Ali Shahriari
**************@*****.*** Cell: 202-***-****
Professional Summary
Highly motivated network engineer with years of experience in an ever-changing telecommunication field., network design, network integration, network operations and network management experience. Creating evaluation test plans with customers, managing the evaluation process, implementation and reporting to a successful handover. Provided hands on technical support small to large international corporations as well as state and federal agencies’ networks through the analysis, design, integration, implementation, and maintenance of complex network solution. Knowledge of Encryption technologies and equipment’s. Worked on satellite communication networks. Working knowledge of SIEM technology and cybersecurity tools (IPS, AV, Firewall, Netflow, etc.).
SPECIAL TECHNICAL SKILLS
Local area network (LAN) and Wide area network (WAN) architecture design and deployment
LAN and WAN Interworking including VoIP, Broadband, IP, routers, switches and firewalls system installation, implementation, configuration, management administration and field maintenance and user support.
Experience in data communications and Internet protocols testing with Knowledge of TCP/IP, RIP, OSPF, BGP and other routing protocols
Write test planes, white papers and application notes to assist network deployment, operations and management
Hands-on Experience with firewalls and network security, Cisco ASA/ACS, Palo Alto, Juniper and SonicWall
Experience Installing and supporting Microsoft and Linux server technologies.
Experience with access switches, aggregation switches, Catalyst, HP and Cisco virtual switches
Analysis of network protocols at the physical, logical, transport and session layers.
U.S. Government encryption devices (KG and KIV).
Provide customized hands-on technical training.
PROFESSIONAL EXPERIENCE
OFFICE OF THE SURGEON GENERAL OF THE ARMY, DEPARTMENT 2017 – 2021
Design, setup and configure complex switching environments; assist in the design of multi-server environments including IP address, schemes, DNS, WINS, Ether-Channel (Bonding)
Resolve incidents, problems, and change requests in accordance with service-level agreements (SLA’s) and approved maintenance windows
Monitor ticket queues during normal business hours
Participate in an after-hours and holiday on-call rotation with other network technicians
Explain and discuss technical issues with customers in face-to-face meetings and conference calls; including regularly scheduled customer update calls and architecture reviews
Proactively identify customer problems and future needs
Collaborate on design and implement network and security solutions
Work with higher-level engineers to design network and security solutions
Install and configure hardware and software according to design specifications
Test and troubleshoot new installations
Produce and maintain documentation
Work with standard, portable document formats (PNG, PDF, etc.)
Develop professional diagrams and illustrations with software such as Visio, and Dia
Supplement existing documentation to reflect all new changes to an environment
Correct errors and deficiencies & continuously expand product proficiency/product diversity
Adopt a vendor-agnostic approach to problem solving; find and use the right product or combination of products for the customer
Test new products and features in a lab environment
Work closely and collaborate with higher and lower level technicians and engineers
Daily "hands on" engineering, Palo Alto and ASA firewalls lifecycle, upgrade, Rules, VPNs, and troubleshooting the issues.
Configured and setup Cisco Firewalls, VPN Concentrators and Security appliances for access to vital business applications
Maintained functionality, security, and integrity of internal IT systems to help support this effort.
Daily monitor traffic management A10 and 1PCS F5 for load balancing and traffic optimization
Configuration and troubleshooting of routing protocols: OSPF, BGP, EIGRP and static routing
Identify Network Vulnerabilities and apply patches
Configuration of VLAN: STP, switch port access, 802.1q, ISL trucking
Linux system administration skills
Daily troubleshooting of Network Access Control (NAC), IP Management, DNS/DHCP Appliances
Utilize and configure: SSH, Telnet, SNMP
Management, tracking and resolution tickets in Remedy
Knowledge of packet capturing utilization Cisco devices and third-party software
INFORMATION & INFRASTRUCTURE TECHNOLOGIES, INC 2012 – March, 2017
Senior Network Engineer
Make recommendation for changes to architecture/networks functions and services
Conduct research, evaluate, and make recommendations on emerging technology.
Engineered, architected, implemented, deployed, maintained, and administered commercial and open-source products
Installed, Wired and Configured Switches, Vlans and Trunk ports, Routers, Firewalls and Servers.
Operate in a dynamic environment with multiple clients, troubleshooting their network and security issues
Daily "hands on" engineering, ASA firewalls lifecycle, upgrade, Rules, VPNs and troubleshooting the issues.
Configured Site to Site and remote Cisco ASA AnyConnect Remote Access VPNs
Maintained functionality, security, and integrity of internal IT systems to help support this effort.
Installed, and upgrade computer hardware and operating systems (Windows, and LINUX) in an enterprise environment.
Reviews, and interprets Federal guidelines and policies, and industry standard best practices.
Set up VoIP phone system
Provides subject matter expertise, support, leadership, and training.
Set up and maintained video surveillance systems for secure labs.
Analysis packet level traffic for forensic analysis and reporting
Part of a team engaged in incident response with a multinational organization providing 24/7 Security Operations Center support. Tools utilized for this effort: Splunk McAfee ESM & EPO, Tanium, FireEye, SourceFire, Exabeam, Palo Alto, SolarWind, SealthWath, Incapsula, Qualys, and FireSight
Communicate alerts with customers & work directly with clients to resolve incidents
Performs systems vulnerability assessments, utilizing Nessus and other system security tools, for compliance and risk management.
ALCATEL-LUCENT 1995 – 2012
Pre-Sales Security Architect :( LGS BELL LABS INNOVATIONS) 2005 - 2012
Provided onsite support for standalone deployment of CDMA/GSM/WiMAX network for both voice and date for US Army. Design, configure, and deployed NNM(Navis) Femtocell Access Point and the backhaul network (A LU equipment, 7750/7705, Cisco, Ciena, Juniper, Foundry) switches and routers, over CDMA/GSM/WiMAX voice and data over Army’s private WAN network
Provide network architecture design of LAN, WAN and NNM (A LU equipment 77xx for DREN’s RFP response
Designed installed, configured, managed and administrated NNM for both local and wide area networks for LGS Bell Labs R&D.
Provided support to Defense Information Systems Agency (DISA) in their migration effort from TDM, ATM, and IP devices to IP/MPLS based transport of their Local/ Wide area networks and upgrade NNM.
Provide consulting support to Alcatel-Lucent Government Solution customers (SAIC, Navy/SPAWAR, DISA, Raytheon and Northrop Grumman)
Provide expertise in systems integration/interoperability, implementation of the Northwest Standard Tactical Entry Point (STEP) site. Added interfaces into its test network, commonly used by Joint Task Force (JTF) war fighters on the battlefield today via GIG-Be project
Authored application notes and test plans for Edge devices for their ability to provide data services, as well as requirements for existing and future networks that provide access to the Department of Defense’s (DoD) Defense Information Systems Network (DISN), Defense Switched Network (DSN), Non-Secure Internet Protocol Router Network (NIPRNET), and Secure Internet Network (SIPRNET).
Provide consulting for design and implementation of NAVY/SPAWAR High Speed Global Ring HSGR
Serve as principal technical marketing resource for sales effort with DISA. Deployment of Pilot Network and provided technical expertise for the Lucent ATM switches used for the test. The assessment combined resources of the Federated Battle Lab and the DICE-00 backbone into an integrated network supporting interconnected switches, routers, and video equipment
Authored application note for Government Agencies to successfully implement secure networks using KIV and KG encryption devices across multiple vendors (e.g. Lucent, Cisco, and Marconi) equipment.
Technical Marketing Senior Systems Engineer, 2000 – 2005
Responsible for Lucent ATM Switches pre-sales support. Maintain laboratory and laboratory equipment for testing and technology demonstrations. Configure and test customer network applications. Document customer requirements and interact with product development teams to ascertain course of action. Research and author product application notes. Prepare responses to customer RFPs / RFIs. Work with ILECs, CLECs, and ISPs presenting, designing and implementing data and voice networks.
Principal technical marketing resource for sales efforts with U.S. Government, Australian, and Indian military.
Implemented product configuration tool enhancing accuracy and speed of sales teams to place orders.
Provide System Engineering support to customer teams. Assist with the resolution of technical issues and queries associated with pre-sales technical support. Review network architecture and test plans proposed for evaluation and deployment. Authored application notes to facilitate, coordinate, and execute during customer testing. Provide international and domestic trade shows support. Coordinate and execute demonstrations in support of marketing and sales efforts. (Supercom, TechNet, and Cebit)
Principal technical marketing resource for Nextel Communication for provisioning the proposed backhaul architecture to support lucent 1xEV-DO, Flarion 4G, and Motorola iDEN traffic. Investigate feasibility of alternate solutions such as HDLC over IP and HDLC over Ethernet. (Sterling, VA)
Sales Engineer, Herndon, VA 1998 – 2000
Provided technical sales support including authoring RFIs and RFPs for Lucent ATM Access Concentrator switches to U.S. and foreign government organizations. Developed strategic relationships with customers and long-term projects resulting in multiple, multi-million-dollar sales contracts.
YURIE SYSTEMS, (AT&T Government Solution Contracts) Landover, MD 1995 – 1998
Network Engineer
Led multi-million-dollar project producing and configuring equipment racks for new Internet Service Provider network. Managed procurement, material management, production, equipment configuration, and testing of completed equipment racks. Supervised engineers, technicians and associated support staff.
Member of engineering team on multi-million-dollar effort to develop and implement an ATM satellite broadcast in association with the DoD Global Broadcast Services (GBS) and Joint Broadcast Services (JBS). Integrated associated data, video and audio software applications for over 40 ATM switches.
Principal engineer for demonstrations of ATM capabilities between terrestrial and airborne network nodes. Responsible for network architecture, systems integration, and installation. Integration includes Yurie (PSAXs), CISCO routers, FORE (Marconi) ATM Switches, U.S. Government encryption devices (KG and KIV), CSU/DSU, SINCGARS, LST, CYLINK radios and satellites modems verity of communication software packages such as HPOV HP Openview and SunNet Manager for network management.
Deployed an ATM video-conferencing network in a military tactical environment (interfaced with terrestrial microwave, tactical radio, and satellite networks) in support of U.S. Army operations.
Created and developed training presentation materials and implementing technical training for System Engineers, U.S. Government technical organizations such as CECOM.
EDUCATION
BS, Electrical Engineering, University of Maryland
PROFESSIONAL AWARDS
U.S. Army Intelligence and Security Command (INSCOM) Recognition Award
Department of the Air Force and Lockheed Martin Recognition Awards
AT&T/Lucent NGN Award
Yurie Systems, Inc. PRE–IPO MEMBER Award
CERTIFICATION
Department of the Army Certificate of Annual DoD Cyber Awareness Challenge Exam (V 5. 0)
JKO Antiterrorism Awareness Training
OPSEC Awareness for Military and Members, DoD Employees and Contractor
OPSEC_CCNP April 2018
DHA Remedy: Incident Management
U.S. ARMY Security Education, Training & Awareness
HIPAA and Privacy Act Training
AKO Army knowledge Online
Code of Conduct
Cyber Security Training
CIO/G-6 NETCOM IA-200-125 – Interconnecting Cisco Networking Devices
Ip_ NETCOM IA-200-125 – Interconnecting Cisco Networking Devices
Army e. Learning: Certificates of Completion
Components Supporting Organization Security
Frameworks Guidelines and Physical Security
ICND1 3.0: Introduction to Networking
ICND1 3.0: Discovering Ethernet and Troublesh
ICND1 3.0: Managing Switches and routers
ICND1 3.0: Working with spanning Tree and FIR
ICND1 3.0: Security Management Access on an IOS Devices
ICND1 3.0: Understanding Host-To-Host Communi
ICND2 3.0: Mitigating threats, Introducing SD
ICND1 3.0: Mastering IPV4 Addressing and subn
ICND1 3.0: The Internet, Transport and APPL1
ICND1 3.0: VLANs Trucking and Inter Vlan Routing – cc_icnd_a10_it_enus
ICND1 3.0: Implementing DHCP and RIPV2
ICND2 3.0: Introducing IPV6
ICND2 3.0: Troubleshooting IPV6 Networks
ICND2 3.0: Configuring and Verifying OSPFV2
ICND2 3.0: Configuring and Verifying EIGRP FOR IPV4/IPV6
ICND2 3.0: Introducing Dynamic Routing Protocol
ICND2 3.0: Troubleshooting EIGRP FOR IPV4/IPV6
ICND2 3.0: Wide Area Networks using PPP, GRE
ICND2 3.0: Introducing and Troubleshooting VLANs
ICND1 3.0: Implementing Port Security and MAN
ICND1 3.0: IPV4 Access control Lists– cc_icnd_a8_it_enus
ICND1 3.0: IPV4 Private to Public Network ADD
ICND1 3.0: Discovering Cisco IOS Routers
Cryptography
Penetration Testing and Vulnerability Scannin
Microsoft Windows 10 first look: Interface and New Features
Microsoft Windows 10 first look: Configuration
Common Account Management Practice
Identity and Access Management Controls
Wireless Security Settings
Cryptography and Wireless Attacks
Public Key Infrastructure
Impacts from Vulnerability Types
Security Assessment Using Software Tools
Implement Secure Network Architecture Concept