Lead Information Security Engineer Resume
SUMMARY:
- Certified Information Systems Security Professional ( Confidential ) with over 10 years of experience and expertise in designing, implementing, and troubleshooting network infrastructure and security.
- Able to evaluate system vulnerabilities in order to recommend security improvements as well as improve efficiency while aligning business processes with network design and infrastructure.
- Superior capacity to solve complex problems involving a wide variety of information systems, work independently on large - scale projects, and thrive under pressure in fast-pace environments while directing multiple projects from concept to implementation.
- I am looking for a position that will allow me to use a combination of existing skills and continued growth to help an organization to reach their mission and goals.
CORE COMPETENCIES:
- Information Assurance & Governance
- Risk Management
- System Architecture Design
- Configuration Management
- Disaster Recover/Business Continuity
- Network Security Administration
- System Security Evaluation
- Systems Administration
- VOIP
- Wireless Networking
TECHNOLOGIES:
Firewalls: Cisco; Checkpoint; WatchGuard; Juniper; SonicWall
Control/Appliances: NAC - Forescout CounterAct, IPS/IDS - Cisco, SIEM - QRadar & LogRythm, Syslog - SolarWinds, Proxy - Blue Coat
Tools: Nmap, Nessus, ACAS, Metasploit, Burp Suit Pro, Perl, Python, C#, Kali Linux, SNORT, WireShark, TCPDUMP, OpenVAS
Information Assurance: Encryption, PKI, Digital Signatures, DLP, HBSS, Risk & Vulnerability Assessments, Access Control
INFRASTRUCTURE TECHNOLOGIES:
- Network design, VLAN, ACL's, DNS, DHCP, TCP/IP, NAT/PAT, SSH, SNMP, TCP/IP, 802.1x, Port-Security, VPN tunnels
- Cisco router & switches, Routing protocols (EIGRP, OSPF, BGP); F5 LTMCisco ACE, Ecessa PowerLink, Juniper WXC Wan optimizer
- T1, DS3, OC3, Frame Relay, Point to Point, MPLS, Metro-E
- VOIP, Cisco Call Manager, Unity, Avaya
- Wireless networking, Cisco Tandberg Video systems
- VMware, Citrix, SAN, NAS
WORK EXPERIENCE:
Lead Information Security Engineer
Confidential
Responsibilities:
- Network design and implementation of local, remote and disaster recovery networks
- Manage Cisco Nexus 5548, 3172; Cisco 3750, 2960 switches, 3845, 2911 routers and various enterprise class network hardware
- Support Cisco ASA 5520, 5525x, 5512x, 5505 firewalls
- Support switch management protocols such as 802.1d, 802.1w & 802.1q
- Manage security controls such as Cisco ASA firewalls, Cisco IPS and Forescout CounterAct, LogRythm SIEM
- Incident response for security threats, alerts, virus and malware infections
- Network security auditing, risk assessment, vulnerability assessment and scanning
- Serve as corporate Information Security Officer for SIPRNet environment
- Design and implement classified DoD network environment
- Support SIPRNet using HBSS, IPS, IDS and Firewalls
- Wireless network management
- F5 LTM load balancer implementation and support
- Active Top Secret clearance
- Recommend, implement, maintain and monitor network security best practices and controls
- Support Certification and Accreditation (C&A) efforts of DoD systems under guidance of NISPOM, DIACAP, NIST 800-53, POA&M, SOPs, IAVM
- Information Assurance Team Lead
- Information Assurance representative for configuration control board
- Develop corporate security plans and policies utilizing various frameworks such as NIST, COBIT, ISO27001
- Design, implement and test corporate disaster recovery solution
Network Engineer
Confidential
Responsibilities:
- Manage largest video network infrastructure in U.S utilizing H.323, H.264 and other video/audio codecs
- Manage Cisco TelePresence and video recording infrastructure
- Manage and support of college campus MPLS WAN for all community colleges in the state of Virginia utilizing BGP & OSPF
- Manage Foundry network switches
- Manage Foundry and Cisco routers
- Manage audio and video conferencing technology utilizing WebEx
- Support Cisco firewall
- Support Cisco Wireless
- Support multi- campus VOIP network using Cisco Call Manager
- Support VMWARE infrastructure
Network Engineer (Consultant)
Confidential, Virginia Beach, VA
Responsibilities:
- Management of enterprise wide technology projects
- Manage Enterprise Class switches such as Cisco 6500
- Manage and support of Juniper EX4200 switches
- Support Cisco ASA 5500 and Juniper firewalls
- Support switch management protocols such as 802.1d, 802.1w & 802.1q
- Support of routing protocols such as BGP, OSPF, EIGRP with redistribution
- Create and support of Vendor and remote access VPN using IPSEC and WebSSL
- Configuration and support of Cisco 9200 Fiber SAN Switch
- Support of multiple remote offices WAN networks using technologies such as ATM, Metro
- Ethernet and Frame Relay
- Provide Senior Network Engineer role encompassing network design, upgrade and support
- Network security auditing, vulnerability assessment and penetration testing
- IT Project management
- Management of junior network engineers and team members
- Management of remote office wide area network utilizing MPLS, Point to Point, Metro
- Ethernet, ATM and Frame-Relay technology.
- Management of local area network consisting of Cisco 6500, 3750, 3560, 2960, 2950 switches
- Manage routing infrastructure consisting of Cisco 7200, 2800, 1700
- Support of EIGRP, OSPF and BGP routing protocols
- Management of Juniper EX4200 series switches
- Management of Cisco 5510 ASA failover pair with IPS module
- Support and management LAN to LAN and remote access VPN
- Monitor local and wide area network bandwidth utilization
- Manage security controls such as Cisco ASA, Cisco IPS and QRadar
- Responsible for information security and assurance
- Develop information security policies and procedures utilizing NIST, ISO27001, COBIT frameworks
- Manage wireless network
- Configuration and support of Cisco 9200 Fiber SAN Switch
- Management of local area network consisting of Cisco 4900M, 2960, 3548 switches
- Support of Barracuda Web Filter, Barracuda F300 firewall
- Assist with PCI DSS and HIPAA security compliance
- Manage technology projects such as total network redesign
- Monitor local and wide area network bandwidth utilization
- Manage wireless network
- Manage help desk
Network Engineer
Confidential, Charlottesville, VA
Responsibilities:
- Responsible for security monitoring, analysis and policy enforcement
- Network security auditing, vulnerability assessment and penetration testing
- Management of enterprise wide technology projects
- Manage Cisco 6513, 3750, 2960, and 3560 switches
- Manage and support of Juniper EX4200 switches
- Support Cisco ACE 4700 load balancers and GSS DNS appliances
- Support of Cisco, 7600, 3845, 2811, 2821, 2851 and 2951 routers
- Support corporate MPLS, and DMVPN infrastructure
- Support Cisco ASA 5500 series, PIX 515, Cisco FWSM and Juniper firewalls
- Support switch management protocols such as 802.1d, 802.1w & 802.1q
- Support of routing protocols such as BGP, OSPF, EIGRP with redistribution
- Manage and monitor network using What's Up professional and Solarwinds
- Design and implement QOS services
- Configure, install and maintain Juniper WXC series Application Acceleration Appliance
- Support corporate VOIP with Cisco Unified Communications and Unity Connections 7.x
- Support Cisco 7960, 7961 phones
- Create and support of Vendor and remote access VPN using IPSEC and WebSSL
- Design, recommend and implement enterprise wireless network
- Manage corporate security appliances such as MARS, Bluecoat and Cisco Firewalls
- Support of national and international global offices
- Project management of technology projects
- Manage and support of junior network engineers
Network Engineer
Confidential
Responsibilities:
- Create and manage VLANS
- Architect, design and implement infrastructure LAN/WAN for remote offices
- Document and update LAN/WAN connectivity
- Maintain router and switch IOS and configuration
- Support corporate communications circuits such as OC3, DS3, and T1
- Support remote office infrastructure
- Support Big IP F5 load balancers
- Support switch management protocols such as 802.1d, 802.1w & 802.1q
- Support of IP routing protocols such as OSPF, EIGRP with redistribution
- Design and implement network infrastructure for remote offices
- Design and implement QOS services
- Support Cisco Access Control Server, Cisco ASA 5540
- Create and support of Vendor and remote access VPN using IPSEC and WebSSL
