Skip to content
Teodor Ivanov

I build networks that stay up and keep attackers out. Nine years of it, most recently at a telecoms operator.

Resilient

Meticulous

Hardened

Auditable

These are the properties I design for. A network that only works on a good day isn't finished, so the failure modes get mapped before they happen rather than explained afterwards. Meticulous is the difference between a firewall policy that passes an audit and one that passes traffic it shouldn't. Default is deny, and every exception has a name attached to it. Whoever inherits the estate can read what I changed and why, without calling me first. I like the work at the edges: the asymmetric route, the legacy rule everyone is afraid to delete. Most incidents I get called into were not clever attacks. They were something ordinary that nobody had thought to write down.

Engagements

FIREWALL MIGRATION schematic diagram

FIREWALL
MIGRATION

Perimeter at end of support, rule base unaudited for years. Rebuilt the policy from hit counts, dropped the dead rules, converted the rest to App-ID, then cut over to an HA pair.
MPLS L3 VPN ROLLOUT schematic diagram

MPLS L3 VPN
ROLLOUT

Separate routing per business unit over one shared core. VRFs and MP-BGP carry it, route targets decide what each VRF imports. BFD catches a dead link before the BGP hold timer does.
NETWORK SEGMENTATION schematic diagram

NETWORK
SEGMENTATION

Flat network, every host reachable from every other. Split it into zones enforced at the access edge, then worked the east-west matrix rule by rule until only named paths were left.

Network and Security

  • Cisco
  • Fortinet / FortiGate
  • Palo Alto Networks
  • Juniper
  • Linux
  • Windows Server
  • Wireshark
  • Splunk

Cloud and Infrastructure

  • AWS
  • VMware
  • NGINX
  • Cloudflare
  • Grafana

Automation and Tooling

  • Python
  • Bash
  • PowerShell
  • Ansible
  • Docker
  • Postman
  • GitHub
  • VS Code
  • Vercel
  • Figma

Software Development

  • TypeScript
  • React
  • Next.js
  • Tailwind CSS
  • Node.js
  • Laravel
  • Composer
  • PostgreSQL

Work history

Network and security consultant, nine years in production infrastructure. Next-generation firewalls, MPLS L3 VPN and BGP design, segmentation and business continuity, from the first audit through to cutover. I also write the tooling that runs alongside it, mostly scanners and config management. Knowing how the applications on a network are built changes how you defend it.

A1 Telekom

Network and Security Engineer

2025–Present

Architect, secure, and manage scalable network infrastructures, specializing in next-generation firewall deployment, proactive business continuity, and the end-to-end integration of complex MPLS L3 VPNs and BGP peering.

Cisco

Senior Voice and Security Engineer

2023–2025

Architect and defend large-scale IP infrastructures through advanced firewall configuration, proactive vulnerability management, and the seamless integration of cross-platform security controls.

Freelance

Full Stack Developer

2020–Present

Building the tooling side of the practice: secure APIs, hardened deployments, and custom automation for scanning, reporting, and configuration management, owning the full lifecycle from planning to production.

Zertios

NOC Engineer

2017–2020

Secured and optimized global network footprints by managing the end-to-end administration of Windows/Linux servers and resolving high-tier L2/L3 infrastructure incidents.