PANAGIOTIS ZERMPINOS
Technical Operations Engineer | Cybersecurity
Kept critical law enforcement infrastructure running nationwide for 3+ years: 50+ forensic instruments, a €3M project, and 99.5% uptime across Greece. Now bringing that operational discipline into cybersecurity and IT operations.
Impact
Experience
Application & Technical Support Engineer
End-to-end technical operations for a ~€3M national law enforcement project and biomedical systems across Greece.
- Critical Infrastructure: Sole technical owner of 50+ criminal photography instruments nationwide, maintaining 99.5% uptime with same-day incident response
- L1/L2 Support: Rapid triage and resolution for security-critical systems in law enforcement environments
- Security & Compliance: Owned Anti-Bribery Policy and maintained multi-ISO standard compliance (ISO 27001, 9001, 13485)
Mechanical Engineer, External Partner
Office-based investigation of electricity theft cases across Greece's national distribution network. Processed around 20 cases per day (roughly 3x the team average) in an 8-person team, identifying theft sources and losses across residential and commercial accounts.
Electrical Systems Technician
Executed UPS, PV, and electrical automation installations across 9 industry verticals (Defense, Maritime, Healthcare, Energy, Telecom and more) under ISO 14001 and ISO 45001 compliance. Delivered projects for enterprise clients including Cisco and Cordia in a 5-person team reporting directly to CTO.
Technical Skills
Cybersecurity & Forensics
IT Operations & Support
Development & Automation
Quality & Compliance
Education
Cyber Security 101 Path
Structured hands-on training covering core cybersecurity domains: networking fundamentals, Linux, web security, exploitation basics, and security operations. Practical lab-based curriculum.
Integrated Master's in Mechanical Engineering
Five-year integrated master's programme covering mechanical systems, thermodynamics, energy engineering, and applied data analysis.
Thesis: Energy performance evaluation of solar-assisted heat pump with photovoltaic-thermal (PVT) collectors for residential dwellings in Greece. Combined TRNSYS thermal simulation with MATLAB data analysis to model and optimise system configurations across Greek climate zones.
Projects & Learning
Armani Katehano Basketball Stats Platform
Statistics, scheduling, and roster-management web app for an amateur basketball team. Serves three audiences: public visitors browsing season stats and upcoming-game rosters, admins with full CRUD and automated box-score ingestion, and a head coach with a separate portal for publishing roster announcements.
- Automated box-score pipeline: discovery service crawls league listings, matches opponents via Greek-to-Latin transliteration and Levenshtein distance, scrapes and classifies the page, then persists stats and recomputes season aggregates transactionally
- Strict Edge/Node runtime split enforced by ESLint import rules, a custom node-only poison-pill marker, and a post-build CI scan of the middleware bundle for Node built-ins
- Admin portal with HMAC-signed sessions, TOTP, CSRF tokens, and per-IP brute-force rate limiting; coach portal with separate credentials and session secret
- Double opt-in email newsletter (Nodemailer + Brevo SMTP) with Cloudflare Turnstile CAPTCHA, token-based unsubscribe, and daily subscriber-purge cron
- Stored totals and averages computed from raw DB sums via Prisma transactions; never approximated from averages
- Strict CSP with per-request nonce, SSRF allow-list with DNS-resolution guard, and Sentry error tracking across server, Edge, and client
- CI covers lint, build, Vitest unit and integration tests, Playwright E2E, Semgrep static analysis, Gitleaks secret scanning, and a daily npm audit; hourly GitHub Actions heartbeat drives the discover-and-import cron independently of Vercel plan limits
Network-Wide Ad Blocking & Privacy Protection
Deployed a Docker-based Pi-hole infrastructure protecting 5+ devices from 350k+ malicious domains (ads, trackers, malware, and phishing) with zero per-device configuration per machine.
- Containerised Pi-hole via Docker with persistent config across restarts
- DHCP server configured so all devices route DNS through the filter automatically
- 4 curated blocklists with daily auto-updates covering ads, trackers, malware, and phishing
- 6 device-specific security policies, from light filtering to maximum IoT lockdown
- 350k+ malicious domains blocked network-wide with zero per-device setup
TryHackMe: Cybersecurity Training
Hands-on cybersecurity labs covering penetration testing, digital forensics, network security, and SOC operations. Practical skill-building in realistic attack and defence scenarios.
HackTheBox: Penetration Testing Labs
Working through HackTheBox machines and challenges to develop practical offensive security skills. Focused on privilege escalation, enumeration, and vulnerability exploitation.
Advent of Code 2024 & 2025
Annual algorithmic programming challenge solved in Python. 9 days in 2024, 8 days in 2025. Covers graph traversal, dynamic programming, parsing, and optimisation.
Personal Linux Security & Hardening
Daily-drives Linux as primary OS with regular Lynis security audits. Applied hardening practices to personal and friends' machines, covering common attack surfaces and misconfigurations.
100 Days of Code: Python Bootcamp
Intensive Python programming course covering automation, scripting, APIs, data processing, and machine learning with PyTorch. Applied to real-world scenarios including system automation tasks.
MSc Thesis: Energy System Modelling & Optimisation
Simulated and evaluated solar-assisted heat pump systems with PVT collectors for Greek residential buildings. Combined TRNSYS thermal simulation with MATLAB data analysis to optimise system configurations.
Get In Touch
Open to roles in cybersecurity, IT operations, and technical support. If you're looking for someone who bridges engineering precision with security operations, let's talk.