We provide IT Staff Augmentation Services!

Network Security Engineer Resume

5.00/5 (Submit Your Rating)

Boston, MassachusettS

SUMMARY:

  • Over 6 years of experience working on Security Products such as Firewalls, Security Gateways, Proxy, Load balancer, VPN (Site to Site and Remote Access)
  • Experience working with Cisco ASA / FWSM, Checkpoint, Juniper SRX, Netscreen, and SA VPN
  • Installation from GROUND UP, Configuration, Troubleshooting, Upgrades and Migration.
  • Experience working with Bluecoat Proxy and F5 Big IP load balancers.
  • Experience with dynamic routing protocols such as BGP, OSPF and EIGRP
  • Experience on VLANs, Trunking (802.1q), VTP, Layer 2/3 switching, Inter - VLAN routing, STP and Port Monitoring. SVI.
  • Good technical skills for rapid troubleshooting of network issues.
  • Worked on high-end Cisco devices like 7200vxr, 7600 Nexus 7k, 5k and switches 6500
  • Good configuration and trouble shooting skills on Checkpoint, ASA Firewall platforms.
  • Good understanding on application layer protocols like HTTP, DNS, FTP, SSH, SNMP and also troubleshooting applications using the same.
  • Perform troubleshooting and root cause analysis (RCA) while documenting the findings and update the standard Operations document as KB article for future reference by team.
  • Fair working knowledge with Shell and UNIX scripts.

TECHNICAL SKILLS:

Firewall/Security Gateway Products: Checkpoint Security Gateway (SPLAT, IP Appliances, Checkpoint 12000 Series Appliances, VSX), Cisco ASA Firewalls (ASA 5585X, ASA 5540, 5525x, 5520 and 5510) FWSM Blades, Cisco Nexus 7K, 5K, 7600, 7200, 6500 Switches ( 6509, 6511), Juniper Firewalls (SRX, ISG 2000, NS 5400, SA VPN 6500, SAVPN 4500, MAG), Load Balancer (F5 Networks LTM, GTM), Proxy Servers (Blue Coat Proxy SG, Bluecoat Director)

Operating System on Network and Security Products: Checkpoint IPSO, GAIA, SPLA OS (R65, R70, R71, R75, R75.40, R76), Cisco ASA IOS ( 9.x, 8.x including 8.2(5) and 8.4 as well as 7.x), Jun OS (11.X, 12.X, Screen OS 6,X, IVE OS 7.X, 8.X), Cisco Router and Switch (ios 11.x, 12.x, 15.x ), Load balancer 11.x

Management Platform on Network and Security Products: Checkpoint Smart Centre R75, R76, Provider-1 MDS R71, R75, Cisco Security Manager CSM 4.x, Juniper Network Security Manager NSM, Bluecoat Director

Security Technologies: TCP/IP, IPsec based Site to Site VPN, Remote Access, SSL, AnyConnect, DMZ, Secure zones on firewalls. Anti-Spoofing, Access-lists, Distributed Denial of Service Prevention, Stateful inspection, Vulnerability Assessments, Syslog, Cisco IDS, IPS ( inline, Promiscuous mode )

High Availability: HSRP, VRRP, GLBP, Active/Standby on ASA, Cluster XL, IPSO VRRP on Checkpoint

Security Authentication Server Protocols: TACACS+, Radius, LDAP

PROFESSIONAL EXPERIENCE:

Confidential, Boston, Massachusetts

Network Security Engineer

Responsibilities:

  • As Network and Security Engineer I am responsible for managing Perimeter, DMZ and third party connectivity for IBM managed services clients. My responsibilities include:
  • Installation Configuration and Troubleshooting of Cisco ASA and Checkpoint Firewalls in the network.
  • Work on Checkpoint Provider -1 with multiple CMA’s for Policy Provisioning.
  • Cisco Firewalls include ASA 5500 Series managed through CLI and CSM.
  • Work with end users to identify and troubleshoot firewall related connectivity issues.
  • My daily activities include implementation of firewall policies (both Cisco ASA, Checkpoint) as well as setup new firewalls as needed for clients.
  • Work on FWSM (FIREWALL Switch Blade Modules) on 6509 and 6513 Switches.
  • Configure CSM Cisco Security Manager 4.x to manage all the Cisco ASA Firewalls for Policy Provisioning.
  • Administer Checkpoint firewalls with cluster gateways including pushing policies and processing user requests to allow access through the firewall using Smart Center based Smart Dashboard.
  • Configure Active-Standby based Failover for Cisco ASA Firewalls. (Stateful failover replication) and LAN based Failover.
  • Monitor the health and logs using Smart view tracker and smart monitor on the Checkpoint firewall.
  • Troubleshoot firewall logs from Smart view tracker as well as Command Line of Security Gateway.
  • Use TCP DUMP on Checkpoint firewalls and Packet capture on ASA for advanced Troubleshooting as required.
  • Creating object, groups, updating access-lists on Check Point Firewall, apply static, hide NAT.
  • Work on Blue Coat Proxy for Whitelisting of web URLs based on business requirements.
  • Manage Bluecoat proxy SG gateways through Bluecoat director.
  • Layer 2 Configurations including VLAN creation, VTP and managing Spanning tree with right priority and switch hardware and inter VLAN routing between these VLAN’s.
  • Configure and support Routing Protocols including BGP, OSPF and EIGRP.
  • Configure and update Intrusion Detection and Prevention systems through CSM for centralized management of Signature updates.
  • Firewall OS upgrades and Maintenance of OS updates as part of addressing Vulnerabilities on Firewalls.
  • Configure and support IDS/IPS using Cisco AIP/SSM Modules as well as IDSM Modules on Cisco Switches and Firewalls. Use CSM to upgrade Signatures.
  • Work with users to verify connectivity and troubleshoot Firewall related connectivity issues.
  • Identify Firewall Ports required for application using CSM as well as CLI logging feature as well as use Packet Tracer to verity Access Policy, NAT and Routing.
  • Juniper Netscreen and ISG Firewall configuration and support through NSM 2010 (Network Security Manager).
  • Change Management procedure based on ITIL standards.
  • Firewall Policy Optimization and access list management using Tufin and syslog using Log Logic tool.
  • Push the policies on checkpoint using Smart Dashboard and work with users to verify connectivity and troubleshoot Firewall related issues using smart view tracker as well as CLI command line.
  • Perform Firewall and Hardware upgrades including IPSO image upgrades, upgrade security gateways.
  • Review Firewall rule conflicts and misconfigurations as well as redundant rules using Tufin.
  • Use Big IP LTM for load balancing with in Data center and use GTM across data centers.
  • Set up of Heath Monitor based on Service check as well as Content check
  • Configure Persistence Profile for session sticky based on Source and cookie
  • NAT and Secure NAT (SNAT) configuration on the LTM
  • Update SOP (Standard Operating Procedure) Documentation including network diagrams using Visio.
  • Create firewall audit reports and compliance metrics for PCI, SOX audit.
  • Configure and support of high availability protocols including HSRP for all cisco routers and VRRP on Checkpoint.
  • VRF configuration and support on the routers.
  • Building and supporting Site to Site IPsec based VPN Tunnels for all Extranet and 3rd party communications.

Confidential, Indianapolis, IN

Network Security Engineer

Responsibilities:

  • Part of team managing and supporting infrastructure services at the Data center.
  • Work on Juniper Netscreen, Checkpoint and Cisco ASA Firewalls for Policy Management.
  • Use Smart Center to manage the Checkpoint Clusters. Push the policies on checkpoint using Smart Dashboard and work with users to verify connectivity and troubleshoot Firewall related issues using smart view tracker as well as CLI command line.
  • Configure Clustering on the Checkpoint firewalls.
  • Configure Active-Standby Failover for Cisco ASA Firewalls.
  • Responsible for PIX as well as ASA 8.x Firewalls configurations and Troubleshooting.
  • Configure ASA firewalls in multiple context mode with resource allocation.
  • Build IPsec VPN tunnels and Troubleshooting.
  • Backup and restore of configurations & firewall IOS Upgrades and maintenance.
  • Work with application users to identify firewall ports and log a change to update the policy.
  • Configure CSM (Cisco Security Manager) for all Firewall, IDS/IPS management in the network.
  • Use NSM for centralized firewall policy provisioning and firewall configurations.
  • Configuration and Support of Juniper Netscreen Firewalls running Screen OS 6.x.
  • Configure Chassis Cluster as Juniper High Availability using NSRP on Juniper SRX firewalls.
  • Configure NSRP based clustering for Netscreen firewall High Availability.
  • Upgrade PIX 535 Firewalls to ASA 5540 and 5550 Firewalls which include hardware and OS upgrade.
  • Troubleshooting Layer 2 and Layer 3 connectivity issues for clients in NA remotely.
  • Configuring and troubleshooting of BGP for ISP routing using Attributes such as Weight and AS Path Prepending. Redistribution of routes internally.
  • Work on OSPF routing as well as Redistributing OSPF and BGP routes.
  • Configure Syslog server in the network for capturing the log from firewalls.
  • Configuring static NAT, dynamic NAT, inside Global Address Overloading, TCP overload distribution, Overlapping Address Translation on Cisco PIX and ASA Firewalls.
  • Cisco Switch and Router configurations on Cisco 6500, 3750, 3560 Switches and 7200, 3800, 2800 Routers.
  • Create VLANs in the network, Configure STP Rapid-PVST, Configure Trunk links and Ether Channels.
  • Use Remedy based ticketing system for Incident and Change management.
  • Configured IPsec based VPN tunnels for site to site communication.
  • Configured Primary and Utility networks to route traffic from servers in such a way that it doesn’t impact the production traffic while the servers are being backed up.
  • Maintain and Updating CMDB repository.
  • Configured Firewall logging, DMZs and related security policies and monitoring.

Confidential

Network Security Engineer

Responsibilities:

  • Work in an Enterprise Operation Center (EOC) supporting network on 24x7 basis
  • Firewall Policy Provisioning on Cisco ASA, Checkpoint and Juniper Firewalls.
  • Schedule firewall changes as part of Business as Usual and processing them during the approved window.
  • Interface with users to validate the connectivity troubleshoot any connectivity related issues
  • Use Smart Center to manage the Checkpoint Clusters. Push the policies on checkpoint using Smart Dashboard and work with users to verify connectivity and troubleshoot Firewall related issues using smart view tracker as well as CLI command line using utilities like TCP Dump and FW Monitor.
  • Hardening of firewalls as well as VPN devices, Routers and Switches as per Vendor recommendations.
  • Firewall Policy optimization and rule base mgmt. in an orderly fashion, using object grouping for network & service
  • Firewall policy cleanup for zero hit count objects, unused, redundant objects.
  • Use different types of NAT on Cisco ASA Firewalls for identity, static and dynamic(PAT) NAT requirements
  • Use Automatic NAT on the checkpoint firewall (static and hide) as well as manual NAT
  • Firewall Policy backup and restore as well as running snapshot on SPLAT.
  • Configure HA on Cisco ASA Firewalls using Active-Standby mode of configuration. (Stateful failover)
  • Configure HA on SPLAT using Cluster XL in active-standby mode. Nokia VRRP on IP Appliances.
  • Follow ITIL based Incident, Problem and change management process.
  • Build site to site IPsec based VPN Tunnels on Cisco 3000 Series concentrators.
  • Support Checkpoint security gateways on Solaris and Open Server platform as well as IP Appliances from Nokia
  • Upgrade IPSO Images as well as Security gateway Firewall package from NGX R65 to R70
  • Configured Firewall logging, DMZs and related security policies and monitoring
  • Perform hardware upgrade from PIX 535 Firewalls to Cisco ASA 5540 Firewalls
  • Upgrade Firewall OS and maintain currency of OS.
  • Manage IDS/IPS in the network configured in Promiscuous mode and update latest signature files using CSM.
  • Supporting Cisco based Routing, Switching and basic Access list provisioning.
  • Configuring Layer 2 configuration including switch ports, VLANs, trunk links, Rapid Spanning Tree.
  • Responsible for Firewall support and Troubleshooting.
  • Work on Cisco based Routers including 3800, 3600 and 2600 series Routers. And 3550 and 2900 series switches.
  • Troubleshoot Phase 1(ISAKMP) and Phase 2(IPsec) issues as well as day to day changes on the extranet segments.
  • Was involved in WAN link troubleshooting including IPLS leased lines and Frame Relay
  • Troubleshoot Cisco VPN Client issues related to Remote Access VPN.
  • Static and dynamic routing including OSPF and BGP in the network.
  • BCP implementation with testing of Failovers at various layers of network on regular basis.
  • Updating Network Diagrams using MS Visio and documentations using MS Word and Power Point Presentations.
  • Maintain and Updating CMDB repository.
  • Work with Development users to identify firewall ports required for applications.
  • Work on Server technologies including Active Directory.
  • Backup of network device configurations and restore as needed.
  • Monitor the network and firewall health using a Portal.
  • Ensure the compliance of Quality and Security procedures related to the hosting environment with implementation and documentation as per ISO 27001 standards and ITIL service delivery as well as support all the clients’ individual auditing requirements including SAS70, SOX compliance and recertification.
  • Schedule and participate in weekly meetings with various teams involved in the project to discuss the bottlenecks if any and contribute to design a solution framework. Maintain Configuration, Documentation (VISIO’s) and Records Management.

We'd love your feedback!