Pakkit.net
Contact Brandon Other role focuses

Network & telecom

Brandon Donaly

Network engineering • AAA • protocol analysis

Denver metro, Colorado · me@pakkit.net · pakkit.net/resume

Subscriber authentication, RADIUS accounting, wireless infrastructure, and repeatable protocol validation.

Experience

Wireless Engineer III — AAA Development & Platform Automation · Charter Communications (Spectrum)

Nov 2024 – Aug 2026 · Previous role

  • Reverse-engineered undocumented RADIUS accounting field derivations from policy logs and packet captures, establishing a behavioural-parity baseline for a platform rewrite.
  • Rebuilt individual accounting derivations to verified parity against that baseline and created replay tooling for repeatable protocol validation.
  • Designed and delivered a state-persistence layer for a telecom policy runtime, then removed 16,390 lines of legacy code using execution evidence to prove what was genuinely unused.
  • Diagnosed two independent causes of silent RADIUS accounting health-check failures—a runtime compatibility issue and missing protocol attributes—and validated the corrected probe with 12 of 12 successful live responses at approximately 140 ms median latency; load-balancer monitor deployment remained pending.
  • Built repeatable IPAM import and drift-audit tooling, reconciled a 233-VM development inventory, and populated a separate integration-test inventory covering 62 VLANs, 144 subnets, and 176 addresses using hypervisor, host, and telemetry evidence.
  • Root-caused a TLS handshake failure blocking OAuth2 token retrieval by isolating the ALPN extension in the ClientHello as the trigger, eliminating DNS resolution, TCP reachability, certificate interception, TLS version negotiation and general HTTPS egress with a positive control for each, then proving with a four-variant differential matrix that the reset followed the extension being present rather than the protocol offered, and restoring token issuance the same day.
  • Root-caused recurring release blockers across build images, registry routing, and artifact authentication, then replaced repository-local workarounds with shared templates. Reconciled three policy-bundle packaging paths and added checks against overwriting vendor runtime files, resolving inconsistent branch and merge-request validation.
  • Diagnosed difficult mutual-TLS and protocol-integration failures across RADIUS-over-TLS and a legacy subscriber-state interface.

Founder / Principal Engineer · Duvall WiFi

Aug 2022 – Nov 2024 · Previous role

  • Built a redundant multi-frequency wireless network capable of serving 160 homes with symmetric gigabit, backed by custom captive-portal and RADIUS software plus virtualized infrastructure, PKI, segmentation, monitoring, VPN connectivity, PBX/CRM integrations, and production Laravel and Spring applications.
  • Founded and ran a technology and ISP services company covering network engineering, software development, hosting, cybersecurity, and managed IT. I owned customer discovery, architecture, implementation, production operations, sales, billing, and support.
  • Built the custom Spring Boot captive-portal and AAA backend implementing the FreeRADIUS REST hook surface for authorization, authentication, interim accounting, post-auth, and proxy phases, plus MikroTik hotspot redirect and prepaid-voucher flows.
  • Built and operated a three-host VMware vSphere/vSAN environment with data-center colocation, an air-gapped root CA, zero-trust segmentation, secure administrative workstations, SIEM monitoring, VM templates, and hub-and-spoke VPN connectivity across customer networks.
  • Installed and spliced indoor and outdoor fiber and copper cabling, engineered point-to-point links, performed site surveys, and maintained routers, switches, access points, and RF paths as the company's field engineer.
  • Operated a GenieACS TR-069/CWMP platform managing 58 MikroTik and Yealink devices through 15 presets and 15 provisions, documented its tag-driven idempotent configuration state machine, and identified security, permissions, provisioning, and device-health defects through live read-only analysis.

Technology & Growth Consultant · Pacific Northwest Plumbing

Jun 2023 – Nov 2024 · Previous role

Delivered technology and growth consulting for a trades business across software, analytics, customer acquisition, and support.

Network & Systems Consultant · Wilderness Awareness School

Nov 2022 – Nov 2024 · Previous role

  • Designed, quoted, installed, and operated a resilient enterprise network across three forested properties using roughly 700 meters of aerial and buried cabling plus point-to-point wireless links. The design avoided the cost of an additional internet circuit and improved outage resilience.
  • Ongoing support covered routers, switches, access points, point-to-point wireless links, structured cabling, monitoring, and day-to-day technical support for staff.

Technical Consultant · Beyond Grey Skies, LLC

Mar 2016 – Jun 2021 · Earlier chapter

  • Supported enterprise networks, data-center fabric, Linux and Windows servers, intrusion monitoring, and emergency technical operations, working across pfSense, VyOS, MikroTik RouterOS, and Cisco IOS.

Independent projects

Secure Compute & Network Automation · Independent project

2026 · Independent project

  • Built a broker issuing short-lived, single-use Tailscale enrollment keys while keeping privileged OAuth credentials off rented hardware, with independent JWT validation for administrative access.
  • Automated deterministic virtual-address allocation, constrained gateway routing, and cleanup of expired nodes; verified the full join, permitted-access, blocked-port, and teardown path using a disposable container.

Private Cloud & Homelab Platform Engineering · Independent project

Ongoing · Ongoing

  • Audited the management and service exposure of a colocated RouterOS core router, validated ordered default-deny containment, and executed a no-reboot reduction of SNMP, bandwidth-test, captive-portal, and obsolete RADIUS exposure while preserving recovery access.
  • Designed the standard internet ingress for self-hosted services: a Cloudflare edge with WAF and identity-gated Access in front of a core router that admits only Cloudflare's ranges, terminating at an nginx origin with per-hostname Origin CA certificates and authenticated origin pulls across roughly 55 virtual hosts.

Embedded, Mobile & Signal Engineering · Independent project

2021 – 2023 · Earlier project

  • Built an Android diagnostic that surfaces live LTE serving-cell identity and channel information through the platform telephony APIs, giving a client-side view of the radio link rather than relying on the operator's own reporting.
  • Built a desktop signal-processing tool with live plotting: multi-tone generation, Hamming-windowed FFT with window correction, power-spectral-density and channel-power computation, peak-to-average power ratio, and BPSK spreading for direct-sequence experiments.
  • Reverse-engineered the undocumented serial output of a consumer radar detector, deriving its frequency scaling constant empirically and decoding packed little-endian multi-byte fields into the main and secondary target frequencies.

Skills demonstrated here

  • RADIUS
  • GitLab CI
  • Pipeline templates
  • JFrog Artifactory
  • Mutual TLS / X.509
  • VMware vSphere / vCenter
  • VM templating
  • IPv4/IPv6 dual-stack
  • Python
  • Java 23 / Spring Boot
  • PHP / Laravel
  • Reverse engineering
  • Root-cause analysis
  • OIDC / OAuth 2.x
  • Cloudflare Access / Workers
  • Tailscale
  • nftables
  • MikroTik RouterOS
  • VMware vSAN
  • FreeRADIUS
  • GenieACS / TR-069
  • pfSense
  • VyOS
  • Cisco IOS
  • Zero trust
  • Supply-chain controls
  • Cloudflare Origin CA / authenticated origin pulls
  • Health checks
  • phpIPAM / inventory reconciliation
  • udev & serial device integration
  • Android SDK
  • NumPy / SciPy
  • FFT & spectral analysis
  • Digital modulation
  • PyQt5 / pyqtgraph
  • TLS handshake analysis (ALPN)

Certifications

CompTIA A+ · CompTIA Network+ · CompTIA Security+ · CompTIA Server+ · Microsoft MTA: Mobility and Device Fundamentals