Timothy Aaron Penner

Senior IT Infrastructure & Systems Engineer

Lathrop, CA

Professional Summary

Senior IT Infrastructure & Systems Engineer with 25+ years of experience (since 1999) designing, securing, and maintaining enterprise production environments across Windows and Linux platforms. Background spans server infrastructure, virtualization, SAN storage, firewall and VPN architecture, identity and access management, automation, and disaster recovery planning.

Led and executed critical infrastructure initiatives including enterprise-wide MFA and privileged access management (PAM) deployment using Delinea/Centrify, firewall and VPN architecture redesign, large-scale server virtualization, hybrid cloud operations across Azure and AWS, and infrastructure automation using Terraform, Python, PowerShell, Bash, and Ansible.

Current work also includes software and product engineering across Python, Kotlin, and Go, APIs and service integrations, Git/GitHub-based CI/CD, network-resilient streaming systems, and Linux-hosted application infrastructure.

Known for operational stability, disciplined change management, strong documentation, calm incident response, and root-cause analysis in mission-critical production environments.

Core Skills

Platforms & Virtualization

  • Windows Server and Linux (Ubuntu, RHEL, CentOS, Debian)
  • macOS (legacy support)
  • Microsoft Hyper-V clustered environments and live migration
  • VMware ESXi and Proxmox
  • Azure and AWS hybrid cloud infrastructure
  • Oracle Cloud Infrastructure (OCI), including hands-on Free Tier deployments
  • SAN / Fibre Channel storage

Identity & Security

  • Active Directory and Group Policy
  • MFA / IAM / PAM (Delinea / Centrify)
  • Privileged access workflows
  • Juniper SRX firewall (NAT, site-to-site VPN, remote access VPN)
  • Cisco switching and routing

Automation & Software Engineering

  • Python, Kotlin, Go, PowerShell, Bash, shell scripting, and JavaScript
  • Go backend services and systems development
  • Terraform and Ansible infrastructure as code
  • Git/GitHub, CI/CD, and automated validation
  • APIs, service integrations, and operational tooling

Networking & Distributed Systems

  • DNS, DHCP, routing, VPN, and network troubleshooting
  • High-availability and multi-link network resiliency
  • Monitoring, alerting, observability, and performance analysis
  • Real-time media transport including RTMP/RTMPS/SRT and SRTLA

Reliability & Operations

  • Incident response and root-cause analysis
  • Patch management (HCL BigFix, WSUS)
  • Backup and recovery systems
  • Disaster recovery planning and readiness validation
  • 24/7 production infrastructure ownership

Enterprise Services

  • Microsoft Exchange and Microsoft 365 messaging
  • Apache, Nginx, HAProxy, and Linux-hosted services
  • MS-SQL-backed application infrastructure
  • DNS, web, mail, and telephony services

Professional Experience

Penner.io / Independent IT Consulting — Infrastructure Consultant January 2019 – Present
  • Provide systems engineering and infrastructure consulting supporting production and development environments.
  • Lead end-to-end development of an Android streaming application and distributed services using modular Kotlin, Camera2/OpenGL, RTMP/RTMPS/SRT, SRTLA across Wi-Fi and cellular, HEVC, platform APIs, and Linux-hosted infrastructure.
  • Architect reusable Kotlin modules for camera, media, streaming, chat, platform integration, updates, and shared application logic, with platform-neutral components designed for future cross-platform reuse.
  • Develop Go backend services for account/session identity, passwordless email OTP, OAuth integrations, encrypted token storage, SMTP, telemetry, service proxying, and production deployment behind Caddy and systemd.
  • Design secure GitHub Actions CI/CD and release workflows with self-hosted runners, parallelized tests, automated validation/review gates, release promotion, deployment safeguards, and certificate-pinned Android updates.
  • Develop and maintain Python and Bash automation for infrastructure and software projects, operational tooling, and repeatable workflows.
  • Design, deploy, and administer Windows and Linux server environments, Proxmox virtualization, Terraform, and Ansible automation.
  • Designed infrastructure for Facebook Gaming Partner streaming and community services, including VPN traffic routing, web/email services, multiplayer game servers, and JavaScript chat commands and integrations.
  • Implement monitoring, system hardening, patch management, performance optimization, and infrastructure reliability practices.
Facebook Gaming Partner Program — Gaming Partner (Contract) November 2019 – June 2026
  • Operated and maintained a self-managed real-time production environment requiring high availability, performance monitoring, and low-latency network optimization.
  • Optimized workstation hardware, OS configuration, and network settings to maintain service uptime.
  • Performed live troubleshooting and root-cause analysis during active production sessions.
  • Monitored bandwidth utilization, system performance, and resource allocation to ensure consistent service delivery.
Transportation Insight — System Engineer March 2022 – March 2023
  • Led enterprise MFA and privileged access rollout using Delinea/Centrify across 800+ Windows and Linux servers.
  • Architected phased rollout onboarding 650+ users to TOTP authentication.
  • Administered VMware ESXi, Hyper-V, Azure, and AWS across multi-datacenter infrastructure with shared SAN storage and workload migration.
  • Supported hybrid messaging infrastructure including Exchange On-Premises and Exchange Online / Microsoft 365.
  • Managed enterprise patching using HCL BigFix and custom fixlets.
  • Participated in on-call production support and incident response.
4D, Inc. — Senior Technical Services Engineer January 2016 – March 2021
  • Led U.S. infrastructure operations spanning servers, virtualization, storage, networking, telephony, monitoring, and production reliability.
  • Owned day-to-day U.S. IT operations, infrastructure availability, vendor coordination, and operational documentation.
  • Sole-administered the separate U.S. Active Directory domain, including Group Policy, authentication services, and forest upgrades from Windows 2000 through 2016 functional levels.
  • Administered Windows and Linux servers, DNS, and clustered Hyper-V infrastructure supporting internal and production systems.
  • Managed Cisco switching, routing, and telephony services supporting U.S. office operations.
  • Administered Juniper SRX firewall, NAT, VPN connectivity, and network security policies.
  • Maintained monitoring and alerting systems supporting 24/7 production availability and incident response.
  • Provided Tier III escalation support for developers and complex infrastructure, connectivity, and application issues.
  • Oversaw service desk operations, assigned support cases, mentored engineers on complex incidents, and coordinated escalation resolution.
  • Developed and published 4D developer tooling, reusable macros, and PHP/Python integration examples using SQL, ODBC, PDO, and the 4D SQL networking stack.
  • Designed custom 4D Method Explorer and Code Object Explorer tools using Design Object Access APIs, with live filtering, code preview, metadata, code-object inspection, method execution, and code-size/line-count analysis.
  • Designed a 4D v18 runtime error-logging framework using Get Call Chain, full error stacks, execution context, JSON persistence, and a parser UI for call-chain analysis.
  • Supported Oracle Database integrations through 4D for OCI (Oracle Call Interface), including connectivity and application-integration troubleshooting.
  • Authored weekly Tech Tips and quarterly long-form Technical Notes with sample databases/applications, code, diagrams, and implementation guidance across infrastructure, connectivity, security, PHP/web integration, application architecture, troubleshooting, and developer tooling.
  • Presented technical sessions at multiple annual 4D Summit developer conferences.
  • Served as A/V liaison supporting conference technical infrastructure and live session operations.
  • Authored and delivered the commercial 4D Server Admin Training course, including a 90+ page technical manual and materials for a six-hour developer/administrator program.
  • Promoted from Technical Services Engineer (2006–2016).

Selected recorded 4D Summit sessions: 2018 — Determining Minimum Requirements for an Application · 2020 — A New Era of Debugging.

Selected public 4D work: 4D Connectivity Options, PHP ↔ 4D connectivity examples, Python ↔ 4D connectivity, and 4D developer macros.

4D, Inc. — Technical Services Engineer December 2006 – January 2016
  • Sole IT infrastructure administrator for U.S. operations, owning servers, networking, telephony, and workstation environments.
  • Architected, procured, deployed, and maintained clustered Hyper-V infrastructure virtualizing 30+ physical servers.
  • Designed and deployed Windows Server Update Services (WSUS) for centralized Windows server patch management.
  • Led selection, budget approval, deployment, and sole administration of Juniper SRX HA firewall architecture spanning DMZ/internal segmentation, NAT, site-to-site VPN, and remote-access VPN.
  • Maintained Fibre Channel SAN storage and validated restores across production backup systems.
  • Implemented BackupPC and later Barracuda backup infrastructure with restore validation.
  • Administered Microsoft Exchange 5.5 messaging infrastructure, including SMTP mail flow, message routing and delivery, message-store maintenance, and operational support.
  • Customized and maintained GNU Mailman services, including modifying Python code to support messaging operations and internal requirements.
  • Administered Active Directory, DNS, Linux services, Apache, Nginx, and HAProxy.
  • Designed and administered Asterisk PBX infrastructure, including IVR call flows, prompt recording, and ongoing telephony operations.
  • Built and documented 4D/Asterisk integration using PHP, Asterisk-PHP-API, and AMI, including AMI configuration and reusable wrapper functions.
  • Created a sample 4D UI for queue management, SIP/IAX peers, parked calls, call origination, channel/status queries, and Asterisk CLI commands.
  • Built a client/server file-transfer framework using 4D Execute on Server with chunked BLOB transfers, server-side browsing, progress reporting, pause/cancel, and multi-process handling.
  • Designed cross-platform 4D client-update automation using Windows batch/Robocopy and Mac shell/rsync workflows backed by network shares, including a script-generator utility for environment-specific deployment configuration.
  • Documented and implemented Apache reverse-proxy patterns for fronting 4D Web Server, including path-specific proxying, SOAP routing, full-site proxying, ProxyPass/ProxyPassReverse configuration, and WSDL deployment considerations.
  • Developed security-focused 4D examples for password hashing/salting, file-integrity verification, file fingerprinting, duplicate-file detection, and selectable hash algorithms using PHP integration.
  • Authored practical PHP/FastCGI troubleshooting guidance for 4D, including PHP EXECUTE, full-response/error inspection, CLI testing, module validation, ODBC/PDO/LDAP usage, and cross-platform interpreter diagnostics.
  • Supported SQL interoperability with Microsoft SQL Server, Oracle, MySQL, and PostgreSQL, troubleshooting vendor-specific syntax and validating queries in native database tooling.
  • Provided Tier III developer support including code reproduction, defect escalation, and technical training.
  • Served as A/V liaison at annual 4D Summits from 2008–2016 and presented technical sessions at the 2008, 2009, 2010, and 2011 Summits.
  • Managed the in-office datacenter and Mae West San Jose colocation facility.
  • Installed and supported Microsoft SQL Server environments and supported Oracle Database connectivity and integration.
NVIDIA Corporation (Contract) — Desktop Support November 2006
  • Supported enterprise end users at NVIDIA’s Santa Clara campus during a major company event.
  • Provided workstation troubleshooting, hardware deployment, account support, and rapid issue resolution in a high-demand environment.
Independent IT Consulting — Consultant July 2005 – November 2006
  • Provided IT consulting to small-business and home-office clients covering workstation deployment, network setup, and infrastructure troubleshooting.
  • Installed Cat5 cabling, routers/switches, printers, shared network resources, and basic server/file-sharing environments.
  • Performed system maintenance, malware remediation, and hardware upgrades to improve stability and performance.
Ireland San Filippo, LLP (Sensiba LLP) — Network Engineer March 2000 – July 2005
  • Designed and implemented a multi-tier Citrix MetaFrame terminal services environment for secure remote access.
  • Administered Windows and Linux servers and Microsoft Exchange 5.5 through 2003 messaging infrastructure supporting firm-wide email services.
  • Managed enterprise tape-backup operations across six Bay Area offices.
  • Implemented and maintained Track-IT Enterprise helpdesk system with MS-SQL backend.
  • Automated workstation patch deployment using Microsoft SUS server.
  • Implemented automated workstation deployment using Norton Ghost network imaging.
  • Participated in deployment of Hummingbird Document Management System.
  • Administered Altigen PBX and BlackBerry Enterprise Server.
  • Conducted security audits and infrastructure assessments.
Milestone Technologies, Inc. — De-Install / Re-Install Technician September 1999 – November 1999
  • Supported enterprise office relocation projects.
  • De-installed, transported, re-installed, and validated workstation and network equipment.
  • Tested connectivity and restored IT services at new locations.

Technical Publications & Knowledge Sharing

Authored an extensive body of 4D Knowledge Base material across more than a decade. This included recurring weekly Tech Tips for concise, practical guidance and quarterly Technical Notes: substantially larger engineering documents accompanied by sample databases or applications, code, diagrams, and implementation guidance. Also authored conference material and developer tools. The examples shown here are only a small representative sample of that larger body of work. Topics included infrastructure, security, client/server connectivity, PHP and web integration, application architecture, database integration, developer tooling, and production troubleshooting.

Representative work includes Error Handling with Call Chains, 4D Summit 2018: Determining Minimum Requirements for an Application, 4D Method Explorer, Mastering 4D Timeouts & Connectivity Settings, Asterisk and 4D via PHP in v12, Apache, Mod_Proxy, & 4D, IIS and ISAPI REWRITE, and File Transfers using Execute on Server.

Education

Heald College School of Technology
Associate of Applied Science (AAS), Computer Technology — Graduated with Honors
Minor: Electronics (circuit design, schematic simulation, oscilloscope labs)
San Jose, CA
Graduated October 2000

Professional Development

Cloud & Hybrid Infrastructure
  • Instructor-led Microsoft Azure administration training covering hybrid identity, resource governance, and production workload management.
Virtualization & Secure Access Architecture
  • Ongoing applied experience designing virtualization clusters and secure access boundaries.
  • Citrix administration training supporting multi-tier terminal services and secure remote access environments.
Automation & Infrastructure as Code
  • Continuous applied development of automation workflows, scripting, and infrastructure-as-code practices.
Enterprise Security & Identity
  • Formal vendor training supporting enterprise MFA and privileged access management implementations.
  • Security platform administration training emphasizing endpoint protection lifecycle and operational hardening.
Enterprise Systems Engineering
  • Advanced application-building training supporting Tier III escalation, structured troubleshooting, and systems analysis.

Certifications

Verified digital credentials: Credly profile.

License

FCC Amateur Radio — General Class License
Current Call Sign: KO6MRL
Originally Issued 2012 (KJ6VTR), Renewed 2026

Contact

Let’s talk infrastructure.