About Me
I’m an IT specialist based in Switzerland with over 25 years of experience. My focus is infrastructure, cloud migration, automation, and security. I’ve worked in regulated environments across finance, healthcare, and the public sector, often bridging legacy systems and cloud platforms.
I prioritise practical, secure, and maintainable solutions. For recurring tasks, I use AI-supported tools only for drafts, structuring, and first-pass analysis of logs or advisories. AI is never used for autonomous production actions or security-critical decisions. Decisions, prioritisation, and production changes always stay with humans inside clear roles, approvals, and controls.
Selected Projects
- Migrated banking services to Azure and AWS with zero downtime and full compliance.
- Developed PowerShell automation for Active Directory, reducing manual effort by 70%.
- Improved monitoring and alerting for healthcare platforms, increasing issue response by 50%.
Skills
- Cloud platforms: Azure, AWS, Oracle Cloud (OCI)
- Automation: PowerShell, Bash, CI/CD pipelines
- Security: IAM, firewalls, system hardening, zero-trust architecture
- Monitoring: Prometheus, Grafana, Zabbix
- Reliability: incident management, SLO/SLI, postmortems, and structured handovers
- Regulated environments: finance, healthcare, and public sector, with auditability and documented changes
- AI workflows: reusable skills, versioned knowledge packs, tool/MCP integration, and human review
- Infrastructure: VMware, Windows Server, Linux
Controlled AI workflows
From raw input to reviewable work steps
This is not about autonomous agents doing everything. It is a bounded workflow: a skill defines the task, a knowledge pack supplies approved context, tools stay narrowly scoped, and a human keeps the final decision point.
- Security advisory triage for SMEs
- Runbook drafts from rough notes
- Structured incident handovers
- Infrastructure change review
- Explainable output from security and support tools
SME tools
Practical tools for SMEs: the Security check reviews only public TLS and security-header posture and performs no intrusive scans, no load tests, and no active interventions. Security warnings aggregate official advisories (vendors/CERT/NVD) with filtering and export, with no proprietary auto-scoring and no automatic actions. Remote support helps with pre-triage. Radar and Radio Map are visualisation and navigation tools based on official sources and do not run hidden scans. Confidential customer data is not sent unchecked to external AI services.
Contact
Email: info@hlukh.ch
LinkedIn: linkedin.com/in/hlukh
Video CV: hlukh.ch/vcv-en