We provide IT Staff Augmentation Services!

Network Security Engineer Resume

5.00/5 (Submit Your Rating)

Philadelphia, Pa

SUMMARY

  • Network Engineer with 7+years of experience in network design, implementation, support analysis and troubleshooting of LAN and WAN environment
  • Expert Level knowledge about TCP/IP and OSI models
  • Virtualization: VLAN, VxLAN, VPLS, PW, GRE. IPSEC, L2TP, EVPN, Link Aggregation, Linux Bridge, OVS, HSRP, VRRP, GLBP
  • Monitored Network Activity using Cisco Prime 2.2, Splunk, Ops Manager, IPAM, Wire Shark
  • Experience in F5, Cisco ACE load balancers.
  • Having knowledge and hands - on experience on IP Addressing, Sub netting, VLSM and ARP, reverse & proxy ARP, Ping Concepts.
  • Proficient in configuration & troubleshooting of different routing protocols OSPF EIGRP RIP,BGP,HRSP,VRRP
  • Implement changes on switches, routers, load balancers (F5 LTM, GTM and CSS)
  • Used load balance applications based on F5 LTM 6900
  • Installed and configured Network Automation System (NA) to validated compliance checks on Cisco routers, switches.
  • Experience in working with Nexus 7K Core and Server Farm Switches with VSS & VPC support.
  • Implemented various EX, SRX & Juniper SRX240,SRX220,and SRX550 series firewalls.
  • Experience with GTM F5 component to provide high availability with providing services across data centers. Setup Inflow Box for local DHCP &DNS configuration
  • Experience in Checkpoint IP Appliances R65, R70, R75, R77 & Cisco ASA Firewalls
  • Hands on configuration/deployment and design of common networking protocols and solutions including: OSPF/EIGRP/BGP routing protocols, Spanning tree protocols, TCP and UDP protocols, Next generation Data center oriented technologies such as virtual port channels (VPC), Fabric path, fiber channel over Ethernet virtual switches, network virtualization
  • Configuring RIP, OSPF and Static routing on Juniper M and MX series Routers.
  • Knowledge of implementing and troubleshooting complex layer 2 technologies such as VLAN Trunks, VTP Ether channel, STP, RSTP and MST.
  • Managed Configuration, Logging and Reporting of Palo Alto Firewall through the Panorama.
  • Managed URL filtering, File blocking, Data filtering by Palo Alto Firewall.
  • Experienced in installation, configuration and maintenance of Cisco Nexus 7K, 5K switches in standalone as well as in V-BLOCK infrastructure
  • Working experience with Load Balancers F5 LTM like 3900, 6900, 4200V over various environments
  • Identified opportunities for implementation of network best practices, particularly F5 load balancer implementations.
  • Involved in the integration of F5 Big-IP load balancers with check point firewalls for firewall load balancing and was responsible was trouble shooting and maintenance.
  • Configuring Cisco routers and switches to enable and troubleshoot a variety of features such as trunk, Vlan, Ether channel, port security, routing protocols including EIGRP, OSPF & BGP and other related technologies such as multicasting, IP Telephony & IP Video. Ability to troubleshoot WAN circuits
  • Performed Installation of Cisco ASA 5585 & 5520 firewalls as well as Palo Alto 3500 series
  • Used different load balance methods, persistence and profiles on F5 LTM
  • Implementation and Proactive Monitoring of MPLS (MPLS-VPN), QoS (Layer2 and Layer3) and BGP technology. Implemented site to site VPN in Juniper SRX as per customer.
  • Implemented routing protocols (RIPv1/2, IGRP, EIGRP, OSPF, BGP), switching (VLANS, VTP Domains, STP and trunking), security on devices hardening (authentication, authorization, and accounting), load balancers.

TECHNICAL SKILLS

Routing: OSPF, EIGRP,PBR, IS-IS, Route Filtering, Redistribution, Summarization, Static Routing, PBR, BGP,RIP-2

Switching: VLAN, VTP, STP, PVST+, RPVST+, Inter VLAN routing & Multi-Layer Switch, Multicast operations, Layer 3 Switches, Ether channels, Transparent Bridging

Network security: Cisco (ASA, PIX) 5510, ACL, IPSEC, VPN, Security context

Load Balancer: Cisco ACE load balancer, F5 Networks (Big-IP)

LAN: Ethernet (IEEE 802.3), Fast Ethernet, Gigabit Ethernet LAN Technology Workgroup, Domain, HSRP, DNS, DHCP, Static, VLAN, STP, VTP, Ether Channel, Trunks. WAN Infrastructure Leased Line, ISDN/Dial-Up, Frame Relay circuits, Metro Ethernet.

WAN: Leased lines 64k - 155Mb (PPP / HDLC), Channelized links (E1/T1/E3/T3)Fiber Optic Circuits, Frame Relay, ISDN, Load Balancing

CISCO Routers: Cisco Routers ASR 06 / 06 / 51 / 2600

CISCO Switches: Nexus 2K/5K/7K, Cisco Catalyst VSS 13 / 00 / 3750- X / 2960

Juniper Switches: Juniper EX4500, 4200

Juniper Routers: Juniper MX480, 240, 80 series

Firewalls: ASA 5585/5520, FWSM, Checkpoint 4200/Nokia IP-560, Juniper Netscreen, Cisco PIX 535/525

Wireless Wi-Fi: Canopy Wireless Device (point to point/point to multipoint), DLink Wireless (point to point), DLink Access

Network Management: SNMP, Cisco works LMS, HP open view, Etherenal, MRTG/PRTG server, Nexus 2000, 5000, 7000 series.

Networking: NAT, VTP, VLAN, L2TP, PPTP, RDP, TCP/IP, IPX/SPX, NetBEUI, UDP, ARP, NTP, EIGRP, OSPF, RIP, VoIP, SIP, SSL, VPN, ESP, 802.11 Wireless, HTTP, HTTPS, FTP, POP3, SMTP, DNS, ICMP

Security & VPN: PIX 500 Firewall, ASA 5505 Firewall, AIP SSM, CSC SSM, FWSM, FortiGate, Cisco CSM, ACL-Access Control List, IPS/IDS, NAT, PAT, Cisco ACS, Juniper NetScreen firewall, PaloAlto Firewalls, Windows Patch Management (WSUS).

Operating Systems: Windows XP, Vista, Windows 7 & 8, Terminal Server, Citrix, Windows 2003 & 2008

PROFESSIONAL EXPERIENCE

Network Security Engineer

Confidential, Philadelphia (PA)

Responsibilities:

  • Working with VPN tunnels, DS1, DS3 & T1 links in networking technologies like LAN, MAN, WAN and peripheral devices.
  • Optimized the Wan traffic through Riverbed and Managing all Riverbed in Corporation through Riverbed CMC. Plan and design network infrastructure.
  • Experience with connectivity of Cisco Networking Equipment with F5 Load Balancer
  • Knowledge and experience with Citrix NetScaler Access Gateway configurations
  • Monitor and troubleshoot BGP, EIGRP, TI circuits, and cellular backup circuits via ICmP and SNMP ticketing systems. Cisco IOS upgrades.
  • Configured Cisco ISE for Wireless and Wired 802.1x Authentication on Cisco Wireless LAN Controllers, Catalyst Switches, and Cisco ASA Firewalls.
  • Knowledge and experience with Citrix NetScaler responder policy configuration.
  • Installation and configuration of Cisco ISR routers.
  • Certifying Cisco routers (ISR 4321, ISR 4331, ISR 4351, and ASR 1001 x) for Level3 Managed Network Services for different features such as testing different routing protocols.
  • Working on Cisco+ 6509 and 4507 series switches for LAN requirements that include managing VLANs, Port Security and troubleshooting LAN issues.
  • Monitoring Traffic and Connections in Checkpoint and ASA Firewall
  • Implementation of various protocols like RIP, OSPF, BGP and STP
  • Basic and advance F5 load balancer configurations, including migrating configurations from Cisco ACE to F5 and general troubleshooting of the F5 load balancers
  • Configuring & Administration of the Checkpoint Firewall that includes creating Hosts, Nodes, Networks, Static & Hide NAT's .
  • Used to handle efficiently a workload of nearly 60 Layer 3 MPLS VPN provision orders which included, MPLS network resource reservation & VPNV4, EBGP configuration checking, Troubleshooting of EBGP sessions with customer carriers in the MPLS cloud which is made up of routers Juniper and Cisco housed in different datacenters (Cisco 7609 and Juniper M320).
  • Experience configuring Catalyst (2900, 3500, 3700 and 6500 Series), Nexus (7000, 5000 and 2000 Series) Switches, and Routers (2800, 3600, 4400 Series) and Wireless AP's (1260, 3600) using CLI and GUI. Supporting EIGRP and BGP based network
  • Troubleshoot all configurations, service issues, and hardware issues associated with the F5 Viprion C2400 chassis and b2100 blades. Responsible for opening trouble
  • Develop Engineering Documentations to record F5 environment and change processes LTM/GTM/iRules. Helped installed F5 VIPRION load balancers for one of our new datacenter
  • My major work is to support Mobily with Juniper Networks Devices (M/T/MX series).
  • Configure trunk ports and implement granular control of VLANs and VXLANs using NX-OS to ensure virtual and flexible subnets that can extend further across the network infrastructure than previous generation of switches.
  • NETWORKING PROTOCOLS: SPBM, SPBMC, SPBoIP, IST, VIST, MACSEC, CFMCMAC, IPv6, Accept Policies, RIP, OSPF, BGP, STP, MSTP, MLT, SMLT.
  • Performed switching technology administration including VLANs, inter-VLAN routing, Trunking, STP, RSTP, port aggregation & link negotiation.
  • Cisco iWan technology and new generation Cisco ISR routers
  • Installation, configuration and maintenance of Palo Alto Firewalls, Cisco ASA firewalls
  • Providing daily network support for national wide area network consisting of MPLS, VPN and point-to point
  • Configuring RIP, OSPF and Static routing on Juniper M and MX series Routers
  • TUNNELING TECHNIQUES: X-Connect, GRE Tunnel, IPSec Tunnel, Pseudo wire
  • Support customer with the configuration and maintenance of PIX and ASA firewall systems
  • Checkpoint Firewall upgrade from R65 to R77
  • Configured Cisco Catalyst 6500, 4500, 3850, 3750, 2960 switches and Cisco 3600, 7200& ASR 1K & 9k Routers for an enterprise network.
  • Firewall management and troubleshooting on Firewalls (Checkpoint, ASA, PIX, FWSM, Juniper SRX/SSG and Palo Alto)
  • Configuration and providing management support for Cisco ASA and Checkpoint Firewalls (R75, R76, R77), VPC,FEX and VDC’s on Nexus 5K,7K
  • Implementation of Juniper Firewall, SSG Series, Net screen Series ISG 1000, SRX Series
  • Manage Active Directory (Windows 2003, Windows 2008 and Windows 2012 Domains)
  • Provide Tier III Level Load Balancer expertise on F5 BigIP Local Traffic Managers (LTM). Designing F5. Implementation of Juniper Router and Switches SRX, J, MX, EX Series
  • Experience in installing, configuring and troubleshooting Catalyst QFX (5100 Series) Switches, SRX (210, 220, 240, 550, 650, 1400, Series) Firewalls solutions/support for migration work of applications and websites from Cisco CSS Load Balancers to the F5 BigIP Load Balancers. Daily Firewall rule base changes on Cisco ASA and Checkpoint firewalls

Network Security Engineer

Confidential, Richmond VA

Responsibilities:

  • Worked on Cisco Layer 2 switches (spanning tree, VLAN).
  • WAN Infrastructure running OSPF & BGP as core routing protocol.
  • Created iOS client which is used to demo Cisco's CloudDVR capabilities at CES and customer sales demos.
  • Responsible for maintaining UNIX OS System and resolving software problems using Informix -SQL database, shell scripts as well as hardware problems- QPSK's, QAM's, etc
  • Management of various hardware including Cisco routers and switches, Tandberg (Cisco) videoconferencing, Cisco CUCM, UPS battery backup monitoring and maintenance and Riverbed Steelhead optimization.
  • Hands-on Cisco CLI administration including Cisco Routers/Switches, Cisco Wireless Access Points, multi-carrier MPLS, DS3, Metro-E, ISDN PRI circuits, DMVPN, ADSL modem support, routing protocols including static, dynamic (BGP, OSPF and EIGRP), 802.1x, VLANs / VTP, STP, Multicast and QOS switching technologies, and ISP Network Connectivity.
  • Project Manager/Supervisor in Firm-wide configuration, maintenance, and support of all network hardware including Cisco and Juniper routers, Nortel, Extreme and Cisco Switches as well as Cisco Wireless access-points. Implementing Cisco ASA and Juniper NetScreen Firewalls, spanning-tree, vlans, TCP/IP, RIP, OSPF, QOS VRRP and VPN technologies.
  • Cisco Wireless WiFi implementation/configuration for Aironet 1240 AG Series Access Points, Aironet 1500 Series Mesh Access Points, Cisco IP Transfer Point, 4400 Series Wireless LAN Controllers and Wireless Location Appliance.
  • Configure Firewalls (Cisco, Fortinet, SonicWall, CheckPoint, Juniper)
  • Implementation and management of BlueCoat proxy servers to replace existing ISA Proxy servers layered with Websense content filtering.
  • Racked and worked with a Cisco 2811 voice gateway with a SIP trunk to carrier
  • Assisted installing cisco ISR 2900 series routers, Cisco 5520 ASA appliance, Wireless LAN upgrade project. Assisted infrastructure team with the installation of 60 cisco 3700 series AP, around the building.
  • Configured and then racked 3 Cisco 2911 voice gateways with H323 to the carrier
  • Leading and supporting role regarding technical topics and solutions within a network implementation organization.
  • Configured VDC's on nexus 7K for creating multiple logical switches and HSRP and VLAN trunking 802.1Q, VLAN Routing on Catalyst 6500 switches.
  • Experience with F5 load balancers and Cisco load balancers (ACE and GSS)
  • VPN Support and Configuration (Cisco, Fortinet, SonicWall.
  • Implementation and Troubleshooting Cisco Routers such as Cisco 1900, 2900, Cisco ASR 1k and Cisco 9k, Configured and deployed QOS and defined class of service (COS) WRED and WFQ for bandwidth management. Tested authentication in OSPF and BGP.
  • Troubleshooting a variety of devices such as Cisco 1841, 2821, 2851, 3845, 2901, 2911, ASR routers, 3750, 3850, 65XX, Nexus 7K & 9K switches, wireless LAN controllers, access points for SNMP, ICMP, LAN/WAN, Copper/Fiber, and switch stack issues, and other network/device related alerts.
  • Configured and troubleshoot OSPF and EIGRP. Web Filtering Support and Configuration (iPrism, McAfee, Cisco, Fortinet, having ASA firewall troubleshooting experience.
  • Worked on VMware's software suites to enable communication between VXLAN enabled VMs using Junipers EX9xx switches as VXLAN gateway. Was awarded Spot bonus for the effort. iRules scripting using TCL (Tool command language) for HTTP redirection, redirection of HTTP traffic from one data center to another data center, content based redirection.
  • Experience with network based F5 Load balancers with software module GTM & Checkpoint
  • IPS/IDS Support and Configuration (Cisco, Fortinet, SonicWall)
  • Administering multiple Firewall of Checkpoint/ASA, in a managed distributed environment
  • Troubleshooting IOS related bugs based on past history and appropriate release notes.
  • Work on different connection medium like Fibre and Copper Connectivity.
  • Implementing, Configuring L3 Protocols ( OSPF, MPLS, GRE, IPsec, QOS )
  • In-depth expertise in the implementation of analysis, optimization, troubleshooting and documentation of LAN/WAN networking systems.
  • Worked on .NET security features such as Form-Based Authentication and Role-Based Authorization.
  • Set up multiple Virtual Servers on our F5 LTM based on the Application Team requirements.
  • Planning and configuring the routing protocols such as OSPF, RIP, and Static Routing on the routers.
  • In depth understanding of IPV4 and IPV6 and implementation of Subnetting
  • Planning and configuring the entire IP addressing plan for the clients' network.
  • Assist the certification team and perform configuration of LAN\WAN technologies such as Ethernet, Fast Ethernet, and Gigabit Ethernet. PV4/IPV6 manage 101 IP networks.
  • WAN Infrastructure running OSPF as a core routing protocol.
  • Follow process & procedures for change & configuration management.
  • Supported nationwide LAN infrastructure consisting of Cisco 4510 and catalyst 6513.
  • Deployed the switches in high availability configuration with HSRP.
  • Knowledgeable with Cisco next generation Unified-Fabric Data Center technologies and protocols, including Cisco Nexus platforms, Fabric Path protocol, Cisco Overlay Transport Virtualization, Cisco VPC, etc.
  • Network Monitoring using tools like Cisco Works 2000.
  • Troubleshooting and verification of Fabric Path.

Network Engineer

Confidential, Orlando, FL

Responsibilities:

  • Work on different networking concepts and routing protocols like BGP, EIGRP, OSPF and other LAN/WAN technologies.
  • Checkpoint Level3 operations support with hardware operations - fixed all problems & RMA's, taking any escalations that dealt with the equipment and its connection: interfaces, VLAN's, routes, etc.
  • Provided technical support for Juniper VPN-Bluecoat Proxy Server administration, Juniper SRX/ EX appliances, F5 APM/LTM VPN, F5 APM/LTM Reverse Proxy, Palo Alto FW, Palo Alto Panorama, Check Point Provider One, Juniper MAG, F5 Backstage Pass, TACACs, Cisco Content Engine, encompassing vulnerability Management of Active Directory, File Servers, Database Servers.
  • Installation and Configuration of Cisco Wireless LAN Controllers on Branch ISR G2 Service Ready Engines (SRE) and Virtual Wireless LAN Controllers for Central Office Infrastructure
  • Working experience with Load Balancers F5 LTM like 3900, 6900, 4200V over various environments
  • Installation and configuration of Citrix NetScaler MPX 8200.
  • Create HPNA diagnostics and policies
  • Rewrite HPNA perl module Create HPNA command scripts
  • Support remote office WAN, PFR & DMVPN technologies
  • Installation and configuration of Citrix access gateway.
  • Used Edge sight for monitoring the citrix farms and troubleshooting the Citrix related issues.
  • User admin on the firewalls, adding and deleting users as they come and go.
  • Configuring rules and Maintaining Palo Alto Firewalls & Analysis of firewall logs using various tools
  • Implementation of HA-JSRP in JUNOS devices, SRX Series Router/Firewall in both A/A and A/P mod
  • Involved in a project for a re-design of the LAN network (Cisco Catalyst 2960 and Nexus 5000 switches) and the virtualization of some systems
  • Developed the Common, Database and Utility libraries using PERL for automation.
  • Implement trunk ports and implement granular control of VLANs and VXLANs using NX-OS to ensure virtual and flexible subnets that can extend further across the network infrastructure than previous generation of switches.
  • Provided proactive threat defense with ASA that stops attacks before they spread through the network.
  • Implemented standard configuration template scripts in various network devices for snmp v2, logging, and ntp.
  • Created standard access lists to allow snmp, ntp and logging servers.
  • Implemented configuration of SRX-110 Juniper firewall
  • Worked on F5 GTM, configuring Wide IPs and pools to load balance the client traffic between the two data centers.
  • Replaced 6500 from access layer and Installed 3750s Switches. Participate in installing and configuring new Firewall policies. Racking and Stacking of Cisco 3750 Switches
  • Networking Hardware Cisco Switches (9k, 7k, 5k), Cisco Routers, ASA/Pix firewalls, Checkpoint firewalls.
  • Expanded the TCP/IP addressing schemes by migrating the main LAN from multiple IPV4 class C networks into a single subnet CLASS B network
  • Co-ordinate with the Data Network and Security team and come up with possible solutions.
  • Provide solutions to Tier 1 escalated issues and tickets.
  • Configuring rules and Maintaining Palo Alto Firewalls & Analysis of firewall logs using various tools
  • Responsible for 6500, 3500, Nexus, switching, ASA, FWSM Firewalls, CSS and F5 load balancers, Riverbed WAN accelerators, IronPort Proxy, and Linux/Bind DNS servers
  • Troubleshoot Juniper QFX series switches. Used NAS- Network Attached Storage for multiple clients on the network with access to the same files. Hands on experience on Juniper MAG-SM360, 4610, SRX, MX and EX. Configuration and troubleshooting of SRX 1400 and SRX 3400.
  • Replaced old 6500 and WAN routers from DR testing site and Installed Nexus 7K and ASR 1006 routers.

Network Administrator

Confidential

Responsibilities:

  • Installed and configured DHCP Client/Server
  • DMVPN Technology, Performance Routing PFR, Ethernet Configuring IPSEC VPN on SRX series firewalls.
  • Had a chance to troubleshoot various application issues with respect to F5
  • Configured and managed networks using L3 protocols like RIPv2
  • Configured VL0ANs, Private VLANs, VTP and Trunking on switches.
  • Troubleshooting complex networks layer 1, 2to layer 3 (routing with MPLS, BGP, EIGRP, OSPF protocols) technical issues.
  • Providing support to networks containing more than 2000 Cisco devices.
  • Ensure Network, system and data availability and integrity through preventive maintenance and upgrade.
  • Involved in L2/L3 Switching Technology Administration including creating and managing VLANs, Port security, Trunking, STP, Inter-Vlan routing, LAN security.
  • Handled Tech Support as it relates to LAN & WAN systems
  • Subnetting networks. Troubleshooting DHCP and DNS Servers.
  • Worked on the security levels with RADIUS, TACACS+.
  • Working on creating new load balancing policies by employing BGP attributes including Local Preference, AS-Path, and Community, MED.
  • Installing and maintaining Windows NT Workstations and Windows NT Server.
  • Providing technical support to LAN & WAN systems.
  • Commissioning and Decommissioning of the MPLS circuits for various field offices.
  • Preparing feasibility report for various upgrades and installations
  • Identify, design and implement flexible, responsive, and secure technology services
  • Handled installation of Windows NT Server and Windows NT Workstations.

Network Administrator

Confidential

Responsibilities:

  • Installed and configured workstations for IP based LAN's
  • Support for load balancer and access policy manager
  • Prototype the basic functionality of scheduling utility using C and C++.
  • Developed PERL data conversion scripts to process and convert claims data into internal data format.
  • Installed and configured DHCP Client/Server
  • DMVPN Technology, Performance Routing PFR, Ethernet
  • Configuring IPSEC VPN on SRX series firewalls.
  • Had a chance to troubleshoot various application issues with respect to F5
  • Configured and managed networks using L3 protocols like RIPv2
  • Configured VL0ANs, Private VLANs, VTP and Trunking on switches.
  • Experience in VMWare NSX and Nexus 1000v hypervisor based networking environments that utilize VXLAN
  • Configured L2 and L3 security features on devices broad Hands on Experience in Inter-vlan routing, redistribution, access-lists and dynamic NAT
  • Efficient in cabling as per co-location contracts with loop-back testing, including all DS1, DS3, T1, T3, CAT 6 and CAT 5 connections as per defined cabling procedures

We'd love your feedback!