Sr. Network Security Engineer Resume
Tempe, AZ
PROFESSIONAL SUMMARY:
- 8 years of experience in Network design, Security, Tier support of Networks in various environments.
- Extensive experience working on Cisco and Juniper routers/switches in complex environments with multiple ISPs.
- In - depth expertise in the analysis, implementation, troubleshooting & documentation of LAN/WAN architecture and good experience on IP services.
- Implemented VPN & troubleshoot into IP-SEC tunnels, GRE Tunnels, SSL-VPN on Cisco, Aruba, Juniper
- Conversions to BGP WAN routing. Which will be to convert WAN routing from OSPF to BGP (OSPF is used for local routing only) which involves new wan links.
- Expert Level Knowledge about TCP/IP and OSI models.
- Cisco ASA/Checkpoint Firewall troubleshooting and policy change requests for new IP segments that either come on line or that may have been altered during various planned network changes on the network.
- Deployed and maintained networks in accordance with HIPAA and PCI compliance standards.
- Design and implement industry leading SD-WAN infrastructure to provide secure, carrier independent WAN connectivity across the enterprise.
- Acquitted with Cisco Meraki for Cisco Wireless Devices Monitoring, managing and troubleshooting Cisco Wireless devices using Cisco Meraki.
- Configured Aruba Switch S3500 & 1200 Complex Stacking topologies.
- Worked with security devices such as Firewalls, VPN switches and Intrusion Detection Systems.
- Replaced aging Checkpoint firewall architecture with new next generation Palo Alto appliances serving as firewalls and URL and application inspection
- Experience with products such as Cisco ISE, Cisco ASA 5500 series firewalls and Cisco ACE 4710 Load balancers.
- Experience in Palo Alto design and installation (Application and URL filtering, Threat Prevention, Data Filtering)
- Expert in dealing with Networking Protocols and Standards such as TCP/IP, OSI, UDP, Layer 2 (VLANs, STP, VTP), Routing Protocols (EIGRP, OSPF, BGP), WAN technologies (Frame relay, IPsec, VPNs ) Qi’s.
- Implemented redundancy with HSRP, VRRP, GLBP, Ether channel technology (LACP, Pap).
- Experience in F5 Load balancers such a BIG-IP LTM Modules.
- Experience on Network Monitoring & Testing tools such as Wireshark/Ethereal, Cisco Works, and IXIA.
- Good understanding of VoIP implementation and protocols such as H.323, RTP, and SIP.
- Expertise in Configuration of Virtual Local Area Networks (VLANS) using Cisco routers and multi-layer Switches and supporting STP, RSTP, PVST, RPVST along with trouble shooting of inter-VLAN routing and VLAN Trucking using 802.1Q.
- Experience in troubleshooting NAT configurations, Access-Lists (ACL), and DNS/DHCP related issues within the LAN network.
- Good understanding of cable management such as CAT3/4/5, Fiber-Optic (Multi & Single mode fibers).
- Worked on Subletting IPv4/IPv6 addresses and IP address management.
- In-depth knowledge and hands-on experience on IP Addressing, Sub netting, VLSM and ARP, reverse & proxy ARP.
- Experience working on Cloud Computing Virtualization using VMware Six 4.0 and Windows Hyper-V.
- Hands-on experience with TCP/IP, LANs, WANs, and WLANs (Wi-Fi) Cisco VPN Concentrators, F5 Fire pass SSL VPN, 6509 Core Datacenter designs.
- Experience on Monitoring and Management tools such as HP Open view, Solar Winds and Wireshark
- Managed inventory of all network hardware, Management and Monitoring by use of SSH, Syslog, SNMP, NTP.
- Exposure to Cisco WAAS, WCS.
- Extensive knowledge in AAA protocols such as RADIUS, TACACS+ and Cisco ACS.
- Responsible for service request tickets generated by the helpdesk in all phases such as troubleshooting, maintenance, upgrades, patches and fixes with all around technical support.
- Excellent communication skills to interact with team members and support personnel and also can act as a mentor to less experienced personnel.
- Hands on experience in designing complex networks in Vector Graphics application like Microsoft Visio Pro.
TECHNICAL SKILLS:
Operating Systems: Windows (Server 2003/2008, Vista, Windows 7), Linux OS
Routers: Cisco GSR12016, ASR1001, 2900, 3900, 7200, 7600, ASR9000 & ISR routers
Switches: Cisco 3750, 3850, 4507, 4510 & 6500 series switches, Nexus 9K, 7K, 5K, 2K
Routing: MPLS, OSPF, EIGRP, BGP, PBR, IS-IS, Route Filtering, Redistribution, Summarization, Static Routing
Switching: LAN, VTP, STP, PVST+, RPVST+, Inter VLAN routing & Multi-Layer Switch, operations, Layer 3 Switches, Ether channels, Transparent Bridging.
Network security: Cisco (ASA, PIX) 5510, Palo Alto, juniper SRX, ACL, IPSEC VPN, GRE VPN, NAT/PAT, Filtering, Load Balancing, IDS/IPS
Load Balancer: F5 Networks (Big-IP) LTM Module, Cisco ACE 30 load balancer
LAN: Ethernet (IEEE 802.3), Fast Ethernet, Gigabit Ethernet.
WAN: Leased lines 128k - 155Mb (PPP / HDLC), Channelized links (T1/DS3/OC3/OC12), Fiber Optic Circuits, Frame Relay, ISDN, Load Balancing. Various Features & Services: IOS and Features, HSRP, GLBP, IRDP, NAT, SNMP, SYSLOG, NTP, DHCP, CDP, TFTP and FTP Management
AAA Architecture: TACACS+, RADIUS, Cisco ACS
Network Management: SNMP, Solar Winds, HP open view, and Wire shark
Reports and Network Diagrams: Microsoft (Visio pro.)
PROFESSIONAL EXPERIENCE:
Confidential, Tempe, AZ
Sr. Network Security Engineer
Responsibilities:
- Involved in Configuration, setup and troubleshooting of Cisco devices to perform functions Confidential Access, Distribution and Core layers.
- Upgraded the Cisco ASA firewalls from 6.2.3.1 to 6.2.3.9 for better performance and to avoid unwanted Health warnings thrown by the FMC.
- Implemented security policies using ACL, Firewall, IPSec, VPN, AAA Security TACACS+ and RADIUS on different series of routers.
- Upgrade PAN-OS from 6.1 to 7.0 in Palo Alto firewalls.
- Configure Security Profiles such as Antivirus, Anti malware, Threat Prevention, Vulnerability
- Implement URL filtering on Palo Alto Firewall and control access to restricted sites.
- Configure and troubleshoot IPSEC VPN form Site to Site with Cisco, Checkpoint Devices as peer.
- Configuring and troubleshoot Global protect SSL VPN for Work from Home Users on Palo Alto
- Configuring Security Policies for Access control, inter zone connectivity, External Access on Palo Alto Firewall
- Worked with Cisco Meraki cloud managed architecture to handle wireless, switching, security, EMM and all security cameras managed from the web.
- Provisioned and maintained HIPAA and PCI compliant networks.
- Implemented VPN & troubleshoot into IP-SEC tunnels, GRE Tunnels, SSL-VPN on Cisco, Aruba, Juniper
- Provided consultation to the Azure, Amazon Web Services and Server teams.
- Planned, and tested Microsoft 365 Business solution using Azure AD and ADDS with Microsoft 365 Admin and Security Center.
- Managed DHCP, DNS and IP address thru Infoblox, and Admin for Internet sites access thru Zscaler.
- Function as part of a Firewall and Security team in support of Cisco Firewalls, Zscaler Proxy, Juniper Portals, SecAuth, Open LDAP, and Active Directory.
- Focused on working with Cisco Channel partners to build practices around Cisco ACI.
- Integrated and evaluated Cisco ACI, VMware NSX, and Arista CVX SDN solutions
- Extensive knowledge of deploying and troubleshooting TCP/IP, implementing IPv6, Transition from IPv4 to IPv6, Multilayer switching, UDP, Fast Ethernet, Gigabit Ethernet, Voice/Data Integration techniques.
- Upgraded the Authentication protocol and secured the Network equipment by limiting the access to users.
- Installed and configured Cisco Meraki (MR66,MR18) wireless Access points in the warehouses.
- Worked with Cisco Meraki centralized cloud managed architecture enables plug and play branch deployment and control across any number of distributed system
- Schedules and perform VMware installations, patching and upgrades and maintains them in accordance with established client’s SLA and procedures
- Configured automatic back up and maintained Firewall and Switch configs (Juniper, PAN, Aruba)
- Performed upgrades to F5 hypervisors from 11.2.5 to 11.4.1 inorder to experience optimal load balancing for the client.
- Design and implementation of the first fully Verizon engineered and managed customer Viptela SD-WAN network that encompassed all nodes.
- Designed F5 solutions/support and configured virtual servers and associate them with pools for internal web servers.
- Troubleshooting Cisco APs and Meraki appliances.
- Installed multiple new Internet circuits Confidential multiple sites ranging from 100Mbps to 1Gbps.
- Created and tested Cisco router and switching operations using OSPF routing protocol, ASA firewalls and MPLS switching for stable VPNs.
- Implemented multiple site-to-site VPN tunnels as per the client requirement.
- Troubleshoot and worked on security issues related to Cisco ASA, and IDS/IPS firewalls.
- Negotiate VPN tunnels using IPSec encryption standards and also configured and implemented site-to-site VPN, remote VPN.
Confidential, Atlanta, GA
Sr. Network Security Engineer
Responsibilities:
- Migrated from Cisco 3650 switches to Aruba 3810 series switches.
- Configured Aruba Switch s3500 & 1200 Complex Stacking topologies
- Implemented Site-to-Site VPNs over the internet utilizing 3DES, AES/AES-256 with ASA and JUNIPER SRX Firewalls
- Cisco Meraki Appliance MX (400, 80, 60) and Meraki wireless Access points (MR66,MR18)
- Worked on Aruba Wireless LAN Implementation for 11n Infrastructure Across the Corporate Network
- Implemented WLAN Aruba Wireless Access Points and its Controllers Confidential various corporate sites fort 11n Infrastructure and its legacy technologies
- Upgraded the NAB NA and Global sites including all Data Centers to comply with PCI audit.
- Design and setup of Aruba Controllers 531, redundant 7211, 3200, 3400 and 6000 series
- Performing administrative tasks with Palo Alto Networks (Panorama) including Security, NAT policy definitions; application filtering; Regional based rules; URL filtering, Data filtering, file blocking, User based policies.
- Installed and configured Cisco Meraki (MR66,MR18) wireless Access points in the warehouses.
- Design and setup of Aruba Controllers 531, redundant 7211, 3200, 3400 and 6000 series
- Interacted with cloud team for AWS service to design and deploy an application based on given requirements
- Design and implementation of the first fully Verizon engineered and managed customer Viptela SD-WAN network that encompassed all nodes.
- Involved in Migrating complex, multi-tier applications on AWS
- Involved in Configuration of Access lists (ACL) on Juniper and Palo Alto firewall for the proper network routing for the B2B network connectivity
- Worked with Cisco Meraki centralized cloud managed architecture enables plug and play branch deployment and control across any number of distributed system
- Migrated the policies from Cisco ASA firewall to Palo Alto Firewall
- Involved in Configuring and implementing of Composite Network models consists of Cisco7600, 7200, 3800series and ASR 9k, GSR 12K routers and Cisco 2950, 3500, 5000, 6500 Series switches
- Configure and troubleshoot Juniper EX series switches and routers
- Involved in moving data center from one location to another location, from 6500 based data center to Nexus based data center
- Involved in Implementation and Configuration (Profiles, I Rules) of F5 Big-IP C-4400 load balancers.
- Network security including NAT/PAT, ACL, and ASA Firewalls.
- Experience with F5 load balancers to provide Land Balancing towards Access layer from core layer and configuring F5 LTM both by GUI and TMSH/CLI
- Involved in Trouble shooting Tickets on F5 Load balancers.
- Involved in configuring Cisco ASA 5585 firewall and PALOALTO 5050 firewall
Confidential, Phoenix, AZ
SR Network Security Engineer
Responsibilities:
- Performed ACS to ISE migration for device administration
- Implemented Zone Based Firewalling and Security Rules on the Palo Alto Firewall.
- Support Panorama Centralized Management for Palo alto firewall PA-500, PA-200 and PA3060, to central manage the console, configure, maintain, monitor, and update firewall core, as well as back up configuration
- Migration and implementation of Palo Alto Next-Generation Firewall seriesPA-500, PA-3060, PA-5060, PA-7050, PA-7080
- Experience in software development using python scripting
- Configuring Cisco Wireless LAN Controllers with ISE to perform Dot1x authentication for Wireless clients.
- Deploying ISE to perform Dot1x port based authentication and configure the Posture polices perform Change Of Authorization for users connecting to the corporate network
- Configuring Cisco Switches for Dot1x support testing the IOS compatibility with ISE
- Involved in working with F5 load balancers, its methods, implementation and troubleshooting on LTMs and GTMs
- Implemented WLAN Aruba Wireless Access Points and its Controllers Confidential various corporate sites fort 11n Infrastructure and its legacy technologies.
- Product testing and support for a wide range of products like routers, Layer2/layer3 switches, 802.11 wireless access points (Aruba - 105, 125) etc.
- Integrating ISE with external identity stores such as Windows AD, Cisco ACS LDAP.
- Working on security levels with RADIUS, TACACS+
- Worked with Meraki systems manager for provisioning and monitoring devices.
- Troubleshooting the Network Routing protocols (BGP, EIGRP and RIP) during the Migrations and new client connections
- Experience working with Nexus 7010, 5020, 2148, 2248 devices
- Integrated Cisco any connect secure mobility client in ISE and perform the posture checks
- Provided Load Balancing towards access layer from core layer using F5 Network Load Balancers.
- Involved in troubleshooting of DNS, DHCP and other IP conflict problems.
- Generating RCA (Root Cause Analysis) for critical issues of layer1/layer2/layer3 problems.
- Technologies include, Cisco ASA, Cisco Firepower 9300/4100 Security Appliances.
- Dealt with NAT configuration and its troubleshooting issues related access lists and DNS/DHCP issues within the LAN network
- Installed and Trouble shoot Cisco call Manager 7.0 and 8.2.
- Monitoring network, providing analysis using various tools like Wireshark, Solarwinds etc.
- Integrating Configuring RSA SecurID with ISE for Token based authentications using RSA Native method RSA RADIUS method for user's remote VPN users.
- Provide oversight and support for Wireless and LAN Implementations and escalation support for Tier3 Operations
- Support after hours cut-over/migration issues, opening trouble ticket with NOC for special support.
- Responsible for providing Tier3 support to Department of Labor wired and wireless deployments of ISE.
Confidential, Middletown, NJ
SR Network Security Engineer
Responsibilities:
- Maintain, upgrade and commission of branch and campus sites connectivity into data centers and create a seamless network hardware standard across all North American branches. Installing, Maintaining and Troubleshooting of Cisco ASR 1K, 7200, 3925E and 2951E Routers and Cisco 6500, 4510, 4500-X, 4948, 3560X, 3750X and 2960S Switches for deployment on production network.
- Installing, Configuring and troubleshooting Cisco Routers (ASR1002X, 3945, 3845, 2800, 3600) and Switches to perform functions Confidential the Access, Distribution, and Core layers.
- Deploying and decommission of VLANs on core ASR 9K, Nexus 7K, 5K and its downstream devices
- Designed and implemented new MCN - III MPLS Cloud network Confidential select Data-centers using latest Cisco ASRs and Nexus 9K switches and Optimizing BGP routing with select Wide-Area carriers Confidential & Confidential, Installed and configured Cisco ASA 5500 series firewall and configured remote access IPSEC VPN on Cisco ASA 5500 series
- Working as a subject matter expert for ArubaOS (WLAN Technology) PRODUCT LINES.
- Responsible for Configuration of Palo Alto 5050 devices with layer 7 filtering of traffic traversing the internet.
- Hands on engineering and implementation of Nexus 7K/5K/2K top of rack architecture for a Scalable Production Multi-Tenant environment using VPC, VDC & VRF in a DC Core/Aggregation layer in a production and DR Data center.
- Experienced in configuring Cisco ASAs in various contexts and modes to have the network secure. Maintained IPSEC and SSL VPN tunnels through the Firewalls
- Experience with MPLS connectivity using VRF id and have broad knowledge on multi-protocol label switching for MPLS-VPN and traffic engineering MPLS-TE.
- Worked as a part of data center deployment where we converted from Cisco 6500 to Nexus.
- Experience with configuring FCOE using Cisco nexus 5548
- Implemented Positive Enforcement Model with the help of Palo Alto Networks
- Worked with engineering team to resolve tickets and troubleshoot L3/L2 problems efficiently.
- Implemented various EX, SRX & Jseries Juniper devices.
- Implemented site to site VPN in Juniper SRX as per customer requirements.
- Design and configuring of OSPF, BGP on Juniper Routers and SRX Firewalls.
- Replaced the Legacy 3750 stackwise with Juniper EX 4200 switches in the LAN Environment
- Worked on Cisco ASA 5580, Juniper NS5400, Juniper SRX550. Implemented cluster and configuration of SRX-100 Juniper firewall
- Experience with setting up MPLS Layer 3 VPN cloud in data center and also working with BGP WAN towards customer
- Expertise in installing, configuring and troubleshooting Juniper EX Switches EX2200, EX2500, EX3200, EX4200, EX4500, EX8200 series.
- Experience in configuring VPC(Virtual Port Channel), VDC(Virtual Device Context) in Nexus 7010/7018
- Worked on F5 BIG IP LTM 3600 load balancers to configure Nodes, Pools and VIP’s on a need basis.
- Migrated, created, and managed pools and clusters in F5 BigIP GTM 3DNS load balancers across multiple Datacenters.
- Worked on design and deployment of MPLS QOS, MPLS Multicasting per company standards
- Building the VPN tunnel and VPN encryption.
- Configured Easy VPN server and SSL VPN to facilitate various employees’ access internal servers and resources with access restrictions
- Configured EBGP load balancing and Ensured stability of BGP peering interfaces
- Worked on Route-Reflectors to troubleshoot BGP issues related to customer route prefixes also route filtering using Route-maps.
- Working on Solarwind and Wireshark in the Network Management, Monitoring and Support.
