We provide IT Staff Augmentation Services!

Network Engineer  Resume

2.00/5 (Submit Your Rating)

SUMMARY

30 Years of experience in Cyber and network security, network design and software products and services. Team Lead and Certification and Accreditation (C&A) Certification Agent for commercial and government systems. Engineering lead for groups in network design, capacity planning, and implementation. Project management experience in LAN/WAN technologies and database development.

  • Ten years of progressive cyber security experience in government and commercial arenas.
  • Two years as certification agent for the NEI 0809 Rev 6 Cyber Security Assessment of nuclear facilities of Florida Power and Light’s (FPL) Turkey Point and Southern Nuclear Company’s Nuclear Hatch, Farley and Vogtle facilities.
  • Developed a 5 - year strategic cyber security plan for the Office of the Chief Technology Officer (OCTO) for the Washington DC government.
  • Five years as certification agent for C&A NIST 800-53A testing of National Oceanic and Atmospheric Administration (NOAA) systems within National Weather Service (NWS), National Ocean Service (NOS) and Office of Marine and Aviation Operations (OMAO).
  • Two years in FDA/CBER and CDER providing C&A, cyber security, disaster recovery and Continuity of Operations Plan (COOP) support for their Oracle systems.
  • Nine years support and leadership for the Metropolitan Washington Airports Authority (MWAA) as security engineer for airport operations; network engineer for planning, designing, implementing and installing MWAA network; software engineer in the development of Oracle and MS Access database applications and application security.
  • Senior network architect and engineer performing design, implementation, management, and security for MWAA's LANS, WANS, and Internet communications projects including Dulles International Airport’s (IAD) main terminal, Reagan National Airport’s (DCA) new terminal network and MWAA Headquarters relocation.

TECHNICAL SKILLS

  • Designed and implemented WAN frame relay to interconnect DCA, IAD, and Consolidated Functions (CF) in Alexandria. This was the first time that all three facilities were able to directly communicate. Developed and implemented the first IP network design for MWAA. The design included the merging of three Class C networks into MWAA’s first router connected network.
  • Planned and implemented Internet connectivity including all security design of DMZ and installation configuration and management of Cisco PIX firewall.
  • Produced logical, functional and physical/virtual designs for the Cyber components
  • Developed a build of material (BOM) for the proposed design
  • Developed catalog entries and realizations for SAIC professional service offerings for the proposal effort.
  • Overlaid the Cyber components on the final physical and virtual Network design
  • Assisted in developing a list of Cyber components in response to and compliance with the draft RFP

PROFESSIONAL EXPERIENCE

confidential,

Principal Cyber Security Engineer

Cyber Security Engineer charged with the development of a 5-year Cyber Security Plan for OCTO. The plan outlined the steps that OCTO and DCnet took to fully implement their plans to build the most reliable, accessible public communications infrastructure possible for the Nation’s Capital capable of handling classified data. The initial steps started with the construction of a SCIF within their current facility to contain the Network Operations Center and Security Operations Center (NOC/SOC), network design for classified and non-classified data, and implementation of a Security Information and Event Management (SIEM) System. Along with a phased staffing plan for eventual 7x24 operation the plan concluded with moving OCTO from an NOC/SOC to a Managed Security Service Provider (MSSP) for DC area clients and agencies.

confidential,Florida 

Principal Cyber Security Engineer

Cyber Security Engineer for SAIC on the Certification Engineer/Agent for Florida Power and Light Turkey Point Nuclear Facility. We analyzed the initial list of 1,500 digital assets (DA) to determine which assets could be classified as CDA. This required examination of plant drawings, engineering change packages, asset inventory, vendor and user manuals. Also performed walk downs of the digital asset where we documented asset with photos, examined, and corrected drawings. Where components were made available, we performed bench testing and examinations using various vulnerability analysis tools.

From the final CDA list, we performed 66 full NIE 08-09 assessments of 627 components in 11 critical systems. This resulted in the generation of 7 SARs that summarized all the findings. We modified an existing SAIC MS Access database to track of all assessments and generate the required reports.

confidential,

Senior Cyber Security Engineer

  • Overlaid the Cyber components on the final physical and virtual Network design
  • Assisted in developing a list of Cyber components in response to and compliance with the draft RFP
  • Produced logical, functional and physical/virtual designs for the Cyber components
  • Developed a build of material (BOM) for the proposed design
  • Developed catalog entries and realizations for SAIC professional service offerings for the proposal effort.
confidential,

Senior Network and Security Engineer

  • Team Lead and Certification Agent for C&A testing
  • Land Based Support System (LBSS)
  • Fleet Ship Support System (FSSS)
  • Center for Operational Oceanographic Products and Services (CO-OPS)
  • Coastal Services Center (CSC/PSC),
  • National Centers for Coastal Ocean Sciences (NCCOS),
  • National Marine Sanctuaries (NMS)
  • Office of Response and Restoration (OR&R)
  • Improved the data entry and reporting capabilities of the System Certification Test Report Matrix (SCTRM) spreadsheet by converting it to an MS Access 2003 database. This gave the SCTRM the ability to display data across multiple rollup charts and a reporting mechanism to quickly analyze the results and transfer them to the SAR. The NMS system had 14 different locations and FSSS consisted of 17 ships, and all SCTRM data were combined into a single SCTRM to show the vulnerabilities across the system as a whole, while maintaining individual SCTRMs for POAM resolution.
  • Continued development of a Nessus parsing tool and database to import and analyze raw Nessus scan data and produce reports on risk and criticality. The raw data can also be examined, sorted and filtered to quickly remove additional false positives to minimize the number of findings that needed to be mitigated. Many new reporting features were added including analysis of the Nessus findings vs. NIST control assessment. The reporting capability of the tool generated all the reports that are included in the SAR, however many additional reports are included to assist in the data analysis.
  • Team Lead in the C&A of NOAA National Weather Service systems:
confidential,

Senior Security Engineer 

  • Completed the NIST 800-53 compliant FISMA of nine production systems for FDA's Center for Biological Evaluation and Research (CBER) division Regulatory Management System (RMS) using ProSite FISMA tool. The systems consisted of several OpenVMS and Windows NT/ 2000 servers, nine Oracle Databases and many Oracle Forms/Reports applications.
  • Oracle Database replication: Implemented a project to replicate CBER/FDA’s production databases to a remote location. Studied several methodologies including, Oracle Streams, Quest Share Plex, and Golden Gate Software to identify the most suitable. Demonstrated a proof of concept for implementation of Oracle Streams. Successfully configured the real-time replication of a small schema consisting of five tables between the VMS test environment to a Windows 2003 server. Replication included DML and DDL changes.
  • Implemented Oracle auditing on the production and test VMS systems. Auditing included login/logoff, DDL, schema changes, server errors, user roles and privileges. The audit records older than 30 days were moved to a remote server daily and retained there for a year. Wrote a series of 20 views to assist the DBA with audit reports and statistics.
confidential,

Senior Security Engineer (Department of Justice Project)

  • Completed security NIST 800-53 assessment, System Security Plan (SSP) and System Test and Evaluation Plan (STEP) for the DOJ Tax C&A process. Performed penetration testing and lockdown for Server 2003, Exchange 2000, SQL Server, Oracle 8i and 9i servers, and XP workstations using SuperScan4, IIS database scanners, Nessus, Oracle and SQL scripts. Developed testing and lockdown procedures using Pedestal Security Expressions and STAT Scanner. User Group Policies, Group Policy Management Console and Microsoft Management Console to enforce security requirements. Created MS Access 2003 database tool to track and report all test results from all server scans.

confidential,

Washington,DC 

Security Systems Engineer

  • Performed NIST C&A security assessment on badging system hardware, software, and network. Risk analysis, SSP, STEP, and disaster recovery. Performed Oracle server and database penetration testing and lockdown using IIS and Pedestal scanners. Designed the Level 3 network to isolate the badging server and workstations from the production network.
  • Performed requirements analysis and developed the requirements document for the procurement and implementation of a new ID badge production system and supporting network. The requirements included design and security specifications for hardware, software, supporting network and interfaces to existing internal and external systems to automate the employee badging process. The secure interfaces included automatically obtaining Security Identification Display Area (SIDA) training results, fingerprint tracking and adjudication, and ID verification into one homogeneous system.
confidential,

Network Engineer 

  • System Manager: Lead DBA of ID badging system which produced, encoded, and activated all badges distributed at the airport, running in an Oracle 8i environment on a Windows NT 4 SP6 platform. Managed the daily operations, backups, tuning, and system statistics. Implemented security lockdown of the Oracle instance, and the NT server. Developed many ad hoc reports for management using Crystal Reports, MS Access and Excel. Developed security policy for all MWAA oracle servers. Performed penetration testing on multiple Oracle instances and Windows Servers. Designed the secure Level 4 badge network to separate it from the production environment. Implemented server and network-based intrusion detection.
  • Project Manager: Managed the relocation of the communications/computer room to new location, which included relocating the access control systems network, CCTV system, the MWAA backbone network, and secure badge network and servers. Provided scheduled development/management, presentations and updates to senior management. Coordinated system and unit testing. Upgraded all terminal premises hubs’ connectivity to backbone. Accomplished all with no user interruption.
  • Design Engineer: Performed requirements analysis, assisted in the console layout for redesign of the airport operations console during Air Operations Center renovation. Set up a temporary Ops Center during the renovation maintaining all network, telcom, radio, and CCTV connectivity as well as weather, air traffic radar, runway monitoring and lighting systems. Managed the layout and connectivity and installation of the new console. Managed the relocation of the operations center to the new console. Accomplished all without the loss of any system or connectivity.
  • During the events of Sept 11 2001, coordinated and managed the installation network connectivity for additional workstations, IP phones, broadcast cable TV and CCTV, connectivity to establish an airport operations emergency response center at DCA. Entire installation was accomplished within 3 hours.
confidential,

Network Engineer / Architect

  • Designed and implemented the fiber and 100 Base-T LAN, WAN, and SCADA connectivity for IAD’s airport expansion in 2000 and in DCA’s new terminal construction in 1997.
  • Designed and implemented upgrade to a 100 Mb redundant campus network using Cisco 5500 series switches. The design connected 13 LAN segments, 5 Novell servers, and 7 NT servers using, Cisco and Bay network Ethernet switches to the 100 Mb backbone.
  • Designed and implemented WAN frame relay to interconnect DCA, IAD, and Consolidated Functions (CF) in Alexandria. This was the first time that all three facilities were able to directly communicate. Developed and implemented the first IP network design for MWAA. The design included the merging of three Class C networks into MWAA’s first router connected network.
  • Planned and implemented Internet connectivity including all security design of DMZ and installation configuration and management of Cisco PIX firewall.

We'd love your feedback!