We provide IT Staff Augmentation Services!

Sr. Network Security Engineer Resume

5.00/5 (Submit Your Rating)

Omaha, NebraskA

SUMMARY

  • 8.11 professional experience in network design, implementation, and support. Routing, switching, firewall technologies, system design, implementation and troubleshooting of complex network systems.
  • Extensive experience in configuring and troubleshooting of protocols v1/v2, EIGRP, OSPF, BGP and
  • Experience on dealing with Cisco Application Centric Infrastructure (ACI) by integration hardware and software products as per network layout, Cisco Firepower Management Center, Cisco Firepower Stealth watch
  • Worked with VLAN’s, Trunking, RSTP, SNMP, Ether Channels, HSRP, Port Security, ACL’s, QoS, Traffic Policing, Shaping, EIGRP, OSPF, NAT, PAT, Inspections, VPN’s, DHCP, Wire Shark etc.
  • Position the VMware and Dell partnership. Deliver the value proposition of new and updated products such as NSX, VSAN, vCloud Air and AirWatch to achieve customer outcomes.
  • Working configuration of new VLANs and extension of existing VLANs on/to the necessary equipment to have connectivity between two different data centers.
  • Extensive experience in configuring and troubleshooting of protocols RIP v1/v2, EIGRP, OSPF, BGP and MPLS.
  • Installing & configuring firewalls like Checkpoint (Provider - 1, R65, R70, and R75), Secure Platform.
  • Experience in F5 load balancers, its methods, implementation and troubleshooting on LTMs and GTMs, (SPLAT), Juniper SRX, Net screen firewall, Palo Alto, Fortinet and Cisco ASA (5510, 5520, and 5550).
  • Experience in Migration from Cisco ASA's to Fortinet’s’ s Fort iGATE firewalls.
  • Generation Firewall, Cisco ASA (Adaptive Security Appliance), Next Generation Intrusion Prevention Systems, and Firepower Threat Defense.
  • Experience of JUNOS platform and worked with JUNOS upgrade of Juniper devices
  • Experience in Configuring and Troubleshooting BIG-IP F5 Load Balancer LTM.
  • Experience in Cisco Firewalls ASA/ Checkpoint and Cisco SD WAN and Cisco ISE deployed and configured.
  • Experience in Cisco Physical cabling, IP addressing, Wide Area Network configurations (Frame-relay & MPLS), Routing protocol configurations (RIP, EIGRP, OSPF, BGP).
  • Creating Virtual Servers, Nodes, Pools and iRules on BIG-IP F5 in LTM module
  • Experience working on Cisco IOS, Junos& basic Nexus (9k,7K, 5K&2K).
  • Managing DHCP,DNS and IPAM services using Infoblox 1050 appliances.
  • Experience in working on cloud AWS cloud EC2, S3, RDS, Load Balancer, Auto Scaling with AWS command line interface and AWS python SDK.
  • Extensive knowledge in AAA protocols such as RADIUS, TACACS+ and Cisco ACS.
  • Experienced working on network monitoring and analysis tools like, SOLAR WINDS, CISCO works and RIVER BED and Wireshark.
  • Experience in Azure network, VPN and Express route, Azure DNS, Traffic Manager, and Load Balancers
  • Worked on F5 load balancers, its methods, implementation and troubleshooting on LTMs and GTMs.
  • Experience with Change management process and Project documentation tools like Excel and VISIO.

TECHNICAL SKILLS

Cisco Platforms: Nexus 9K 7K, 5K, 2K and 1K, Cisco routers (7600,7200, 3900, 3600, 2800, 2600, 2500, 1800 series) & Cisco Catalyst switches (6500, 4900, 3750, 3500, 4500, 2900, 6807 series)

Juniper Platforms: SRX, MX, EX Series Routers and Switches

Networking Concepts: Access-lists, Routing, Switching, Subnetting, Designing, CSU/DSU, IPSec, VLAN, VPN, WEP, WAP, MPLS, VoIP, Bluetooth, Wi-Fi

Firewall: ASA Firewall (5505/5510/5520 ), Checkpoint (R75/R76), Palo Alto (2k, 3k, 5k), Juniper SRX (240).

Network Tools: Solarwinds, SNMP, Cisco Works, Wireshark, Netcool, Netbrain

Load Balancers: Cisco CSM, F5 Networks (Big-IP)

WAN technologies: Frame Relay, ISDN, ATM, MPLS, leased lines & exposure to PPP, DS1,DS3,OC3, T1 /T3 & SONET

LAN technologies: Ethernet, Fast Ethernet, Gigabit Ethernet, & 10 Gigabit Ethernet, Port- channel, VLANS, VTP, STP, RSTP, 802.1Q

Security Protocols: IKE, IPSEC, SSL-VPN

Networking Protocols: RIP, OSPF, EIGRP, BGP, STP, RSTP, VLANs, VTP, PAGP, LACP, MPLS, HSRP, VRRP, GLBP, TACACS+, Radius, AAA, IPv4 and IPv6

Operating System: Windows 7/XP, MAC OS X, Windows Server 2008/2003, Linux, Unix

PROFESSIONAL EXPERIENCE

Confidential, Omaha, Nebraska

Sr. Network Security Engineer

Responsibilities:

  • Worked on Palo Alto PA-5050 design and installation (Application and URL filtering, Threat Prevention, Data Filtering).
  • Involved in deploying SD-WAN with cisco infrastructure
  • Involved in working with Nexus 9k, 7k, 5k, 2k devices.
  • Testing and prod support of Cisco ACI Data center in network centric mode and EM for customers with multitenancy using Clustered APIC controllers M1 C220 M3/M4.
  • Worked in for the NextGenDatacenter Cloud Architecture, using Cisco ACI and Nexus 9K.
  • Advanced skills of designing, coding, and troubleshooting iRules Executed the F5 Viprion to deal with high traffic volume for L7 traffic on 2250 blade while Thunder 6630 using Viprion chassis
  • Participated in troubleshooting SDN/SD-WAN deployments.
  • Involved in t roubleshooting and implementing Monitors and I rules on f5 equipment.
  • Deployed CISCO ACI Greenfield and Migrated from Legacy network.
  • Involved in Configuration and Implementation of Juniper SRX Firewalls across various new Branch sites as a part of tech refresh.
  • Performed OSPF, BGP, DHCP Profile, HSRP, IPV6, Bundle Ethernet implementation on ASR 9Kredundant pair.
  • Developed ACI (Cisco Application Centric Infrastructure) based Cisco Validated Designs for Enterprises and Service Providers to transform Traditional 3 Layer Architecture to ACI based (Spine, Leaf and APIC) Architecture.
  • Conversions to BGP WAN routing. Which will be to convert WAN routing from OSPF to BGP (OSPF is used for local routing only) which involves new wan links.
  • Completed project to evaluate Cisco Next-Generation Firepower 4100 Series security appliances for both the virtual Firepower Threat Detection and the Virtual ASA modules to increase security in a production environment.
  • Involved in administration Big IP F5 LTM for all Local Load balancing and use GTM for load balancing across Data Centers.
  • Involved in troubleshooting DNS/DHCP issues within the LAN network.
  • Configured active directory domain, DNS and DHCP on Windows 2012 R2 standard
  • Worked on F5 LTM/GTM, BIG-IP, load balancing, I Rules and WAN acceleration.
  • Successfully installed Palo Alto PA-3000/PA-5000 firewalls to protect Data Center and provided L3 support for routers/switches/firewalls.
  • Involved in working on Cisco ISE to authorize users based on protocols PEAP and EAP-TLS, also manage and monitor user's access privileges.
  • Provide expertise in engineering secure networking technical solutions for the Information System within a Virtualized environment using VMWare NSX
  • Regular upgrade and maintenance of Infrastructure including Cisco Router and Switches, Juniper Routers and Firewalls, Nexus 7k,5k & 2k, F5 BIG IP and Palo Alto Firewalls.
  • Configure, monitor, and repair of Active Directory domains Analyzed user needs and recommended appropriate hardware.
  • Provided in depth analysis using but not limited to Vital net, Net QoS, Net screen Manager (NSM), Wireshark, Net cool Monitoring and Infinistream Management Console.
  • Created different application policies in the ACI including Tenants, Application Network Profile (ANP), End Point Group (EPG), Contracts, Subjects, and Filters & Labels.
  • Tested various networks which works on the protocols like of TCP/IP (IP, TCP, UDP, SNMP, DNS, DHCP, FTP, HTTP, HTTPS, ICMP, SMTP, ARP, IPSEC, and NAT).
  • Extensively worked with configuration of Network and Security devices such as Cisco routers and switches (Cisco 7K/3K/Nexus 9K/7K/5K),, Load Balancers, DNS and IP Manager (Infoblox)
  • Configured rules and maintained Palo Alto Firewalls & analysis of firewall logs using various tools
  • Provided administration and support on Bluecoat Proxy for content filtering and internet access to headquarters, remote site offices and VPN client user
  • Responsible Implementing NAT solution's on WAN applications with Cisco ASA based solution.
  • Involved in design and implementation of security infrastructure for clients focusing on Cisco Firepower and ASA suite of products.
  • Worked on Cisco Routers, Active /Passive Hubs, Switches, Cisco ASA Firewalls, NAT and Juniper SRX firewall.
  • Defined and deployed monitoring, metrics and logging systems on Aws. Migrated existing on-premises applications to AWS
  • Monitored infrastructure with Nagios like Firewalls, Servers, Services, Network devices, applications, web portals etc. Resolution of tickets fresh & pending
  • Selecting appropriate AWS service to design and deploy an application based on given requirements.
  • Automated network implementations and tasks and designed monitoring tools using python scripting.
  • Dealt with creating VIP(virtual servers), pools, nodes and applying I Rules for the virtual servers like cookie persistency, redirection of the URL
  • Involved in configuring BGP, OSPF in Juniper MX series routers for branch/back office locations.
  • Worked in configuring all Palo alto Networks Firewall models (PA-2k, PA-3k, PA-5k etc.) as well as a centralized management system (Panorama) to manage large scale firewall deployments
  • Responsible for providing on-going support to application centric infrastructure (ACI) solution.

Confidential, El Segundo, CA

Senior Network Engineer

Responsibilities:

  • Worked on providing management connectivity, HA configuration, setting up RSA for MFA, license and updates management, VSYS support, L3, aggregate Ethernet and sub interfaces configuration, configuration of BGP on both Nexus and Palo Alto, moved SVI (server VLAN) interfaces from ASA core to Palo Alto.
  • Worked on data center segmentation project to create segmentation between the user and server traffic by deploying Palo Alto firewalls (5250s) in the datacenter including cabling to the Nexus 9K, 7K VDCs and HA.
  • Worked on in corporate Cisco Nexus 9000 NXOS to ACI fabric to work in concert with the existing Nexus 7000s.
  • Security policy review and configuration in Palo Alto and Juniper SRX Firewall in Datacenter.
  • Managed the F5 BigIP GTM/LTM appliances to include writing iRules, SSL offload and everyday task of creating WIP and VIPs.
  • Design and implement Cisco ACI in data centers create a strategy that allows use of containers, cloud orchestration tools for end users and developers.
  • Implemented site to site VPN in Juniper SRX as per customer.
  • Designed the ACI fabric to ensure each tenant/host is secured and has separated from other tenants/hosts. Used of L3/L2 outs via common tenants to reduce TCAM and RAM utilization.
  • Created ACI migration plan (brownfield) create L2/L3 transitions. Map traffic flows for EPGs and BDs. Handled drivers for ML2 and GBO Open Stack integrations.
  • Implemented Positive Enforcement Model with the help of Palo Alto Networks
  • Maintenance and administration of Palo Alto Network firewalls, Panorama.
  • Configure all Palo Alto Networks Firewall models (PA-2k, PA-3k, PA-5k etc.) as well as a centralized management system (Panorama) to manage large scale firewall deployments.
  • Responsible in troubleshooting on Cisco ISE added new devices on network based on policies on ISE.
  • Selecting appropriate AWS service to design and deploy an application based on given requirements
  • Provided day-to-day support in the maintenance and troubleshooting of OSPF at the core layer
  • Providing IT Network Engineering and Systems Engineering support on a wide range of technologies, including: VMWare NSX, Cisco, VMware Workstation, VMWare Vsphere, VMWare Networking, Routers, Switches, Software-based networking, Firewalls, ACLs, DMZ, VMware, VMWare Networking, Windows Server 2012 R2, Sentris, Active Directory, SAN, Sentris 3, and PKI (two-factor authentication)
  • Implemented VPN solutions for site-to-site connectivity using Juniper SRX services gateway and remote access VPN solutions using Juniper Pulse secure access.
  • Work with Load Balancing team to build connectivity to production and disaster recovery servers through F5 Big IP LTM load balancers.
  • Worked on setup and installation of Cisco ASAs with Firepower and configured it for URL filtering.
  • Experience in Azure network, VPN and Express route, Azure DNS, Traffic Manager, and Load Balancers
  • Azure Platform development and deployment Lifecycle
  • Upgraded the existing Panorama to V8. Integrating the new firewalls to Panorama and responsible for working on change tickets for existing 3250 Palo Firewalls in the environment.
  • Configuration and installation of LAN switches and wireless network infrastructure equipment and cabling all uplink and user network connections.
  • Deployed Nexus switches 2248, 5548, 7018 and implemented features like FEX Links, VPC, VRF, VDC, and OTV, Fabric Path.
  • Experience with Cisco ACI (Application Centric Integration) technology implementation.
  • Created VSYS Builds from Checkpoint to Palo Alto Panorama Database Zone, Access Zone.
  • Determined the VPN connectivity requirement for users, VPN pool and gateway information, integration of RSA for VPN authentication, defined rules for non-console administrative access, implemented and tested non-console admin rules for firewalls.
  • Created script in python for calling REST APIs.
  • Review and analyze events from logs and Source Fire IDS/IPS
  • Worked on Nexus 7018/7010, 5020, 5548, 2148, 2248 devices.
  • Involved in working with OTV & FCOE on the nexus between the datacenters.

Confidential, Atlanta, GA

Network Security Engineer

Responsibilities:

  • Responsible to evaluate, test, configure, propose and implement network, firewall and security solutions with Palo Alto networks.
  • Reviewed and optimized firewall rules using Netscout firewall monitoring tool by creating customized firewall audit reports. Migrated datacenter firewall rules based on Zenoss Analysis/query and Reports.
  • Staged, planned and deployed Palo Alto 5060 within Data Centers. Worked with Palo Alto firewalls using Panorama performing changes to monitor/block/allow the traffic on the firewall.
  • Installed and configured Meraki (MX80, MX60) Appliance via Meraki MX400 Cloud.
  • Fortinet firewall deployment for multiple locations.
  • Installed and configured Cisco Meraki (MR66, MR18) wireless Access points in the warehouses.
  • Installed and configured Cisco Nexus 9k/7k/5k/3k switches for VPC, Vlans, MST and 802.1q for Top of the Rack switches and Distribution layer switches.
  • Configured active directory domain, DNS and DHCP on Windows 2012 R2 standard.
  • Experience with products such as Cisco ISE, Cisco ASA 5500 series firewalls and Cisco ACE 4710 Load balancers.
  • Palo Alto/Checkpoint Firewall troubleshooting and policy change requests for new IP segments that either come on line or that may have been altered during various planned network changes on the network.
  • Extensive work with MPLS, configuring BGP, policy-based routing, redistribution, VPN etc.
  • Worked on troubleshooting of tickets in complex LAN/WAN infrastructure using packet captures, protocol analyzers, syslog servers etc. Worked on CA spectrum network monitoring tool.
  • Configure and maintain site to site VPN using Netscreen firewalls.
  • Configuration of Arista DCS7300, 7010, MX960s to replace end-of-life devices.
  • Defined and deployed monitoring, metrics and logging systems on AWS. Migrated existing on-premises applications to AWS.
  • Managed Cisco PIX firewall for ACL and VPN. Also worked with the physical server migration to AWS data center.
  • Involved in designing and implementation of AWS network and connectivity b/w physical and AWS DC.
  • Installed Arista core and distribution solution to replace current Cisco environment.
  • Working experience on tools and devices like Source Fire, Cisco ASA, Cisco ISE.
  • Corrected configuration issues and implemented best practices for configuration of VDC, VPC, VRF, FEX

We'd love your feedback!