Miguel Jacq · sysadmin & DevSecOps

Linux infrastructure for organisations where security, privacy, and reliability matter.

I'm Miguel Jacq. I help small and specialist teams run important systems safely: untangling inherited Linux estates, automating change, hardening security, improving monitoring, and making recovery practical.

Security & privacy Infrastructure as code Monitoring & incident response Remote (UTC+10/11)

The short version

If your infrastructure is important enough that failure, data exposure, or a risky deployment has real consequences, but you don't need another full-time hire, I can work as your senior hands-on sysadmin/DevSecOps person or alongside your existing team.


Working on production systems since 2007. Fully remote from Melbourne, Australia.

Since 2007
Hands-on work with real production systems.
Linux first
Servers, networks, deployments, identity, observability, and the glue between them.
Security & privacy
Controls that reduce real risk without making systems impossible to operate.
Leave it understandable
Automation, documentation, playbooks, and reviewable changes instead of new mysteries.
When to call Miguel

When I tend to be useful

The technology varies. The recurring theme is infrastructure that matters, has accumulated complexity, and needs experienced hands without a wholesale rewrite.

  • Production has become something nobody wants to touch.
  • Too much depends on one person's memory or undocumented "tribal knowledge".
  • Deployments are manual, fragile, or difficult to roll back.
  • Backups exist, but nobody is very confident about restoring them.
  • Security or compliance requirements have outgrown the current setup.
  • An incident exposed gaps in monitoring, access control, or recovery.
  • Sensitive data means the usual SaaS or outsourcing assumptions need more scrutiny.
  • A small team needs senior infrastructure depth without another full-time hire.
What the work looks like

Make important infrastructure less fragile.

More detail

Understand & stabilise

Map inherited systems, find the dangerous assumptions, fix the immediate risks, and make changes safer.

Automate & document

Turn snowflakes and manual procedures into reproducible configuration, pipelines, and playbooks.

Harden & control access

Practical hardening, identity, encryption, secrets, logging, patching, and audit-friendly change.

Detect & recover

Monitoring that tells you what matters, backups you can restore, and recovery plans you can actually execute.

Good alignment

Mission matters to me, too.

I particularly value work with organisations concerned with security, privacy, human rights, civil society, public-interest technology, and open source. That isn't a requirement; it's simply where a lot of my work and interests have converged.

I also work with web agencies when the problem is a good fit. The common denominator is taking the systems, the risks, and the people affected by them seriously.

Not a general-purpose web agency
I normally join an existing organisation or technical team to solve infrastructure and operational problems. I don't need to own the whole stack, resell you a platform, or turn every engagement into a rebuild.
Open source

Tools that grew out of real problems

All projects
Enroll
Reverse-engineer existing servers into Ansible

Existing production servers are often too important to rebuild just because they pre-date configuration management. Enroll harvests the state that matters and turns it into a practical starting point for Ansible.

cspresso
Brew a Content Security Policy from real page loads

Content Security Policy is valuable, but building a useful policy by hand is tedious and error-prone. cspresso observes what a site actually loads and gives you a policy you can inspect, tighten, and ship.

Tools for the job, or are the job.
I still like solving recurring operational problems in code and publishing the useful parts.
Read technical notes

Have one of these problems?

Send me a summary of what's up, and let's see where I can help.