Independent engineering portfolio

Security architecture.
Built, tested,
documented.

I’m Jamal Wheeler, a Security Consulting Manager specializing in Cloud & Infrastructure Security. My independent lab brings architecture, controlled delivery, and recovery validation into one practical environment.

Chicago, Illinois Network & infrastructure security

Architecture sketchIndependent lab
Private application architecture with controlled delivery and recovery Private clients reach an ingress layer. Selected applications integrate with an identity provider. Application networks connect to durable state. Reviewed Git definitions support delivery, and isolated restore checks validate recovery. PRIVATE CLIENTSPrivate DNS & access INGRESS LAYERHTTPS reverse proxy IDENTITYSelected-app SSO APPLICATIONSDedicated networks DELIVERYReviewed Git DURABLE STATEData & recovery copies RECOVERYRestore checks DECIDE → DELIVER → VERIFY
Illustrative design, with operational addresses omitted. Identity integration applies to selected services.

Documented lab milestones

September 2026 validation

130Application stacks migrated
to Git-managed definitions
88SQLite integrity checks
in recovery validation
5Database technologies
with native restore probes

Selected engineering work

Decisions with
verification behind them.

Three independent lab case studies showing how I approach security, delivery, and operational resilience.

01Deployment governanceSeptember 2026

Bring application delivery
under version control.

Migrated 130 registered application stacks to Git-managed Compose definitions while preserving workload states and existing image versions.

Docker ComposeForgejoDockhandRenovate
Read the case study

Challenge

Move individually managed application definitions into a consistent, reviewable workflow without combining source migration with software upgrades.

Design decisions

  • Track Compose definitions in Git and retain protected environment values outside the repository.
  • Require reviewed dependency proposals, human approval, and a separate deployment step.
  • Preserve image identities, mounts, data paths, and intended running or stopped states.

Validation & outcome

The completion audit covered 130 stacks and 311 containers. Renovate validation covered 291 image references with zero errors and zero lookup failures. Source synchronization and runtime deployment were verified separately.

Evidence: migration completion, estate audit, dependency dry run, and manual-control reports.

02Recovery engineeringSeptember 2026

Validate recovery
before the next change.

Established recovery checks appropriate to each application's state, with isolated restore exercises and engine-specific database verification.

ZFSSQLitePostgreSQLMySQL / MariaDBMongoDB / Redis
Read the case study

Challenge

A retained archive or snapshot alone does not establish that an application can be recovered. Different databases and local images need different checks.

Design decisions

  • Quiesce application writers and retain consistent recovery generations.
  • Use isolated clones and native database probes rather than testing against production state.
  • Validate local-image recovery through checksummed save/load archives.
  • Document application-specific rollback and distinguish data recovery from image rollback.

Validation & outcome

Documented 127 cold-recovery generations and three representative recoveries. Checks included 88 SQLite integrity checks and native restore probes for PostgreSQL, MySQL, MariaDB, MongoDB, and Redis.

Evidence: estate recovery summary, isolated restore reports, and the recovery runbook.

03Private application architectureAugust–September 2026

Define access boundaries
at every layer.

Designed private application patterns combining reverse-proxy ingress, dedicated backend networks, centralized DNS, and identity integration for selected services.

CaddyTechnitium DNSAuthentikOIDCDocker networking
Read the case study

Challenge

Make self-hosted services accessible to their intended users while keeping backend services private and preserving a recovery path for authentication.

Design decisions

  • Place selected applications behind HTTPS reverse-proxy ingress without publishing their backend ports.
  • Use dedicated application networks and private DNS records.
  • Apply group-restricted OIDC integration where appropriate and retain native recovery accounts.
  • Document authentication requirements per application instead of assuming one access model fits every service.

Validation & outcome

Verified private DNS on both resolver nodes, TLS and application health, and denied-access behavior for a representative private application. A separate identity-integrated service passed browser SSO; native recovery credentials were retained.

Evidence: private ingress acceptance checks and identity-integration deployment notes. Browser and server checks were recorded separately.

Working approach

Architecture is a decision.
Operations prove it.

The same habits guide each lab project: define the boundary, control the change, and verify the result.

  1. 01 / Define

    Make boundaries explicit.

    Identify users, ingress, application networks, identity requirements, and durable state before deployment.

  2. 02 / Control

    Keep changes reviewable.

    Separate source updates, image upgrades, deployment, and data migration. Keep rollback procedures tied to the change.

  3. 03 / Verify

    Test the recovery path.

    Check runtime behavior and restored data. Record the limits of each test alongside its result.

Professional context

Consulting delivery.
Independent engineering.

My professional experience at Accenture includes enterprise SASE and firewall migrations, per-application segmentation, Prisma Browser proofs of concept, Fortinet operations, and client architecture presentations.

This portfolio documents completed independent lab projects. Their case studies and milestones are recorded separately from my professional client engagements.

Let’s connect

Talk architecture,
security, and delivery.

jamal.wheeler@outlook.com

For consulting opportunities, project discussions, or a copy of my professional resume.