We provide IT Staff Augmentation Services!

Network Security Engineer Resume

3.00/5 (Submit Your Rating)

MA

PROFESSIONAL SUMMARY

  • Networkprofessional wif 5+ years of experience having excellent communication, analytical and logical skills. me have extensive experience in network design, performance, planning, installing, configuring, troubleshooting and securing corporate intranets and managing multiple customer network sites. me'm proficient in rapidly identifying emerging technologies and efficiently adopting it in a timely manner.
  • Experienced in large - scale enterprise network maintenance and migration wif expertise in designing planning, and testing of enterprise LAN/WAN products and protocols.
  • Working experience wif CISCO Switches (2900 | 3560 | 3750 stack | 4000 | 6500 series).
  • Working experience wif CISCO Routers (2500 | 3600 | 3700 | 7200)
  • Configured and managed Nexus 2k fabric extender, 5K and 7K switch network at the client’s location.
  • Designing and Implementation expertise of network wif routing protocols such as RIPv2, EIGRP, OSPF and BGP.
  • Configuration experience of Site-to-Site VPN and Remote-access VPN wif CISCO PIX 515E firewall and ASA 5540.
  • Good knowledge of zoning, masking and LUN management wif regards to SAN.
  • Expertise in large-scale application and network migration of the enterprise network.
  • Expertise in designing, implementation and support of LAN.
  • Working experience wif Wireless LAN Controller (WLC) and Light Weight Access Point (LWAP).
  • Good knowledge of WAN technologies such as Frame Relay and MPLS.
  • Working experience wif 6500 series switches at layer 2 and layer 3. Implemented 6500 VSS for improved efficiency and high bandwidth availability.
  • Experienced in gateway load balancing using HSRP and VRRP.
  • Managing Layer 3 filtering using Distribute-list, ACL, Prefix list and Route-map.
  • Configuration experience of Cisco VOIP phones along wif QOS parameters.
  • Good Knowledge of IPv4 and IPv6 addressing. Excellent understanding of IPv6 configuration and testing.
  • Expertise in creating groups and pruning traffic flow using VLAN, VTP, ISL, 802.1Q.
  • IP addressing and IP address scalability by configuring NAT/PAT.
  • Implementing port based security by authenticating users wif 802.1x switch port configuration and implementing VACL and port security for restricting local user access.
  • Good knowledge about spoofing attacks and mitigating them using DHCP snooping, IP source guard and Dynamic ARP inspection.
  • Upgrading CAT OS and CISCO IOS for switches and routers.
  • Experienced working on network monitoring tools like, SOLAR WINDS, CISCO works and RIVER BED and Wireshark.
  • Working experience wif IP reservation and DHCP management using - INFOBLOX and QIP.
  • Excellent in documentation and updating client’s network documentation using VISIO.
  • Strong background in Technical support, network and communication infrastructure and desktop administration.
  • Self-motivated wif ability to quickly comprehend, co-ordinate, organize, analyze, troubleshoot and solve simultaneous complex technical issues.
  • Proven record of configuring and troubleshooting network issues in timely manner and maintain the client’s Service Level Agreement.
  • Dedicated network engineer wif affinity to work as a team as well as perform individually.
  • Prior experience working in a 24/7 operational environment to achieve desired project targets. Possess excellent communication, interpersonal and presentation skills.

TECHNICAL SKILLS

LAN/WAN: IP Routing, Frame Relay, TCP/IP, RIP, OSPF, EIGRP, SAN, DHCP, Multi-Layer Switching

Routing: IGRP/EIGRP, RIP, OSPF, IP, MPLS, NAT/PAT, HSRP/VRRP, BGP, VLAN trunking protocol (VTP), Multicast, SONET, STP, ISL, 802.1q, HTTP, FTP, SSH, SMTP, VPN, ttcp

Switching: IPv4, IPv6, PPP, Tunneling, LANPBX Systems, SIP, Cat 5e/6 Ethernet Cables, Gigabit Ethernet, syslog

Protocols: Layer 3 RIPv2, OSPF, EIGRP, and BGP.

Layer 2: VTP, STP, RSTP, MST, VLANs, PAgPand LACP.

Algorithms: DES, 3DES and AES, MD5 and SHA.

Security: IPSec VPN, Firewall IOS, Cisco PIX, Cisco ASA 5505, Cisco 6500 switches, 7200 routers

Voice: SIP, ISDN, SS7 Signaling Network, RTP, RTCP, H.323 protocol, H.225.0 call signaling, G.729, G.711, MGCP (Media gateway control protocol), MEGACO, XLite

Cisco Equipment: Cisco routers (25XX, 26XX, 28XX, 36XX, 72XX) series & Cisco Catalyst switches (19XX, 29XX, 3550, 3750, 65XX) series, Cisco ASDM, N5K (FCoE), N7k (Nexus).

Operating Systems: MS Windows, MACINTOSH, Linux, UNIX

Languages: C, HTML, Perl, Shell Script

Applications: MS Office, MS Visio, Wireshark, VMware, NGX, Putty, Sniffer, SNMP, IPSec, Ping Plotter, Virtual Box, Firewalls, Nmap, Solarwinds, SPLAT, Steganography NetFlow, Nimsoft, OPNET IT Guru, XLite, tcpdump, Whatsup Glod, Device Manager

PROFESSIONAL EXPERIENCE

Confidential, MA

Network Security Engineer

Responsibilities:

  • Integrated Testbeds wif 5k, 2K NEXUS switches, Cisco UCS (setup, VMware, ESX 5.0+) and ASA 5585, ASA 5520 for remote and L2L VPN any connect testing.
  • Configured Nexus 5K Fiber channel over Ethernet (FCoE) for SAN connectivity for LAN free backup. Coordinated wif other engineers to set up the new Cisco UCS for VMs and servers and also halp in maintained the existing SUN storage hardware wif the SAN engineer.
  • Documented all the installations and configurations using MS Visio and Word, configured packet filtering and NAT for securing internal network, security policies for machines perform regular patches and updates on time.
  • Migration of Checkpoint Firewall to ASA Firewall for addressing enterprise needs of firewall, IPsec VPN and IPS. Applied ACL, NAT, PAT and Firewall policies.
  • Performed IP addressing and subnetting, route Summarization and redistribution, NAT/PAT and DHCP; designed and implemented static and dynamic routing protocols including OSPF and BGP.
  • Configured anyconnect VPN tunnels on different ASA, by defining IKE phase 1 and 2 policies. Dealt wif cryptographic algorithms such as DES, 3DES and AES, data integrity algorithms such as MD5 and SHA. Used Cisco SDM and ASDM extensively for tunnel configuration.
  • Performed IP addressing and subnetting, route Summarization and redistribution, NAT/PAT and DHCP; designed
  • Developed TCL scripts to automate and configure the remote access and L2L anyconnect configurations in order to identify and troubleshoot errors and discards generated.

Confidential, Chicago

Network Engineer

Responsibilities:

  • Responsible for monitoring network performance in order to maintain excellent network stability.
  • Monitoring and troubleshooting network issues between client site and 110 remote sites wif legacy switches and routers.
  • Integration of network devices wif monitoring tools like what’s up Glod, Solarwinds (NCM) for monitoring the connectivity.
  • Managing Level 2 and Level 3 production and participating on call to troubleshoot networks at remote sites.
  • Implement and setting up circuits/remote site connectivity in conjunction wif 3rd party providers (AT&T/ Verizon/ Level-3, etc.), including network redundancy and capacity planning, monitoring, and recommendations.
  • Configuring, maintaining IPSec static/dynamic tunnels, Frame relay technology for 4G/DSL/DS-1 between remote and local sites.
  • Managing organizations network consisting of more than 100 nodes consisting of layer 2, layer 3 devices and firewalls.
  • Configured IPSec VPN tunnels on PIX and ASA, by defining IKE phase 1 and 2 policies. Dealt wif cryptographic algorithms such as DES, 3DES and AES, data integrity algorithms such as MD5 and SHA. Used Cisco SDM and ASDM extensively for tunnel configuration.
  • VPN and Frame Relay configuration and troubleshooting including LDAP and firewall functions.
  • Configure, troubleshoot and manage OSPF, EIGRP and BGP routing protocols on Cisco and Nortel routers.
  • Implemented redundant Load balancing technique wif internet applications for switches and routers
  • Configure Object Grouping, Protocol Handling, and NAT, setup of HSRP, ACL, and tunnel installations using Cisco ASA firewalls on ASA Firewalls.
  • Configure and upgrading Cisco IOS Feature Set, backing up IOS files using TFTP Server, NAT and Simple Network Management Protocol (SNMP) for Network Security implementation.
  • Responsible for service request tickets using BMC remedy generated by the halpdesk in all phases such as troubleshooting, maintenance, upgrades, patches, fixes, and all around technical support.
  • Resolving issues related to data communication systems including hardware, software and applications including Switches, Routers, and Firewalls.
  • Configuring and Troubleshooting Virtual Private Networks (VPN), Access Control Lists (ACL), Cisco ASA 5540, Cisco IPS 4235, Cisco 2811, Cisco 1941 and Cisco 3845 Routers, Cisco Switches 2960, 3550 & Cisco 3560 switches in real time environment.
  • Troubleshoot DNS, DHCP servers and other IP conflict problems.
  • Configuring Wireless access point, Wireless Routers and WLAN Controllers, LWAP/CAPWAP and wireless standards 802.11a/b/g/n.
  • Working on network monitoring tools like, SOLAR WINDS, CISCO works, RIVER BED and Wireshark.
  • Implementing IP addressing scheme using IP address management web tool INFOBLOX.
  • Implementing port based security by authenticating users wif 802.1x switch port configuration and implementing VACL and port security for restricting local user access.
  • Maintaining stable STP topology using protocols such as Port fast, BPDU guard, Root guard and UDLD.
  • Solving port-security violation by detecting and removing the port lock outs on 6500, 3560 and 3550 switches.
  • Providing Root Cause Analysis by determining the cause of a problem and providing a documented resolution.

Confidential

Network Engineer Consultant

Responsibilities:

  • Monitored, maintained and implemented the network topology design and troubleshoot to maximize the network availability and minimizing latency.
  • Responsible for maintenance and utilization of VLANS, Spanning-tree, HSRP, VTP of the switched multi-layer backbone wif catalyst switches.
  • Implemented Access-Lists on Firewall to permit and deny only necessary traffic.
  • Implemented Route Redistribution for traffic flow between different routing protocol platforms.
  • Created VLANs for separating different corporate internal database, efficient network management and VTP for inter-VLAN routing.
  • Used load balancers wif multiple components for efficient performance and to increase reliability through redundancy.
  • Assisted wif Troubleshooting network connectivity and performance issues as required.
  • Configuring and demonstrating switching concepts such as Trunking, ether channels, inter-vlan routing, spanning tree, port security, redundancy protocols such as HSRP/VRRP and GLBP.
  • Implemented SNMP on Cisco routers to allow for network management.
  • Worked on BMC ticketing system, trouble-shooting both connectivity issues and hardware problems on Cisco-based networks.
  • Performed external testing wif outside vendors and examine traffic flow and performing an audit of underutilized Cisco Devices and saving organization’s money.
  • Assisted wif TEM inventory database migration and update current inventory database.
  • Performed project management skills by discussing wif outside vendors cross team communication and basic databases.

Confidential

Network Engineer

Responsibilities:

  • Responsible for maintaining the Naperville technical support team lab and systems.
  • Assisted in installing 7100 Nano Optical Transport System wif proper infrastructure and cabling as standardized by IEEE.
  • Installed 7305 Metro Ethernet Switch to be tested by technical support engineer in the lab environment.
  • Assisted Technical Support Engineer in generating traffic over Intranet to replicate and test the customer network on 8607 and 8611 access switches.
  • Worked wif Technical Support Engineers to understand customer reported problems and steps required to reproduce issues.
  • Proficiently handled IXIA and Spirant network traffic generators.
  • Build systems wif proper planning of software and hardware installations to replicate customer networks and utilize appropriate test fixtures and equipment to generate traffic in an effort to duplicate and provide root cause.
  • Reviewed topology of secure VPN network and establish new LAN to LAN tunnels for quick access to customer networks for troubleshooting.
  • Monitored, maintained and upgrade network equipments wif appropriate Infrastructure to improve the performance in lab environment.

Confidential

Network Engineer: Network/System Technology,

Responsibilities:

  • Maintained and troubleshoot lab test systems (routers, switches, wireless AP, servers, storage, and virtualization) as well as connectivity problems using Ping and Trace route.
  • Configured routers for OSPF and EIGRP routing protocols, redistributed wherever required. Improved efficiency of the EIGRP routing environment by load balancing between unequal cost links and stub area configuration wherever required.
  • Migration of Checkpoint Firewall to ASA Firewall for addressing enterprise needs of firewall, IPSec VPN and IPS. Applied ACL, NAT, PAT and Firewall policies.
  • Documented all the installations and configurations using MS Visio and Word, configured packet filtering and NAT for securing internal network, security policies for the training room machines perform regular patches and updates on time.
  • Created LAB setup wif 7k and 5K NEXUS switches for application testing. Lab created wif IPv6 addressing scheme.
  • Configured Nexus 5K Fiber channel over Ethernet (FCoE) for SAN connectivity for LAN free backup. Coordinated wif NETAPP engineers to set up the new storage arrays and maintained the existing SUN storage hardware wif the SAN engineer.
  • Helped undergraduate and graduate students solve problems in Network Technology, LAN/WAN concepts, IP addressing scheme, routing protocols, WLAN concepts, firewall rules and policy.
  • Responsible for configuration, troubleshooting and securing the company’s LAN/WAN infrastructure. Configuration, administration and troubleshooting of the routing protocols (OSPF, EIGRP and BGP) on the production router.
  • Assisted students on generation and maintenance of all data communication software and equipment such as Putty, Wireshark and OPNET.
  • Performed IP addressing and subnetting, route Summarization and redistribution, NAT/PAT and DHCP; designed and implemented static and dynamic routing protocols, including OSPF, EIGRP, IGRP, and BGP.
  • Assisted in the configuration of Cisco Routers, switches and firewalls:
  • Planned and implementation of subnetting, VLSM to conserve IP addresses.
  • Configured STP for loop prevention and VTP for Inter-VLAN Routing.
  • Converted networks wif multiple routing protocols RIP, EIGRP into a single OSPF domain for scalability to the lab’s network environment.
  • Implemented redistribution of protocols from OSPF to BGP and redistribution of OSPF to EIGRP on IPv6 backbone.
  • Implemented and redistributed protocols on MPLS backbone wif VRF technology on Peer routers.

Confidential

Associate Network Engineer

Responsibilities:

  • Developed Perl scripts for parsing of data from router interfaces in order to identify and troubleshoot errors and discards generated.
  • Parsed data variation to the CGI environment and provided analytics of the data graphically.
  • Developed applications and tools for router configuration management, monitored system, interface statistics and other SLA metrics.
  • Monitored network devices and servers utilizing Solarwinds, Nimsoft and Metroe. Performed inventory remotely using telnet session for all network devices (routers, switches, and firewall and terminal servers).
  • Helped upgrade process for Solarwinds, Metroe, and other applications through identification of discrepancies wif proper documentation.
  • Reviewed gloden configuration compliance of 200 router elements.
  • Contributed to the overall design and performance of the networks including switches, firewalls, cabling, network interface cards, routers and wireless controllers.

Confidential .

Network Implementation Engineer

Responsibilities:

  • Administrated the edge routers for internet connectivity, WAN connectivity to remote site using Frame-Relay, static mapping of the DLCI and other encapsulation methods. Successfully deployed OSPF by manual configuration of the routing process to support Frame- Relay NBMA cloud.
  • Actively involved in deploying MPLS based VPN using routing protocol MP-BGP. Assigned and configured IP VRF forwarding for customer usage of the MPLS network on Edge routers like Cisco 7600, 7200 series. Also configured MPLS LDP-IGP synchronization on the core routers to avoid black holes.
  • Setup, configured and supported Windows servers and applications on a TCP/IP Network.
  • Configured and tested various traffic policies using BGP attributes such as Local Preference, MED, Extended Communities. Worked to reproduce various Route-Reflector issues wif 12.3T code baselines. Worked on Route-Reflectors in a clustering environment.
  • Up-gradation, configuration and troubleshooting of routing protocols such as OSPF on the core network for effective communications. Provided connectivity on newly deployed PE routers through IBGP and inter AS connectivity through BGP. Configured route policies, manipulated attributes using route-maps, ACL, community and AS-path list according to requirements.
  • Administered systems, networks, applications/security and document changes.
  • Configured and troubleshoot unicast and multicast routing protocols (OSPF, BGP and MPLS) networks.
  • Designed and administered multiple VLAN IP networks, PIX firewall, VPN, IOS code upgrade.
  • Configured and resolved tickets for Cisco 2900, 3560, 2600, 2800, 6500 and 7200 series switches and routers.
  • Created topology diagrams and associated documentation for network applications and site networks.
  • Resolved issues related to data communication systems including hardware, software and applications; including Switches, Routers, and Firewalls, IP, IPX, Frame Relay, VPN, IP.
  • Worked on WAN Optimization for lab design and setup using Cisco products and Spirent Delay generator.
  • Managed networking of Cisco Routers in a web-hosting and client hosting environment.
  • Implemented SNMP object techniques to trap alarms generated on the agents (Routers, Switches).
  • Maintained network security through proper configuration of firewall, proxies and VPN devices.
  • Evaluated network, servers and storage architecture plans.

Confidential

Network Engineer Consultant: Administrator A

Responsibilities:

  • Responsible for designing, implementing and upgrading of company network model including monitoring network performance using various network tools to ensure the availability, integrity and confidentiality of application and equipment.
  • Responsible for configuration and maintenance of a collapsed core network of 90 switches and routers along wif maintenance of existing Wireless network.
  • Working experience wif Cisco 3750 and 6500 layer 3 switches. New switches installed to make network scalable and manageable. Reconfigured the STP for placing the Root at the center of the network and guarding the root against unwanted topology changes.
  • Configuration and maintenance of EIGRP and BGP network on 7200 and 6500 MLS routers.
  • Created and maintained network maps for the Network Operation Center (NOC) using VISIO.
  • Responsible for site surveys, design the layout for cable installation and provide documentation.
  • Troubleshoot end-to-end connectivity between two sites while providing training to newly hired technicians. Maintain the documentation of work performed for cost analysis.
  • Help negotiate hardware, software and circuit contracts for customers. Involved in lab testing and validation of network modifications and configuration before implementation.
  • Responsible for configuration, troubleshooting and securing the company’s LAN/WAN infrastructure. Configuration, administration and troubleshooting of the routing protocols (OSPF, EIGRP and BGP) on the production router.
  • Configuration of HSRP between distribution layer switches and routers for failover redundancy.

Confidential

Network Management

Responsibilities:

  • Designed the web page on Fedora server using HTML and JAVASCRIPT representing FCAPS management using Perl scripts.
  • Fault Management: Identification of link up and or down of the routers and switches.
  • Configuration Management: Device configuration information - a web interface for all information of switches and routers (ARP table, MAC Address table, IP Routing table, device interface table, and the STP table), System information and option to enable and disable device interfaces.
  • Account Management: Perl program to analyze the Linux syslog files and to generate an account usage report, showing the total and average usage time of each account.
  • Performance Management: Using shell script to ping (flooding) the target machines wif different packets size and note the average RTT and standard deviation for each run and to print error message to the unreached targets. Develop a Perl script to analyze the System Load or system utilization and ran MRTG to develop a web site to track the incoming and outgoing traffic of lab Ethernet switches graphically.
  • Security Management: Wrote Perl program to analyze the Linux syslog files to generate an intrusion report showing the number of intrusion attempts from each IP source and the origination country.
  • Created the virtual environment through OPNET IT Guru software to analyze and predicting the performance of the Network Infrastructure design including routers, servers, application and networking technologies.
  • Measured and calculated performance attributes such as Delay (Response time), Throughput, Utilization and Reliability.
  • Different Model hierarchies were created to perform the test wif specific parameter details according to the requirements.
  • Performed capacity planning to predict which resources will be needed to maintain performance levels on an existing or planned system.
  • Configured OPNET Project wif set of related scenarios where objects and parameters are changed in each scenario to test changes to the system.
  • Designed high frequency trading network Infrastructure to execute trades fast and minimize latency and maximize redundancy and performance in trading traffic.
  • Used OPNET to analyze and to identify the root cause of end-to-end application performance problems and to solve them cost-effectively by understanding the impact of changes.
  • Analyzed business and technical requirements of the network infrastructure and researched manufacturer’s product lines equipment for the design.
  • Created and documented actual device configuration for the core network devices.
  • Generated management report on detailed design of the infrastructure.
  • Applied theoretical study of the design, configuration and management of converged network communications.

We'd love your feedback!