Senior Network Security /consultant Resume
Objective
- To obtain a challenging long - term position utilizing my advanced networking experience, with specialty technologies such as Wireless Design, Network Security Architecture and Design implementation, and Advanced Internetworking Design implementation.
PROFESSIONAL EXPERIENCE
Confidential
Senior Consultant / Project Manager
Responsibilities:
- Managed Merger and Acquisition for Confidential Beverage groups purchase of Major Beverage Distribution Division. Redesigning and Integrating MPLS data network, along Wireless, and Voice networks. Utilizing WLC 5508s, 4331 Routers, 2900 series switches, and 3850 series switches. Managed companies Legacy Aruba wireless infrastructure and voice pick integration.
- Created New Integrated Information Security Policies for New Beverage Distribution Division.
- Updated DMVPN network for use as site backup.
- Managed, Updated, and merged Palo Alto Panorama security Environment consisting of 2Panorama Domains and 200+ firewalls (Virtual Firewalls, PA-3300 Series firewalls, PA-5500 Series firewalls, and PA-520 series firewalls) at varying OS levels into a Single Panorama Domain running 7.1.9.
- Implemented Tufin Management for Network and Palo Alto security devices.
Confidential
Senior Consultant / Project Manager
Responsibilities:
- Network Security Architect with Proven track record designing, Implementing, Optimizing and Troubleshooting Networks.
- Redesigned and optimized Client WAN ultimately migrating Client from a combination of MPLS and MPLS VPN to DMVPN.
- Designed and Implemented a Distributed Cisco ISE (Identity Services Engine) Version 2.1 utilizing Cisco 3495 Virtual Appliances for Hospital support 35000 users and endpoints.
- Updated information Security Plan for Major Rehabilitation Hospital.
- Designed and implemented an updated Palo Alto infrastructure supporting a merger for Multiple International sites for Fortune 500 client. Merged ASA, Juniper SRX, and Checkpoint Infrastructures into Palo Alto.
- Implemented Tufin Management for Network and Palo Alto security devices.
- Integrated Client’s Network Security Monitoring M/A through Arc sight.
- Implemented Aruba for Southern California Teaching Hospital using Aruba wireless and Clearpass. Designed infrastructure to support 4500 internal users and 5000 guest users.
- Designed new Manufacturing Network project replacing disparate networks at each site with teh ONE Network design project.
- Redesigned Amazon Web Services Security Infrastructure implementing a hardened security environment, using Amazon security groups, AWS Key management services, Amazon Inspector, and AWS Shield.
- Designed and Setup Multiple SOC Environments deploying State of teh art Management, Monitoring, and Forensic Tools including Tufin, Arc sight, GRR Rapid Response, Kali, Service Now, Redline, Encase and Splunk. At teh Clients request a Dashboard integrating teh multiple tools into a user-friendly interface would be developed custom for each client.
- Managed, Updated, and merged Palo alto Panorama security Environment consisting of 3Panorama Domains and 300+ firewalls(Virtual Firewalls, PA-7080 Series firewalls, PA-3300 Series firewalls, PA-5500 Series firewalls, PA-520 series firewalls, and PA-220 series firewalls) at varying OS levels into a Single Panorama Domain running 7.1.5.
- Created New Information Security Policies for International Fortune 100 Manufacturing client.
- Implemented new Global VPN replacing ASA with Global Protect.
- Completed Hard Outer Shell Audit and remediation of all Firewalls.
- Implemented RSA Two Factor Autantication for International Fortune 100 Manufacturing client.
Confidential
Senior Network Security /Consultant
Responsibilities:
- Designed and Implemented a Distributed Cisco ISE (Identity Services Engine) Version 2.0 utilizing Cisco 3495 Virtual Appliances for Government Agency support 200000 users.
- Updated teh Information Security Plan to reflect modern threats and updated technologies that were implemented.
- Designed and implemented an updated Prime and MSE infrastructure supporting teh dual data Centers supporting teh County. Utilizing teh Cisco Gen2 Prime appliances and Virtual Appliances for MSE.
- Managed vBlock Virtual Cloud and Load Balancers for LA County.
- Configured and tuned Arc sight within teh Network security and Cloud Environments.
- Managed Palo Alto Firewall Infrastructure Consisting of Panorama using version 7.0,5, Virtual Firewalls, PA-3300 Series firewalls, PA-5500 Series firewalls, PA-520 series firewalls, and PA-220 series firewalls.
Confidential
Senior Network Security Architect/Consultant
Responsibilities:
- Designed and Implemented an updated Distributed Cisco ISE (Identity Services Engine) utilizing Cisco 3495 and 3395 appliances for Confidential Corporation during a divestiture.
- Upgraded AWS infrastructure implementing a hardened security infrastructure to protect company assets.
- Designed and implemented an updated Prime and MSE infrastructure supporting teh divestiture for teh Company. Utilizing teh Cisco Gen2 Prime appliances and Virtual Appliances for MSE.
- Re-configured and tuned Arc sight for teh Divested Infrastructures.
Confidential
Senior Network Security Architect/Consultant Project Manager
Responsibilities:
- Designed and Implemented Distributed Cisco ISE (Identity Services Engine) utilizing Cisco 3495 and 3395 appliances for Fortune 100 Public Utility.
- Designed and Implemented Multiple Use Cases within ISE for teh Company based upon NERC CIP to allow employee’s, visitor’s, and contractor’s devices access resources within teh company.
- Developed Daily operation run book for ISE and managed Day to Day Operations of ISE while working with teh Functional team within teh Operations team to takeover long-term management of ISE.
- Managed and Tuned Arc sight for teh Network Infrastructure team.
- Implemented an Amazon AWS Infrastructure for teh Network Infrastructure team to store updates and upgrades on.
- Developed updated NERC CIP use cases for BYOD utilizing ISE 1.3, Mobile Iron, and Afaria.
- Developed updated NERC CIP use cases for 802.1x for Wired Network on teh Operation Data Network.
- ISE 1.3 upgrade for medium size company implementing BYOD with MDM, Dot1x for 25000 Clients, Sponsor portal, Guest Portal, SSL VPN, Multiple Defined policies for User’s Conveniences while on teh Company Network and on Guest Network.
- ISE 1.4. Upgrade for medium sized company creating updated portals, updating switch and controller Configurations for Dot1x. Updating BYOD policies for EAP-TLS for IOS devices using ISE native PKI technology.
- Managed 150 Palo Alto Firewalls along with Panorama and PA-5505 series, PA-3300 series, PA-220 series and integrated them with Tufin Management.
Confidential
Senior Network Architect/Consultant Information Security Manager / Project Manager
Responsibilities:
- Implemented worldwide MPLS network and VPN WAN backup for a major client utilizing Cisco 3845 routers.
- Designed and Implemented PKI Environment for Fortune 100 Defense Contractor.
- Updated Information Security Policy to reflect up to date threats and policies
- Designed and Implemented Microsoft Exchange on VBlock for cloud based Email, managing Exchange and Active Directory using NetIQ tools.
- Designed and Implemented Distributed Cisco ISE (Identity Services Engine) Implementing multiple use cases utilizing ISE Virtual machines on Cisco UCS and 3395 appliances for Fortune 100 Defense Contractor.
- Designed and Implemented teh BYOD policy within ISE for teh Company to allow employees, visitor’s, and contractor’s devices access to teh internet.
- Implemented UCS Server farm as part of teh VBlock infrastructure utilizing UCS director and UCS Central to manage server provisioning and hardware management to reduce TCO, this also allowed defense contractor to secure cloud data into private cloud.
- Developed Daily operation run book for ISE and managed Day to Day Operations of ISE while managing and training a Functional team within teh Network team and teh Security Team to take over management of ISE.
- Designed and implemented Datacenter Network utilizing Nexus 7000, 5500, 1000v switches, Catalyst 6509E switches, and F5 load Balancers.
- Implemented 802.1x on Client’s Network and Converted Wireless From a variety of solutions to a unified EAP/TLS solution under ISE utilizing Cisco Wireless Solutions utilizing WLC Flex 7500 and 3602 as well as 2602 access points.
- Created private cloud for International Freight Company utilizing Cisco UCS infrastructure managed by UCS director and UCS Central.
- Provided Project Management Duties on Project.
- Integrated Palo Alto Firewalls into Clients Network to replace Checkpoint firewalls integrated them with ISE.
Confidential
Senior Network Architect /Project Manager
Responsibilities:
- Designed and implemented worldwide network utilizing Arc sight, Cisco, Juniper, Palo Alto, and Talari networking hardware.
- Deployed Cisco ISE for Wireless, Dot1x, VPN, and BYOD Autantication for client.
- Deployed PKI and RSA for Client VPN and Dot1x autantication
- Deployed Nexus 5500 and 7000 switches into teh Data Center as teh Core and Access Layers of teh Data Center.
- Deployed Cisco 5508 WLC’s with 2602 access points using EAP-TLS autantication at company headquarters.
- Deployed Cisco Catalyst 3750 switches throughout network as access layer.
- Deployed Cisco B-Series UCS Chassis and blades utilizing UCS Director on EMC and Netapp storage as teh Server Virtualization Hardware Layer to be utilized with teh VMware Hypervisor.
- Provided Project management duties for Project in Lieu of Company not having PM resource.
Confidential, Santa Clara, CA
Senior Network / Storage Architect
Responsibilities:
- Designed and implemented a distributed virtual cloud I\infrastructure utilizing teh VCE Private Cloud technologies with vBlock 0, vBlock 1, vBlock 300 and Cisco Nexus switches and UCS B200, B250, B440.
- Re-designed laboratory network infrastructures utilizing Cisco, EMC, and Dell technologies for vendor and customer testing.
- Utilized FWSM in Catalyst 6509s as part of effort to Silo Client operations in SAAS Proof of concept Lab, creating VPNs between Clients and POC lab using FWSM and ASAs.
- Deployed Microsoft Exchange over VBlock cloud.
- Designed and Implemented Palo alto Firewall Edge and silos for customer segmentation.
- Developed and deployed VCE RSA and PKI infrastructure.
- Provided Project Management duties for project.
Confidential, Folsom, CA
Senior Network Architect Project Manager
Responsibilities:
- Designed and implemented Private cloud infrastructure using Dell PowerEdge servers, EMC storage, Cisco ASA 5500s, Aventail VPN concentrators, Checkpoint VPN Concentrators and Cisco Nexus 5020 switches.
- Designed and Implemented PKI solution utilizing Windows 2008 CA to meet security and encryption regulatory requirements covered under EUDPD and HIPAA, for Patient data at rest on medical devices and servers.
- Evaluated Palo Alto Firewalls to replace Aventail.
- Implemented Cisco WCS and 1130 access points for wireless networks.
- Provided project management duties for project in lieu of company not having PM resources.
Confidential, San Mateo, CA
Senior Network Infrastructure Architect Consultant Project Manager
Responsibilities:
- Designed a Cisco Nexus network architecture to upgrade teh existing network to support VMware and an EMC SAN.
- Implemented Catalyst 3750 switched network environment replacing Catalyst 6509 switched network environment.
- Implemented wireless networking utilizing Catalyst 3750 integrated WLC along with 1130 and 1240 access points using EAP-TLS autantication.
- Created PKI environment consisting of an Enterprise CA connecting to School Districts Active Directory to autanticate wireless devices onto Network.
- Designed and Implemented Trapeze Wireless Mgmt. solutions including Ringmaster and Smart pass, utilizing WPA2 - PSK Enterprise utilizing enterprise PKI Solution created using Windows 2008 CA.
- Implemented Cisco Catalyst 3560 access layer switches in new acquisitions and manufacturing facilities.
Confidential, San Francisco, CA
Senior Messaging Support Engineer
Responsibilities:
- Implementation engineer responsible for teh PKI re-design to automate certificate delivery to reduce implementation time of messaging devices and prepare for teh corporate iPhone rollout.
- Senior Support Engineer responsible for Managing Messaging Support infrastructure for Microsoft Exchange Environment, Mobile Device Management, Message Retention, and Backups
- Implemented NetIQ tools to Manage Active Directory and Exchange to reduce TCO.
Confidential, Sacramento CA
Active Directory Consultant
Responsibilities:
- Evaluated, documented, and redesigned clients Active Directory Infrastructure in preparation for migration to Active Directory 2003.
- Created PKI Solution utilizing Windows 2003 CA for use in State Parks wireless network.
- Implemented Cisco wireless network using 1100 series Access Points and 802.1x with EAP-TLS.
- Created Active Directory SLA for account creation and management.
Confidential, San Francisco, CA
Senior Security Consultant
Responsibilities:
- Redesigned and implemented company’s new Active Directory.
- Provided third level support for network and SAN.
- Migrated kluged Gauntlet and Checkpoint firewall solution to Cisco PIX solution.
Confidential, San Francisco, CA
Chief Network Architect
Responsibilities:
- Designed and implemented a 20000 node Active Directory environment for a call center solution.
- Implemented international infrastructure solutions for clients using Active Directory, PKI, and multiple vendors’ hardware.
Confidential, San Francisco, CA
Chief Network Architect / Director of IT
Responsibilities:
- Designed, implemented, and managed teh infrastructure of a secure, scalable, international, multi-site, multi-channel call center network utilizing Cisco Catalyst 6509 Switches and 7206VXR and 3660 Routers.
- Designed and implemented an Active Directory to support in excess of 20,000 clients across 4 continents, 8 countries, including regions of limited data internetworking support.
Confidential, Folsom, CA
Consulting Network Architect / Project Manager
Responsibilities:
- Designed and implemented a scalable Active Directory and network infrastructure for teh Field Sales Engineering Group, using Cisco, Nortel, And Intel switches, Cisco, Shiva, and Nortel Routers and VPN Concentrators.
- Implemented 2500 seat Active Directory rollout.
Confidential, Sacramento, CA
Consulting Network Engineer
Responsibilities:
- Designed and tested teh Cisco network infrastructure for Marin General Hospital’s (MGH) Y2K project including all proof of concept lab testing.
- Successfully Implemented HP Openview for Monitoring SNMP traps from Network Devices and Creating Automated responses for Technicians.
Confidential, San Francisco, CA
Network Consultant / Project Manager
Responsibilities:
- Designed and deployed teh corporate LAN/WAN Infrastructure emphasizing utility, scalability, VPN connectivity, network security and reliability using 3com, Cisco, and Ascend Hardware.
- Deployed HP Openview Monitoring for NOC
Confidential, South San Francisco, CA
Senior Network Consultant / Project Manager
Responsibilities:
- Configured Cisco Routers, Switches, and PIX firewalls for Clients.
- Installed Windows servers for clients
Confidential, San Francisco, CA
Senior Systems Engineer
Responsibilities:
- Designed and implemented teh Company’s Corporate WAN Infrastructure utilizing Ascend and Bay routers.
