Senior Network · Security · System Engineer

Michael
Schmidiger

Over 25 years in enterprise IT — networks, security and system infrastructure. Responsible for 3 sites, shared firewall responsibility across 8 EU sites. Cybersecurity Lead since 2026. Focus on the Fortinet ecosystem, Identity & Zero Trust and sustainable architecture.

Fortinet Ecosystem FortiGate · EMS · FortiManager SD-WAN · Routing NIS2 · Wazuh · SIEM Entra ID · AD · RADIUS VMware · Backup Exec · NetBackup Forescout NAC Knonauer Amt, Zurich
25+Years experience
8EU sites
16+FortiGate instances
~500Users managed
01 /

Profile

I am a Senior IT Systems Specialist and Cybersecurity Lead EU with roots in classical system administration and a consistent development towards network security and enterprise architecture.

My strength lies in understanding complex IT environments holistically — from OT networks to cloud integration, from single firewall deployments to group-wide SD-WAN architecture across eight European sites.

I build systems the way they should be built — documented, scalable, secure — not as a "minimal viable" solution, but with the ambition to still be maintainable in five years.

Outside of work I run an extensive homelab with 67 self-hosted containers, Proxmox cluster and Home Assistant automation — because the best further education is hands-on.

Location Mettmenstetten, Knonauer Amt, Zurich
Target role Senior Network · Security · System Engineer
Focus Fortinet environments, mid-size companies
Languages German (native) · English (business fluent)
02 /

Expertise

// 01 · NETWORK-SECURITY

Fortinet Ecosystem

Complete Fortinet stack — design, deployment, operations and troubleshooting across FortiGate instances EU-wide.

FortiGateFortiManagerFortiAnalyzerFortiClient EMSFortiAPSAML-VPNIPSecCheckPoint
// 02 · ARCHITECTURE

SD-WAN & Networking

Contribution to the group-wide SD-WAN rollout — design for two EU sites in collaboration with other specialists. Performance SLAs, dual-WAN failover and central policy management via FortiManager.

SD-WANRoutingVLANArubaUniFiHPE
// 03 · IDENTITY

Identity & Zero Trust

Multi-domain environment with 2 managed Active Directory domains, EAP-TLS Wi-Fi, RADIUS-based access controls, MFA/SSO and Forescout NAC.

Entra IDActive DirectoryNPS / RADIUSEAP-TLSMFA / SSOForescoutMicrosoft Intune
// 04 · INFRASTRUCTURE

Virtualisation & Backup

Operations and migration of production environments on VMware, storage architectures, backup concepts with Veeam, Backup Exec and NetBackup.

VMware vSphereHyper-VVeeamVeritas Backup ExecNetBackupDell VNX/UnityHP MSANFS / iSCSIDR-Sites
// 05 · COMPLIANCE

Cybersecurity & NIS2

Contribution to NIS2 compliance (Italy pilot), SIEM architecture based on Wazuh and FortiAnalyzer, vulnerability management and security monitoring.

NIS2FortiAnalyzerWazuh / SIEMPRTGSophos UTM GatewaySymantec Mail GatewayTrellix / McAfeeVulnerability Mgmt
// 06 · AUTOMATION

Automation & Scripting

Infrastructure automation with Ansible (incl. fortinet.fortios collection), scripting for monitoring and deployment. Contribution to Netbox (IPAM) and BookStack (documentation) adoption.

PowerShellAnsibleLinuxBash / PythonDocker / ComposeGrafanaNetboxBookStackClaude / Claude Code
// 07 · SYSTEMS

Server, Client & Support

Complete server and client infrastructure across multiple generations — from installation to 3rd-level support. Exchange migration path, MDM, SAP Basis and sole responsibility for 500 users.

Windows Server 2000–2022Exchange / M365WSUS · GPOSAP BasisKnox MDMSecurePIMHighsystemSolarwinds ARMTrellix / McAfeeMS Defender for ExchangeDamewarePrinter MgmtVC SystemsInnovaphone VOIPAscom DECT1st–3rd-Level-Support
03 /

Experience

Jan 2026 — present
Senior IT Systems Specialist · Cybersecurity Lead EU
Kolb Distribution Ltd · Hedingen, Switzerland
  • Extended responsibility as Cybersecurity Lead for all European sites
  • SIEM expansion concept (Wazuh, AI triage); contribution to NIS2 project (Italy pilot)
  • Strategic coordination with Group IT Malaysia
2010 — 2025
Senior IT Systems Specialist
Kolb Distribution Ltd · Hedingen, Switzerland
  • Responsibility for network, security, backup and OT support (~500 users, 3 production sites)
  • Firewall management for 8 EU sites (IT, CH, DE, NL, BE)
  • Setup and operation of the entire Fortinet infrastructure EU-wide
  • SAML/SSO VPN, FortiClient EMS, SD-WAN, PKI; NIS2 compliance IT (contribution)
  • IP restructuring and complete network segmentation during live operations
1999 — 2010
PC Support / IT Specialist
Kolb Distribution Ltd · Hedingen, Switzerland
  • Built the Active Directory domain from scratch — migration from NT4 to Windows 2000, incl. Exchange, GPO structure, DNS, DHCP and desktop management
  • 1st–3rd-level support for 200–500 users
  • Custom development KredScan — ASP-based creditor workflow with SAP export, 15+ years in production
1993 — 1999
PC Technician · IT Support
Vobis · CD Computer Distribution · Isatel
  • PC technician and sales at Vobis MPARC and MaxiSTORE
  • IT support and system administration at CD Computer Distribution AG
  • Electronics service technician at Isatel Electronic AG (post-apprenticeship)
04 /

Education

Formal education
1991 – 1993
Apprenticeship Electronics Technician
Isatel Electronic AG · Cham · Vocational school Zug
Foundation for technical understanding at system level — electronics, circuits, measurement technology. The hands-on precision flows into IT work to this day.
Training & courses
Administering Microsoft SQL Server 2012
Microsoft
Configuring and Managing SharePoint 2010
Microsoft
Office Communications Server 2007 R2
Microsoft
Business English Certificate Preliminary
Cambridge
Upgrading Administration Skills to Exchange 2007
Microsoft
Implementing and Managing Microsoft Exchange
Microsoft
04 /

Planned Certifications

NSE4
Fortinet NSE 4 — FortiOS
Fortinet Network Security Expert
In preparation 2026
NSE5
Fortinet NSE 5 — FortiManager
Fortinet Network Security Expert
Planned 2026
SD-W
SD-WAN Specialist
Fortinet Specialist Track
Planned 2026
AZ
Microsoft Azure / M365
Microsoft Certification
In planning
05 /

Key Projects

EU-wide · 8 sites

SD-WAN Rollout

Concept and contribution to the EU-wide SD-WAN implementation with performance SLAs, dual-WAN failover and centralised policy management via FortiManager. Operations and optimisation in live production.

Security · Italy pilot

NIS2 Compliance Project

Contribution to NIS2 compliance with the IT pilot in Italy: technical implementation of measures, input to gap analysis and coordination with Group IT Malaysia.

Network · Planning

PKI Infrastructure Concept

Design of a hierarchical PKI (Offline Root CA + Online Issuing CA) with automatic certificate rolling via GPO and EAP-TLS Wi-Fi over NPS. Planning stage — implementation pending.

Zero Trust · VPN Migration

SAML-VPN & FortiClient EMS

Setup and operations of FortiClient EMS with SAML-based SSL-VPN, Zero-Trust-Network-Access preparation and IPSec-IKEv2 rollout for mobile devices.

Monitoring · SIEM

SIEM Architecture & Monitoring

Replacement of PRTG with Zabbix (completed). Wazuh-based SIEM architecture with FortiAnalyzer in planning — playbooks drafted, deployment pending.

Network · Site migration

IP Restructuring

Complete planning and implementation of IP readdressing at a production site — incl. DHCP, DNS, firewall ruleset, VLAN adjustments and coordination across all departments. Executed without downtime during live operations. Concept for further EU sites in progress.

Network · Segmentation

Complete Network Segmentation

Design and implementation of complete VLAN segmentation: separate zones for IoT, printers, servers, Wi-Fi and clients — with consistent inter-VLAN firewall policies and unified zone concept. Fully executed during live operations without shutdown.

NAC · Network Access Control

Forescout — 12 Years in Operation

Long-term operation and development of a Forescout NAC environment over approximately 12 years. Device detection, compliance checks, automated responses and integration into the existing network infrastructure.

Custom development · 15+ years in production

KredScan

Custom development of an ASP-based creditor workflow with digital coding, validation, multi-stage signing and SAP export — in production for over 15 years.

Microsoft · Generation migration

Exchange Migration Path

Planning and execution of the complete Exchange migration path across multiple generations: 5.5 → 2000 → 2007 → 2013 → Microsoft 365 via Hybrid Cloud — solely responsible.

Identity · Network · Concept

Global Wi-Fi SSID with EAP

Concept for a vendor-agnostic global WLAN SSID with EAP/RADIUS authentication across all EU sites — NPS-based, independent of FortiAP. In planning.

// Homelab & Automation Personal lab projects · Own initiative
Homelab · Zero Trust

Authelia Zero-Trust Gateway

Production reverse-proxy stack (NGX FW → NGINX → Authelia) for all internal web services. Trusted-IP segments get direct access — all other networks go through Authelia MFA. Started as a POC, now fully in production.

Homelab · SIEM & AI

Wazuh AI-Triage Pipeline

Wazuh agents on all hosts (clients, servers, Proxmox). Alerts from level 12 trigger a Claude AI analysis via n8n webhook — the AI evaluates criticality and automatically controls alerting through Home Assistant.

Homelab · Automation

Infrastructure as Documentation

Automatic inventory from UniFi (DHCP clients, switches) and Proxmox into NetBox (clusters, VMs, IPs). A daily Python script exports network data in structured form to BookStack — supplemented by container inventory via Dockhand.

Homelab · CMDB · in development

NetBox Full Automation

Planned full automation: pre-register devices in NetBox via webhook + AI (model, IP, MAC, location), automatically enrich specs via SNMP/SSH, credentials from password manager. Weekly config backups and structured export as emergency handbook and system overview to BookStack.

Let's
talk.

An overview of my technical experience and projects.