Curriculum Vitae · Michael Herbst

Learning.

Entirely self-taught · nothing claimed as complete unless it is

Certifications and self-directed study, split honestly: what is in progress, what is applied and complete, and what comes next. Nothing on this page is presented as a finished qualification unless it is one.

01 In Progress

Certification · Studying

CompTIA Security+ In progress

  • Currently studying toward the Security+ examination, building formal structure around security work already carried out in production: hardening, endpoint protection, identity and access control, and applied POPIA review.

Offensive security · Practical work

eJPT, PNPT and OSCP Next

  • Practical, hands-on work toward eJPT, PNPT and OSCP, built on TryHackMe practical foundations. Presented as a progression in progress, not as certification held.

Service management

ITIL Service Management Practice

  • Working knowledge of ITIL service management practice, applied to structured incident, request and change workflows and to SLA response and resolution targets on a live service desk.

Cloud fundamentals

Microsoft Azure & Google Cloud

  • Active self-directed study across both ecosystems, alongside existing Windows Server, VPS and Microsoft 365 tenant administration experience.

Self-directed, project-based study

Full-Stack Web Development

  • Actively developing hands-on coding skills in Python, Node.js and client-side JavaScript through project-based self-study, building on existing front-end work and .NET application-support experience.

Emerging technology

The AI / LLM Ecosystem

  • Ongoing study of the AI and LLM ecosystem, from local model deployment through agentic tooling and API integration, applied directly to documentation, scripting and operational workflows.

02 Applied & Complete

Capability with shipped production work behind it, rather than coursework.

Certification · Held

TechSmith Snagit Certification

  • Certified in advanced screen capture and tutorial production; applied daily across user-guide, training and documentation work, including the video-training and user-guide programme developed at Civilsoft Systems.

POPIA Compliance Awareness & Applied Review

  • Practical depth built through real work: document and compliance workflow design, drafting regulatory pages (POPIA, ECTA) and reviewing data-handling practice for professional-services clients.

Windows & Linux Hardening

  • Hardening and debloating as routine practice across six years of Windows Server and VPS administration, plus Linux across Arch, Debian, Ubuntu and the security-focused distributions.
  • Endpoint protection and antivirus administration (Microsoft Defender); firewall configuration and egress control on both Windows and Linux hosts.

Digital Evidence Handling

  • Evidence handling to ACPO good-practice guidance and ISO/IEC 27037, with CAINE imaging and SHA-256 integrity verification.

Local & Cloud LLM Deployment

  • Deployed and evaluated local LLM tooling (Ollama, AnythingLLM) and integrated Claude, Claude Code and the Anthropic API, Gemini and Gemini CLI, and GitHub Copilot into daily documentation, scripting and development workflows.

Microsoft 365, Identity & Endpoint Administration

  • Learned and then run in production as sole administrator: tenant administration at Global Administrator level, Entra ID, conditional access, multi-factor enrolment, Intune-managed endpoints and joiner/mover/leaver administration.

Google Workspace Business Administration

  • Configured and solely administer Kouga Digital's Google Workspace Business environment, including ongoing maintenance, alongside deeper, longer Microsoft 365 production experience.

03 How I Learn

Entirely self-taught across the technical stack, with a record of learning fast and delivering in production without formal training or courses.

Production first:

A competency is only listed as a skill once there is real, shipped work behind it, demonstrable and able to survive probing in an interview. Until then it stays on this page.

Written down as it is learned:

Runbooks, snags-and-gotchas records and knowledge-base notes are produced while the work is happening, not reconstructed afterwards, so a fault that has cost time once cannot cost time again.

Learned by building:

Study is project-based. Scripting, hosting, automation and AI tooling have all been learned by putting them into live client and internal environments and then maintaining them.

04 Planned

  • Security+ completion, then the offensive-security path: sit CompTIA Security+, then progress the practical eJPT, PNPT and OSCP work toward formal certification.
  • Cloud certification: convert the Azure and Google Cloud self-study into a formal associate-level certification alongside the existing on-premises and hybrid administration record.
  • Full-stack development: grow the Python, Node.js and JavaScript work from project-based study into production delivery within the practice.
  • Service management: formalise the working ITIL knowledge already applied on the service desk.