Operator Profile

About

I'm Nhat Nguyen — an IT Infrastructure & Cyber Security professional with over 20 years of enterprise experience across network engineering, datacentre operations, and security governance. OneLabs is the private lab I designed, built, and operate to keep that experience current: every platform documented on this site — Kubernetes, GitOps, eBPF network security, and a full SOC stack — runs on hardware I administer myself.

20+
Years in ICT
6
Certifications
26
Platform Components Built
AU
Based · Open to Relocate
Professional Experience

Career Timeline

Enterprise ICT roles spanning real estate, insurance, and national telecommunications — the operational background this lab is built to extend.

Sep 2022 – Present
IT Consultant
Bold Vision Real Estate, Melbourne VIC · Remote from Geelong, VIC
Administer the organisation's Google Workspace environment — Gmail, Drive and collaboration tools — including 2-Step Verification and Context-Aware Access policies, and maintain the VPS infrastructure hosting the company's website.
Mar 2016 – Mar 2022
IT Technical Operation Lead
Cambodia-Vietnam Insurance PLC (CVI)
Directed IT strategy and Level 1/2 support for the organisation's enterprise network. Authored the corporate Business Continuity Plan and Disaster Recovery framework aligned to ISO/IEC 27001, led a company-wide Active Directory migration and datacentre virtualisation onto VMware ESXi, and resolved recurring network incidents for a 30% improvement in core response times.
Aug 2007 – Aug 2015
IT Manager
Vietnam Posts and Telecommunications Group (VNPT)
Led IT operations for a national carrier network serving over 1 million customers across 26 branches; directed the migration of branch LAN/WAN links to a Metropolitan Area Network, managed the technical support team and vendor contracts, and directed NOC/SOC security initiatives.
Mar 2000 – Jul 2007
IT Technical Support
Vietnam Posts and Telecommunications Group (VNPT)
Provided on-site and remote Level 1/2 technical support for enterprise network hardware and critical application servers, resolving complex connectivity escalations — the frontline foundation for the IT Manager role that followed.
Credentials

Certifications & Education

Hands-on alignment: ISO/IEC 27001 · ITIL v4 · NIST CSF · ASD Essential Eight

CISSP — (ISC)² SSCP — (ISC)² CCNP — Cisco Systems ITILv4 — AIICT RHCSA (EX200) — In Progress AAISM (ISACA) — In Progress ↗
Bachelor of Information TechnologyHaiphong University, Vietnam
Diploma of Electronics & TelecommunicationsPosts and Telecommunications Institute of Technology, Vietnam
Governance, Risk & Compliance

Frameworks I Work Across

Job requirements vary by employer — Australian government roles specify ASD Essential Eight, enterprise vendors reference ISO 27001 or SOC 2, EU-facing work references GDPR or the AI Act. I maintain a working control-mapping reference across 18 major frameworks so I can speak directly to whichever one a role requires.

🇦🇺 AU GOVERNMENT BASELINE
ASD Essential Eight

The mandatory security baseline for Australian Commonwealth entities and the de-facto standard across VIC/QLD state government IT roles. I track all 8 mitigation strategies — application control, patching, MFA, restricting admin privileges, and more — against Maturity Levels 0–3 as part of my compliance mapping work.

Also mapped: ISO/IEC 27001 · NIST CSF 2.0 · PCI DSS v4.0.1 · SOC 2 · CIS v8 · GDPR · NIS2 · EU AI Act · ISO/IEC 42001 · NIST AI RMF · ITIL 4 · COBIT 2019 · HIPAA · GLBA · SOX · DPDPA · CRA

Applied Skills

Core Competencies

Each area below is backed by production experience and demonstrated hands-on across this platform.

Infrastructure & Networking
Kubernetes/Talos Linux, VMware ESXi, Cisco/Juniper/Fortinet, VLAN segmentation, IPSec VPN, load balancing.
See it running
SOC & Threat Intelligence
Wazuh, Splunk, MISP, OpenCTI, TheHive/Cortex, Breach & Attack Simulation, honeypots.
See it running
Automation & DevSecOps
GitOps (ArgoCD), Ansible/AWX, Git-based RBAC change control, container registry with Trivy scanning.
See it running
Identity & Access Security
Active Directory (hybrid Entra ID), Enterprise PKI/CA, Vault, Authentik SSO, MFA, Conditional Access.
See it running
Observability & Diagnostics
Prometheus, Grafana, Loki, Wireshark, tcpdump, iperf, mtr — root-cause analysis under production pressure.
See it running
Governance, Risk & Compliance
ISO/IEC 27001-aligned security posture, BCP/DR framework authorship, vendor risk assessment, executive risk reporting.
See it running
Purpose

Why OneLabs Exists

OneLabs is a private, enterprise-grade lab I run to keep pace with the practices used in modern IT and security teams — GitOps delivery, eBPF-based network security, centralised identity, and SOC operations — before recommending or applying them in production. It's a working environment, not a demo: every component listed on this site is deployed, monitored, and maintained by me. I built it to stay sharp between roles and to give hiring teams a concrete, inspectable view of how I work.

Get In Touch
Open to new opportunities

Based in NSW, Australia — open to relocating anywhere for the right role.