Michael
Schmidiger
Over 25 years in enterprise IT — networks, security and system infrastructure. Responsible for 3 sites, shared firewall responsibility across 8 EU sites. Cybersecurity Lead since 2026. Focus on the Fortinet ecosystem, Identity & Zero Trust and sustainable architecture.
Profile
I am a Senior IT Systems Specialist and Cybersecurity Lead EU with roots in classical system administration and a consistent development towards network security and enterprise architecture.
My strength lies in understanding complex IT environments holistically — from OT networks to cloud integration, from single firewall deployments to group-wide SD-WAN architecture across eight European sites.
I build systems the way they should be built — documented, scalable, secure — not as a "minimal viable" solution, but with the ambition to still be maintainable in five years.
Outside of work I run an extensive homelab with 67 self-hosted containers, Proxmox cluster and Home Assistant automation — because the best further education is hands-on.
Expertise
Fortinet Ecosystem
Complete Fortinet stack — design, deployment, operations and troubleshooting across FortiGate instances EU-wide.
SD-WAN & Networking
Contribution to the group-wide SD-WAN rollout — design for two EU sites in collaboration with other specialists. Performance SLAs, dual-WAN failover and central policy management via FortiManager.
Identity & Zero Trust
Multi-domain environment with 2 managed Active Directory domains, EAP-TLS Wi-Fi, RADIUS-based access controls, MFA/SSO and Forescout NAC.
Virtualisation & Backup
Operations and migration of production environments on VMware, storage architectures, backup concepts with Veeam, Backup Exec and NetBackup.
Cybersecurity & NIS2
Contribution to NIS2 compliance (Italy pilot), SIEM architecture based on Wazuh and FortiAnalyzer, vulnerability management and security monitoring.
Automation & Scripting
Infrastructure automation with Ansible (incl. fortinet.fortios collection), scripting for monitoring and deployment. Contribution to Netbox (IPAM) and BookStack (documentation) adoption.
Server, Client & Support
Complete server and client infrastructure across multiple generations — from installation to 3rd-level support. Exchange migration path, MDM, SAP Basis and sole responsibility for 500 users.
Experience
- Extended responsibility as Cybersecurity Lead for all European sites
- SIEM expansion concept (Wazuh, AI triage); contribution to NIS2 project (Italy pilot)
- Strategic coordination with Group IT Malaysia
- Responsibility for network, security, backup and OT support (~500 users, 3 production sites)
- Firewall management for 8 EU sites (IT, CH, DE, NL, BE)
- Setup and operation of the entire Fortinet infrastructure EU-wide
- SAML/SSO VPN, FortiClient EMS, SD-WAN, PKI; NIS2 compliance IT (contribution)
- IP restructuring and complete network segmentation during live operations
- Built the Active Directory domain from scratch — migration from NT4 to Windows 2000, incl. Exchange, GPO structure, DNS, DHCP and desktop management
- 1st–3rd-level support for 200–500 users
- Custom development KredScan — ASP-based creditor workflow with SAP export, 15+ years in production
- PC technician and sales at Vobis MPARC and MaxiSTORE
- IT support and system administration at CD Computer Distribution AG
- Electronics service technician at Isatel Electronic AG (post-apprenticeship)
Education
Planned Certifications
Key Projects
SD-WAN Rollout
Concept and contribution to the EU-wide SD-WAN implementation with performance SLAs, dual-WAN failover and centralised policy management via FortiManager. Operations and optimisation in live production.
NIS2 Compliance Project
Contribution to NIS2 compliance with the IT pilot in Italy: technical implementation of measures, input to gap analysis and coordination with Group IT Malaysia.
PKI Infrastructure Concept
Design of a hierarchical PKI (Offline Root CA + Online Issuing CA) with automatic certificate rolling via GPO and EAP-TLS Wi-Fi over NPS. Planning stage — implementation pending.
SAML-VPN & FortiClient EMS
Setup and operations of FortiClient EMS with SAML-based SSL-VPN, Zero-Trust-Network-Access preparation and IPSec-IKEv2 rollout for mobile devices.
SIEM Architecture & Monitoring
Replacement of PRTG with Zabbix (completed). Wazuh-based SIEM architecture with FortiAnalyzer in planning — playbooks drafted, deployment pending.
IP Restructuring
Complete planning and implementation of IP readdressing at a production site — incl. DHCP, DNS, firewall ruleset, VLAN adjustments and coordination across all departments. Executed without downtime during live operations. Concept for further EU sites in progress.
Complete Network Segmentation
Design and implementation of complete VLAN segmentation: separate zones for IoT, printers, servers, Wi-Fi and clients — with consistent inter-VLAN firewall policies and unified zone concept. Fully executed during live operations without shutdown.
Forescout — 12 Years in Operation
Long-term operation and development of a Forescout NAC environment over approximately 12 years. Device detection, compliance checks, automated responses and integration into the existing network infrastructure.
KredScan
Custom development of an ASP-based creditor workflow with digital coding, validation, multi-stage signing and SAP export — in production for over 15 years.
Exchange Migration Path
Planning and execution of the complete Exchange migration path across multiple generations: 5.5 → 2000 → 2007 → 2013 → Microsoft 365 via Hybrid Cloud — solely responsible.
Global Wi-Fi SSID with EAP
Concept for a vendor-agnostic global WLAN SSID with EAP/RADIUS authentication across all EU sites — NPS-based, independent of FortiAP. In planning.
Authelia Zero-Trust Gateway
Production reverse-proxy stack (NGX FW → NGINX → Authelia) for all internal web services. Trusted-IP segments get direct access — all other networks go through Authelia MFA. Started as a POC, now fully in production.
Wazuh AI-Triage Pipeline
Wazuh agents on all hosts (clients, servers, Proxmox). Alerts from level 12 trigger a Claude AI analysis via n8n webhook — the AI evaluates criticality and automatically controls alerting through Home Assistant.
Infrastructure as Documentation
Automatic inventory from UniFi (DHCP clients, switches) and Proxmox into NetBox (clusters, VMs, IPs). A daily Python script exports network data in structured form to BookStack — supplemented by container inventory via Dockhand.
NetBox Full Automation
Planned full automation: pre-register devices in NetBox via webhook + AI (model, IP, MAC, location), automatically enrich specs via SNMP/SSH, credentials from password manager. Weekly config backups and structured export as emergency handbook and system overview to BookStack.
Let's
talk.
An overview of my technical experience and projects.