Dallas skyline
Dallas, TX
Tyran Tran

Tyran Tran

>building AI Infrastructure for businesses that deserve better tools_

Location

Dallas-Ft Worth, TX

Phone

Email

LinkedIn

linkedin.com/in/tyrantra

Experience

Lexitas Legal, Dallas

IT Administrator

Aug 2022 - Aug 2025

  • Reduced system outage 30% through proactive server maintenance, security patching, and network optimization
  • Designed and deployed hybrid cloud architecture increasing scalability by 60% while maintaining strict compliance
  • Implemented cloud cost optimization cutting monthly infrastructure costs by 20%, reducing deployment time from hours to minutes

Westwood Professional Services, Plano

System Administrator

Jun 2020 - Aug 2022

  • Strengthened data resilience through robust backup schedules and disaster recovery protocols, achieving zero data loss during incidents
  • Delivered targeted user training and authored reusable system documentation, reducing support requests by streamlining onboarding

Lennox International, Richardson

IT Deskside Support

Aug 2018 - Jun 2020

  • Developed scripts to automate ServiceNow ticket assignment, boosting team productivity and response efficiency
  • Managed Active Directory OUs, security groups, and user accounts at domain level, enhancing access control and security compliance
  • Streamlined software updates and installations using SCCM and PowerShell, reducing manual effort and minimizing downtime

Capabilities

What I built, not what I watched tutorials on

Infrastructure & Systems

ProxmoxUbuntu 24.04VLAN SegmentationKernel HardeningCloud-initsystemdIOMMU/VFIO
  • 7-VM Proxmox cluster on Dell R730 — vmbr0 outbound-only, vmbr1 internal-only
  • Kernel hardening: SYN cookies, rp_filter, IPv6 disable, fail2ban SSH jail

Networking & Security

Cloudflare TunnelCaddyTLS 1.3pfSenseUFWZero TrustCSP
  • Dual-network perimeter: Cloudflare → Caddy → internal VMs, zero port forwarding
  • 10-layer security model: network → auth → file upload → prompt injection → AI governance → monitoring

AI / LLM Infrastructure

vLLMOllamaLangGraphLangChainQdrantRAGStructured Output
  • Self-hosted dual RTX 3090 inference — zero cloud API dependencies, zero per-token costs
  • Multi-agent orchestration with quarantined extractor → privileged formatter architecture

Backend Engineering

FastAPIPyJWTbcryptRedisPostgreSQLasyncpgPydantic
  • Hardened Auth API: dual JWT (15min access + 7day refresh), token rotation, rate limiting
  • HIBP breach checking with fast-fail timeout — protects users without blocking when offline

Frontend & UX

AstroReactTypeScriptTailwind CSSNanostoresIBM Plex
  • Astro static site with React islands: zero JS on public pages, hydrated where needed
  • Anti-scraping: JS-rendered contact info, X-Robots-Tag noai, right-click deterrent

Scripting & Automation

Python 3BashPowerShellPyYAMLTerraformCloudFormation
  • Async Python with asyncio, httpx, and concurrent.futures for parallel agent execution
  • Infrastructure as code: Caddyfile, cloud-init, systemd units — no containers needed

How I Work

TDDThreat ModelingIncremental TeachingVersion PinningAudit Logging
  • Zero tolerance for untested code: every endpoint curl'd before declared done
  • Systems thinking: design for failure, graceful degradation, observability first

Projects

OpenCode Multi-Agent AI Coding Engine

2025-Present

Built a fully local, multi-agent AI coding engine. OpenCode serves as the dev interface. LangGraph runs the control orchestrator. Graphify maps the codebase knowledge graph. The entire stack runs on dual RTX 3090 GPUs via Ollama, cycling Qwen3-Coder 30B for code generation, Qwen3.6 27B for parallel review, and DeepSeek-R1 32B for adversarial red-teaming. Hardened by OpenCode skills — Superpowers, Caveman, Grill Me, Handoff, Firecrawl, and Understand-Anything — to enforce bulletproof coding methodology with zero cloud API dependencies.

OpenSOC Security Operations Control

2025-Present

Built and deployed OpenSOC, local-first SOC agent that ingests firewall syslog into a SQLite property graph engine, reasons over threats with a local LLM via llama.cpp, and contains them through the firewall's REST API. Added SOCbot, a two-way interactive communicator over Discord (with email/SMS as pluggable future channels) supporting allowlisted operator commands (!soc ban, status, blocks, unblock) plus a daily automated briefing. A modular connector framework ships with built-ins for firewall, SIEM, threat intelligence, and GeoIP enrichment service, with custom user-written connectors supported. The pipeline is fully automated with a human in the loop: nothing is blocked without an allowlisted approval through SOCbot and guardrails.

Personal AI Inference Platform

2025-Present

Self-hosted GPU infrastructure for production AI inference and contract analysis. Dell R730 with dual RTX 3090, Proxmox hypervisor, vLLM inference engine, FastAPI orchestration, PostgreSQL/Redis/Qdrant backends.

Contract AI Analyzer (Prototype)

2021

Proof-of-concept AI system to extract key clauses and generate risk summaries from legal contracts. Implemented REST APIs to handle PDF uploads, parse content, and return structured JSON outputs.

Multi-Tenant Document AWS Platform

2022-2023

Built a semantic search platform for enterprise documents with per-tenant isolation, embedding-based search, and access control via RBAC.

Azure IAM Audit & Cloud Automation

2021-2023

Automated audit logging and tenant-specific access reporting using AWS CloudTrail, CloudWatch, and AWS Config. Deployed repeatable security controls with Terraform and CloudFormation.

Contact

Available for infrastructure, AI systems, and consulting work in the Dallas-Fort Worth area and remotely.