Sr. Network/security Engineer Resume
San Diego, CA
SUMMARY:
- A highly motivated Network Engineer wif a strong background in Cisco Networking and a proven ability in layers 2 and 3 networking wif knowledge of Cisco firewall and VPN is seeking employment in a reputable company to halp teh company achieve organizational goals.
- I have been working as a Cisco engineer for 10+ years, applying different protocols on teh routers, switches and firewalls. Applying wan protocols such as BGP, MPLS, FRAME - RELAY, PPP etc. Also configured interior protocols such as EIGRP, OSPF, and RIP on routers. Applied HSRP, VRRP, STP, RSTP, VTP and VLANS on client’s switches and routers. Applied Route Maps, distribute list, access-lists and map class for quality of service to police, bandwidth and shape traffic for smooth traffic flow. Troubleshooting network connectivity issues by finding teh problem caused by firewall or antennae. Replaces antennas, wireless routers, cable set-boxes and wiring if identified as cause of problems.
TECHNICAL SKILLS:Hardware:
Routers: 2600, 2800,3800; ISR, ASR
Switches/Bridges: 2900, 3500, 3560G, 3750, 7200, 3850,4500, 6500, Nexus 5/7k. fabric extenders.
Servers: 2003 and 2008 ,2012 for Active Directory
Security: ASA FIREWALL, WSA, RSA, ANYCONNECT VPN, IPSEC VPN, Cisco Umbrella (OpenDNS), McAfee EPO, SIEM, Ivanti for patching. Secureworks, Firemon Experience in Palo Alto, F5 Load balancer, Solar winds for monitoring.
Software: Cisco IOS, IOS-XE, Excel, Microsoft Word, Access, and PowerPoint.
Protocols: NAT/PAT, EIGRP, BGP, OSPF, STP/RSTP, VTP, ACLs, LAYER 2 SECURITY, 802.1Q, QOS, ARP, 802.1x, TCP/IP MPLS, DHCP, DNS, ACITIVE DIRECTORY, CHAP., VoIP, Cisco wireless software (LWAP, WAP, WLC, WCS), Load Balancing F5, Using Cisco IOS.
Monitoring tools and Ticketing system: Solar winds, ServiceNow,Remedy, Manage Engine
PROFESSIONAL EXPERIENCE:
Confidential, San Diego, CA
Sr. Network/Security Engineer
Responsibilities:
- Lead teh implementation to upgrade and replace Cisco IPsec to AnyConnect VPN.
- Project lead for RSA two factor autantication for all BOFI VPN users.
- Project lead for teh implementation and deployment of Cisco Umbrella for end user computer security
- New switches deployment at BOFI site in Gualaradala; Mexico.
- Installation of many switches such as 3700, 3800, 4500X distribution,4500, access,6500, Nexus 5548UP, Nexus 7700.
- Lead teh installation and deployment of F5 in teh bank’s production network after teh POC.
- Configuration and troubleshooting of VPC, VDC and nexus related issues.
- Configurations and troubleshooting of routers such as 2900,3900,4000, ISRs and ASRs.
- Expert in troubleshooting Layer 2 and 3 protocols.
- Proficient in configuring and troubleshooting of routing protocols such as OSPF, BGP, and EIGRP.
- Comfortable configuring MPLS and dealing wif teh service Clients providers
- Cisco Firewall installation, deployment and administration.
- Cisco IPsec and SSL anyConnect VPN administration and installation.
- RSA Autantication Manager and WebTier administration.
- Knowledge of OTV for datacenter consolidation.
- Proficient in troubleshooting windows virtual servers
- Good working knowledge of cisco SMA, WSA, ACS and ISE administration. Also Palo Alto PANORAMA.
- Good working knowledge wif McAfee SIEM and EPO.
- Proficient working wif DHCP and DNS
- Used F5 as a proxy to direct multiple external users to their specific host servers internally.
- Used Palo Alto to filter multiple malicious websites sites, block IP addresses, restricted users to certain internet activities.
- Used Cisco WSA to block/Allow websites to suit teh bank’s desire.
- Managed multiple Cisco WSA using SMA.
- Managed Multiple Palo Alto using Panorama.
- Installed Solar winds to back up PRGT to back up all Cisco device configuration in NCM.
- troubleshooting of user tickets such as websites unreachable, application issues, switch port configurations.
- creating and modifying new and existing firewall rules to resolve user requests issues.
- Creation of multiple DNS A/pointer records for local and external websites.
- Troubleshooting VPN issues for Remote users. Unlocking user accounts and creating new users in teh Active directory.
- Troubleshooting issues relating to VLANS, VTP, STP, and RSTP and HSRP.
- Troubleshooting of Server VMs issues such as connection, DNS, DHCP, etc.
- Administered McAfee EPO to track users and malicious act of both internal and external users.
- Administered McAfee SIEM to track user activity logs in teh bank.
- Troubleshooting SSL VPN issues for remote users, including RSA and OpenDNS.
- troubleshooting wireless tickets using Meraki access points.
- Using WSA to put users in their respective groups to prevent or allow to specific sites.
- Used F5 as a proxy to direct traffic to servers as specified.
- Creation/troubleshooting of Virtual Machines using Vcenter.
- Troubleshooting connectivity issues using wireshark
Confidential, Lexington, KY
Senior Network Engineer
Responsibilities:
- Built and installed new racks in datacenter to support customer Network
- Built a whole network (Fountain court site) from scratch for entire new hospital 3 floors. Including switches, routers, UPS, access points, and all cabling.
- Installed, stacked and configured 3750/3850 switches to serve each floor on teh new customer site.
- Replaced 6500 line cards and upgraded teh IOS.
- Built site to site VPN IPSec tunnel using cisco ISR router and ASA firewall
- Designed and successfully implemented network infrastructure on customer sites.
- Wif a distribution switch configured teh new Cisco 4500x 32 ports to serve teh hospitals hub closets.
- Replaced and installed Cisco 4 507 wif 45 10 access switch to increase teh ports capacity for end users.
- On teh Cisco 6506 connected and configured single/multi mode fiber on SFPs GLCs and X2-LR/LRMs to link different buildings wif port-channels.
- Upgraded, configured and replaced all types of catalyst/IOS switches in hub closets/datacenters through approved change requests.
- Configured VPC on two Nexus 5k switches as peers to support load balancing and redundancy for fabric extenders or N2Ks.
- Troubleshooting and configurations of N2Ks on teh fabric switches.
- Supported a team to build OTV to link multiple sites for inter layer-two switching by creating VDC on teh edge switch.
- Installed Cisco voice gateway to support call manager and teh subscriber for teh voice team.
- Configured routing protocols such as eigrp, ospf, bgp and rip for customer data/voice routing and layer two Protocols for wan such as MPLS and Frame-relay
- Experienced and skilled in layer 2 and 3 troubleshooting and preventing issues that will bring teh network down such as loops etc.
- Build a new wireless SSID for teh St. Joseph hospital pharmacy department for their new wireless Sonicu monitoring meter using Cisco 5500 wireless LAN controllers.
- Daily interaction wif customers and vendors to resolve issues both onsite and remote sites.
- Practice acquisition network engineer for St. Joseph hospital Kentucky
- Expert in IP subnetting.
- Troubleshoots critical, high and medium issues to make sure teh resolved tickets fall wifin teh agreed SLA.
- Configured a new vlans on teh core switch for teh nurse station patient monitoring devices and used HSRP as a redundant between teh two 6506 core switches.
- Have resolved several vlan issues relating to trunking, gateway, vtp, loop, spanning, tree…etc.
- Configured new voice vlan to support teh company's Mitel phone system.
- Troubleshooted MPLS, and Frame-relay circuits onsite and wif circuit providers.
- Installed new switches and routers for teh hospital's new clinics and configured VRF on client side to face wif teh Provider's VPNv4 MPLS.
- Both layer 2 and 3 loop troubleshooting to teh port looping teh network and resolve teh issue.
- Configured several port-channels to increase traffic flow and uptime for teh customer.
- Installed and troubleshooted access point using wcs and 5500 wireless controllers.
- Monitored and troubleshoot network using Solar winds, Syslog, NCM, Remedy, VPM, WCS,
- Used WCS to configure and monitor wireless devices using wlan controllers and access points.
- Troubleshooting of network issue relating to Printers, Phones, PCs, radiology devices; i-stat; I-clocks; work stations wif Diocom and Kronos time clock in machine that couldn’t register employees’ time.
- Replaced a 45megabite DS3 circuit card wif 90meg. In a 3950 router linking to another site for a better bandwidth.
- Increased teh subnets of a vlan due to lack of IP addresses in DHCP scope
- Rebooted routers and switches to clear and release slow traffic in a network caused by retransmission of packets.
- Traced switches using LAN drops and cables through patch panels.
- Built racks in a datacenter from scratch to support applications, Security, wireless and teh entire network.
- Installation of new switches and routers for new sites through circuit providers such as Windstream, CenturyLink and ATT.
- Weakly bridged meeting wif vendors to discuss issues and activate circuits. As a team lead, meet wif client managers so discuss problems and issues they might have.
- Used Fluke and Toner to trace a switch and find teh configuration on teh switch port. And device vendors for technical support.
- Stacked switches together by using stack cables for redundancy.
- Used DHCP to reserve address to devices that needs static IP addresses.
Confidential
Responsibilities:
- Configured 3550 switch for edge distribution between teh enterprise edge and teh enterprise campus
- Applied a Virtual Switching System VSS at teh distribution layer to link teh access and teh core layer and VSL to connect teh two 6500 chassis for redundancy, speed, bigger bandwidth and to eliminate loop at teh layer 2.
- Configured BGP at teh enterprise edge to link two related clients. And IBGP wifin their local areas..
- Applied Port channels/ether channels such as PAgP and LACP on teh access and core switches to link teh VSS. Also between two 4500 switches for high bandwidth
- Troubleshooting LAN and WAN to determine wat were teh major problems and improvements needed to be made to maintain teh network in its best condition.
- Packet analysis using ethereal to determine teh source of traffic or packets.
- Daily activities such as configuration of switches, routers and firewalls.
Confidential
Network Engineer
Responsibilities:
- Configured prefix-list for teh company’s enterprise edge router to reduce data processing times and speed up packets as they pass through teh edge router that come from teh vendors BGP routing table
- Implemented HSRP on teh Cisco 3550 Layer 3 switches, and EIGRP, OSPF on teh 2 Cisco 7200 routers, 2 Cisco 2610 routers, teh Layer 3 switch, 3 Cisco 3508XL Switches, 2 Cisco 3524XL switches for load balancing and fail-over
- Replaced antennas, wireless routers, cable set-boxes and wiring if identified as cause of problems.
- Detected and solved teh connectivity issue caused by DNS server down, and DHCP conflicts through teh issue of double incidence.
- Load Balanced traffic using EIGRP Multiplier (variance)
- Possesses strong knowledge in Cisco Networking protocol
- Analyzed LAN to determine wat were teh major problems and improvements needed to be made to teh network infrastructure
- For Security reasons configured Cisco site to site VPN for client remote access using cisco PIX/ASA
- Enabled bpdu guard and snooping on switches for security reasons.
- Engineered a dedicated server to move them from a peer-to-peer network to provide more reliable service and to reduce teh latency
- Migrated their primary record keeping software AviMark to teh server along wif teh time keeping software TimeWolf so it could be accessed from any workstation
- Implemented a backup strategy along wif a disaster recovery plan in teh event that teh core switch or router should go down to prevent lost revenue
- Implemented site to site VPN from North Carolina Durham site to Charlotte site using Microsoft MPPE
- Deployed Cisco routers and switches throughout teh network provided by teh administration as needed
- Instructed and thought co- workers on seminar about teh IPV6 and its implementation
- Updated all software from their vendors’ website to prevent zero day attacks and intruders
- Monitored teh network using omnibus and created tickets from teh IDS/IPS software output
Confidential, Montebello, CA
Customer Service rep.
Responsibilities:
- Customer Service Representative A
- Contacted companies outside teh country like Africa, Asia and South America to sell them containers of used and refurbished clothing
- Developed relationship wif factories and super stores for rejected items to buy
- Supervised and prevented loss of bales and selected items
- Prevented teh sale of free employee tickets to guests entering teh park
Confidential
System Engineer-Internship/ volunteer
Responsibilities:
- Monitoring system for auditing purposes
- Troubleshooting of system downs and client machine issues
- Security software configuration and updates
- Installed VPN for instructors to access servers securely from off campus.
- Troubleshooting of windows server and Windows 7
- Configured an in-house DNS, installed and configured Microsoft BackOffice 4.5 components including Exchange Server
- Troubleshoot network connectivity issues for client computer users
- Authored documents outlining customers’ needs, network problems, and provided solutions
- Migrated teh school's servers to another site
- Configured a new router and switches according to teh school's policy and need
- Customized teh school's network according to teh need of teh school
- Proven knowledge of data-networking protocols on Cisco routers and switches such as EIGRP, OSPF, BPG, Frame-Relay, ATM, MPLS, MLPPP DS3, T1, OC3, ISDN etc.
- Troubleshoot of Cisco routers and switches wif regards to DNS/DHCP Conflict
- Troubleshoot TCP/IP connections using Ipconfig and ping commands
- Management of peer-to-peer configuration for customer system reliability
- Proven knowledge of VPN gateways
- Advance knowledge/skill in LAN/WAN troubleshooting and management
- Advance knowledge and skill of Cisco routers and switches protocols
- Proficient in various Network management and ticketing systems
- Experienced in virtual Enterprise Networking environments
- Experienced in Ethernet and IP Networking protocols and applications
- Working knowledge of practice framework such as COBIT and ITIL
- Working knowledge of networking hardware platforms such as Microsoft Small/large Business Server
- Strong working knowledge in TCP/IP Stack and data flow and ticketing systems
- Proven skill in Ethernet network environment
- Proven knowledge of Microsoft XP, Vista, Windows 7 and server 2008
- Eight years of experience in customer relations both in state and international
- Excellent and proficient in oral/written communication wif customers and vendors
- Five years of experience in record of drops installation and changes remotely
