We provide IT Staff Augmentation Services!

Senior Network Security Engineer Resume

3.00/5 (Submit Your Rating)

OBJECTIVE

  • Seeking an interesting position with a great company. I am looking for full time, permanent (no contract or contract to hire), remote or onsite, less than 25% travel, and I am open to relocation.

TECHNICAL SKILLS

Palo Alto firewalls: VM, 3000, 3200, 5000, and 5200 series

Cisco firewalls: Meraki, ASAv, ASA 5500, ASA 5500 - X, Firepower 2100 and 4100

Amazon Web Services: Solution design, VPC, CloudFront, ELB, Autoscaling, EC2, EFS, RDS, VPN, Cloud Watch, S3, Glacier, Route 53, IAM, custom AMIs, and hybrid cloud integration

Cisco routers: 2500 to 7500 models and ASR 1000 series

Cisco switches: 2900 to 6500 models and Nexus 7000 and 9300

Arista switches: 7010, 7050, and 7060 series

F5 load balancers: Virtual edition, 2000, 3000, 5000 series

Checkpoint firewalls: 4.1 to R70

VMWare: Version 2 to 6.7, VCenter, vSAN, VDS, DRS, clusters, resource pools, and creating templates

WAN setup: ISDN, T1, T3, OC3, Frame-Relay, MPLS, VPLS, ATM, and 1/10 Gb Ethernet

Network Security: Nessus and NMAP security scans, IDS and IPS management (Snort, ASA, IOS, Palo Alto), firewall policy auditing, vulnerability remediation, and Wireshark packet analysis

Network Monitoring: Solar Winds, SevOne, PRTG, Manage Engine, Cisco Works, MRTG, QRadar, Splunk, and Elastic Search

PROFESSIONAL EXPERIENCE

Senior Network Security Engineer

Confidential

Responsibilities:

  • Support of a global network consisting of roughly 200 Cisco ASA, Cisco Firepower, and Palo Alto firewalls located in 10 datacenters and dozens of offices
  • AWS and Azure cloud integration, redundant VPN setup, and firewall setup
  • Global SSL decryption implementation with different policies for different regions
  • Ensured compliance with various regional security standards (PCI DSS, GDPR), audited firewall policy, and remediation of security vulnerabilities
  • Security and Incident response, support, and root cause analysis
  • Supported globally distributed VPN concentrators for thousands of remote access users and hundreds of site to site customer connections

Senior Network Security Engineer

Confidential

Responsibilities:

  • Network support for global multi-site LAN/WAN
  • Successfully migrated firewalls from Juniper (ScreenOS) to Palo Alto
  • Ensured compliance with security standards (PCI DSS, HIPAA), audited firewall policy, security scanning, and remediation of security vulnerabilities
  • DDOS protection implementation using Imperva / Incapsula
  • Implemented and supported 802.1x and NAC implementation using Cisco ISE
  • VPN support for employees, consultants, and partners using Cisco ASA and IOS VPN

Senior Network Engineer

Confidential

Responsibilities:

  • Setup and supported the companies network in multiple locations, maintaining 99.9% availability (monitored externally) for the SaaS applications
  • Datacenter to AWS cost analysis and migration
  • Performed several large (hundreds of hosts) P2V migrations
  • Performed several datacenter migrations and vendor migrations
  • Designed and implemented the LAN for a new datacenter using the Cisco Core/Distribution/Access model consisting of 12 6509 L3 switches, 20 4006 switches, 6 CSS 11000 series load balancers, and 8 Checkpoint firewalls
  • Migrated several company locations from static routing or EIGRP to OSPF and BGP dynamic routing to increase network availability and better utilize WAN resources
  • Managed routing for a LAN/WAN running OSPF as the IGP and BGP as the EGP in a multi-vendor (Cisco, Checkpoint, Juniper) network covering 12 locations
  • Managed company and customer IPSEC VPNs using Cisco, Checkpoint, Juniper, and IOS and remote access VPNs using the Cisco IPSEC VPN client, the AnyConnect client as well as SSL clientless VPNs
  • Created a custom web site for monitoring the companies SaaS products using Python, PowerShell, MRTG, and a custom application testing tool
  • Disaster Recovery planning, implementation, and testing both for our internal systems as well as customers with multiple datacenters

We'd love your feedback!