Nelson Thomas

Nelson Thomas

Engineering student at INP ENSEEIHT, apprentice in networks and cybersecurity

I keep networks running and find out when someone is trying to break in. From SOC alert triage to Proxmox clusters, I like work where a script or a well-read log saves real time.

$ traceroute nelson-thomas
1ups-toulouse2022Maths & CS double degree, year 1
2iut-blagnac2023BUT Networks & Telecom, cyber track
3iut-blagnac.lab2025Network technician intern
4itrust.soc2026SOC analyst L1 intern
5enseeiht.n72026Engineering apprentice, 3 years

I bring both sides of a network: I build the infrastructure, and I've sat in a SOC watching what attacks on it look like.

First year of the Computer Science & Telecom engineering degree at N7, alternating between school and company as an apprentice.

Certified

Cisco CCNA: Switching, Routing and Wireless Essentials. Cisco Ethical Hacker. TOEIC 845.

Heading for

Defensive security: detection engineering, SOC and secure network architecture.

Toolbox

Code and scripting

  • C
  • Python
  • Bash
  • HTML
  • CSS

Systems and virtualisation

  • Linux
  • Proxmox
  • VMware
  • Docker
  • Windows Server

Networks and security

  • TCP/IP
  • VLAN
  • OSPF / RIP
  • NAT & ACL
  • IPsec VPN
  • DMZ
  • Wireshark
  • Nmap
  • SIEM: Wazuh, Reveelium
  • EDR
  • IDS / IPS
  • Fortinet
  • iptables

Background

My studies and my work experience, most recent first.

Education

  1. Entrance of INP ENSEEIHT, Toulouse
    2026 – now

    Engineering degree in Computer Science & Telecom (SN), apprenticeship track

    Three-year engineering programme alternating between school and company.

  2. Students at IUT de Blagnac
    2023 – 2026

    Bachelor of Technology (BUT) in Networks & Telecommunications

    Cybersecurity track. Projects: multi-site MPLS network with IPsec VPN and IPv6, VoIP infrastructure for a healthcare practice, secured information system.

  3. Université Paul Sabatier main building, Toulouse
    2022 – 2023

    Double Bachelor's in Mathematics & Computer Science, first year

    Programming in C and Python. Moved to a more hands-on networks and security path after the first year.

  4. Lycée Ernest Ferroul, Lézignan-Corbières
    2019 – 2022

    French Baccalauréat (general), with highest honours

    Mathematics and Economics & Social Sciences, with the Advanced Mathematics option.

Experience

  1. 2026 – now

    Apprentice engineer, networks & cybersecurity

    Apprenticeship with INP ENSEEIHT

    Three years alternating between the engineering school and the company.

  2. ITRUST security operations centre
    Mar – Jun 2026 · 12 weeks

    SOC Analyst (Level 1), intern

    • Triaged and qualified alerts from the Reveelium SIEM and EDR platforms, investigated and correlated events, notified clients.
    • Extended the client knowledge base with new alert signatures and analysis guidelines.
  3. Apr – Jun 2025 · 10 weeks

    Network Technician, intern

    • Deployed and managed VMs on a high-availability Proxmox cluster.
    • Automated lab re-imaging with a Bash script and the FOG PXE API: 60 → 10 minutes.
    • Set up the Wazuh SIEM and hardened the lab system images.

Details of these missions are in Projects.

Projects

Each project follows the same frame: the context, what I did, the tools, and what came out of it.

Internships

Automated lab re-imaging

IUT de Blagnac, network technician intern, 2025
Context
Lab machines had to be re-imaged by hand between classes.
My part
Wrote a Bash script driving the FOG PXE API to redeploy images automatically.
Result
Redeployment time cut from 60 to 10 minutes.
BashFOG PXEProxmox HA
View the code on Gitea (opens in a new tab)

Wazuh SIEM deployment

IUT de Blagnac, 2025
Context
No central view of security events on the teaching network.
My part
Configured Wazuh, onboarded hosts, hardened the lab system images.
Result
Network incidents now detected and logged centrally.
WazuhLinuxHardening

Security alert triage

ITRUST, SOC analyst L1 intern, 2026
Context
Managed security service watching client environments.
My part
Qualified SIEM and EDR alerts, correlated events, notified clients.
Result
Client wiki extended with new alert signatures and analysis tips.
Reveelium SIEMEDRIncident analysis

Academic

Multi-site MPLS network

IUT

MPLS backbone with IPsec VPN and IPv6 between sites, simulated in GNS3.

MPLSIPsecIPv6GNS3

VoIP for a healthcare practice

IUT

Full ToIP infrastructure for a paramedical practice, running on a type 1 hypervisor.

ToIPVirtualisation

Securing an information system

IUT, SAÉ 4.1

Small network secured with VLAN segmentation, VRF and firewalling.

VLANVRFFirewall

Career

I'm aiming for defensive security: detection engineering, SOC work and secure network architecture. Here is where to find my CV and follow my path.

LinkedIn

My up-to-date profile, experience and recommendations.

View my profile

Mobility

Seventeen weeks abroad during my final year. Three destinations I am considering, and why each one fits.

Tallinn, Estonia

Option 1

Home of the NATO cyber defence centre and one of Europe's most digitised states.

Montréal, Canada

Option 2

Large cybersecurity sector, French and English working environment.

Dublin, Ireland

Option 3

European base for many cloud providers, full English immersion to push past B2.

Passions

Self-hosting

I run web services and a private cloud on my own NAS and a friend's, and handle their security and administration. Everything is deployed as containers with Docker Compose. Gitea and BentoPDF are public: click to try them.

Offensive training

Hack The Box Academy, TryHackMe and Root-Me: learning how attackers think so I defend better.

Photography

Nature, wildlife and landmarks, including drone shots.

Geopolitics

Following world affairs, which often explains the threats a SOC ends up seeing.

Civic engagement

Volunteering and awareness actions, with a goal of forty hours over my engineering degree.

5 of 40 hours completed

Poster of the play Le Procès de King-Kong

Le Procès de King-Kong

3 h
Interactive theatre,

An interactive play about sexual and gender-based violence. The audience takes part in the story, which opens a discussion on how to recognise this violence, react as a witness and support the people affected.

AwarenessSexual & gender-based violence
Volunteer in gloves picking up a plastic bottle from the grass

Clean walk in Toulouse

2 h
Volunteer litter pick-up,

A group walk through the streets of Toulouse to collect litter and keep it out of drains and green spaces.

EnvironmentLocal action

Contact

An apprenticeship question, a project, or just a chat about security? Use the form and I'll reply within a few days. My code is on my Gitea.