Technical Support Engineer · Shelton, CT

I fix what breaks,
and document
everything.

10+ years diagnosing complex systems — from enterprise BCDR stacks to self-hosted homelab networks. I don't just resolve tickets; I eliminate the conditions that create them.

$ whoami
roger-castro  # IT Support · Datto alum · Homelab operator
$ uptime
12 years in support  # no reboots
$ ping opportunity
PONG  — open to remote roles ✓
Open to Work Remote-First Windows 10/11 Linux ZFS Datto/BCDR Intune/MDM Autopilot Docker TCP/IP & DNS ServiceNow
// 01 — Background

Where I've been.

End User Support Consultant
Subway — Corporate HQ
18 Months · Shelton, CT

Provided enterprise-level end user support at corporate HQ, serving as SME for Ali Office — a legacy proprietary application unsupported for 13+ years — managing compatibility challenges introduced by Windows 11 migration. Identified and resolved a broken Autopilot reimaging workflow the team had abandoned for 3+ years, diagnosing the root cause, restoring functionality, and establishing it as the new SOP for device reimaging across the organization. Participated in the company-wide laptop refresh program, shipping new devices to users, guiding them through provisioning and configuration remotely, and managing ticket lifecycle through hardware return. Managed Okta identity operations including password resets and group management. Coordinated the recycling and responsible disposal of damaged and end-of-life laptops.

BCDR Technical Support Engineer
Datto, Inc.
~5 Years · Norwalk, CT

Supported MSPs and their clients through complex BCDR incidents over nearly 5 years. Performed hands-on data migrations via SSH and rsync across local appliances, and managed ZFS storage pool migrations during in-place drive upgrades. Handled cloud-side migrations by SSHing into Datto cloud infrastructure to realign datasets with new device IDs. Diagnosed and resolved hardware-level issues including failing drives, PSU/NIC failures, and memory faults — remotely where possible, coordinating on-site partner assistance when required. Conducted deep agent software troubleshooting including config file repairs, install/reinstall walkthroughs, Windows Event Viewer and Datto agent log analysis, and BSOD investigation on protected servers. Advised partners on appliance storage management and right-sizing — identifying when undersized hardware was the root cause of backup and restoration failures, and recommending appropriately scaled solutions.

Homelab Architect & Operator
Nora-Net (Self-Hosted)
Ongoing

Designed and maintain a production-grade self-hosted home network and server environment. Core stack includes pfSense for routing and firewall management, Pi-hole and Unbound for ad-blocking and recursive DNS resolution, and Tailscale for zero-config mesh VPN access. Runs multiple Dockerized services including Uptime Kuma for infrastructure monitoring, Nginx Proxy Manager for reverse proxy and SSL termination, and WeTTY for browser-based SSH access. Storage managed via ZFS. Entire environment is documented in a self-hosted BookStack wiki.

Team Captain & Event Organizer
Extra Life — Children's Miracle Network
12 Consecutive Years

12-year Extra Life participant and team co-captain for 7 years, leading a team that has raised $96,095 for Connecticut Children's Hospital — approximately 11% of total regional funds raised annually, with 3–4 team members consistently placing in the top 10 leaderboards. Oversee all logistics for an annual 24-hour gaming marathon averaging 40 attendees, including securing food sponsorships from local restaurants for breakfast, lunch, and dinner, managing seating and event layout, and assisting with on-site networking. In 2024, organized a separate public board game event that drew 100+ attendees, secured $2,000+ in donated prizes from local sponsors, and raised $6,400. Maintain a direct relationship with CMN and CT Children's Hospital. Manage a year-round Discord community of ~100 members.

// 02 — Projects

Things I've built.

Nora-Net

A production-grade self-hosted home network and server environment following a Horizon Zero Dawn naming convention. Built around pfSense (fireclaw) for routing and firewall management, a primary and backup Pi-hole (thunderjaw/stormbird) with Unbound (demeter) for recursive DNS, and a dedicated Docker host (minerva) running 14 active containers including Nginx Proxy Manager, Uptime Kuma, WeTTY, ntfy, MariaDB, Portainer, and BookStack. Storage managed via ZFS on both servers. Remote access via Tailscale and DuckDNS. Fully documented in a self-hosted BookStack wiki organized across Infrastructure, Network & DNS, Services, Backup & Recovery, and Troubleshooting.

pfSense Pi-hole Unbound Docker ZFS Tailscale Nginx Proxy Manager Uptime Kuma BookStack Linux DNS DuckDNS
GitHub →
TechBarTools

A plug-and-run USB toolkit built for enterprise tech bar and helpdesk environments. A single menu-driven CMD launcher consolidates the most common Windows support tasks: adding and removing local administrators, clearing Windows Hello PINs, capturing Autopilot HWIDs with group tag selection, driver version snapshots across four imaging stages, and returning devices to OOBE via Sysprep — with a dynamically written unattend.xml that preserves the Autopilot-assigned hostname through the specialize pass. Runs on Windows 10 and 11, requires no installation, and automatically creates its own output folders on first launch.

CMD/Batch PowerShell Autopilot Sysprep Unattend.xml Intune/MDM Windows 10/11 USB Deploy
GitHub →
// 03 — Toolkit

What I work with.

Networking
pfSense / Firewall Rules Tailscale DNS (Unbound, Pi-hole) VLANs & Subnetting NAT / Port Forwarding / UPnP
Linux & Storage
Linux CLI & Administration SSH / Remote Access ZFS Pool Management rsync / Data Migration Log Analysis (Event Viewer, Datto Agent, syslog)
Infrastructure
Docker / Containers Portainer BCDR (Datto Platform) Backup Replication & Restores Virtualization
End User & Deploy
Microsoft Autopilot Intune / MDM Sysprep & OOBE Hardware Lifecycle Okta (Identity & Groups)
Scripting & Automation
Batch / CMD Scripting PowerShell Bash / Shell Scripting XML Config (Unattend) Menu-Driven Launchers
Identity & Ticketing
ServiceNow Zendesk Salesforce Okta Windows Hello for Business
Documentation
BookStack (Self-Hosted Wiki) Network Topology Diagrams Runbook / SOP Writing Knowledge Base Authoring
Soft Skills
Remote Troubleshooting MSP / Enterprise Support Event & Community Leadership Escalation Management
// 04 — Write-Ups

How I think.

I Thought Portfolios Weren't for People Like Me. So I Built a Wiki Instead.

I'm in IT support — not a developer. I thought portfolios weren't for people like me. So I built a self-hosted wiki instead. Turns out that was a portfolio all along.

Read on Dev.to →
We Were Reimaging Laptops the Hard Way for 3 Years. I Fixed It in an Afternoon.

Our team had abandoned Autopilot Reset years ago because "it didn't work." Nobody had tried it since. I tried it. It worked. Here's how we cut a 6-hour reimaging process down to 2.

Read on Dev.to →
How I Finally Got Remote Access to My Homelab (And the Workaround That Made It Actually Work)

Tailscale on pfSense gave me remote access to my whole network in one install. SSH into my Docker host was a different story — here's the routing problem I hit and the WeTTY workaround that solved it.

Read on Dev.to →
// 05 — Contact
Let's work
together.

I'm actively looking for Technical Support Engineer or similar roles — remote preferred, open to hybrid within a reasonable commute of Shelton, CT. If you're hiring or know someone who is, I'd love to connect.