Tarun B
Senior Network Security Engineer
Phone: 551-***-****
Email: ******.*******@*****.***
Professional Summary:
Network Engineer with Over 11+ years of experience in testing, troubleshooting, implementing, optimizing, and maintaining enterprise data network and service provider systems with Network Security Experience, working on various Firewall technologies and migration technologies like Palo Alto, Checkpoint Juniper, Cisco ASA, and Fortinet.
Knowledge of scripting to efficiently create policies and implement them. Worked mainly with REST API Palo alto.
Implementation, Configuration and Support of Checkpoint (R80.40, R80.20, R77.30 Gaia, R75 and R71), VSX, MDM/MDS, Provider-1, Juniper Firewalls (SSG 550M, SSG520M, ISG 1000, ISG 200, SRX5400, SRX5600, and SRX5800), Cisco Firewalls (ASA 5505, 5506-X, 5585, 5525X with firepower), Palo Alto Networks Firewall models (Panorama M-100,M-200, PA-220, PA-440, PA-1k, PA-3k and PA-5 k) and Fortigate 601F.
Experience with Firewall migrations from ASA, Checkpoint firewall to Palo Alto firewalls using the expedition tool.
Implementation, integration and post-implementation Planning of security platform and network infrastructure products by using Palo Alto Strata, VM (Virtual Machine) and CN (Cloud Native) series firewalls, Sonic, Juniper, Illumio policy generator and Fortinet firewalls.
Palo Alto design and installation (Application and URL filtering, Threat Prevention, Data Filtering, User-ID and Wildfire).
Implemented security rules using Checkpoint Smart Console, NSM, ASDM, Panorama and also via CLI.
Extensive understanding of networking concepts, (IE. Configuration of networks, router configuration and wireless security, TCP/IP, VPN, Content Filtering, VLANs, and routing in LAN/WAN, Ethernet Port, Patch Panel and wireless networks.)
Provides management level reporting of firewall and Intrusion Protection System (IPS) activity on a periodic
Utilized the Blue Coat Proxy URL filtering, Splunk SIEM, IBM Qradar, Nessus, Infoblox, Tufin, Algosec, Firemon, CSM, NSM, ASDM, Source fire IPS/IDS.
Extensive experience in configuring and troubleshooting protocols RIP v1/v2, EIGRP, OSPF, BGP and MPLS. Basic knowledge on Wireless Access points of 802.11 a,b,g
Provide scalable, supportable military grade TCP/IP security solutions along with expert TCP/IP network designs that enable business functionality.
Administration, Engineering, and Support for various technologies including proficiency in LAN/WAN, routing, switching, security, application load balancing and wireless.
Policy development and planning / programming on IT Security, Network Support and Administration.
Good knowledge of CISCO NEXUS data center infrastructure with 5000 and 7000 series switches includes (5548, 7010) including CISCO NEXUS Fabric Extender (223, 2248)
Experience in working with Cisco Nexus Switches and Virtual Port Channel configuration.
Experience with Checkpoint VSX, including virtual systems, routers and switches.
Experience with DNS/DFS/DHCP/WINS Standardizations and Implementations.
Experience with F5 load balancers and reverse proxy design and setup and Configured Virtual server, service groups, Session persistence, Health monitors and Load balancing methods in new F5 and A10 LTMs
EDUCATION:
Master of Sciences Electronics and Computer Sciences, University of Utah, USA 2016-2018.
Bachelor of Technology (Electronics and Communications Engineering) - JNTU, INDIA. 2012-2016.
CERTIFICATIONS:
Cisco Certified Network Associate (CCNA)
Checkpoint Certified Security Administrator (CCSA)
Palo alto ACE
PROFESSIONAL EXPERIENCE:
Client: MUTB/MUFG (Mitsubishi Trust and Union Bank), Manhattan, NYC, NY Oct 2021 – May 2026
Senior Network Security Engineer
Responsibilities:
Implementing security Solutions using Palo alto firewalls PA220 PA1410 PA3220 PA 3050 and PA 5220. Cisco ASA and Fortinet Firewalls
Creating multiple firewall policies in Panorama and Palo alto, FortiGate Web UI and ASA ASDM.
Using REST API scripts to work on Cumbersome operations such as creating large number of address objects and policies and automate the process.
Setup Zscaler VPN tunnels for internal on prem end user devices such as VDIs (which use PAC files on web browsers) to have Zscaler policy enforcements for outbound traffic rather than firewalls.
Understand the Zscaler architecture and Setup Zscaler connectivity and tunnels. SIPA, ZIA and ZPA.
Configuring Zscaler and setting up Zscaler policies on ZIA and ZPA.
Troubleshooting Zscaler latency issues that could arise due to SIPA and traffic flow from Zscaler cloud to on-prem.
Configuring Firewall Policies ranging from simple to advanced policies which involve NAT, Data filtering, file blocking, URL filtering, User-ID, Threat ID exceptions (based on the app team requirements) and app-ID based policies, Wildfire etc. Configured FW policies, NAT, decryption Bypass and policy based Forwarding Firewall policies.
Extensive knowledge of Active-Passive and also Active- Active Firewall config setups. Worked on both the configurations based on the requirement of the company.
Working and troubleshooting issues on Palo Alto, Panorama and ASA and FortiGate Web UI.
Supporting the connections for M365 environment and mail exchange servers on Palo Alto using FW policies, NAT rules, IP assignment etc.
Understand the flow of traffic through all of the MUTB NY network and to other clients and troubleshoot connectivity issues using advanced troubleshooting from Command Line Utilities. Setting up connections that involve multiple firewalls by gaining deep insight into the company’s network.
Created multiple Static routes on Palo alto, ASA and Fortinet using CLI and on Panorama, Palo Alto and FortiGate using Web UI. 17. Static routes and route redistributions for multi-protocol network environment.
Joining bridge lines with customers and troubleshooting Firewall related issues such as packet drops and connection status of the route etc.,
Handling the ticketing systems in closing out the requests that are successfully implemented on Service Now system.
Working on the MOP for the Firewall staging process, implementation, back out and testing plan and preparing the necessary files for the process.
Maintained multi-vendor firewalls Palo Alto 3k, 5k and 5k series firewalls, Cisco ASA 5540,
Implemented Cisco Firepower NGIPS, perimeter protection, DMZs.
Edge Security design and implementation of Cisco ASA security appliances with Firepower services.
Strong troubleshooting skills specific to network security and ability to effectively work in cross functional teams as needed to resolve issues
Performing migration of 90% of the Palo alto firewalls from M100 to M200.
Worked independently as a sole Firewall Engineer and as a team with strong technical managers on maintaining, troubleshooting, upgrading, and replacing Firewalls and network infrastructure.
Firewall upgrades from PAN OS 8.0 to 10.1 and eventually to 11.1.14hx of both Active-active and Active-Passive Firewalls.
Setting up Kerberos and LDAP connectivity with active directory for user ID based authentication and usage of User ID in firewall policies.
Performed Palo alto Vendor’s BPA (Best Practice Analysis) and applying fixes wherever possible.
Performing firewall vulnerability scanning using tenable and Firewall hardening based on the CIS guidelines.
Configured, upgraded, troubleshooted Global protect portal, gateway and app configs for version 6.2.5 and later 6.2.8. Used RADIUS Multi factor authentication using DUO and setup DUO profile for Palo alto working with server team. Later switched to SSO.
Configuring, Migrating and troubleshooting more than 20 IPsec tunnels to various vendors and also to Zscaler cloud.
Setting up BGP OSPF config to neighbors and troubleshooting interface down scenarios that arose due to bad configuration or compatibilities of physical interfaces or between interface and cable.
Link and path monitoring profiles for detecting and generating alarms for business-critical applications.
Replacing EOL firewall with new ones and working in the data centers during such operations.
Monitoring the network devices using Solar winds and setting up alerts and reports of Device health, network interface utilization etc.
Coordination with teams during Disaster recovery site test operations.
Setting up custom reports related to most used apps, URLs categories and Data uploads in Panorama for tracking.
DLP prevention security profiles. (Data filtering, URL filtering, file blocking, anti-virus, spyware, disabling default decryption profiles)
Firewall reviews using Firemon to optimize policies and also identify legacy objects and clean them up using change tickets
Used Palo alto Expedition tool to analyze the logs and created RBAC and IBAC rules for specific User-ID/AD groups in Panorama.
Support in Migration of Firewalls from ASA to Fortinet by creating policies and objects and initial config.
Analyzing the logs in log collector LogRhythm to determine rule usage, troubleshooting etc.
Using Wireshark to analyze network traffic for troubleshooting.
Opening support tickets and working with Vendor supports issues on devices that are due to bugs in OS and root process malfunctions during device setup.
Client: Cisco/Bank of America – RTP, North Carolina April 2020 - Oct 2021
Sr. Network Security Engineer
Responsibilities:
Implementing security Solutions using Checkpoint firewalls R80.10, R80.20 Juniper SRX Firewall and Fortinet FortiGate Firewalls.
Creating multiple firewall policies in checkpoint smart dashboard, FortiManager and Junos Security editor.
Working and troubleshooting issues on checkpoint smart dashboard, FortiManager and Junos Security editor.
Understand the flow of traffic through the Check Point Security gateway cluster and troubleshoot connectivity issues using advanced troubleshooting from Command Line Utilities.
Created multiple Static routes on checkpoint and Junos Security editor using CLI and on Fortigate using Web UI.
Joining bridge lines with customers and troubleshooting Firewall related issues such as packet drops and connection status of the route etc.,
Handling the ticketing systems in closing out the requests that are successfully implemented on remedy and econnect systems.
Working on the MOC for the Firewall staging process and implementation and preparing the necessary files for the process.
Maintained multi-vendor firewalls Palo Alto 3k, 5k and 5k series firewalls, Checkpoint 12k and 15k appliances, Checkpoint R77.30, R75, Cisco ASA 5540, 5585 firewalls with firepower and Juniper SRX 540, 1400 series firewalls.
Implemented Cisco Firepower NGIPS, Imperva WAF, OOB solutions, perimeter protection, DMZs.
Edge Security design and implementation of Cisco ASA security appliances with Firepower services.
Worked on Palo Alto APP-ID, User-ID and other security profiles like Anti-virus, Threat Prevention, URL-filtering and Wildfire etc.
Strong troubleshooting skills specific to network security and ability to effectively work in cross functional teams as needed to resolve issues
Performing migration of Checkpoint R77.30 to R80.10 for all management servers (MDM’s & MLM’s) and all the firewall gateways in the production environment.
Lead the team of 4 specialized engineers in upgrading 80+ Physical and VSX virtual firewalls upgrades from R77.30 to R80.10 version.
Performed Checkpoint MDS upgrade from R77.30 to R80.40 in Lab and in Production.
Deployed Palo Alto firewalls in Microsoft Azure Cloud and Checkpoint firewalls in Amazon AWS, configured security policies to access cloud-based applications.
Managing different Juniper SRX firewalls across the board consisting of SRX 240, SRX 3560 and SRX 1400 using CLI.
Used Paloalto Expedition tool to analyze the logs and created RBAC and IBAC rules for specific User-ID/AD groups in Panorama.
Working with Paloalto TAC to resolve the technical issues with PAN devices and User-ID issues.
Client: Caterpillar, East Peoria IL Mar 2019 – Apr 20
Network Security Engineer
Responsibilities:
Implementing security Solutions using PaloAlto Pa-5000/3000, Cisco ASA, Checkpoint firewalls R77.30 Gaia, VSX and Provider-1/MDM.
Deployed Cisco ASA Firepower Services Delivers cultivating rapid threat detection and mitigation using Cisco Sourcefire IPS with AMP
Support Panorama Centralized Management for Palo Alto firewall PA-500, PA-200 and PA-3060, to central manage the console, configure, maintain, monitor, and update firewall core, as well as back up configuration.
Develop policies from Illumio policy generator on various workloads like bare metal, virtual machines and segmented policies on most granular level like application, role, risk-based polices by using policy generator
Deploy Illumio edge on cooperate end point devices for visibility, allowing peer to peer apps with no disruption to users.
Deploy and create policies for end point protection via Illumio edge lightweight agent with zero trust policy creation.
Creating multiple firewall policies in checkpoint smart dashboard in VSX cluster environment.
Performed the code upgrade from Checkpoint R77.10 to R77.30 Gaia on MDM and Log servers.
Build and configured the Checkpoint R80.10 firewall and management servers in the lab environment.
Upgraded Panorama to version 8.1.9 and upgraded all Palo Alto firewalls to PAN-OS 8.1.9 which are at different client locations across the globe
Working and troubleshooting issues on Paloalto firewalls Pa-7050 and PA-5k series firewalls and managing them via Panorama.
Implemented user based IBAC/Identify based firewall rules using User-ID in Paloalto firewalls for all the campus users.
Working with Paloalto TAC to resolve the technical issues with PAN devices and User-ID issues.
Migrated Cisco ASA and Checkpoint firewalls to Paloalto firewalls using Paloalto Expedition tool.
Used Algosec for firewall optimization purpose and removed unused rules.
Knowledge on Amazon AWS Virtual private cloud services
Worked on network security design and installation using Palo Alto Firewall (Application and URL filtering, Threat Prevention, Data Filtering).
Executed various migration/upgrade projects across F5 and hands on with F5 BIGIP LTMs/EM.
Researched, designed, and replaced aging Checkpoint firewall architecture with new next generation Palo Alto appliances serving as firewalls and URL and application inspection.
Understand the flow of traffic through the Check Point Security gateway cluster and troubleshoot connectivity issues using advanced troubleshooting from Command Line Utilities.
Performing URL filtering and content filtering by adding URL's in Bluecoat Proxy SG's.
Support Blue Coat Proxy in explicit mode for users trying to access Internet from Corp Network.
Working on Service now tickets to solve troubleshooting issues.
Client: State farm, Bloomington, IL Jan 2018- Feb 2019
Network Security Administrator
Responsibilities:
Managed large enterprise environment containing Palo Alto Firewalls, Checkpoint Firewalls, Bluecoat proxies, F5 LTMS/GTM, Cisco routers, Switches and Cisco ASA.
Deployed, designed new infrastructure using checkpoint firewalls, Palo Alto, bluecoat proxies, f5 load balancer, and source fire devices
Designed, implemented of Out of Region Disaster Recovery data center to consolidate 4 data centers into a single environment and performed the role of primary POC from Network team for all Disaster Recovery test activities and troubleshooting.
Performed upgrade for checkpoint gateways/MDS/MLM from R75.40VS/R70 to R77.30 checkpoint firewalls running Gaia.
Successfully installed Palo Alto PA-3050, PA-5050 firewalls to secure zones of network.
Managed and configured all Palo Alto PA 3000 series, PA 5000 series, PA 7000 series firewalls.
Palo Alto design and installation (VSYS, Application and URL filtering, Threat Prevention, Data Filtering).
Performed firewall migration from Cisco ASA to Paloalto firewalls using PaloAlto expedition tool.
Experience creating and troubleshooting IPSEC tunnels on checkpoint and CISCO ASA.
Expertise in complete checkpoint suite and experienced in deploying/troubleshooting standalone, cluster or VSX environments.
Experience with rule base analysis, rule deployment, risk analysis for access across various environments through the firewall.
Experience working on checkpoint next-Gen modules such as Application control and URL filtering.
Implemented identity awareness in production environment using checkpoint Identity agent and AD query resulting in intelligent access design aided by active directory integration.
Working experience with Splunk to forward the Checkpoint Firewall and Bluecoat proxy logs.
Troubleshooting issues using advanced techniques such as tcpdump, FW Monitor, Opnet packet captures, pcap analysis using Wireshark/Infinistream and system/process debug commands on the appliances.
Prepared detailed procedural documentation for firewall upgrades, password changes on various platforms, firewall rule base Audit and MOP (Method of procedure) for firewall and proxy.
Implementation, configuration and troubleshooting issues related to virtual servers, pools and nodes on LTM and GTM.
Working On network equipment like Nexus 5k/7k Series and Cisco 6500 series switches, configure OSPF and route policies.
Configured, deployed and upgraded bluecoat SG, BCAAA servers and proxy client.
Client: HSBC, India May 2015- May 2016
Network Engineer
Responsibilities:
Responsible for the configuration of Cisco Routers (7000, 5300, 4000, 2500, 3000, 2600) using RIP, OSPF, EIGRP, BGP
Managed office network with Cisco devices with network devices including 2500 and 3600 series routers and 3500, 2900, 1900 series switches
Dealt with customer problems to management and support groups utilizing standard escalation model.
Extensive experience in configuring and implementing OSPF and BGP.
Supported core network consisting of Cisco 7200 series routers running multi area OSPF.
Configured EIGRP and OSPF as interior gateway protocol with route filtering and route redistribution, installed and maintained Cisco 3600, 2600 and 7200 backbone routes with HSRP.
Implemented stub/Totally stub areas and various OSPF features like route-summarization and SPF throttling.
Configured Security policies including NAT, PAT, VPN, Route-maps and Access Control Lists.
Configured, maintained and troubleshot routing protocols such as OSPF, EIGRP and BGP.
Engaged in office moves, helped in identifying network requirements of new building, installed new networking hardware, and coordinated with vendors for cabling/wiring.
Performed troubleshooting, while maintaining trouble ticket tracking, following both internal/external routes.
Assisted with escalation procedures and customer notifications.
Configured Cisco Routers for OSPF, IGRP, RIPv2, EIGRP, Static and default route.
Upgraded Cisco Routers, Switches and Firewall (PIX) IOS using TFTP.
Worked on the security levels with RADIUS, TACACS+.
Involved in configuring Checkpoint (R65) Firewall rule base and objects as per the requirements.
Troubleshooting checkpoint firewall connectivity related issues using Smart view tracker.
Involved in the integration of F5 Big-IP load balancers with CheckPoint firewalls for firewall load balancing and was responsible was troubleshooting and maintenance.
Determining the functionality with the DNS naming conventions and migrations from old load balancing environments to the F5 environment.
Acted as Tier 3 support for connectivity, failures, configuration, implementation, and troubleshooting.
Provided project management for data center cabling, documented all network drawings using Visio.