Network Security Engineer Resume
5.00/5 (Submit Your Rating)
Houston, TX
SUMMARY:
Information security architect with experience building, protecting and automating resilient, distributed systems.
PROFESSIONAL EXPERIENCE:
Confidential, Houston, TX
Network Security Engineer
Responsibilities:
- Built out and supported private and public cloud web - application and email delivery systems based on F5 LTM GTM load balancing proxies.
- Final level of support for F5 load balancers and proxies as well as F5's APM network access control suite.
- Built out monitoring and reporting using Splunk and other o -the shelf systems, e.g. SiteScope. Built a web app to report on F5 LTM con guration and status using F5's iControl API.
- Worked with internal threat researchers to contain discovered exploits via custom rule-sets in McAfee Intrushield IPS.
- Managed Checkpoint, Palo Alto rewalls and Aruba ClearPass NAC.
Confidential, Houston, TX
Data Security Architect
Responsibilities:
- Responsible for developing applications, systems & network security solutions from concept to imple - mentation.
- Enacted security standards, advised leadership and technical sta on security risks and best practices.
- Served on the \Architectural Review Committee" to approve the design of proposed IT systems, create technical standards and advise policy.
- Built an application delivery system around F5's BIG-IP technologies using Global and Local Tra c Managers.
- Set up a centralized multi-factor authentication system for websites with a mix of F5's Access Policy Manager (APM) and RSA's Adaptive Authentication.
- Installed and con gured F5's SAML-capable proxy to allow SSO with third-party applications. Protected web applications with F5's Applications Security Manager and SourceFire IPS.
- Built a DDOS mitigation scheme by peering with ISPs and incorporating Arbor's Pravail APS.
- Developed baseline security con gurations for MS Windows 7, Linux & AIX systems along with popu-lar applications like MS O ce, Internet Explorer & Firefox applications on NIST and CIS Benchmarks.
- Set up Symantec's Control & Compliance Suite to audit system compliance to con guration standards.
- Set up a meaningful risk assessment and reporting practice through the integration of Symantec's CCS with Symantec's Data Leak Protection, Endpoint Protection, and Rapid 7's Nexpose vulnerability scan results.
- Ran popular security tools including Checkpoint and Cisco rewalls, BlueCoat forward proxies, Rapid 7's and and RADIUS AAA servers.
- Set up phishing campaigns using Rapid 7's Metasploit.
Confidential, Houston, TX
Enterprise Systems Engineer
Responsibilities:
- Worked on improving Microsoft Active Directory Services, PKI, and Microsoft Exchange systems.
- Integrated Wi authentication with Active Directory through RADIUS & 802.1x capable APs.
- Automated common administrative tasks through VBscript and PowerShell.
Confidential, New York, NY
Systems Engineer
Responsibilities:
- Lead for MS Active Directory and MS Exchange.
- Created detailed continuity and disaster recovery plans for messaging, DNS and web services.
- Minimized disaster recovery times by integrating VMWare's Site Recovery Manager with EMC Clari - ion snapshot and mirroring services.
- Managed encryption tools: PGP, Bitlocker, EFS, and Safend.
Confidential, New York, NY
Systems & Networking Lead
Responsibilities:
- Designed a highly available, multi - o ce WAN through dedicated inter-o ce frame relay links, backed by IPSec VPNs over the Internet.
- Led all Network, MS Active Directory and MS Exchange-related work.
- Designed a multi-homed data center by way of BGP-peering with two ISPs.
- Built a multi-site WLAN around Cisco APs and Active Directory-based authentication.
- Automated desktop deployment using Microsoft's Remote Installation Server and distributed lesys-tem storage.
- Secured systems, rewalls, and networking equipment using NSA, NIST, and vendor guidelines. Managed SonicWall/NetStructure, and Cisco rewalls.
- Migrated from 3M /Motorola/Intel network to Cisco switches and routers. Set up detailed network monitoring.