Network Security Engineer Resume
Fremont, CA
SUMMARY:
- 7+ years of experience in routing, switching, firewall technologies, systems design, and administration and troubleshooting
- Experience in designing, architecting, deploying and troubleshooting Network & Security infrastructure on routers, switches (L2/L3) & firewalls of various vendor equipment.
- Experience in handling tickets opened for network related issues and resolving as per SLA.
- Experience in installing, configuring, and troubleshooting of Cisco Nexus 7k, 5k, 2k, Cisco 7600, 7200, 3800, 3900, 2800, 2900 series Routers, Cisco Catalyst 6500, 4500, 2960 and 3750 Stack Switches.
- Expertise in configuring, troubleshooting network topologies which includes OSPF, Hands - on Experience in configuring and troubleshooting firewalls like Palo Alto, Cisco ASA, Checkpoint, Juniper SRX.
- Expert in troubleshooting F5 software modules, including BIG-IP LTM, ASM, APM.
- Proficient in Cisco IOS for configuration & troubleshooting of routing protocols: MP-BGP, OSPF, LDP, EIGRP, RIP, BGP v4, MPLS, ISIS.
- Good knowledge in ACL, NAT/ PAT, Ether Channel, IP Sec and VPNs. Experience in Troubleshooting for connectivity and hardware problems on Cisco Networks.
- Experience in L2/L3 protocols like VLAN, STP, ISL, MPLS and Trunking protocols.
- Experience in set up, configuration and management of Cisco ASA Firewall and Cisco ISE in various domain such as Internet, DMZ, Business-Partner and Remote-Access VPN etc.
- Worked on network topologies and configurations, TCP/IP, UDP, Frame Relay, Token ring, bridges, routers, hubs and Switches.
- Experience in installing and configuring DNS, DHCP server and involved in designing and commissioning WAN infrastructure for redundancy in case of link failure.
- Extensive hand on experience with complex routed LAN networks, CISCO Routers and Switches.
- Multiple data center migrations and transformation projects, with great expertise on Wireshark. Upgrade and Maintenance of Service router such as Cisco router.
- Managing global outsourced services SLA with external third-party vendors on the systems and applications side such as SUN, Red Hat, HP-UX, Oracle Linux, HP-UX, Symantec (to name a few).
- Protocols in high availability environment. Experience with different Network Management Tools and Sniffers like SNMP, HP-Open view, and Cisco works to support 24 x 7 Network Operation Center.
- Supported enterprise environment including: Aruba controllers, Airwave and APs/Cisco wireless controllers.
- Strong experience in Black box, White box, responsive design and usability and exploratory testing, PKI (Public key Infrastructure) Encryption algorithms.
- Strong problem-analysis talent, driven by a global view/attention-to-detail approach.
- Hands on technical knowledge Experience with different Network Management Tools and Cisco works support 24 x 7 Network Operations Center
TECHNICAL SKILLS:
Routers: Cisco ASR 9001, Cisco Router 7600, 7200, 3800, 3600, 2900, 2800, 2600, 1800, 1700
Routing Protocols: OSPF, EIGRP, BGP, RIP v1/v2, MPLS, Static Routing Redistribution, Summarization
Switches: Nexus 1K/2K/5K/7K/9K, Cisco Catalyst 2900, 3500, 3700, 6500, 4500, 3850, 3560, 3750, 2960
Switching: LAN, VTP, STP, PVST+, RPVST+, Inter VLAN routing & Multi-Layer Switch, Ether channels, Transparent Bridging
Network Security: Cisco ASA (5505, 5510), ACL, IPSEC, F5 Load Balancer, Checkpoint (R76, R77), Cisco ISE, Palo Alto
Load Balancer: F5 Networks (Big-IP) LTM and GTM (8900 and 6400)
LAN: Ethernet (IEEE 802.3), Fast Ethernet, Gigabit Ethernet
WAN: PPP, HDLC, Channelized links (T1/T3), Fiber Optic Circuits, Frame Relay, VOIP
Network Monitoring: SNMP, HRPing, Cisco Secure ACS, Wireshark, Cisco Prime Infrastructure
PROFESSIONAL EXPERIENCE
Confidential, Fremont, CA
Network Security Engineer
Responsibilities:
- Administration of Palo Alto Network Device, Configuration of New Access Policy, Firewall Rules, QOS Rules, User ID agents, Threat Policy.
- Responsible for monitoring Large scale deployments of Palo Alto firewalls on our global network using centralized management system Panorama.
- Configured Routing protocols such as RIP, OSPF, EIGRP, static routing and policy-based routing.
- Team member of Configuration of Cisco 7206 router with VPN and Configuration of Catalyst switches.
- Configuration 7500, 7200 with OSPF and catalyst 6505, 4500, 3550 switches with various VLAN.
- Create and test Cisco router and switching operations using OSPF routing protocol, ASA 5500 Firewalls, and MPLS switching for stable VPNs.
- Troubleshooting the Network Routing protocols (BGP, EIGRP and RIP) during the Migrations and new client connections.
- Hands on experience in Aruba S2500 switches, Aruba 7200, 3600 series wireless controllers, Aruba IAP 105, Airwave Products and clear pass Servers.
- Configuring & managing around 500+ Network & Security Devices dat includes Cisco Nexus & Arista Switches, Juniper MX Series Routers, Juniper SRX Firewalls.
- Configured VMware and Managed and maintained large scale VMware ESX infrastructure.
- Experienced with Juniper: EX-2200, EX-4200, EX-4500, MX-480, and M Series, SRX210, SRX240.
- Optimized performance of the WAN network consisting of Cisco 3550/4500/6500 switches by configuring VLANs.
- Configured OSPF and BGP on Juniper M and MX series Routers
- Configuration and troubleshooting of Cisco 7500, 7200vxr, 3800, 3600, 2900, 2800, 2600,1800,1700 routers.
- Worked with Cisco Nexus, Catalyst and Aruba wireless devices.
- Implemented, configured BGP WAN routing, converting OSPF routes to BGP (OSPF in local routing).
- Experience in set up, configuration and management of Cisco ASA Firewall and cisco ISE in various domain such as Internet, DMZ, Business-Partner and Remote-Access VPN etc.
- Experience in creating DAP Policies on Cisco ASA for Remote-access users and Creating IPSEC tunnel on ASA with Business Partner Firewall.
- Technical assistance for LAN/WAN management and complex customer issues.
- Configuring, monitoring and Troubleshooting on Cisco Prime Infrastructure 1.2, 1.3, 2.0, 2.2 physical appliances.
- Worked with Network Engineer’s in the installation and configuration of firewalls.
- Designing and configuration of F5 load balancer both BIG-IP LTM and DNS.
- Configured Check Point Firewall and Cisco ASA Firewall.
- Migration of Check Point to Palo Alto Firewalls.
- Installation, upgradation and troubleshooting of Palo Alto firewalls.
- Wrote python scripts to parse XML documents and load the data in database.
- Configuring, implementing and troubleshooting IGMP, VLAN’s, VTP, STP, Trunking, Ether channels.
- Configuring and maintenance of layer2 switching tasks which advocate VLAN, VTP, STP, RSTP, PVST, RPVST, configuring of ether channel with LACP and PAGP along with troubleshooting of inter-VLAN routing.
- Packet capturing, troubleshooting on network problems with Wireshark, identifying and fixing problems
- Maintenance of F5 Load balancers-6600/6800
- Experience with Office 365 Data Loss Prevention
- Performing network monitoring, providing analysis using various tools like Wireshark, Solarwinds etc.
Environment: Cisco 2948/3560/4500/3560/3750/3550/3500/2960/6500 switches and Cisco 3640/12000/7200/3845/3600/2800 routers, Cisco Nexus 9K/7K/5K, Cisco ASA five hundred, F5 BIGIP remembering, RIP, OSPF, BGP, EIGRP, LAN, WAN, VPN, HSRP
Confidential, Fort Worth, Texas
Network Engineer
Responsibilities:
- Responsible for service request tickets generated by the halpdesk in all phases such as troubleshooting, maintenance, upgrades, patches and fixes with all around technical support.
- Supporting EIGRP and BGP based PwC network by resolving level 2 &3 problems of internal teams & external customers of all locations.
- Deployed and configured ASM load balancer.
- Participate as a rotating member of the SDN Control Center including on call support. Monitor applications (24/7) environment.
- Perform CMTS chassis upgrades, card upgrades, frequency changes, QAM modifications, and node moves.
- Familiar with command line interface of Alcatel-Lucent Routers (SR-7750, SAR-8 7210 & 7705).
- Upgraded Cisco ACI, Switches and Firewall (PIX) IOS using TFTP
- One of the team members for the designing of SAML and secure Ops.
- Provided support for the VMware installation and management.
- Installing, troubleshooting, and maintenance of Sophos endpoint protection and Sophos safeguard for encryption.
- Configured DNS, IPAM and DHCP using infoblox
- Installed and configured the Brocade switches.
- Installed SCUP and integrated with SCCM 2012 R2.
- Configuring HSRP between the 3845-router pairs for Gateway redundancy for the client desktops.
- Involved in L2/L3 Switching Technology Administration including creating and managing VLANs, Port security, Trunking, STP, Inter-Vlan routing, LAN security, arista switches.
- Configuring STP for switching loops prevention and VLANs for data and voice along with Configuring port security for users connecting to the switches.
- Ensure Network, system and data availability and integrity through preventive maintenance and upgrade.
- Involved in L2/L3 Switching Technology Administration including creating and managing VLANs, Port security, Trunking, STP, Inter-Vlan routing, LAN security.
- Completed service requests (me.e. - IP readdressing, bandwidth upgrades, IOS/platform upgrades, etc.)
- Involved in Configuration of Access lists (ACL) on Juniper and Palo Alto firewall.
- Modified internal infrastructure by adding switches to support server farms and added servers to existing DMZ environments to support new and existing application platforms
- Configured switches with port security and 802.1x for enhancing customers security.
- Configuration of Palo Alto firewalls for remote site implementation
- Monitored network for optimum traffic distribution and load balancing using Solar winds.
Environment: Cisco 6509/ 3750/3550/3500/2950 switches, Cisco 7200/3845/3600/2800 routers, Checkpoint firewalls (SPLAT), Net Flow, TACACS, EIGRP, RIP, OSPF, BGP, VPN, MPLS, CSM, SUP720, Ether Channels, Fluke and Sniffer.
Confidential, Alexandria, VA
Sr. Network Engineer
Responsibilities:
- Implementation of analysis, optimization, troubleshooting and documentation of LAN/WAN networking systems.
- Configured and troubleshoot OSPF and EIGRP.
- Planning and configuring the routing protocols such as OSPF, EIGRP, RIP, and Static Routing on the routers.
- Tested autantication in OSPF and BGP.
- Troubleshoot traffic passing managed firewalls via logs and packet captures
- Configured and resolved various OSPF issues in an OSPF multi area environment.
- Managed fast Layer 3 switched/routed LAN/WAN infrastructure as a part of Network team. The LAN consisted of Cisco campus model of Cisco 3550 at access layer, Cisco 6513 at distribution/core layer.
- Worked with telecom vendors regarding network fault isolation.
- Hands-on experience with WAN (ATM/Frame Relay), Routers, Switches, TCP/IP, Routing Protocols (BGP/OSPF), and IP addressing.
- Configured CIDR IP RIP, PPP, BGP and OSPF routing.
- Involved in the configuration & troubleshooting of routing protocols: MP-BGP, OSPF, LDP, EIGRP, RIP, BGP v4. Configured IP access filter policies.
- Experience with Firewall Administration, Rule Analysis, Rule Modification
- Modified internal infrastructure by adding switches to support server farms and added servers to existing DMZ environments to support new and existing application platforms.
- Deployed 7613 as PE and CE router and Configured and troubleshoot the Edge Routers.
- Excellent troubleshooting knowledge on T1, T3, OC-3 and OC-12.
- Generated RCA (Root Cause Analysis) for critical issues of layer1/layer2/layer3 problems.
- Configuration and troubleshooting of Cisco catalyst 6509, 7613 with supervisor cards.
- Worked with Juniper Firewalls.
- Experience with implementing and maintaining network monitoring systems (Cisco works and HP Open view) and experience with developing complex network design documentation and presentations using VISIO.
- Estimated Project costs and created documentation for project funding approvals.
- Configured ASA 5540 to ensure high-end security on the network with ACLs and Firewall.
- Used IPSec VPN tunneling to provide access to user machines and partners in another network. Provided application level redundancy and availability by deploying F5 load balancers LTM.
- Experience with convert Checkpoint VPN rules over to the Cisco ASA solution. Migration with Cisco ASA VPN experience.
- Configured RIP, PPP, BGP and OSPF routing, and involving in the configuration & troubleshooting of routing protocols: MP-BGP, OSPF, LDP, EIGRP, RIP, BGP v4. Configured IP access filters policies.
- Identify, design and implement flexible, responsive, and secure technology services
- Experience with Firewall Administration, Rule Analysis, Rule Modification
- Troubleshoot traffic passing managed firewalls via logs and packet captures
- Created standard access lists to allow SNMP, NTP and logging servers.
- Racking, Stacking, configuring, Nexus 5K and 2K
- Troubleshooting and verification of Fabric Path.
- Negotiate VPN tunnels using IPSec encryption standards and also configured and implemented site-to-site VPN, Remote VPN.
- Created Monitoring requirements around security (SNMP, syslog) for ASR1k, WLC, AP and NCS Etc.