Sr.network Security Engineer Resume
Chicago, IL
SUMMARY:
- 8.3 years of professional experience in Planning, Implementing, Configuring, Troubleshooting of networking system on both Cisco and Juniper Networks
- Experience with the escalation problems for Routing, Switching and WAN connectivity issues using ticketing systems like remedy and Magic
- Experience of routing protocols like EIGRP, OSPF, RIP, and BGP
- Excellent knowledge of TCP/IP protocols IPV - 4 and IPV-6
- Worked on Cisco 7200, 3800, 3600, 2800, 2600, 1800 series Routers andCisco 2900, 3500,4500, 5500 Switches
- Worked on MX-80, MX-480, SRX-100, SRX-110, SRX-550 and EX-4200 Juniper devices
- Strong knowledge of VMware vSphere administration within Cisco Unified Computing System environment
- Extensive hands-on experience with complex routed LAN and WAN networks,routers and switches
- Hands-on configuration and experience in setting up Cisco routers to perform functions at the Access, Distribution, and Core layers
- Experience in the setup of Access-Lists, and RIP, EIGRP, and tunnel installations
- Proficiency in configuration of VLAN setup on variousCiscoRouters and Switches
- Experienced in trouble-shooting both connectivity issues and hardware problems on Cisco based networks
- Hands-on experience in using network stimulator tools like OPNET, Solarwinds Orion
- Experience deploying BIG-IP F5 LTM, GTM Load Balancers for load balancing and traffic management of application
- Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5500 with ACL, NAT, Object Groups, Failover, Multi-Contexts
- Strong knowledge in HSRP, VRRP redundancy Protocols
- Experience in Network Management Tools and sniffers like SNMP, Wireshark and Cisco works to support 24 x 7 Network Operation Center
- Experience working with network Automation using Python
- Experience in physical cabling, IP addressing and subnetting with VLSM, configuring and supporting TCP/IP, DNS,VOIP-Cisco Call Manager installing and configuring proxies
- Access control server configuration for RADIUS & TACACS+
- Hands-on experience using Cisco Virtual Switching System (VSS)
- Knowledge of advanced technologies like Multicasting, MPLS and MPLS-VPN
- Good knowledge on Riverbed Virtual Services Platform (VSP) and Big-IP F5 Load balancers
- Ability to Install, Manage & Troubleshoot Large Networks & Systems Administration on Windows & Linux platforms in Development, Lab & Production Environments
- Good knowledge of CISCO NEXUS data center infrastructure with 5000 and 7000 series switches includes (5548, 7010) including CISCO NEXUS Fabric Extender (223, 2248)
- Hands-on Experience with CISCO Nexus 7000, Nexus 5000, and Nexus 2000 platforms
- Knowledge of virtual firewalls like checkpoint VSX, IDS, IPS as well as encryption techniques
- Good knowledge on VLAN Trunk Protocol (VTP)
- Design, configure, and implement LAN/WAN networking solutions for mid-sized to enterprise-level clients
- Conduct Wireless RF Surveys and document results
- Develop comprehensive project-based System Designs, Network Diagrams, Migration Plans, and Test Plans
- Effectively communicate with internal Account Executives and potential clients to assess and make solution
- Develop Bills of Materials (BOMs) and technical Statements of Work (SOWs)
- Great team player and able to work under pressure
TECHNICAL SKILLS:
Routing Protocols: RIPv1, RIPv2, BGP, OSPF, IS-IS, IGRP, EIGRP
Security: Cisco ASA, Check point, Juniper SRX, Palo Alto
Switches: Cisco Catalyst 2960, 3500, 3750, 3850, 4500, 4900, 6500, Nexus
2000, 5000 and 7000 series:
Routers: Cisco 2800, 2900, 3800, 3900, 7200 and 7600 series routersJuniper M & T Series
L2 Switching: VLAN, VTP, STP, Dot1Q, RSTP, DTP, PVST and MST
L3 Switching: Ether channels, HSRP, GLBP
Communication Protocols: TCP/IP, UDP, DHCP, DNP, ICMP, SNMP, ARP, RARP, PPP
WAN: Frame Relay, ATM, T1, T3, OC3, OCX, OC48, MPLS VPN
Physical: Ethernet, Fast Ethernet, Gigabit Ethernet, Serial
Network Management Tools: MRTG, HP Open view, Cisco WAN manager and Cisco works
AAA Architecture: TACACS+, RADIUS, Cisco ACS
Tools: Wireshark, VMWare, tcpdump
Operating System: DOS, Windows XP, Vista/7/8/10, Cisco IOS, Linux, Mac OS, Cisco IOS
PROFESSIONAL EXPERIENCE:
Confidential, Chicago, IL
Sr.Network Security Engineer
Responsibilities:
- Implemented antivirus and web filtering on Juniper SRX 240 at the web server
- Dealt with creating VIP(virtual servers), pools, nodes and applying I Rules for the virtual servers like cookie persistency,
- Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5585 Security appliance
- Failover DMZ zoning & configuring VLANs/routing/NATing with the firewalls as per the design.
- Establish AWS technical credibility with customers and external parties
- Help customers build scalable, resilient, and high-performance applications and services on AWS
- Develop/capture/document architectural best practices for building systems on AWS
- Implementation and Configuration ( Profiles, I Rules) of F5 Big-IP LTM-3600 load balancers
- Provided Layer-3 redundancy by implementing HSRP and GLBP for High availability
- Experience configuring VPC, VDC and ISSU software upgrade in Nexus 7010
- Experience working with Cisco Nexus 2148 Fabric Extender and Nexus 5000 series to provide a Flexible Access Solution for datacenter access architecture.
- Experience configuring Virtual Device Context in Nexus 7010
- Installed and configured Cisco ASA 5500 series firewall and configured remote access IPSEC VPN on Cisco ASA 5500 series
- Automated network implementations and tasks and designed monitoring tools using python scripting
- Upgraded load balancers from Radware to F5 BigIP v9 which improved functionality and scalability in the enterprise. Managed the F5 BigIP GTM/LTM appliances to include writing iRules, SSL offload and everyday task of creating WIP and VIPs.
- Migrating the policy from Cisco ASA firewall into Palo Alto.
- Experience with deployment of Palo Alto firewalls for different NAT, video conferencing traffic
- Implemented Positive Enforcement Model with the help of Palo Alto Networks
- Experienced with Palo Alto products installation and configuration
- Administration of ASA firewalls in the DMZ and FWSM in the Server Farm to provide security and controlled/restricted access.
- Implementation and Configuration ( Profiles, I Rules) of F5 Big-IP LTM-6400 load balancers
- Experience in Configuring, upgrading and verifying NX-OS operation system with OSPF, BGP
- Troubleshooting of complex LAN/WAN infrastructure that include routing protocols EIGRP, OSPF & BGP,
- Configure / Troubleshoot CISCO 12000, 7500, 3800, Juniper MX 480, MX960 series routers and EX4200 & EX3200, 3560 series switch for LAN/WAN connectivity.
- Implemented Access lists and policy mapping onJuniperrouter installed in each branch across all the locations.
- Worked on external customer wireless network infrastructure
- Supported day to day operational needs for customer infrastructure
- Support pre-sales wireless network engineering activities
- Leverage understanding of LAN/WAN technologies in order to support, design, and integrate complex wireless LANs
- Worked with a team on planning, designing, configurations, deployments and support of LAN/WAN/WLAN infrastructure
- Worked with VMware hypervisor and virtualization monitoring tools
- Participated in the evaluation of vendor hardware, software, and wireless communications products
- Operational support and troubleshooting of production wireless network issues
- Provided technical support case escalation for customer wireless infrastructure
- Documentation of advanced enterprise wireless solutions and designs
- Experience working with ASR 9000 series switches with IOS-XR
- Experience with deploying PIM Sparse-mode/Dense-mode multicasting in Campus locations.
- Actively involved in Switching technology Administration including creating and managing VLANS, Port security- 802.1x, Trucking 802.1Q, RPVST+, Inter-VLAN routing, and LAN security on Cisco Catalyst Switches 4507R+E, 6509-E and Cisco Nexus Switches 2232, 5596, 7009.
- Tests scope to include application modules, integration layer and full end-to-endtesting incorporating various device &WebTop clients
- Tested various networks which works on the protocols like of TCP/IP (IP, TCP, UDP, SNMP, DNS, DHCP, FTP, HTTP, HTTPS, ICMP, SMTP, ARP, IPSEC, and NAT)
- Serve as part of a team of network engineers responsible for network upgrade from Cisco Layer 3 Catalyst switches to Juniper Layer 3 EX4200 & EX3200 switches across multiple offices.
- Design, implement and administer enterprisenetworkinfrastructure utilizing Juniperrouters across locations.
Confidential, Chicago, IL
Network Implementation Engineer
Responsibilities:
- Responsible for implementing, supporting, and maintaining 24x7 network services
- Packet capturing, troubleshooting on network problems with Wireshark, identifying and fixing problems
- Configured and troubleshooting BGP, OSPF, EIGRP, WAN, QoS and Route Maps
- Configure BGP features such as as-override, Local pre, EBGP load sharing on client connections
- Configured and resolved various OSPF issues in an OSPF multi area environment between multiple branch routers.
- Configuring rules and Maintaining Palo Alto Firewalls & Analysis of firewall logs using various tools
- Configured and maintained IPSEC and SSL VPN's on Palo Alto Firewalls.
- Configuration and Administration of Palo Alto Networks Firewall to manage large scale Firewall deployments
- Upgraded load balancers from Radware to F5 BigIP v9 which improved functionality and scalability in the enterprise. Managed the F5 BigIP GTM/LTM appliances to include writing iRules, SSL offload and everyday task of creating WIP and VIPs.
- Deployment of datacenter LAN using Cisco Nexus 7k, 5k, 2k switches
- Providing technical security proposals, detailed RFP responses, security presentation, installing and configuring ASA firewalls, VPN networks and redesigning customer security architectures.
- Migrated to Juniper EX series switches from Cisco 3500 series and 6500 series switches
- Experience in working with cisco Nexus 5000 series switches for data center
- Experience working JuniperT-Series, M-Series, MX-Series, J-Series Routers
- Performed redistribution with OSPF, EIGRP to enable communication with backbone
- Troubleshoot connectivity issues involving VLAN's, OSPF, and QoS
- Configured VLANs with 802.1q tagging. Configured Trunk groups, ether channels, and Spanning tree for creating Access/distribution and core layer switching architecture
- Design and implement Catalyst/ASA Firewall Service Module for various LAN’s.
- Implemented, configured redundancy protocols HSRP, VRRP, GLBP for Default Gateway Redundancy
- ConfiguredJuniperMX480s, EX8200s, EX4500s, EX4200s, and SRX5800s from scratch to match design
- Managed the Cisco network infrastructure using Cisco Prime
- Supporting accounts on implementation and maintenance of DDI/IPAM Servers on various platforms
- Implementing Cisco VPN Solutions includingDMVPN
- Experienced with Juniper: EX-2200, EX-4200, EX-4500, MX-480 and M Series, SRX210 and SRX240
- Establishing VPN Tunnels using IPSec encryption standards andalso configuring and implementing site-to-site VPN, Remote VPN
- Executed several implementations ofCiscoCME and Unity Express
- Maintain Cisco Unified Customer Voice Portal
- Configured the Cisco ASR to use the VRF routing functions to completely split the traffic through the network.
- Worked on F5 BIG-IP LTM 8900, configured profiles, provided and ensured high availability
- Worked on F5 and CSM load balancers and multiple components for efficient performance
- Involved in Configuration of Access lists (ACL) on ASA firewall for the proper network routing for the B2B network
Confidential, Henderson, VA
Network Engineer
Responsibilities:
- Responsible for service request tickets generated by the helpdesk in all phases such as troubleshooting, maintenance, upgrades, patches and fixes with all around technical support.
- Design and configuring of OSPF, BGP on Juniper Routers and SRX Firewalls.
- Experienced with Juniper: EX-2200, EX-4200, EX-4500, MX-480 and M Series, SRX210 and SRX240.
- Performed redistribution with OSPF and EIGRP to enable communication with backbone.
- Involved in troubleshooting IP addressing issues and Updating IOS images using TFTP.
- Hands-on experience with WAN (ATM/Frame Relay), Routers, Switches, TCP/IP, Routing Protocols (BGP/OSPF)
- Experienced in WAN environments, installing and troubleshooting data circuits (OC, T1, E1, T3, and MUXES).
- Installed and configured ASA 5500 Firewall
- Experience with convert Checkpoint VPN rules over to the Cisco ASA solution
- Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5500 security appliance
- Upgraded load balancers from Radware to F5 BigIP v9 which improved functionality and scalability in the enterprise. Managed the F5 BigIP GTM/LTM appliances to include writing iRules, SSL offload and everyday task of creating WIP and VIPs
- Built an accruing network via MPLS circuits to split the trusted and un-trusted traffic via a Cisco ASR Router
- Actively involved in Switching technology Administration including creating and managing VLANS, Port security- 802.1x, Trucking 802.1Q, RPVST+, Inter-VLAN routing, and LAN security on Cisco Catalyst Switches 4507R+E, 6509-E and Cisco Nexus Switches 2232, 5596, 7009.
- Maintaining Checkpoint security policies including NAT, VPN and Secure Remote access
- Responsible for installation and administration of Checkpoint Firewalls
- Building site-site VPN connections for third party connectivity using ASAFirewalls.
- Experience in network monitoring tools like Net flow, RSA envision and Cisco IPS event viewer.
- Implementing traffic engineering on top of an existing Multiprotocol Label Switching (MPLS) network using Frame Relay and Open Shortest Path First (OSPF)
- Involved in design and implementation of Data Center Migration, worked on implementation strategies for the expansion of the MPLS VPN networks
- Configured Wireless Access Points in order to control them with RADIUS server
- Built site-to-site IPSec VPNs over Frame-relay & MPLS circuits on various models of Cisco routers to facilitate adding new business partners to new and existing infrastructures
- Involved in the team of Data Center Operations to perform duties like administration and deployment of Cisco Routers and Switches according to the organization requirements
- Worked with the data center planning groups, assisting with network capacity and high availability requirements.
- Configured VLAN's on Switches for Wireless Access Points
- Configured Access control list and also configured Cisco ACS for AAA services using Tacacs and Tacacs+.
- Responsible for the implementation and maintenance of firewall based security zones (DMZ*s).
- Provide support to internal project teams by adding firewalls, switches and routers to managed DMZs.
Confidential
Network Engineer
Responsibilities:
- Support Network Technicians as they require training & support for problem resolution including performing diagnostics, & configuring network devices.
- Configuring of IP Allocation and sub netting for all applications and servers and other needs throughout company using FLSM, VLSM addressing.
- Experience installing & configuring of Cisco PIX, ASA & FWSM (Firewall service module).
- Experience with convert PIX rules over to the Cisco ASA solution
- Worked on F5 Load Balancers, Cisco ASA 5540 Firewalls
- Involved in the configuration & troubleshooting of routing protocols: BGP, OSPF, EIGRP and RIP.
- Tuned BGP internal and external peers with manipulation of attributes such as metric, origin and local Preference.
- Supporting EIGRP and BGP based on the network by resolving level 2 & 3 problems of internal teams & external customers of all locations.
- Performing troubleshooting on slow network connectivity issues, routing issues that involves OSPF, BGP and identifying the root cause of the issues.
- Experience in WAN connectivity using Cisco routers by using T1, T3 and frame relay connections and its troubleshooting issues.
- Design and implementation of the LAN IP infrastructure using Layer 2 / Layer 3 switching, STP, Gigabit Ethernet and Trunking / channeling technologies.
- Responsible for maintenance and utilization of VLANs, Spanning-tree, HSRP, VTP of the switched multi-layer backbone with catalyst switches.
Confidential
Network Technician
Responsibilities:
- Experience in Cisco switches and routers: Physical cabling, IP addressing, Wide AreaNetwork configurations.
- Managed IP addressing and implemented IP Access Lists.
- Documented the design, implementation and troubleshooting procedures.
- Involved in network monitoring, alarm notification and acknowledgement.
- Performed switching technology administration including VLANs, inter-VLAN routing, Trunking, STP, RSTP, port aggregation & link negotiation.
- Maintained complex LAN/WAN networks with several VLANS and provided support for routing protocols.
- Maintaining Network Integrity on LAN and WAN Networks.
- Configuring and Troubleshooting Routing protocols OSPF, RIP, EIGRP & BGP.
- Have sound knowledge of Firewall architecture, routing and VPN.
- Installed and configured the ACE and CSM for firewall/Server Load balancing for Cisco Catalyst switches.