Matthew Biel

Senior Network Engineer · Infrastructure Architect · Cybersecurity Practitioner

Senior network engineer and infrastructure architect with 10+ years of hands-on experience designing, deploying, and securing enterprise networks across K-12 education, municipal government, construction, and managed services. Proven track record executing large-scale, multi-site infrastructure projects — including 2,000+ access point deployments, district-wide switching overhauls, and core network modernization spanning 140+ locations. Hands-on cybersecurity practitioner: detected and stopped a live ransomware attack mid-execution, then designed and implemented the resulting enterprise security program including EDR/MDR deployment and 24/7 SOC integration. Owner of HardenedHive Technology Consulting, delivering enterprise-grade open source infrastructure to SMB clients. Active MS-ISAC member and CISA stakeholder through the U.S. Department of Homeland Security. U.S. Citizen.

Cisco IOSVLANs/STP/HSRPInter-VLAN RoutingBGPOSPFExtreme CloudIQCisco WLC802.1X / Cisco ISE2,000+ AP Deployment FortiGateSSL-VPN / IPsecCisco ASACrowdSec IDS/IPSIncident ResponseRansomware ContainmentEDR/MDRNIST CSFSIEM VMware vSphere/ESXiProxmox VEHyper-ViSCSI SANDocker / ComposeTraefik v3Cloudflare TunnelsAuthentik SSO Windows Server ADAzure ADIntune MDMGoogle WorkspaceM365 / Exchange OnlineConditional Access Prometheus / GrafanaBarracudaVeeam B&RMitel / Cisco VOIPBash / YAMLUbuntu / Windows Server
Information Technology Infrastructure Manager May 2020 – June 2026
Elmbrook School District · Brookfield, WI
  • Managed all network and technology infrastructure for a multi-site K-12 district of 5,000+ users — owning design, implementation, and operations across networking, server infrastructure, endpoint management, security, and telephony.
  • Designed and executed district-wide network refresh: engineered new routing architecture, configured and deployed all switching infrastructure, and replaced the full wireless infrastructure — migrating wireless management to Extreme CloudIQ for centralized visibility and policy enforcement.
  • Detected and interrupted a live ransomware attack against the district mid-execution — identified indicators of compromise, mapped and contained lateral movement, halted the threat before encryption occurred, and led the post-incident executive and board-level briefing.
  • Drove the resulting enterprise security program: scoped, procured, and deployed an EDR/MDR solution with 24/7 SOC coverage; defined MSSP escalation workflows, alert triage procedures, and incident response runbooks; applied NIST CSF and MS-ISAC guidance throughout.
  • Administered Google Workspace (5,000+ accounts), Azure AD, Microsoft Intune MDM, FortiGate firewall, and Mitel telephony; managed vendor relationships and technology budget planning.
  • Served as MS-ISAC member and CISA stakeholder — applied federal threat intelligence, KEV advisories, and Shields Up guidance operationally to harden district infrastructure and inform security investment decisions.
Principal Consultant 2020 – Present
HardenedHive Technology Consulting · Milwaukee, WI
  • Deliver enterprise-grade network and infrastructure solutions to SMB clients using open source tooling — providing capabilities equivalent to large-organization environments at a fraction of licensing cost.
  • Design and deploy FortiGate firewall architectures, IPsec/SSL-VPN configurations, network segmentation, and zero-trust access (Cloudflare Tunnels + Authentik SSO) for client environments.
  • Build and operate self-hosted production stacks on Proxmox VE with Docker, Traefik v3 reverse proxy, CrowdSec IDS/IPS, and automated TLS — replacing expensive SaaS subscriptions with open source equivalents.
  • Conduct security risk assessments, develop hardening documentation, and advise clients on technology investments aligned to their risk tolerance and budget.
Network Engineer Sep 2018 – May 2020
Milwaukee Public Schools · Milwaukee, WI
  • Primary network engineer for one of Wisconsin's largest school districts — 140+ buildings, Cisco IOS routers, multilayer switches (VLANs, STP, inter-VLAN routing), Wireless LAN Controllers, and Cisco ISE for district-wide 802.1X NAC enforcement.
  • Led VOIP telephony deployment to all 140 schools simultaneously; replaced 2,000+ legacy wireless access points across the district; initiated core firewall and core router modernization.
  • Managed contractors, vendors, and internal staff across concurrent large-scale projects; maintained network diagrams, change documentation, and project records.
Network Administrator Oct 2017 – Sep 2018
Hunzinger Construction · Greater Milwaukee, WI
  • Sole IT administrator for a regional construction firm — managed all Cisco networking, VMware vSphere environment, on-premises Exchange Server, Barracuda appliances (spam/web filter/archiver), Citrix Receiver, Sage CRE 300, and WDS workstation imaging.
  • Owned all procurement, configuration, deployment, and incident resolution; maintained Windows Server AD environment and backup/DR posture independently.
Support Desk Engineer (L1/L2) Apr 2015 – Sep 2017
Technology Resource Advisors, Inc. · Greater Milwaukee, WI
  • Multi-client managed services support in a fast-paced MSP environment; first-contact triage and escalation through L2 resolution across diverse SMB client environments.
MS-ISAC Member
Multi-State Information Sharing & Analysis Center
CIS / CISA / U.S. DHS — active member participating in threat intelligence briefings, vulnerability disclosures, and security events for SLTT government and education sectors.
CISA Stakeholder
Cybersecurity & Infrastructure Security Agency
U.S. Department of Homeland Security — engaged stakeholder in DHS-coordinated security briefings and outreach programs.
B.S., Information Technology Management
University of Wisconsin – Milwaukee
2017 – 2019 · GPA 3.5
A.A.S., Systems, Networking & LAN/WAN Management
Milwaukee Area Technical College
2013 – 2015 · Honor Roll, Dec 2015