Seeking an apprenticeship · Toulouse & across France

Infrastructure, Networking & Security.

2nd-year student in the BTS SIO (SISR track), a two-year French IT degree roughly equivalent to a U.S. associate degree. I'm seeking a paid work-study apprenticeship during the final year of a bachelor's degree (Licence Pro or L3) in infrastructure, systems and networking. I already run a physical and real personal infrastructure: an HP ProLiant server on Proxmox VE, up 24/7 and reachable only over a Tailscale VPN. My long-term goal is to move into cloud engineering and cybersecurity, ideally in an international environment.

// Target environments: aerospace & defense (Airbus, Thales), IT services & consulting (Sopra Steria, CGI, Capgemini), cyber defense (Orange Cyberdefense).

bash - root@homelab
▸ Seeking a Bachelor's-Level ApprenticeshipInfrastructure • Cloud • CybersecurityToulouse • Opportunities Across France
01

Expertise

Two areas of focus: building infrastructure, then monitoring and securing it.

INFRASTRUCTURE

Building segmented foundations with secure remote access.

  • → Virtualization and containerization with Proxmox VE and Docker.
  • → Routing and switching (Cisco NetAcad, VLANs, trunking).
  • → Firewalls and remote access (pfSense, OPNsense, Tailscale, IPsec).
  • → Directory services with Active Directory: domain, GPOs, DNS/DHCP (see the AD Lab).

SECURITY & MONITORING

Limiting exposure and keeping visibility into what happens on the infrastructure: least privilege, segmentation, centralized logs.

  • → Centralized logging.
  • → Real-time monitoring with Grafana, Loki and Syslog.
  • → Secure web publishing behind reverse proxies (Nginx, Caddy).
  • → Events I follow: failed SSH logins, blocked traffic, application errors (see Monitoring).
02

Selected Projects

Environments I build and maintain in my homelab to practice real enterprise infrastructure problems.

Vintrack: Automation Project

View the architecture

Automation project hosted on Proxmox and deployed with Docker: Linux services, a PostgreSQL database, a Redis cache and remote access through Tailscale.

// Skills demonstrated: deploying Docker services, databases, networking, Linux administration.

Docker Proxmox VE PostgreSQL Redis Linux Tailscale

Multi-Site Network Lab

View the topology

A virtualized network spread across several sites: VLANs, inter-VLAN routing, firewall filtering and site-to-site traffic over an IPsec VPN.

// Skills demonstrated: segmentation, filtering, site-to-site VPN.

pfSense Cisco IOS VLAN & Trunking IPsec VPN

Log Monitoring & Centralization

View the pipeline

Logs from network devices and servers are centralized with Syslog and Loki and viewed in Grafana dashboards.

// Skills demonstrated: log centralization, monitoring, log analysis.

Grafana Loki Syslog Debian Linux
03

Active Directory Lab

A lab Active Directory domain: centralized identities, permissions and policies, following the principle of least privilege.

LAB SCOPE

  • → Deployment of Windows Server (AD DS, DNS, DHCP) on a Proxmox VM.
  • → Organizational Unit (OU) tree, accounts and groups, using the AGDLP model for permissions.
  • → GPOs (Group Policy): password policy, workstation restrictions, mapped network drives.
  • → Windows client machines joined to the domain and administered with PowerShell.
  • → Hardening: separate admin accounts, auditing of security events (4624, 4625, 4740).

// Next step: forward Windows events to the Loki / Grafana stack.

Windows Server Active Directory DNS / DHCP GPO PowerShell
Discuss this lab
// ad-structure.ps1
corp.lab
├─ OU=Utilisateurs    (Users)
│  ├─ OU=Direction    (Management)
│  └─ OU=Support-IT   (IT support)
├─ OU=Postes          (Workstations)
├─ OU=Serveurs        (Servers)
└─ OU=Groupes         (Groups)
   ├─ GG_Support_IT   (Global)
   └─ DL_Partage_RW   (Domain Local, share R/W)
PS> New-ADOrganizationalUnit -Name "Serveurs" -Path "DC=corp,DC=lab"
PS> New-ADGroup -Name "GG_Support_IT" -GroupScope Global
PS> Get-WinEvent -FilterHashtable @{LogName='Security';Id=4625} -MaxEvents 5
04

Homelab Infrastructure

My testing ground: a Proxmox VE server hosting my labs and services, reachable only over a Tailscale VPN.

root@SRV-PM: ~
root@SRV-PM:~# fastfetch
root@SRV-PM
───────────
OSProxmox VE 9.2.11
HostHP ProLiant ML150 G6
CPU2x Intel Xeon E5504
Memory25 GB
VirtualizationProxmox VE
Availability24/7
LocationSecured room · air-conditioned · controlled physical access
VPN AccessTailscale (only)
Exposed ports0 (no port open to the Internet)
MonitoringGrafana + Loki
ServicesAD · DNS · DHCP · Docker · Nginx · Caddy · PostgreSQL · Redis · OPNsense / pfSense

// Used daily for my personal projects.

// architecture.txt (simplified diagram)
Internet
   │
┌──┴─────────┐   IPsec    ┌────────────────┐
│  pfSense   ├────────────┤  Remote site   │
└──┬─────────┘            └────────────────┘
   │ trunk 802.1Q
┌──┴─────────┐
│ Switch     │
│ Cisco      │
└─┬──┬──┬──┬─┘
  │  │  │  │
  │  │  │  └─ VLAN MON  : Loki · Grafana · Syslog
  │  │  └──── VLAN LAB  : AD Lab · Network Lab
  │  └─────── VLAN SRV  : Docker · Nginx/Caddy · PostgreSQL · Redis
  └────────── VLAN MGMT : Proxmox VE (SRV-PM)

Tailscale: encrypted remote access (mesh)

DESIGN PRINCIPLES

  • Segmentation first

    One VLAN per purpose (management, servers, lab, monitoring), with filtering rules on the firewall.

  • Remote access without needless exposure

    Tailscale and IPsec handle remote administration and site-to-site links, instead of services exposed to the Internet.

  • Everything is observable

    Logs are centralized with Syslog and Loki and viewed in Grafana.

  • Virtualization and containers

    A Proxmox VE server, containerized services with Docker, published through Nginx or Caddy.

Proxmox VE pfSense Tailscale Docker Nginx / Caddy
04.1

Ongoing Improvements

The infrastructure keeps evolving: availability, redundancy and monitoring.

Active Directory Redundancy
[ IN PROGRESS ]

Adding a second domain controller to remove the directory's single point of failure.

Multi-Site Architecture
[ IN PROGRESS ]

Extending the inter-site lab, with sites linked by IPsec VPN.

Service Continuity
[ IN PROGRESS ]

Identifying critical services and what must stay available during an outage.

Monitoring Improvements
[ IN PROGRESS ]

Windows events into Loki / Grafana, plus more targeted alerts.

05

Monitoring & Logging

Collect logs, make them readable and spot abnormal behavior.

1. Sources

pfSense firewall, Linux servers, reverse proxies.

2. Collection

Centralized Syslog: a single entry point for all logs.

3. Storage

Loki indexes logs by label for fast queries.

4. Analysis

Grafana dashboards and alerts to visualize and respond.

EVENTS I FOLLOW

  • → Repeated failed SSH login attempts (brute force).
  • → Traffic blocked by pfSense, grouped by source.
  • → Application error spikes on Nginx and Caddy.
// queries.logql
# SSH failures over 5 minutes
count_over_time({job="sshd"} |= "Failed password" [5m])
# Hosts logging the most errors
topk(5, sum by (host) (rate({job="syslog"} |= "error" [5m])))
06

Certifications & Training

What I've completed, what I'm studying now, and the certifications I'm aiming for.

// COMPLETED CERTIFICATIONS & COURSES
ANSSI – SecNumacadémie

Online course from ANSSI, the French national cybersecurity agency: security awareness, operational security, best practices and digital risk management.

Introduction to the EBIOS Risk Manager Method

Fundamentals of risk analysis and threat management, using the risk-assessment method published by ANSSI.

CNIL – GDPR

Personal data protection and regulatory compliance, from the French data protection authority (CNIL).

GDPR Certificate of Completion

Data governance principles.

OpenClassrooms – Introduction to Cybersecurity

Overview of the threat landscape and how systems are defended.

OpenClassrooms – Python Programming Basics

Automation, scripting and programming logic.

// CURRENT STUDIES
BTS SIO – SISR track
[ IN PROGRESS ]

Two-year French higher-education diploma in IT, roughly equivalent to a U.S. associate degree: infrastructure, systems, networking, virtualization.

Cisco Networking Academy
[ IN PROGRESS ]

Routing, switching, VLANs, networking fundamentals.

// GOALS
Cisco CCNA
[ PRIORITY ]

Networking: routing, switching, VLANs.

CompTIA Security+

Cybersecurity fundamentals.

Microsoft SC-900

Security, compliance and identity fundamentals.

Cisco CCNP Enterprise
[ MID-TERM ]

Enterprise networking.

Infrastructure→Networking→Cloud→Security
07

Career Roadmap

A clear direction: start from infrastructure, move up to networking and then cloud, and secure everything I build.

  1. NOW

    BTS SIO SISR, 2nd year

    Strengthening my systems and networking foundations through hands-on labs: Active Directory, homelab, monitoring.

  2. NEXT STEP

    Infrastructure / Networking Apprenticeship

    Joining a team, in Toulouse or elsewhere in France, to learn on real systems: operations, incident handling, hardening and documentation.

  3. THEN

    Bachelor's Degree in Infrastructure or Cybersecurity

    Going deeper into networking and infrastructure security, and validating my skills with the CCNA, then Security+.

  4. THEN

    Cloud & Security

    Extending my infrastructure skills to cloud platforms and cloud security.

  5. LONG-TERM GOAL

    Moving into cloud engineering and cybersecurity

    Long-term goal: designing and securing cloud infrastructure, ideally in an international environment.

08

Background

Background and goals

I'm in the 2nd year of a BTS SIO (SISR track), a two-year French IT degree. I built my own homelab: a Proxmox VE server, VLANs, OPNsense and pfSense firewalls, a site-to-site IPsec VPN and Grafana / Loki monitoring.

I'm looking for a work-study apprenticeship at bachelor's level in infrastructure, systems or networking, with an interest in security and, later, cloud. I'm open to relocating for the right opportunity: my first choice is Toulouse, but I'm open to opportunities across France.

Outside the terminal, running my own micro-business (French micro-entrepreneur status) and leading a Scout pack (Meute Notre Dame La Réal) taught me project management, team leadership and real independence.

// profile.ts
const Anatole = {
status: "BTS SIO SISR, 2nd year (≈ US associate degree)",
targetRole: "Infrastructure & Networking apprenticeship",
locations: ["Toulouse", "France"],
nextStep: "Bachelor's in Infrastructure / Cybersecurity",
longTerm: "Cloud engineering & cybersecurity",
focus: "Infrastructure, Networking, Security"
};
09

Tech Stack

Linux
Debian
Docker
Bash
Grafana
OPNsense
Nginx
Windows Server
Proxmox VE
pfSense
Cisco
Active Directory
Tailscale
Loki
Syslog
10

Let's Talk About an Apprenticeship

I'm looking for a team that will support me on infrastructure, networking and security work. Here's what I can bring, depending on your environment.

AEROSPACE & DEFENSE
Airbus, Thales

Rigor, network segmentation and controlled remote access: habits I practice in my homelab.

IT SERVICES & CONSULTING
Sopra Steria, CGI, Capgemini

Technical versatility, fast ramp-up and the ability to adapt to a wide range of client environments.

CYBER DEFENSE
Orange Cyberdefense

An interest in monitoring and log analysis, practiced in my homelab with Loki and Grafana.

// No mail client? sabater.anatole.pro@gmail.com