Network Security Engineer Resume
NY
PROFESSIONAL SUMMARY:
- Network Professional with 5+ years of experience in designing, deploying, troubleshooting, and maintain Network & Security infrastructure on routers, switches (L2/L3) & firewalls of various vendor equipment.
- Skilled at operating in wide range of platforms, capable of resolving complex IT software and hardware issues, Self - starter capable of looking at new areas and taking responsibilities for business development.
- Work as Layer 3 IP Network Engineer on ASR9k Edge router with IOS-XE Platform in a network lab environment.
- Worked with F5 Load balancing, IDS/IPS, Bluecoat proxy servers and Administrating, authentication controls (Radius, TACAACS+) and Technical Knowledge on Cisco ASA 5500 series firewalls.
- Demonstrated history of working with International and National Organizations to help support their Network/System infrastructure and perform a wide range of troubleshooting techniques with innovative and effective solutions.
- Experience with Windows, Linux, vulnerability assessment tools, firewalls, IDS/IPS, Nessus, NMAP, SIEM, Splunk, ArcSight, Rapid7, Routers, Switches, LAN/WAN, TCP/IP protocols, VMware, Umbrella, WAF, Endpoint Security, Cloud Security.
- Experience in Managing Windows Domains, Active Directory, GPO’s, DNS, DHCP, IIS, DFS, File /Print Server and NT Backup.
- In-depth knowledge of deploying and troubleshooting LAN, WAN, Frame-Relay, Ether-channel, IP Routing Protocols - (RIPV2, OSPF, EIGRP & BGP), ACL\'s, NAT, VLAN, STP, VTP, HSRP & GLBP
- Worked on version control tools like subversion and Git and utilized Source Code Administration customer apparatuses like GitHub.
- Having good exposure to multiple technologies and builds/troubleshooting: VSAN/NSX/SDN/VXLAN, etc.
- Managed VMware ESX 3.x and 4.x with Virtual Center server 2.5 and vCenter 4.0 for managing multiple ESX servers.
- Went through 50 Lotus Notes database and wrote requirements for each to assess their complexity in order to plan a migration to Sharepoint 2016 and Office 365 mixed environment.
- Experienced in Monitoring the Availability and Performance of Windows Servers using Performance Monitoring.
- Designed and configured the commands for QoS and Access lists for Nexus 9K, 7K and 5K.
- Highly Motivated and Target Oriented Team Player who enjoys working with Multi-Functional Teams towards achieving a common GOAL with excellent communication, interpersonal, delegation and status reporting skills.
- Worked in fields like Home Appliances, Architecture & various different sectors.
- Installed and configured Active Directories and managed roles for multiple users and user groups.
- Worked with GPMC tool and Local Security policies to maintain domains and authenticating the users.
TECHNICAL SKILLS:
Routing Protocols: RIP, EIGRP, OSPF, BGP, Static Routing, IP Addressing, Subnetting, VLSM
Communication Protocols: TCP/IP, UDP, DHCP, DNS, ICMP, SNMP, ARP, PPP
Network Hardware: Cisco Nexus (1110, 1010, 1000v, 2248, 3172, 5010, 5020, 5672, 5596, 5548, 7010, 7018,93180, 9396, 9508, 9504), IOS platform (2600, 2500, 3600, 6500 series, 3750, 4900, 4946, 3945, and 3845), ACI Switches (93180, 9396, 9508, 9504), ASR (9000-XR) and ISR (2800/2900/3000 ), Cisco ASA 5500 series, FirePower, CSU/DSU s, network cards.
SDN: Application Centric Infrastructure (ACI), Cisco DNA
Load Balancers: Citrix NetScaler, F5 Networks, Cisco ACE
WAN Technologies: ATM, ISDN, PPP, MPLS, ATT, 802.11, 802.11a, 802.11b, APLUS.
Redundancy Protocols: HSRP, VRRP, GLBP
Topologies: Ethernet, MPLS, Cable Modem, Voice and Wireless
Switch Technologies: VLANs, VTP, STP, DTP, ISL and dot1q
Security: NAT/PAT, Ingress & Egress Firewall Design, VPN Configuration, Internet Content Filtering, URL Filtering -Web-sense, SSL, IPSEC, IKE, Static, Dynamic, Reflexive ACL, and authentication AAA
Firewall: Cisco ASA, Palo Alto
Network Simulators: GNS3, Packet Tracer, Wire shark
WORK EXPERIENCE:
Confidential, NY
Network Security Engineer
Responsibilities:
- Design, implementation and operational support of routing/switching protocols in complex environments including IS-IS, BGP, OSPF, EIGRP, Spanning Tree
- Juniper Contrail SDN deployment assistance to the senior engineering team
- Collaborated with the network engineers to identify areas of high risk that can be resolved using ISE
- I was a key evangelist in promoting the DevOps culture and processes at Compuware. I was responsible for its adoption throughout various groups.
- Citrix Netscaler Architecture and implemented Infrastructure Redundancy of Federal Home Loan Bank in addition to completing the SANS Top 20 Controls within a Scrum Agile Team.
- Responsible for design and implementation/migration from Cisco wireless platform to Aruba wireless platform.
- Performed various mathematical operations using python libraries to avoid lengthy code.
- Implemented EIGRP, BGP, IOS-XE/IOS on Cisco ISR 4451, Cat 4500-X, 2900X, 3750, 3550.
- Strong experience on Ansible for network configuration automation and management using built-in libraries.
- Strong knowledge on operating systems for various platforms such as Windows XP/2000 Server/Vista, 7/8/10, Linux, Ubuntu 10/11, and UNIX based OS, also Cisco IOS XR, and Junos.
- Configured access and trunk ports and implemented granular control of VLANs and VXLANs using NX-OS to ensure virtual and flexible subnets across the network than with previous generation of switches.
- Extensive knowledge and troubleshooting in data communication protocols and standards including TCP/IP, IEEE 802.3, Cable Modem, POE, Multilayer Switching.
- Provided Secure Web Gateway using Bluecoat Proxy servers for both Forward and Reverse Proxy.
- Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5500/PIX security appliance, Failover DMZ network zoning & configuring VLANs/routing/NATing with the firewalls as per the design.
- Hands-on experience in network monitoring using tools Solarwind Orion, Geneva Monitoring, Cricketnet
- Working experience in Core technologies include Windows XP / Vista / 7 / 8 / 8.1, Mac OS, LAN, WAN, TCP/IP, WLAN, ATM / Circuit / IP Routing, Routers, Switches, Modems, and DSLAM.
- Developed IDS/IPS implementation for North American Internet and Market Data DMZ network
- Hot and cold cloning of Virtual Machines using VMware Converter.
- Working as Network engineer supporting CISCO routers, switches & Bluecoat proxy servers.
- Developed HLD/LLD/SOP for Network security infrastructure as Technical lead. Products like Cisco, Checkpoint Juniper and Bluecoat Proxy, BIG IP, Palo Alto firewall. Citrix VM ESXi, WAF, MacAfee, DLP antivirus solution etc.
- Cisco ACI (Application Centric Infrastructure) deployed, monitored, and managed in a way that benefits different teams in the IT organization including SDN Network, Cloud and DevOps, and Security.
- Configured Catalyst devices as an HA pair for redundancy and Performed Cisco IOS, IOS-XE, NX-OS code upgrades across multiple different branches.
- Configured BGP-MPLS, VRF, VLANs, Cisco ASR 1001/1002, IOS-XE, Cisco 4500/3560.
- Experience with EIGRP, OSPF, BGP routing protocols.
- Part of ATT NetBond Cloud onboarding team.
- Worked on connecting to database and fetch the data with Perl/Python.
- Creating and running VBscripts and Powershell scripts in relation to Active Directory migration and Domain Administration
- Designing and implementing OSPF Areas for reliable Access Distribution and for Core IP Routing.
- Investigated interference issues and found the culprit devices with Agilent Spectrum Analyzers
- Acted as a primary interface with equipment vendors, resolved an OSPF RIB re-conversance issue within the N7018’s & discovered a 9448 IOS-XE overloading its CPU do to a bug issue.
- Introduced content management using squid and squid guard proxy servers to allow internal end users internet access while still being able to monitor and report on usage.
- Integrated Jenkins with GitHub private repositories builds Automation tools (Maven and Ant), and Artifact repository for pushing successful build code.
- Experienced with RSA DLP, Symantec DLP versions 12.5, 14.0, 14.5, and 14.6, McAfee, Symantec DLP or native GPO controls and other tools.
- Black listing and White listing of web URL on Blue Coat Proxy servers.
- Market Data network DMZ network builds to support the regional and international trading floor news feeds and trade executions
- To deploy instances used Ansible playbooks and wrote modules in Ansible to integrate with Apache Tomcat and AWS. And used Ansible playbook to deploy applications.
- Implementation of VOIP IP Phones at branches and upgrading old branch Avaya analog phones with Cisco IP Phones, configuration ports to support VOIP, IP Helpers, Voice VLAN, & QoS.
- Responsible for Checkpoint firewall management and operations across our global networks.
- Implemented site to site VPN in Juniper SRX as per customer and various EX, SRX & J series Juniper devices.
- Utilized Cisco BGP communities and advanced route filtering on Cisco IOS .
- Manage LAN & WAN and BlueCoat proxy servers.
- Working on security devices ASA, Juniper, Palo Alto Firewalls, Routers, and Switches.
- Implementing security Solutions using Palo alto PA 5000, CheckPoint Firewalls R75, R77.20 Gaia and Provider-1/MDM.Coordinated and designed the implementation of a disaster recovery site for UNDP Country office in Kabul. In addition.
- Implemented the BCP business continuity plan for provisioning the overall IT backup system for UNDP.
- Worked on installation, maintenance, and troubleshooting of LAN/WAN (ISDN, Frame relay, NAT, DHCP, TCP/IP).
- Performed troubleshooting, fixed and deployed many Python bug fixes.
- Controlling antivirus servers, installation and monitoring of the network infrastructure of regional offices with day to day ICT Support for country office for 500 users.
- Providing P2P network for sub offices and managing support for voice infrastructure CISCO CUCM.
- Experience in configuring, upgrading and verifying NX-OS operation system with OSPF, BGP
- Support the front-end developers regarding DevOps tools, Environments and Automation.
- Configured Cisco IOS Feature Set, NAT and Simple Network Management Protocol ( SNMP) for Network Security implementation .
- Experience working with and designing network architectures with IP Routing protocols such as BGP, OSPF, EIGRP, DMVPN, and iWAN. Layer-2 switching technologies and related WAN technologies like MPLS, DWDM, T1, T3 OC3 and other WAN Technologies
- Experienced in SYSLOG analysis & Proxy servers
- Attended Agile sprint meetings and SCRUM's for Software QA, and development
- Hands on experience on Checkpoint firewalls and Cisco ASA.
- Troubleshoot Firewall connectivity issues between Servers and Users as well as various third party, DMZ network and internet zones.
- Extensive MPLS, EIGRP and BGP design. Using DMVPN as a backup connectivity to our Data Centers
- Switch 2960 - XR or S, 3750, router 3845, 3560,6509,4500, Router 2811, 2911, 7206VXR, Nexus 5010, 4431 IOS-XE, 4451, Netflow version 9 with PRTG setup, Solarwinds monitor, Netrin configure Visual troubleshooting and sites creation
- Setup and configuration VTC and implementation Office 365 cloud infrastructure management and support.
- Troubleshooting network issues including boundary protection devices, Cisco Proxy Servers like bluecoat
- Upgraded and updated Cisco IOS from twelve.3T to 12.4. Accustomed DHCP to mechanically assign reusable information science addresses to DHCP shoppers.
- Worked with F5 Load balancing, IDS/IPS, Bluecoat proxy servers and Administrating.
- Setup and configuration of Cisco layer 2&3 Switches Routers and network devices, fully administration of Dell servers and installation.
- Manage a very large DNS environment using Lucent QIP and manual management of DNS for DMZ network/External servers
- Wrote python routines to log into the websites and fetch data for selected options.
- Implementing and troubleshooting firewall rules in Cisco ASA 5525, 5580, Checkpoint R77.20 Gaia and VSX as per the business requirements.
- Configuration of system admin servers and services for end users, managing Active Directory, DHCP, DNS, TCP/IP addressing design Scheme.
- Actively monitored and responded to activity impacting various enterprise endpoints facilitating network communication and data handling (McAfee End Point Security, DLP, Splunk)
- Involved in Network Designing, Routing, DNS, IP Subnetting, TCP/IP protocol.
- Deploy and configured all DevOps tools in multiple cloud providers (AWS and Azure).
- Automate the installation of ELK agent (file beat) with Ansible playbook .
- Configured Firewall logging, DMZ network & related security policies & monitoring
- Good experience on tools and devices like Source Fire, Fire eye, Aruba, Cisco ASA, Cisco ISE.
- Configure all Fortinet Firewall models (300C, 500D, 600c, 1000D, 3600C) as well as a centralized management system (Forti-Manager) to manage large scale firewall deployments
- Monitor and maintain AOL Internal Computing Network and data centers equipment. Daily support and troubleshooting of network IP routing related problems including BGP, ISIS, and OSPF principles, policies and traffic engineering.
- Implementation of secure enclaves with Palo Alto and ASA firewalls
- Remote access and site-to-site VPN administration using Cisco ASA/ASR and Palo Alto
- Worked on Extensively on Cisco Firewalls, Cisco PIX (506E/515E/525) & ASA 5500(5510/5540) Series
- Assisted in entering and updating Issues (Epics, Stories, and Tasks) onto JIRA Agile application.
- Application Deployments & Environment configuration using Chef, Ansible.
- Of Global network consisting of Fortinet Firewalls, BlueCoat Proxy Servers along with
- Firewall zoning including DMZ network and other secure zones for application and database as well as internal traffic.
- Collaborated with the network engineers to identify areas of high risk that can be resolved using ISE
- Install and configured IOS images on routers and switches (IOS, IOS-XE, XR, NX-OS).
- Upgrade BlueCoat Webproxy OS to latest as per Vendor suggestions.
Confidential, NJ
Network Engineer
Responsibilities:
- Data Center hard & soft activities involved in system administration field for, Linux and Microsoft windows Operating systems. Administering Microsoft services as Domain ADDS, DNS, FTP, Exchange2010, File Server, ISA Server 2006, Windows Server 2008/2012, DHCP, WDS, VSS, IIS7.0, RIS, GPO / RSOP, RODC
- Modified internal infrastructure by adding switches to support server farms and added servers to existing DMZ network environments to support new and existing application platforms.
- Worked with Automation script with Python module like Chef& Ansible.
- Conducted mentoring session in python and setting up django environments to junior developers.
- Monitored and maintained client firewall, intrusion detection systems and VPN systems including (Checkpoint FW-1 / VPN-1/ Secure VPN / Secure IDS).
- OSPF, BGP, ACL, VPN, Policy routing, IP address Natting and other network related issues.
- Maintenance and trouble-shooting of LAN, WAN, IP Routing, Multilayers Switching
- Controlling the URL access by using the Bluecoat proxy servers and also McAfee web gateway.
- Experience in Configuring, upgrading and verifying the NX-OS operation system.
- Implement 3850 stackwise switches in the access layer and perform IOS-XE upgrades.
- Translating Cisco IOS Route maps to Cisco IOS XR routing policies.
- Designing and deploying EIGRP, OSPF, BGP, MPLS- VPN protocols and routing technologies for connecting data center to remote locations
- Administering Red hat/Centos Linux services as. NFS, DHCP, LVM, ACL’s, Quotas, NIS & etc. Analyzing system logs and identifying potential issues with computer systems, Introducing and integrating new technologies into existing data center environments.
- Active directory managing and controlling Adding, removing, or updating user accounts information, resetting passwords, Installing, mounting and configuring new hardware EMC SAN, HP, Dell Servers, RAID Configuration and setup.
- Worked on installation, maintenance, and troubleshooting of LAN/WAN ISDN, Frame relay, NAT/PAT, DHCP, TCP/IP,Radius
- Answering technical queries and assisting users. Responsibility for documenting Network and system configuration of the system, performing routine audits of systems and software/hardware applying operating systems updates, patches, and configuration changes.
- Responsible for Backup daily official data and weekly Enterprise Server Configuration Backup System design and disaster recovery for service failures, responsible for administration and Managing network firewalls, as SonicWALL, Cisco ASA, Checkpoint, PFSENS, Cyberoam, Indian firewall.
- Implemented the Policy Rules, DMZ network and Multiple VDOM's for Multiple Clients of the State on the Fortigate Firewall
- Planning Designed Implemented Network and System infrastructure configuration and testing documented system configuration and infrastructure information.
- Experience with Checkpoint Firewall policy provisioning and modification of Palo Alto PA-500, PA-2k, PA-3k, and PA-5 k.
- Designed & Implemented database Cloning-using Python.
- Implementing and configuration of Layer2/3 Network devices switching, routing, firewall.
- Configuring routing protocols and core network services as RIP, EIGRP, Static and dynamic routing, NAT, PAT, ACL/VlLAN Switch port security, STP, RSTP Storm controller.
- Implemented Network monitoring system using Nagios xi, CACTI, WIRESHARK, NTOP 5.0.1. SolarWinds, Established Secure VPN over IPSEC between main and sub offices. (SSL and IPSEC, VPN)
- Worked on Ansible scripting to perform Network Automation in the infrastructure.
- Strong working experience on Cisco IOS, IOS-XE, IOS-XR and Cisco NX-OS operating systems.
- Implemented and Configured IP Routing Protocols: OSPF, EIGRP, and RIPv2
- Implementing and managing WDS, WSUS, DFS, NLB, RADIUS, DNS, DHCP, Active directory, VMware vSphere.
- Done troubleshooting of TCP/IP problems and connectivity issues in multi-protocol Ethernet environment
- Implementing and setup of VTC video Teleconferencing system polycom setup and configuration. Conference system support cisco skype for business, office 365.
