ncrew.
Salt Lake City, UT  /  Open to remote

NathanCrewdson.

Security-minded, self-taught & passionate about AI.

I build websites, keep them running, and automate the parts of a job nobody should be doing by hand. The IT and networking side came first and still backs it up. Nearly all of it is self taught, on my own hardware, because I'd rather break something than read about it.

Target role
AI Automation / IT
Location
Salt Lake City / Remote
Availability
Available now
Security+
In progress
01 / What I do

What I'm actually good at

Three things that back each other up more than they look like they should.

Websites & Web Apps

I build sites and web apps, then I keep them alive. React, JavaScript, Node, HTML and CSS, concept through launch. After that comes the part most people skip: the form that submits and routes nowhere, the layout that collapses on a phone, the thing that quietly stopped working three weeks ago. I do my own QA across browsers and I write it down so the next person isn't guessing.

  • React
  • JavaScript
  • Node.js
  • HTML/CSS
  • Git
  • Vercel

AI Automation & Internal Tools

If somebody on your team is doing the same thing by hand every week, that's the job. I build the scripts, workflows and small internal tools that do it instead. Reporting that builds itself. Two systems that finally talk to each other. A dashboard that replaces a spreadsheet somebody updates manually. I build the whole thing, the logic through the integrations through the part where it fails without taking everything down with it. And I'll tell you straight where AI helps and where it just makes a mess faster.

  • Workflow automation
  • APIs
  • JavaScript
  • Node.js
  • AI tooling
  • n8n

IT, Networking & Security

This is where I started and it still backs everything else up. When the printer, the POS terminal or the wifi drops in the middle of service, I'm the one who finds out why instead of restarting it and hoping. Networking underneath that, TCP/IP through DNS and VPN. Security on top, out of a lab I run myself. I take a ticket all the way to fixed and then I document it.

  • Windows 10/11
  • Hardware
  • Printers & AV
  • POS systems
  • TCP/IP
  • DNS
  • VPN
  • SIEM
  • Kali
02 / AI & Automation

Where AI actually pulls its weight

I use this stuff every day, not as a party trick. Some of it saves real hours. Some of it doesn't, and I'll tell you which is which.

Workflow automation

n8n flows that wire AI into reporting and the repetitive work, so a job runs the same way every time instead of depending on who happens to be doing it that day.

Small internal tools

Built for one specific annoying problem. Usually a form, a script and an API call, and suddenly nobody's copying rows by hand at the end of a shift.

AI-assisted development

Daily, in real client work, from first draft through production bugs at 11pm. I know where these tools are strong and where they'll hand you something wrong with total confidence.

Documentation that gets finished

The part of IT everyone skips. AI-assisted writeups mean the notes actually exist, which is the whole difference between a fixed problem and a fixed problem the next person can use.

03 / Lab work

Built because I wanted to

Nobody assigned these. Reading about a system isn't the same as running one, so I run them.

Cloud honeypot

T-Pot on Oracle Cloud

I wanted to see real attack traffic instead of reading about it, so I put a T-Pot honeypot on Oracle Cloud, exposed it, and watched what showed up. Automated scanners find an open host within minutes. The sheer volume is the part no course prepares you for.

The attack data wasn't even the best part. Setup broke on a DNS and networking issue with nobody to escalate to, so I sat with it until it came up. That's the closest thing to the actual job I've done.

Capture sample  /  illustrative
02:14:07185.*.*.41SSH / 22root : adminbrute force
02:14:0945.*.*.118Telnet / 23default credsbrute force
02:16:33159.*.*.203HTTP / 80/wp-login.phpscanner
02:17:5191.*.*.77SMB / 445enumerationrecon
02:21:12103.*.*.12SSH / 22admin : 123456brute force
Platform
Oracle Cloud
Stack
T-Pot
Exposure
Public
Debugged
DNS / net
Detection & monitoring

Home lab SIEM deployment

A SIEM running across a few VMs on a segmented network, built so I could get real reps on log monitoring and alert triage instead of clicking through someone else's screenshots. Getting collection stood up and logs actually arriving taught me more than any dashboard did.

It's also where the SOC Level 1 material stopped being abstract. Brute force detection reads different once you've watched it hit your own box.

Hosts
Multiple VMs
Network
Segmented
Focus
Log monitoring
Practice
Alert triage
Offensive fundamentals

Web application security lab

Kali Linux against deliberately vulnerable targets in a controlled lab, recon and enumeration through to actual findings. Then I wrote them up the way a real client report reads, with impact and remediation instead of a wall of tool output.

The writing was the harder half and the more useful one. A finding nobody can act on isn't a finding.

Tooling
Kali Linux
Scope
Controlled lab
Method
Recon / enum
Output
Findings report
04 / Background

How I got here

Jul 2022 - Present

Independent Frontend Developer

Remote / Self-employed

React, JavaScript and Node, building and maintaining client sites and web apps start to finish. Which also means I'm the one debugging production at 11pm, sorting out hosting and connectivity, and translating all of it for people who don't speak tech.

Mar 2024 - Dec 2025

Bartender

Bronze Buffalo at Teton Springs / Driggs, ID

High volume service at a resort property. I picked up the tech side informally and turned into the person staff came to when something broke: POS and registers, wifi and connectivity, computers, printers and AV. I also built automations that pulled repetitive back of house reporting off people's plates.

Ongoing

PC Build & Repair

Salt Lake City, UT

Custom builds and upgrades, part selection through stability testing. Diagnosing hardware and performance problems, and keeping people updated, backed up and reasonably secure.

05 / Training

Still learning, on purpose

In progress

CompTIA Security+

Studying daily. Happy to sit whichever certification a role actually needs.

Completed

TryHackMe SOC Level 1

Log analysis, brute force detection, phishing investigation, alert triage.

Completed

TryHackMe Jr Penetration Tester

Reconnaissance, enumeration, exploitation fundamentals, technical reporting.

Let's talk about the work.

I'm after AI automation or IT work, Salt Lake City or remote. If you've got a problem that needs someone who will actually chase the root cause instead of rebooting it and walking away, I want to hear about it.

Nathan Crewdson
Salt Lake City, UT
0