One interview. Nine battle-tested topics.
The hiring manager wants deep, on-prem BGP and network hardening ownership — plus OpenShift, MetalLB, and the Windows-to-OpenShift migration. This site is the study syllabus: concepts, configs, and the questions he is most likely to ask.
What each bullet is really asking for
The posting is short, but every line maps to a specific skill the hiring manager will probe. He has already said it plainly: on-prem experience beats cloud-managed services.
| JD bullet | What he's really probing | Your story |
|---|---|---|
| Design, configure, support BGP | Can you peer, filter, and debug real sessions without a cloud console? Do you know eBGP/iBGP, attributes, path selection, BFD? | BGP peers, route advertisements, and routing policies at Penske — on-prem + AWS. |
| Deep BGP + network hardening ownership | GTSM, prefix limits, RPKI, communities, secure peering — and owning the result end to end. | Network hardening, PCI DSS patching, Nessus critical/high remediation. |
| Red Hat OpenShift + Linux | Day-2 reality: upgrades, operators, etcd, node maintenance — not just `kubectl apply`. | Production OpenShift for enterprise Java microservices; RHEL 6–9, Oracle Linux 7–8. |
| Migrate Windows VMs → OpenShift | Do you know MTV/Forklift, warm vs cold, virtio drivers, cutover planning? | V2V across ESXi/VxRail/PowerFlex; workload migrations between OpenShift, vCenter, Hyper-V, Nutanix, Exadata. |
| MetalLB as the load balancer | L2 vs BGP mode, IPAddressPools, ECMP announcements, what breaks. | F5 LTM/GTM + production K8s; LB concepts carry straight over. |
| NinjaOne RMM | Endpoint lifecycle: policies, patching, scripting, alerting. | CrowdStrike to 1,000+ Linux servers; WSUS/SCCM patching; Ansible automation. |
| Team of two, one person owns it all | Can you become the redundancy — runbooks, cross-training, shared ownership? | Mentored 15+ admins; runbooks; DR/failover testing; 24/7 on-call. |
Nine pages. Read in order, drill in any.
Pages 1–8 build the technical story from the network up. The Interview page turns it all into answers.
1 · BGP
Peering, attributes, path selection, filtering, BFD, FRR configs, and the hardening moves he'll probe.
Study →2 · MetalLB
L2 vs BGP mode, IPAddressPool/BGPPeer, ECMP announcements, FRR under the hood, OpenShift operator.
Study →3 · OpenShift
Control plane, operators, upgrades, etcd, SCC, OVN-Kubernetes, day-2 admin on bare metal.
Study →4 · Migration (MTV)
Migration Toolkit for Virtualization: warm/cold plans, network/storage maps, Windows virtio, cutover.
Study →5 · L4 vs L7
Where MetalLB, kube-proxy, the OpenShift Router, and F5 BIG-IP each sit — and TLS termination.
Study →6 · Hardening
BGP security, SELinux, firewalld, CIS, TLS, patching — PCI DSS-shaped discipline.
Study →7 · NinjaOne
RMM fundamentals: policies, patching, scripting, alerting — and how to sound fluent in 15 minutes.
Study →8 · Interview
Likely questions with answer frameworks, STAR stories mapped to the JD, questions to ask him.
Study →9 · Recon
What Proforma is, what their public footprint says, and what to infer — carefully — about their stack.
Study →Seven days to fluent
Read for recall, not recognition. Every day: read the page, close it, then answer the drill questions out loud — and type the configs from memory.
- Day 1 — BGP fundamentals + path selection. Drill: explain best-path algorithm cold.
- Day 2 — MetalLB + L4/L7. Draw the traffic path: client → router → MetalLB VIP → pod.
- Day 3 — OpenShift day-2: upgrades, operators, etcd backup, SCCs.
- Day 4 — MTV migration deep dive. Build a warm-migration plan for a Windows app VM.
- Day 5 — Hardening + NinjaOne. Map every JD bullet to a Penske story.
- Day 6 — Interview page: answer every question out loud, timed. No notes.
- Day 7 — Company recon + your questions. Dry run the whole conversation once.
Terminal muscle memory matters more than reading. When a page shows a config, type it into a scratch file or a lab VM. If you can reproduce it from memory, you can defend it under pressure.
Why you, in one line
They have a team of two and one person owns the whole environment. You are the redundancy they're hiring — and you've already done that job at Penske: runbooks, mentoring 15+ admins, DR testing, shared ownership.
BGP on-prem
Peering, policy, and troubleshooting on real hardware — not a cloud console.
OpenShift in prod
Upgrades, operators, scheduling — the day-2 work this role is actually about.
Migration scars
V2V at scale, platform dependencies, the things that break at cutover.
De-siloing instinct
Runbooks and cross-training by default. A team of three with no single point of failure.