in a real enterprise environment.
  • Coursework highlights: computer networks, security, distributed systems, databases, AI.

Certifications & Roadmap

Cloud networking & security credentials

Ongoing
AZ-700

Azure Network Engineer Associate

Microsoft

in progress
AZ-104

Azure Administrator Associate

Microsoft

roadmap
CCNA

Cisco Certified Network Associate

Cisco

roadmap
LABS

HackTheBox · TryHackMe

hands-on security labs

active

0x06 :: Curriculum Vitae

Full professional CV available for download as PDF.

Sergio Shmyhelskyy

Curriculum Vitae — Network Engineer

PDF · Last updated July 2026

CV Preview scroll inside to read · or download directly

0x07 :: Get in Touch

I'm open to internships, junior roles and collaborations in cybersecurity, cloud/network engineering or backend development — or just a good conversation about breaking and building systems.