Network Engineer Resume
Suitland, MD
SUMMARY:
IT professional with goals aligned in IT Security. I have a wealth of knowledge in spaces pertaining to Banking/Finance, Government (Federal/State and Local), Non - Profit, Healthcare and Communications. All have been held to rigorous compliance standards like PCI, SOX, ISO 27001, HIPAA and Hitech. With more than 20 years in the industry, I have honed my skillset to include an array of areas in IT.
PROFESSIONAL EXPERIENCE:
Confidential, Suitland, MD
Network Engineer
Responsibilities:
- Working on a contract for Confidential at their Confidential Satellite Operations Facility. Daily action items included working to remediate Confidential vulnerabilities (collecting evidence of remediation) for Confidential & Confidential milestones.
- Partnering with the Network Engineering teams, Satellite Operations (Geostationary Operational Environmental Satellite ( Confidential ), Polar Operational Environmental Satellite ( Confidential ), Confidential - Ocean Surface Topography Mission, and the Confidential - Earth System Prediction Capability (assisting with the implementation of Palo Alto firewalls) programs, respectively). Attending change control meetings for all programs.
- I assisted the Network Team on Confidential in implementing the Palo Alto 7050 implementations, as no one has a datacenter experience.
- I was the sole person to review all configurations. I was also running nessus scans monthly on each program.
- Researching vulnerabilities and working with other vulnerability scanning teams to check for any new plugins for nessus enterprise.
- Assisting other areas where needed.
- Writing of SSP’s and SOP’s for the various programs.
Senior Information Security Engineer/Team Lead
Confidential, Elkridge, MD
Responsibilities:
- Worked on a contract for the State of Maryland Department of Human Resources providing oversight for applications ranging from Child Support to Benefit Eligibility.
- Daily action items include revising/creating SSPs, SIAs, PTAs and more. Manage the team Sharepoint collaboration site.
- Review change control items, create plans for Network Engineering team to upgrade Confidential firewalls that interface with the client side.
- Creating new VLAN’s to accommodate growth within the facility.
- Review group policies for potential NIST SP 800-53 Rev4 violations.
- Look at password policies across all platforms for issues. Look at contracts for ways to possibly consolidate some areas (eg, IDS and webfilter) into a cheaper solution that can do a more effective job, thus saving the bottom line for the company.
- Mentor junior personnel in the proper way to work with the client while still being able to provide the best service.
- Generally I pick up the things that fall off the managers’ plate and accept the responsibility to get it done right the first time.
- Assisted in the implementation and project planning of major data center migration from Confidential corporate DC in Dallas to Indianapolis Data Center along with implementing a backup DC simultaneously in Baltimore over the 2 years.
- In conjunction, stood up new Seim for all applications (IBM LogRhythmn).
Senior Information Security Engineer
Confidential, Washington, DC
Responsibilities:
- Team lead for Information Security, 4 person team.
- Managed day to day security activities including project management (Approximately 96 ongoing projects).
- Responsible for all Confidential firewalls (2 border internet, 2 VPN, 2 Application (Palo Alto) and many others for one off projects) from implementation to maintenance and auditing of rule sets.
- Interfaced with project management office, a separate department outside of IT, along with other department heads to acquire business requirements and offering up alternatives that were safer which fell inside any security controls.
- Reviewed monthly access logs to all DC’s and network closets.
- Issued and maintained all SSL certificates for the institution.
- Investigated and tested new products.
- Maintained Proxies (reverse) in the DMZ, used for remote access to Exchange.
- Started project to virtualize the DMZ including placing new switches along with separate VLANs for VMware.
- Implemented application layer firewall, with integrated URL filtering, threat prevention and integrated LDAP for categorization allowances.
- Mitigated problems that escalated to my level, to include but not limited to, Active Directory clustering problems, Citrix gold image issues, AntiVirus spawning multiple instances in one VM, virus eradication, change management problems, power distribution.
- Migrated Confidential Ironport to Proofpoint hosted solution, along with setting up automated encryption of emails depending on content.
- Put in foundation for roadmap for IAM automation.
- Upon hiring, took inventory of existing firewalls (turned out to be the old Pix platform, using old conduit rule set instead of Confidential ’s); issued request for newer hardware and upgraded the old architecture to the latest Confidential platform, this process took me over 6 months to convert old language to newer, more conventional language. The original code was approximately 800 lines and expanded to over 20,000 lines. I planned and put into place all Confidential ’s within our facilities.
- Confidential controls (via Confidential ) put in place around the environmental system implementation for all DC’s, 3 in total.
Information Security Specialist
Confidential, Reston, VA
Responsibilities:
- Platform owner for Novell/Windows AD and RSA SecurID.
- Responsible for procedures, updates and content.
- Trained delegated Security Administrators in their respective divisions, as they needed to be trained more in depth than the average user, whom also was trained via billboards and newsletters, monthly.
- Interfaced with internal and external auditors on a 2 week rotational basis
- Helped out other platforms when they were short handed, such as Lotus Notes and Sybase.
- Used ePO for standardization on all workstations.
- Worked with functional divisons to deliver security schemas. Also adapted security relations with divisional leaders to deliver BCP expectations.
- Was instrumental in the adoption of true disaster recovery of many departmental areas of key corporation functionality.
- Worked with department heads to designate data/object owners for the Oracle IAM solution. Attended weekly change control meetings that concerned the platform, departmental or key area issues concerning data ownership, assignment, or transferrable.
- Assisted the firewall team with management of Confidential web proxies as a cross training initiative.
Consultant
Confidential, Reston, VA
Responsibilities:
- Contracted to Confidential for Security Administration. Responsibilities include granting access to contract workers and Confidential employees to various services and shares. Conduct security assessments or reviews of shares that are incorrectly setup and correcting the problem. Answering trouble tickets with the use of Vantive. Novell 5 NDS administration is used to setup new users or granting access to current users as well as creating shares. Windows 2000 Active Directory administration is shared between another contractor, 2 full time employees and me. Issuing secureID tokens for VPN authentication. Setup of Biometrics and single sign on. Setup of Lotus Notes R5 and troubleshooting (Non DBA).
Network Engineer/Manager
Confidential, Washington, DC
Responsibilities:
- Head of IT Department (Washington Office) 3 person team
- Managed capital and operational expenditures
- Supervised 2 other positions, one a Lotus Notes Admin, the other a Helpdesk member
- Implemented an asset inventory system.
- Placed a Confidential pix on the circuit to my home office, replacing Confidential ’s on the router.
- Updated WAN routers to IOS 12.4 to allow for H323 traffic for VC
- Upgraded Rightfax servers to newer technology since “Blast” faxing was major part of the business.
