Portrait of Matt Haave

Matt Haave

Infrastructure · Automation · Systems

Omaha metro, Nebraska · open to remote

I build and operate systems, and I care most about the part where they keep running without anyone watching. Twenty years around technology and the people who use it; the last stretch spent going deep on infrastructure.

What I do

I design, build, and run a private compute environment end to end — self-healing services, scheduled automation, monitoring that tells me when something is wrong, encrypted backups, and locally-hosted AI models. It spans several machines and it stays up on its own.

Before that, and alongside it, I built the internal tools people actually use day to day: intranet spaces, CRM pages, and small utilities that remove repeated manual work. The hard part of an internal tool is rarely the technology — it's understanding the work well enough that nobody needs training to use it.

How I work

A claim you can't execute is a guess. Everything I build has a test that tries to break it, and nothing counts as working until that test passes. I reboot the machine rather than assume the service comes back.

I use AI models as a force multiplier and say so plainly. They collapse the distance between not understanding something and having a working version to test. They don't decide what to build, and they don't carry the responsibility when the result is wrong — that part stays mine.

Working with

  • Linux
  • Containers
  • systemd
  • Mesh networking
  • Monitoring & alerting
  • Encrypted backups
  • Bash & Python
  • Self-hosted LLMs
  • Hardware & imaging
  • Zero-trust & hardware-key access
  • Identity & device provisioning
  • System hardening
  • DNS, TLS & web hardening
  • Microsoft 365 / SharePoint
  • Web (HTML/CSS)

Selected work

A private environment that runs itself

ongoing

Several machines operating as one system: services that restart themselves when they fail, scheduled jobs that keep running whether or not anyone is watching, and alerting that reaches my phone when something needs a human. Measured by how rarely I have to touch it.

Encrypted backup and restore, end to end

ongoing

Automated encrypted backups with offsite copies, and — the part most backup setups skip — restores that get tested. A backup nobody has restored from is a rumour, not a backup.

Continuous integrity checking

ongoing

Scheduled verification that the machines are in the state I left them in, with anything unexpected surfaced rather than logged and forgotten. Built after learning the hard way that a check which can't fail is not a check.

Hardware-key authentication across the estate

2026

Phishing-resistant hardware-key sign-in standardised across services, so access depends on something physically in hand rather than a password that can be replayed.

Locally-hosted AI inference

ongoing

Language models running on my own hardware, so the capability works with no external service in the loop and nothing leaving the network.

Internal tools people actually use

ongoing

Dashboards, generators, and small utilities that remove repeated manual work. The measure I care about is whether anyone needed training.

Earlier work — production & communications

Documents

Reach me directly — [email protected], or message me on LinkedIn (open my profile and choose Message; connecting first isn't necessary). I answer both.

Code and builds: github.com/haavem

Professional references are available on request — I'll send them over, and give my referees a heads-up that you'll be in touch.

What I'm looking for

Individual-contributor work on teams that measure results rather than hours. Remote preferred; on-site in the Omaha–Bellevue metro works too. I'm most useful where the job is making infrastructure and access dependable for the people who rely on it.

  • Enterprise / Corporate Infrastructure Engineer
  • Internal Tools Engineer
  • Platform Engineer
  • Infrastructure Engineer
  • Systems Engineer
  • Security Engineer (Infrastructure)
  • Identity & Access Engineer
  • Automation Engineer
  • IT Operations Engineer

Public sector & defense. U.S. citizen, based minutes from Offutt AFB, and open to roles that sponsor a security clearance. Actively working toward CompTIA Security+ for DoD 8140 / 8570 IAT Level II compliance.

The work I do on my own time maps closely to federal IT: Linux administration, network segmentation, monitoring and integrity checking, restore-tested encrypted backups, and hardware-key access control — all documented well enough that someone else could run it.

A record of being trusted with sensitive information. I spent a decade in direct support of adults with developmental disabilities — work that required background vetting, strict confidentiality, and mandatory reporting, with real consequences for shortcuts. I then spent four years at a health information exchange operating under HIPAA, where protected health information and its handling rules were the daily context of the job.

Across both, I worked alongside state, regional and federal agencies and their vendors — public health, human services, provider networks and the contractors serving them. I am used to environments where access is scoped, disclosure is governed, and the rules are not optional.

  • IT Specialist (SYSADMIN) — GS-2210
  • IT Specialist (NETWORK) — GS-2210
  • IT Specialist (INFOSEC) — GS-2210
  • Systems Administrator (cleared contractor)
  • Cyber Defense Analyst
  • Clearance sponsorship welcome
  • Private / air-gapped AI deployment
  • HIPAA
  • Background-vetted
  • Confidential information handling
  • State & regional agency experience

What I can do

If a report can be defined, I can make it happen. That is the whole loop: work out what question is actually being asked, find where the data lives, get it out of whatever it is trapped in, shape it into something that answers the question, and put it in front of the person who has to decide — on a schedule, without anyone re-running it by hand.

On my own systems: tens of thousands of records parsed, classified and made searchable; monitoring that notices when a service stops telling the truth; encrypted backups that I then restored from to prove they worked; hardware-key access in front of the parts that matter. In my current role I have built internal pages and small tools on my own initiative to take repetitive manual steps out of a quoting workflow.

Formats are not a barrier. If a computer can open, edit or export it, I can get the data out of it and into something usable. Where a tool does not exist I write one, and I prefer open source so the result is not hostage to a licence.

Local AI, run privately. I deploy and operate open-weight language models on hardware I own — model serving, routing between models by cost and capability, grounding one in a private corpus so it answers from your data rather than guessing, and sandboxed tooling that lets it act without handing it the keys. It runs fully offline: no third-party API, nothing leaving the network. For an organisation that cannot send its data to someone else’s inference endpoint, that distinction is the whole point.

Where I stop. I deploy and build on models; I do not train them. No fine-tuning, no architecture work, no statistical modelling, and I will not pretend otherwise in an interview. If you need someone who can defend a validation methodology, that is a different hire. My production experience is also my own environment plus internal tooling at previous employers — not a fifty-person team and a nine-figure estate. Better you know now than in month three.

What I am reliably good at: the plumbing and the discipline around it — making the pipeline dependable, making the access defensible, and writing it down so the next person is not stuck asking me. I also learn fast, and I would rather show it than say it: I went from no infrastructure background to running a multi-machine environment in production, solo, in about six months.

The range. I am a generalist who ships. Over about twenty years that has meant video and audio production on deadline for regional broadcast, photography and graphic work, WordPress and hand-written HTML and CSS, internal intranets and CRM spaces on SharePoint and Salesforce, and now Linux, networking, VPN and mesh, containers and automation.

The through-line is not the tools. It is that I take something complicated, get it working end to end on my own, and then make it understandable to whoever has to live with it. That is the same skill whether the output is a thirty-second spot, a quoting workflow, or a network that has to stay up.

What breadth costs. I am not the deepest specialist you will interview in any single one of those. If you need ten years of nothing but Kubernetes, or a broadcast editor who does only that, there are better hires and I would rather you find them.

Where it pays. Small teams, internal tooling, and the jobs that fall between two departments and never get owned. If the work is ‘figure out what this actually needs to be, build it, and explain it to the people who did not ask for it’, that is the thing I am genuinely good at.

Background

Infrastructure & automation — independent

2026 – present

Designing and operating a multi-machine private environment: automated backups, monitoring, self-healing services, and local AI inference.

Lighting quotations specialist

2026 – present

Technical quoting for the lighting industry. Built internal pages and tools on my own initiative for the team I work with.

Content & marketing specialist — nonprofit health data organisation

2022 – 2026

Ran the internal intranet and CRM spaces a whole staff relied on. Translated complex technical capability into language people could act on.

Creative services & real-time desk — regional broadcast

2015 – 2021

Live production and content under deadline.

B.S., Broadcasting & Communications — University of Nebraska at Omaha

magna cum laude

Plus a decade of direct support and hardware repair work.

Profile

Contact