Suresh K C Senior Network Engineer
SURESH K C
SENIOR NETWORK ENGINEER NETWORK ARCHITECTURE CYBERSECURITY Richmond, TX 561-***-**** *********@*******.*** PROFESSIONAL SUMMARY
Senior Network Engineer and security practitioner with deep experience designing, modernizing, and protecting enterprise, campus, data center, cloud, and high-availability event networks. Combines architecture-level expertise in routing, switching, wireless, segmentation, firewalls, and hybrid Azure connectivity with hands-on leadership across Cisco ISE, Catalyst Center, TrustSec/SGT, Cisco Secure Firewall, Palo Alto, Cisco Umbrella, Proofpoint, and security monitoring. Proven in translating business and operational requirements into resilient designs, controlled migrations, hardened access policies, actionable runbooks, and audit-ready documentation. Experienced supporting mission-critical stadium operations, vendor engagements, cyber advisory response, change control, vulnerability remediation, and cross-functional troubleshooting under demanding availability requirements. CORE EXPERTISE
Network & Cloud: BGP, OSPF, VRF, VLAN, STP, HSRP, QoS; Azure VNets, Peering, VPN Gateway, UDR, Private Endpoints, KQL Security & Access: Palo Alto, FMC/FTD, ISE, TrustSec/SGT, Umbrella, VPN, 802.1X, MAB, TACACS+, RADIUS
Wireless & Infrastructure: Extreme Networks, RF planning, Catalyst, Nexus, ISR, Nutanix NC2, VMware, Rubrik, AD Security Operations: Proofpoint, DMARC/DKIM/SPF, UltraDNS, SolarWinds, Log Analytics, incident response, DR, audit evidence SELECTED ARCHITECTURE & SECURITY PROJECTS
• Identity segmentation: Integrated Cisco ISE and Catalyst Center for TACACS+, 802.1X, MAB, profiling, TrustSec/SGT, and phased micro- segmentation.
• Firewall and cloud security: Supported Palo Alto and Cisco FMC/FTD HA, VPN, policy/NAT, upgrades, hotfixes, Azure peering, gateways, UDRs, private access, and KQL validation.
• Stadium infrastructure: Engineered wired and Extreme Networks wireless services for NFL and major events, including SSIDs, Ethernet drops, RF/non-DFS planning, failover testing, and readiness checks.
• Security operations: Strengthened Umbrella, UltraDNS, and Proofpoint controls; investigated BGP/ISP, DHCP relay, firewall, authentication, and hybrid-cloud issues; maintained audit-ready diagrams and evidence. PROFESSIONAL EXPERIENCE
Senior Network Engineer Houston Texans CURRENT ROLE Houston, TX
• Architect and support resilient campus, data center, stadium, and hybrid-cloud networks using Cisco Catalyst and Nexus switching, BGP, OSPF, VLANs, STP, HSRP, VRF, QoS, DHCP relay, DNS, NAT, IPsec VPNs, and redundant ISP connectivity.
• Engineer Azure network connectivity across North Central US and South Central US, including VNets, cross-region peering, VPN gateways, route tables and UDRs, private endpoints, Storage and SFTP access, NAT and SNAT analysis, and Log Analytics or KQL- based traffic validation.
• Administer Palo Alto and Cisco Secure Firewall environments, including FMC and FTD high availability, security and NAT policies, remote-access and site-to-site VPNs, software and hotfix lifecycle management, packet and log analysis, and controlled production changes.
• Design and troubleshoot identity-based access controls with Cisco ISE and Catalyst Center using TACACS+, RADIUS, 802.1X, MAB, profiling, authorization policies, security group tags, TrustSec, and phased micro-segmentation strategies.
• Operate high-density Extreme Networks wireless infrastructure for stadium and event environments, including SSID provisioning, AP and client troubleshooting, RF and channel planning, non-DFS allocation, interference analysis, and event-day readiness validation.
• Secure DNS, web, and email services through Cisco Umbrella, UltraDNS, and Proofpoint; investigate SPF, DKIM, DMARC, impersonation and BEC rules, malware controls, mail-flow issues, certificate renewals, and false-positive or false-negative events.
• Support Nutanix NC2, VMware, Rubrik, Active Directory, and Windows Server dependencies; troubleshoot DHCP relay, routing, replication, backup connectivity, and application traffic across on-premises and cloud environments.
• Build operational visibility with SolarWinds and platform-native logging; analyze routing adjacencies, firewall sessions, VPN health, authentication failures, wireless client behavior, and cloud flow data to isolate root cause and reduce service impact.
• Plan and execute infrastructure migrations, vulnerability remediation, emergency changes, failover testing, and maintenance windows with implementation steps, rollback plans, validation criteria, executive communications, and audit-ready CLI and log evidence.
• Maintain network diagrams, IP and asset inventories, SmartNet renewal data, architecture standards, runbooks, security exceptions, vendor SOW reviews, incident records, and post-change documentation for enterprise governance and operational continuity. Network Engineer City of Coral Springs OCT 2022 – PRIOR ROLE Coral Springs, FL
• Designed, upgraded, troubleshot, and maintained citywide wired and wireless networks and connectivity to local and federal government agencies.
• Deployed Cisco DNA Center and Cisco ISE to centralize device authentication with TACACS+ and endpoint access with 802.1X and MAB, while automating network-device firmware workflows. Suresh K C Senior Network Engineer
• Designed resilient inter-city connectivity for 911 dispatch expansion using primary dark fiber and secondary internet paths, and used Peplink VPN connectivity to sustain fire-station operations during outages.
• Administered and backed up a large multi-vendor environment of Cisco routers, switches, access points and wireless controllers, Palo Alto and Fortinet firewalls, and Peplink routers.
• Patched servers, endpoints, switches, routers, and voice gateways using Qualys and CIS-aligned practices; advised on end-of-life replacement and secure lifecycle planning.
• Helped design and implement a new Emergency Operations Center and regularly exercised disaster-recovery failover scenarios to prepare for hurricane-driven continuity needs.
IT Security Specialist City of Coral Springs SEP 2021 – OCT 2022 Coral Springs, FL
• Responded to cybersecurity incidents and Tier 2/3 escalations; performed threat research, containment, eradication, recovery support, continuous monitoring, and leadership reporting.
• Assessed vulnerabilities based on severity, likelihood, and impact; coordinated software and security patching through Qualys and SCCM and maintained secure configuration baselines.
• Deployed Palo Alto and Fortinet next-generation firewalls and created security, NAT, policy-based forwarding, Zero Trust, GlobalProtect, and IPsec VPN configurations.
• Migrated and upgraded firewalls with minimal interruption using high-availability designs; established backup and contingency procedures for security platforms.
• Monitored phishing, malware, compromised credentials, outdated software, and endpoint threats using security mailboxes, CrowdStrike, Forescout, and supporting tools.
Network Analyst City of Coral Springs APR 2018 – SEP 2021 Coral Springs, FL
• Designed and deployed redundant wired and wireless infrastructure for a newly built facility serving more than 1,000 users and connecting to primary data centers.
• Managed Cisco Catalyst, Nexus, ISR, WLC, Prime, CMX, DNA Center, and ISE platforms; performed firmware lifecycle management, network monitoring, performance troubleshooting, and documentation.
• Implemented encrypted remote-site VPNs aligned with FIPS 140-2 and designed a disaster-recovery site using MACsec encryption to support CJIS compliance.
Data Operations Analyst Utility Warehouse FEB 2016 – AUG 2017 London, UK
• Resolved advanced DSL, VDSL, Wi-Fi, VoIP, authentication, email, and performance faults; acted as escalation point and coordinated service-provider engineering activity.
• Coached first-line support teams and produced detailed fault reports covering line tests, expected speeds, network history, and recommended actions.
Network Engineer National Technology Center AUG 2013 – SEP 2015 Kathmandu, Nepal
• Configured and troubleshot Cisco routers, switches, voice gateways, WAN links, EIGRP, and OSPF; maintained patches, LAN/WAN diagrams, operations procedures, PCs, and servers. CERTIFICATIONS & TRAINING
CERTIFICATIONS
• CCNA, Routing & Switching
• Certified Ethical Hacker (CEH)
• PCCET, Palo Alto
• ITIL Foundation • CJIS • ICS
ADVANCED TRAINING
• SANS FOR572: Advanced Network Forensics
• Cisco ENCOR • Cisco ENARSI
• PenTest+ coursework / training
EDUCATION
Bachelor of Engineering, Computer Engineering Kantipur Engineering College, Nepal Full scholarship recipient; graduated with distinction. Major: Internet and Intranet.