Senior Security Engineer · Vienna
15+ years designing, operating and troubleshooting complex networks and security systems — today as the go-to expert for global Check Point infrastructures.
With more than 15 years of extensive experience in the operation and management of complex computer networks and security systems, I am as excited about IT as I was on the first day. In my current role as Senior Security Engineer at Bacher Systems in Vienna, I am responsible for the installation, planning, and maintenance of Check Point global infrastructures — from large-scale Maestro hyperscale deployments to multiple MDS/MLM installations for global corporations.
For the past six years I have been the main escalation point for complex Check Point issues, bringing a holistic viewpoint shaped by hands-on experience across Windows/Unix servers, VMware, networking, routing and security. I work closely with cross-functional teams, stay current with industry trends, and focus on continuous improvement in network security and performance.
I am highly resilient under pressure, quick to learn, and I genuinely enjoy mastering new technologies — most recently, exploring extensive AI capabilities with Check Point.
In my free time I test and optimize my own infrastructure — from virtualization to machine learning and AI-based image detection.
Security is strongest when deep product knowledge is combined with an understanding of the entire infrastructure around it.Dominik Kappel
A steady path through infrastructure, networking and security — each role broadening the foundation the next one builds on.
Installation, planning and maintenance of Check Point global infrastructures — including large-scale Maestro hyperscale deployments and multiple MDS/MLM installations for global corporations. Deployment and maintenance of SentinelOne solutions. Main escalation point for complex Check Point issues.
Cisco routing, switching, wireless (CAPWAP/WLC), ASA multicontext clusters and Barracuda infrastructures. Configuration and maintenance of Cisco ISE.
Managed Check Point global infrastructures (CCSA, vSEC, VSX, SandBlast) alongside Cisco routing, switching, wireless and ASA multicontext clusters, plus Cisco ISE.
Installed, planned and maintained Cisco routing, switching, wireless and ASA multicontext clusters with Firepower. Managed global Barracuda infrastructures, Palo Alto IPS/Wildfire, HP/Aruba networking and Cisco ISE.
VMware ESXi installation and configuration, Unix system administration and server hardening, Cisco ASA and Barracuda firewalls, Cisco network infrastructures.
Deployed Lync 2010/2013 with PBX integration, archiving and DLP. Ran clustered OTRS ticketing, VMware ESXi/vCenter, Windows Server with replicated domain controllers, NAS/SAN (FreeNAS, NetApp), hardened Unix services, and pfSense firewalls with DMZ, IDS/IPS and VPNs.
Installed and maintained HP ProLiant servers, VMware ESXi, domain services (DNS, DHCP, WSUS, IIS), Unix-based external DNS and Fortigate firewalls.
Elite-level mastery of the full Check Point portfolio, from design to troubleshooting.
Enterprise routing and switching, plus security and identity services.
Vendor-agnostic security operations across diverse enterprise environments.
Design and operation of resilient campus and data-center networks.
The full stack beneath the security layer — servers, storage and platforms.
Hands-on exploration of what's next — tested at home before it hits production.
The Check Point Certified Security Master Elite (CCSM Elite) is the pinnacle of the Check Point certification track — held by only a small group of engineers worldwide.
Whether it's a global firewall architecture, a stubborn escalation, or the next security technology worth exploring — I'm always happy to connect.