HARSHITHA S
NETWORK ENGINEER
+1-254-***-**** *************@*****.*** LinkedIn
PROFESSIONAL SUMMARY
Highly motivated and results-driven Network Engineer with 7+ years of experience in IP network design, integration, deployment, and troubleshooting across enterprise, data center, and multi-cloud environments.
Specialist in deploying and managing Arista solutions, including EVPN-VXLAN fabrics, L2LS/L3LS architectures, CVaaS for large-scale enterprise and service provider networks.
Skilled in network protocols (OSPF, EIGRP, BGP, MPLS), VLANs, STP, QoS, and enterprise WLAN (Cisco Wireless LAN controllers and access points).
Expertise in implementing advanced Cisco SD-WAN (Viptela, Versa, Silver Peak) solutions and Cisco ACI fabric for data center modernization.
Experienced with SDN architectures, including Cisco ACI APIC policy modeling, OpenFlow controllers, and network virtualization overlays for multi-tenant data center segmentation.
Hands-on expertise in multi-vendor security and connectivity platforms including Fortinet FortiGate, Cisco ASA/FTD, Palo Alto, Cisco ISE, Juniper, and Arista within large-scale enterprise environments.
Specialized in F5 BIG-IP LTM/GTM with experience in BGP-advertised VIPs, iRules, SSL omoad, and multi-tier application traffic steering across hybrid cloud environments
Expert in securing large-scale AWS environments using Security Groups, NACLs, AWS Network Firewall, AWS WAF, VPC peering, Transit Gateway, PrivateLink, and centralized egress architectures.
Proficient in implementing ExpressRoute, configuring VNets, Network Security Groups (NSGs), and Azure VPN Gateway to enable scalable, secure hybrid cloud architecture.
Proficient in implementing GCP network architectures, including VPC design, Cloud Router, Cloud VPN, Cloud Interconnect, Shared VPC, VPC peering, firewall rules, Cloud NAT, Cloud Armor, and Identity-Aware Proxy (IAP).
Deep ITIL expertise in change/incident/problem management, RCA, MoPs, rollback procedures, and compliance workflows for enterprise network transformations.
Conducted Nmap/Nessus vulnerability assessments across 200+ devices, delivering remediation reports and implementing security hardening for compliance.
Experienced in supporting hybrid infrastructure services, hardware, OS (Windows Server, Linux), both network and software platforms in high-availability cluster environments.
Strong Infrastructure as Code background using Terraform and CloudFormation to provision VPCs, subnets, route tables, Security Groups, Network ACLs, Gateway/Interface Endpoints, and AWS WAF/Web ACL policies.
Adept at managing advanced load balancing solutions, including F5 BIG-IP (LTM, GTM, iRules, ASM) and Citrix NetScaler ADC.
Skilled in Splunk Enterprise Security and SolarWinds NPM/IPAM for centralized syslog correlation, NetFlow analysis, capacity planning, and real-time security event monitoring.
Proficient in network automation using Python, Ansible, and REST APIs for firewall policy validation, compliance checks, and operational reporting.
In-depth knowledge of routing protocols, including BGP (path manipulation, RPKI, BFD), OSPF (multi-area design, NSSA), EIGRP, across enterprise and data center environments.
Skilled in wireless network design and management using Cisco WLCs (Catalyst 9800), Aruba Mobility Controllers, and Cisco Meraki, including Ekahau site surveys.
TECHNICAL SKILLS
Network Architecture
& Design
Enterprise LAN/WAN Architecture, SD-WAN, Multi-Site Network Design, TCP/IP
(IPv4/IPv6), VPN (IPsec, SSL, DMVPN)
Data Center &
Switching
EVPN/VXLAN Fabric Design, BGP-EVPN, VLAN (802.1Q), STP (RSTP/PVST+/MSTP),
EtherChannel (LACP/PAgP), Layer 2/3 Data Center Architecture
Advanced Routing
Protocols
BGP (eBGP/iBGP, Route Manipulation, Traffic Engineering), OSPF (Multi-Area), EIGRP, IS-
IS, Multicast (PIM, IGMP), MPLS
Cloud & Hybrid
Infrastructure
VPC, Subnets, Transit Gateway, PrivateLink, VPC Peering, Route 53, CloudWatch,
ALB/NLB, AWS Network Firewall, AWS WAF, Azure (Virtual Network, ExpressRoute)
Network Automation
& DevOps
Python, Ansible Playbooks, Terraform (IaC), CloudFormation, REST/RESTCONF APIs,
Git/CI-CD, CloudVision/AVD
Enterprise Hardware
Platforms
Cisco ISR/ASR/Catalyst 8K-9K/Nexus 2K-9K, Arista 7000 Series, Juniper MX/M/T/EX/QFX
Series
Enterprise Security &
Zero Trust
Next-Gen Firewalls (Palo Alto PA-5440/7080, Cisco Firepower, Fortinet, Checkpoint), NAC
(Cisco ISE, 802.1X), Zero Trust Architecture, SASE (Zscaler)
Application Delivery
& Load Balancing
F5 LTM/GTM (TMOS), Global/Local Load Balancing, Health Monitoring, SSL Omoad, High
Availability
Network Monitoring
& Analytics
Packet Analysis (Wireshark, PCAP), Network Monitoring (SolarWinds, Nagios), Log
Analytics (Splunk, SIEM), IPAM (Infoblox DDI), Telemetry (NetFlow, sFlow)
Network & Server
Operating Systems
Cisco (IOS, IOS-XE, IOS-XR, NX-OS), Arista EOS, Juniper Junos, PAN-OS, FortiOS, Linux
(Shell Scripting), Windows Server
PROFESSIONAL EXPERIENCE
POPULUS FINANCIAL GROUP
Network Security Engineer Remote February 2026 - Current
Supported a fleet of 45+ FortiGate 600E and 1500D NGFWs, maintaining firewall policies, NAT, IPS, SSL inspection, and security profiles across production and disaster recovery environments.
Managed centralized firewall administration through FortiManager for 45+ FortiGate appliances, deploying policy packages, maintaining shared objects, configuration revisions, and device groups across multiple environments.
Utilized FortiAnalyzer to monitor firewall events, VPN activity, IPS detections, and traffic trends, supporting incident investigations and policy validation across enterprise security infrastructure.
Completed the migration of 1,500+ firewall policies, 3,000+ network objects, and 75+ IPSec VPN tunnels, validating routing, object dependencies, and application communication before production cutover.
Brought new branch locations onto the enterprise Fortinet SD-WAN fabric by configuring WAN members, SLA policies, application-aware traffic steering, and automated failover across MPLS and broadband circuits.
Built and maintained 75+ site-to-site IPSec VPN tunnels connecting branch offices, third-party partners, and cloud-hosted applications using IKEv2, AES-256 encryption, and dynamic routing with BGP and OSPF.
Supported enterprise LAN/WAN infrastructure by maintaining Cisco Catalyst, Nexus, FortiGate, and FortiSwitch platforms, performing VLAN provisioning, trunk configuration, Layer 2/Layer 3 troubleshooting, and routing updates.
Maintained dynamic routing by updating BGP peerings, OSPF adjacencies, route maps, prefix lists, static routes, and VRFs, ensuring reliable traffic flow during network expansion and infrastructure changes.
Investigated VPN negotiation failures, asymmetric routing, NAT translation issues, MTU mismatches, interface errors, and application connectivity problems using FortiOS CLI, packet captures, Wireshark, and routing diagnostics.
Tuned firewall rule sets by removing obsolete policies, consolidating duplicate objects, optimizing NAT translations, and refining rule placement to improve policy management while maintaining PCI DSS compliance.
Managed F5 BIG-IP LTM virtual servers, pools, health monitors, persistence profiles, SNAT configurations, SSL profiles, and load-balancing methods supporting highly available enterprise applications.
Performed SSL certificate renewals across 150+ F5 BIG-IP virtual servers, validating application availability after deployment and coordinating production cutovers with infrastructure and application teams.
Automated firewall deployment activities using Python, Jinja2, REST APIs, and PowerShell, generating standardized FortiOS configurations and reducing manual effort during large-scale policy migrations.
Maintained FortiGate High Availability (HA) clusters by performing firmware upgrades, failover validation, configuration synchronization, and post-maintenance health checks to ensure uninterrupted service.
Monitored network performance using FortiAnalyzer, SolarWinds, SNMP, Syslog, and interface statistics, proactively identifying circuit degradation, bandwidth utilization, and device health issues.
Assisted with firewall integrations for AWS and Azure environments by implementing VPN connectivity, updating security policies, and validating hybrid network communication for cloud-hosted applications.
Integrated firewall policies with Active Directory security groups and enterprise authentication services, enforcing role-based access controls for remote users and internal business applications.
Supported vulnerability remediation by implementing vendor-recommended security updates, IPS signature enhancements, URL filtering policies, and firewall hardening based on security assessment findings.
Participated in switch deployment and refresh projects involving Cisco Catalyst 9000, Nexus 9000, and FortiSwitch platforms, validating configurations, interface assignments, and production readiness.
Installed replacement firewall hardware, completed interface migrations, verified HA synchronization, and performed post-implementation testing during scheduled maintenance windows.
Supported IPAM operations by managing IPv4 address space, subnet allocations, VLAN-to-network mappings, DHCP ranges, and IP utilization tracking to improve address management and reduce duplicate assignments.
Coordinated DNS changes for new applications and infrastructure deployments by creating A, CNAME, PTR, MX, and TXT records while validating name resolution across internal and external environments.
Integrated DDI platforms with network security and infrastructure services by aligning DNS/DHCP configurations with firewall policies, Active Directory environments, and enterprise authentication requirements.
Assisted with Infoblox Grid member deployments and upgrades, validating DNS/DHCP service availability, database synchronization, and failover functionality across distributed network environments.
Validated wireless deployments using Ekahau for RF surveys, optimizing AP placement and channel plans, and integrated Aruba APs with ISE/ClearPass for secure BYOD and guest access.
Managed 30+ production change requests following ITIL change management practices, preparing implementation plans, validating rollback procedures, and completing post-change verification for production environments.
Produced firewall standards, migration runbooks, network diagrams, implementation procedures, and operational documentation to improve deployment consistency and support knowledge sharing across engineering teams.
ARISTA NETWORKS
Professional Services Network Engineer September 2024 – January 2026
Deployed brownfield migration from Cisco Nexus 7K/5K/9K, Juniper MX/QFX to Arista 7280/7050 EVPN- VXLAN fabric, validating routing parity, STP/VLAN standardization for 200+ devices.
Configured BGP routing with eBGP peering between spines and leafs using /31 point-to-point links, implementing EVPN address-family with send-community extended for Type-2/5 route propagation.
Implemented MLAG leaf pairs, VXLAN head-end flooding, Type-2/5 EVPN, BGP route-reflector architecture, and BFD-based underlay for fast convergence and workload mobility.
Configured OSPF multi-area design with Area 0 backbone for underlay routing, implementing NSSA areas for external route filtering and BFD for sub-second failure detection.
Standardized RSTP/MSTP, VLANs, trunks, and MTU (underlay 9214, overlay 9100) to prevent fragmentation and reduce spanning-tree complexity across DC and campus.
Implemented MLAG across 60+ leaf pairs with active-active redundancy, configuring peer-link on Port-Channel interfaces with VLAN trunk via management VRF heartbeat.
Integrated Cisco Nexus 9k aggregation and SD-WAN Viptela with Arista 7500E border leafs via eBGP, redistributing 1,200+ routes to 250 branch edge routers over dual 100GbE uplinks.
Deployed Versa and Silver Peak SD-WAN elements for key sites, with application-aware routing and policy- based steering, reducing MPLS-based traffic by up to 40%.
Configured CVP Studios for automated compliance checks (TACACS+, NTP, ACL audits) and ZTP DHCP relay/option 67 infrastructure for mass device provisioning.
Integrated Palo Alto PA-5250 firewalls with Arista 7010T leafs using eBGP and BFD (300ms interval, 3 multiplier) to provide sub-second failover across 18 DMZ VRFs.
Configured Check Point R80.30/R80.40 multi-domain firewall environments spanning corporate headquarters, enforcing consistent threat prevention profiles, NAT policies, and access control rules across geographically distributed networks.
Migrated 10,000+ firewall rules, NATs, and routes from Cisco ASA to Palo Alto, including IPsec tunnels, ACLs, NAT, and policies, with 50% fewer overlapping rules.
Implemented Cisco Firepower FTD 2100 with Arista border leafs, enabling IPS/malware analysis integrated with ISE for threat prevention.
Implemented Zscaler ZIA, ZPA, and AAA for 5,000+ remote users, using GRE-based and IPsec-based traffic forwarding, Azure AD integration, and ZCC-based tunneling.
Deployed Cisco ISE 3.1 and Aruba ClearPass 6.10 as NAC platforms on Arista 7020SR/7048T, enabling 802.1X, MAB, dynamic VLAN assignment, dACLs, RADIUS CoA for 3,500+ wired, wireless, VPN endpoints.
Integrated F5 BIG-IP and Citrix NetScaler ADC clusters with LACP, BGP - VIPs on Arista leafs, SSL-offloading, and iRule-based traffic steering, tied to firewalls via PBR + DSCP marking.
Deployed Riverbed WAN optimization, BlueCoat proxies where required, ensuring consistent performance and content inspection while coexisting with SD-WAN and DC-edge designs.
Implemented VMware NSX-T overlay with Arista EVPN underlay, enabling micro-segmentation and distributed firewalling for virtualized workloads.
Developed Python and Ansible automation for firewall policy changes, DNS/DHCP updates, and configuration validation on Arista fabric, reducing manual effort by 30–50%.
Engineered hybrid connectivity using AWS Direct Connect 10Gbps on Arista 7150S, Azure ExpressRoute on Arista 7060CX, GCP VPN, advertising 45 on-prem subnets via BGP to Transit Gateway, Azure VNets, and GCP Cloud Routers.
Implemented DNS and DHCP with BlueCat, including anycast-based eBGP-advertised DNS services, split-horizon policies, and VRF-based DNS views for multi-tenant environments.
Configured Cisco ISE 3.1 and Aruba ClearPass 6.10 with Arista 7048T using TACACS+ and RADIUS, implementing 50+ IoT profiling policies with automated VLAN assignment.
AUSTIN ENERGY
Network Engineer August 2023 - August 2024
Led Cisco SD-WAN (vManage 20.12/21.3) rollout across 250+ utility substations using ISR 4451 and Catalyst 8200 routers, replacing T1/MPLS with DIA to cut WAN costs by 40%.
Optimized Viptela Application-Aware Routing (AAR) with BFD 50ms timers, dynamic QoS (LLQ 30%, CBWFQ), and route maps for SLA-aware path selection, prioritizing SCADA, AMI metering, and outage management traffic.
Integrated Zscaler ZIA with SD-WAN DIA breakouts at 50+ remote sites, configuring cloud SWG policies and PAC files for secure utility worker internet access.
Managed and ensured high availability for vManage, vSmart, and vBond controllers (v20), including certificate management and disaster recovery protocols for the SD-WAN fabric.
Configured virtual networking in lab environments with Catalyst 9000, Juniper MX routers, Arista 7000 switches, deploying BGP, OSPF, and VLANs to mirror production EVPN-VXLAN topologies.
Installed Cisco ACI (APIC version 5.x/6.x) in dual multi-POD data centers, using Cisco Nexus 9k switches as spines and leafs, completing fabric bring-up, APIC cluster formation, VMware NSX integration for container networking.
Integrated and validated Cisco ACI L3Outs using OSPF (Area 0, NSSA) and BGP (iBGP/eBGP with AS path prepending, MED tuning) for resilient external and shared services connectivity.
Supported developer testing with Cisco Nexus 9000 ACI integration and VMware vCenter VMM for VM-aware network policies.
Delivered escalated tier support internally and with vendors, resolving complex Layer 2/3 network issues across multi-vendor environments.
Applied end-to-end QoS with LLQ for VoIP (CUCM 14.1), video surveillance, and SCADA using DSCP EF/AF41 markings across SD-WAN fabric, Catalyst LAN, and WLAN controllers.
Delivered L2/L3 lab validation using Wireshark 4.2, IOS-XE 17.12 debugs, and Junos 22.4 CLI, resolving MTU mismatches and BGP dampening issues pre-production.
Installed, upgraded, and maintained Palo Alto Networks PA-5200/PA-7000 series firewalls (PAN-OS 10.2/11.0) in active/passive HA pairs at data center perimeters and internet edges.
Developed granular security policies on Palo Alto firewalls utilizing App-ID, User-ID, Content-ID, and advanced Threat Prevention (WildFire, DNS Security, Anti-Spyware).
Implemented GlobalProtect VPN (v5.x/6.x) with Okta SAML 2.0 MFA and HIP endpoint compliance checks for BYOD access serving 10K+ field technicians accessing CIS/CSC applications.
Acted as Load Balancing SME for enterprise applications, providing architecture design, platform upgrades, and advanced troubleshooting across F5 BIG-IP, Citrix NetScaler, and Infoblox/BlueCat DDI platforms, ensuring resiliency and HA for mission-critical services.
Utilized SolarWinds Orion Suite (NPM, NCM, NTA, UDT v2023.x) for comprehensive monitoring, configuration compliance, and flow analysis of 5000+ network devices.
Created 30+ Ansible playbooks and roles for automating repetitive network configurations, device provisioning (Cisco, Palo Alto, F5), and policy deployments across hybrid environments.
Provisioned resilient AWS multi-account networks using Terraform, building VPCs, Transit Gateway attachments, Security Groups, NACLs, AWS Network Firewall policies, and ALB/NLB configurations.
Configured secure Azure VNet hub-spoke architectures using Terraform, including UDRs, NSGs, Azure Firewall, Application Gateway, and ExpressRoute.
Integrated and managed Juniper MX Series routers and SRX firewalls with MPLS L3VPN for secure extranet peering within the hybrid cloud architecture.
Generated IP utilization reports and performed address audits through Infoblox IPAM and BlueCat BAM, improving visibility into available address space and subnet consumption.
Managed Cisco Meraki MX security appliances, MS switches for rapid deployment in small office/pop-up retail locations, integrating them into corporate WAN via SD-WAN tunnels.
OPTUM
Network Engineer Dallas, TX May 2022 - April 2023
Migrated brownfield campus infrastructure for the hospital system, migrating legacy Cisco switches to Catalyst 9300/9400 Series (IOS-XE 17.3/17.6), enhancing performance, enabling DNAC integration for scaling.
Segmented departmental traffic using VLANs (Clinical, Admin, Guest, IoT) with QoS policies prioritizing PACS radiology (COS 5), EMR (COS 4), telemetry traffic while ensuring HIPAA-compliant traffic isolation.
Optimized internal routing using OSPF (multi-area design) across the extensive hospital campus network for efficient and resilient L3 connectivity.
Managed BGP routing for external connectivity and disaster recovery, implementing route filtering and path selection policies on edge routers.
Deployed Palo Alto Networks PA-3200 series firewalls (PAN-OS 10.1/10.2) for securing critical data center segments, implementing application-based security policies and User-ID for granular access control.
Configured Cisco ASA 5516-X firewalls (ASA v9.12+) for perimeter security, including granular ACL implementation and managing software updates to ensure security compliance.
Configured secure site-to-site IPsec VPNs (IKEv2, AES-256) on Cisco ASA and PA-220 firewalls to connect the main hospital campus with remote clinics and partner facilities.
Leveraged Cisco DNA Center (DNAC v2.x/v2.4) for network assurance, monitoring health of Catalyst 9k switches, employing its analytics capabilities for troubleshooting network issues.
Designed and implemented DMVPN (Phase 2/3 using NHRP, IPsec, EIGRP) solutions for secure and scalable connectivity to a cluster of newly acquired outpatient facilities.
Administered Symantec Blue Coat ProxySG appliances for secure web gateway solutions, configuring web filtering and SSL inspection policies to protect against web-based threats.
Managed F5 BIG-IP LTM (15.1.1) load balancing PACS, Epic EMR, and Cerner applications, creating health monitors, iRules, and SSL offloading for 99.99% application availability.
Administered Infoblox NIOS 8.6/9.0 appliances supporting 15K+ DHCP leases across multi-DC environment, implementing DNSSEC and extensible attributes for device tracking.
Configured Cisco Catalyst 8000 Edge SD-WAN (vManage 20.6) pilot for 5 remote clinics, defining centralized data/voice policies and application-aware routing.
Migrated legacy ASA firewalls to Cisco Meraki MX appliances using Meraki Dashboard APIs for automated template-based provisioning and zero-touch branch deployment.
Deployed Silver Peak Unity EdgeConnect SD-WAN across 30+ clinics, implementing dynamic path selection and WAN optimization for Epic MyChart patient portal traffic.
Contributed to Cisco ACI L3Out configurations with OSPF route leaking to integrate new data center fabric with existing Catalyst core, maintaining IP subnet continuity.
Collaborated with healthcare IT teams and cloud architects to design secure, scalable hybrid cloud networks integrating AWS Transit Gateway, Azure ExpressRoute, and GCP Cloud VPN, ensuring compliance with HIPAA and healthcare regulatory frameworks.
Developed Python automation to query AWS APIs for Security Group audits, unused rules cleanup, and AWS WAF configuration validation as part of security compliance checks.
Led implementation of VPC/VNet connectivity, using BGP route reflectors, NAT gateways, PrivateLink for secure, low-latency access between clinical applications and cloud services.
Supported Cisco ISE for 802.1X NAC deployments with EAP-TLS and PEAP authentication, integrating posture assessments and guest onboarding policies.
Automated routine network tasks, such as configuration backups and compliance reporting for Cisco IOS/NX- OS devices, using Python scripts leveraging Netmiko and Paramiko.
Utilized Ansible for automating the deployment of standardized configurations across groups of Cisco switches and Juniper EX4300/EX4600 series switches.
Leveraged Terraform for defining and provisioning network infrastructure components in a lab environment for testing cloud connectivity models.
Implemented Aruba ClearPass Policy Manager (CPPM 6.10) for 802.1X NAC, BYOD onboarding, and ensuring HIPAA compliance for wireless network access.
Managed DNS, DHCP, and IPAM services using Infoblox (Blue Cat) Trinzic DDI (NIOS 8.x/9.x), ensuring reliable IP addressing and name resolution for thousands of medical endpoints.
Managed network incidents and configuration changes via the ServiceNow ticketing system, prioritizing SLA adherence in a fast-paced environment.
Utilized Splunk Enterprise for centralized log management and analysis of network device logs (firewalls, routers, switches), creating dashboards for security event monitoring.
SYNTEL
Network Engineer India June 2018 - June 2021
Participated in campus LAN redesign projects for SME clients, focusing on implementing L2/L3 architectures using Cisco Catalyst 2960, 3750, and 3850 series switches.
Configured and verified OSPF and EIGRP routing protocols on Cisco routers under the guidance of senior engineers for small to medium-sized client networks.
Deployed and troubleshot Cisco Catalyst switches, implementing VTP (client/server modes), STP (RSTP, PVST+), and EtherChannel (LACP/PAgP).
Configured First-Hop Redundancy Protocols (HSRP, GLBP) on distribution layer switches to ensure default gateway availability.
Provided daily operational support for Cisco ASA 5505/5510 firewalls, managing ACLs for inter-VLAN and internet access, and configuring NAT/PAT as per senior engineer instructions.
Assisted in troubleshooting basic site-to-site IPsec VPN connectivity issues on Cisco ASA firewalls, escalating complex issues when necessary.
Performed L2/L3 troubleshooting of network connectivity, performance issues using tools such as Wireshark for basic packet analysis, Ping, Traceroute, and detailed switch/router CLI diagnostics, resolving an average of 15+ tickets per week.
Executed Cisco IOS upgrades on 2800/2900/3800/3900 series routers and switches, following client-approved change management procedures with pre-staged fallback configurations to minimize maintenance window risk.
Handled DNS and DHCP services on Windows Server and entry-level Infoblox appliances, handling scope creation, static reservation assignments, and DHCP pool troubleshooting for client endpoint environments.
Documented network diagrams using Visio, updated device configurations, and maintained troubleshooting guides and incident resolution steps in ticketing systems.
Monitored network device health, availability, and performance using tools like Nagios and WhatsupGold, reporting anomalies to senior staff.
Assisted in setting up and tuning basic QoS policies for VoIP traffic on client networks to improve call quality, based on pre-defined templates.
EDUCATION
MASTER OF SCIENCE – Computer Science Texas State University, Texas