Skip to content
View bastiaan365's full-sized avatar

Highlights

  • Pro

Block or report bastiaan365

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
bastiaan365/README.md

Hey, I'm Bastiaan πŸ‘‹

bastiaan@365:~$ whoami

IT Engineer with 8+ years of experience in IT infrastructure, endpoint management and Microsoft 365.
From managing 15,000+ endpoints at KLM to healthcare IT at a leading oncology hospital β€” now looking for my next challenge in Security Engineering.

I'm passionate about AI-assisted workflows β€” I actively use AI tools to automate tasks, build documentation, and accelerate my work. This profile? Built with AI.


πŸ’Ό What I work with

Domain Technologies
πŸ”§ Microsoft 365 Intune Β· Entra ID Β· Defender Β· Conditional Access Β· Exchange Online
πŸ›‘οΈ Security Suricata IDS/IPS Β· OPNsense Β· Zero Trust Β· GDPR Β· NEN 7510 Β· NIS2
πŸ€– AI & Automation Claude Β· LLM workflows Β· AI-assisted development Β· Prompt engineering
πŸ“Š Monitoring Grafana Β· InfluxDB Β· Telegraf Β· Syslog Β· Alerting
🌐 Networking VLANs · WireGuard VPN · DNS-over-TLS · DNSSEC · TCP/IP
πŸ–₯️ Infrastructure Windows Server Β· Active Directory Β· PowerShell Β· SCCM/MECM Β· Linux

🏠 Security Homelab

I build and maintain a fully segmented home network as a hands-on security lab:

  • πŸ”’ OPNsense firewall with 7 isolated network segments
  • 🚨 Suricata IDS/IPS for real-time threat detection
  • πŸ” WireGuard VPN with kill switch and Mullvad integration
  • πŸ“Š TIG stack (Telegraf, InfluxDB, Grafana) on Raspberry Pi
  • 🏑 Home Assistant on isolated VLAN
  • 🌐 DNS-over-TLS with blocklists, DNSSEC validation and Unbound
  • βš™οΈ Automated hardening scripts with rollback capability

Full write-up and details on my website β†’ bastiaan365.com


πŸ“‚ Featured Projects

Repository Description
🏠 homelab-infrastructure Full homelab setup with OPNsense, Suricata IDS/IPS, 7 VLANs, WireGuard VPN and TIG monitoring
πŸ”§ powershell-it-toolkit PowerShell scripts for Windows IT: PC cleanup, AD management, Intune deployment, M365 automation
πŸ›‘οΈ ubuntu-hardening-scripts Automated security hardening for Ubuntu/Debian with CIS benchmarks and rollback capability
🌐 dns-security-setup Secure DNS with Unbound: DNS-over-TLS, DNSSEC validation, ad/malware/tracker blocklists
πŸ“Š grafana-dashboards Custom Grafana dashboards for network traffic, Suricata alerts, DNS queries, system metrics

πŸ€– AI & Continuous Learning

I believe in learning by doing. AI is not just a tool I use β€” it's how I accelerate everything:

  • Building scripts, documentation and tooling with AI-assisted development
  • Exploring LLM integrations for IT automation and monitoring
  • Using prompt engineering to streamline daily IT operations
  • Every day I learn something new through AI β€” and I apply it immediately

πŸ“œ Certifications

Certification Status
MD-100: Windows Client βœ…
MD-101: Managing Modern Desktops βœ…
AZ-900: Azure Fundamentals βœ…
SC-900: Security, Compliance & Identity βœ…
ITIL v4 Foundation βœ…
Lean Six Sigma Orange Belt βœ…
CompTIA Security+ ⏳ In progress

πŸ“’ Career Highlights

  • 🏒 8+ years in IT across aviation, healthcare, legal and childcare sectors
  • ✈️ KLM β€” Lifecycle management of 15,000+ Windows endpoints & 20,000+ iPads
  • πŸ₯ KLM Health Services β€” 3+ years as ICT consultant, NEN 7510 compliance
  • πŸŽ“ Aviation Engineering background β€” engineering mindset in everything I do
  • πŸ›‘οΈ Security-focused β€” from homelab to enterprise, security is my common thread
  • πŸ€– AI-driven β€” actively integrating AI into my workflows and skill development

πŸ“« Get in touch

Pinned Loading

  1. bastiaan365 bastiaan365 Public

    IT Engineer | 8+ years in Microsoft 365, Endpoint Management & Security | Homelab enthusiast

  2. dns-security-setup dns-security-setup Public

    Secure DNS configuration with Unbound: DNS-over-TLS, DNSSEC validation, blocklists for ads/malware/trackers. Privacy-first DNS for OPNsense or standalone.

  3. grafana-dashboards grafana-dashboards Public

    Custom Grafana dashboards for homelab monitoring. Network traffic, Suricata IDS alerts, DNS queries, system metrics and OPNsense firewall stats.

  4. homelab-infrastructure homelab-infrastructure Public

    Fully segmented home network with OPNsense, Suricata IDS/IPS, VLAN isolation, WireGuard VPN and TIG monitoring stack. Defense-in-depth architecture with 7 isolated zones.

  5. powershell-it-toolkit powershell-it-toolkit Public

    PowerShell scripts for Windows IT administration. PC cleanup, user provisioning, Active Directory management, Intune deployment and Microsoft 365 automation.

  6. ubuntu-hardening-scripts ubuntu-hardening-scripts Public

    Automated security hardening for Ubuntu/Debian systems with built-in rollback capability. Designed for both homelab and production environments.