hostwitteshadovv.devsurfacestatic / low-jstelemetrynoneruntimeminimal jsstatusemployed · open to selected consulting

Cyber Security Engineer · Linux systems engineer

WitteShadovv

Building NixOS-first systems, security tools, and repeatable infrastructure.

Based in Zürich and working as a Cyber Security Engineer. MSc in Information Security from Stockholm University. Background in Linux systems engineering, automation, and security work, with current public projects focused on NixOS, privacy-focused system design, and forensic testing.

session.plan current work / study / hands-on experience

Command summary

  • $ whoami

    Cyber Security Engineer · Linux systems engineer

  • $ role --current

    full time in Zürich · open to selected consulting

  • $ study --completed

    MSc in Information Security · Stockholm University

  • $ build --with

    NixOS first · Rust for core tooling · Python and Bash for automation

  • $ work --history

    8+ years with Linux systems · 4 years at ETH Zürich

  • $ maintain --upstream

    nixpkgs · portmaster package and NixOS module

  • base 8+ years Linux-heavy environments
  • current Zürich Cyber Security Engineer
  • public 3 projects NixOS and security work
  • bias deterministic builds, boundaries, and inspectable systems

selected work

Selected work

project list 3 public repositories
01 active artifact-01
sha:ed01f77

NAILS

Plausibly deniable dual-environment computing for NixOS

Language
Rust
License
GPL-3.0
Updated
Aug 18, 2026
Stars
7
  • anti-forensics
  • cli
  • declarative
02 research artifact-02
sha:cb4e8f9

NAILS OS

Privacy-focused amnesic NixOS live distribution built for NAILS

Language
Python
License
GPL-3.0
Updated
Aug 18, 2026
Stars
1
  • amnesic
  • anti-forensics
  • calamares
03 iterating artifact-03
sha:2bf0cd8

deferred-apps

Download apps on-demand while still showing them as installed to keep the host lighter

Language
Nix
License
GPL-3.0
Updated
Aug 18, 2026
Stars
22
  • applications
  • home-manager
  • lazy-loading

Repository data from GitHub as of 2026-09-10.

research thesis
04 published artifact-04

Toward Plausibly Deniable Dual-Environment Computing

MSc thesis · Stockholm University · 2026. The academic groundwork behind NAILS. Combines declarative NixOS configuration and overlay filesystems into a reproducible dual-environment design, with a forensic evaluation of what traces remain.

  • plausible deniability
  • anti-forensics
  • NixOS
  • OverlayFS
upstream merged contributions
  • nixpkgs · portmaster merged 2026
    NixOS/nixpkgs#442904

    Packaged the Portmaster application firewall and wrote its NixOS module. Maintained in nixpkgs since August 2026.

consulting

Consulting Services

consulting services NixOS · Linux · security

I work full time as a Cyber Security Engineer. Consulting stays limited to a few scoped engagements that do not conflict with that role. Typical work is fixed scope audits, reviews, and tooling.

NixOS Infrastructure

Design and deploy fully declarative NixOS systems from scratch.

  • Flakes-based system design
  • Home Manager integration
  • Module and overlay development

Dev Environments

Same shell, same tools, same versions on every machine that runs it.

  • Per-project Nix devshells
  • CI and local environment parity
  • Contributor onboarding guide

Security Hardening

Reduce your Linux system's attack surface against a real threat model.

  • Threat model scoping
  • Privilege and boundary review
  • Prioritized remediation plan

Custom Tooling

Purpose-built CLI tools and automation in Rust, Python, or Bash.

  • CLI tool development
  • Linux and NixOS automation scripts
  • Packaged as Nix derivations

Forensic Evaluation

Structured testing of what traces your systems leave behind.

  • Storage and memory trace audit
  • Encrypted volume analysis
  • Written findings report

Privacy Infrastructure

Audit where your infrastructure retains or leaks data beyond intent.

  • Data persistence mapping
  • Telemetry and logging review
  • Minimization gap report

Engagements are scoped individually. Reach out at contact@witteshadovv.dev with context on your situation.

tools / approach

Tools and approach

tools and approach platform / infrastructure / security / bias / site

platform

What I use most right now.

  • Linux and NixOS as the current default base
  • Rust for systems code and core tooling
  • Python and Bash for automation and day-to-day glue

infrastructure

How I build and run systems.

  • Nix is the current default for reproducible builds and host setup
  • Puppet and Ansible are part of earlier infrastructure work
  • Docker and Kubernetes when packaging and orchestration help

security work

Security work tied to real systems and real investigations.

  • digital forensics and systems that can be examined after the fact
  • security architecture, hardening, and review of system boundaries
  • systems kept readable during testing and review

operating bias

The defaults behind my design choices.

  • repeatable builds over one-off fixes
  • clear system boundaries over vague promises
  • tools people can understand and maintain

site

  • static-first
  • minimal JS
  • no analytics
  • semantic HTML
  • anchor-based navigation

Static public site. Minimal JavaScript used only for theme choice and small interface polish.

contact / verification

Contact and verification

contact and verification one clear place to reach me