Nasrin Eshaghi
New York, NY ********@*****.***
Security Engineer
Security Engineer with experience securing large-scale enterprise environments across hybrid cloud and on-prem environments. Proven expertise in Zero Trust architecture, next- generation ϐirewalls, data loss prevention, and cloud security. Skilled at strengthening security posture, reducing risk, and optimizing security operations across AWS, Azure, and GCP.
Core Skills
Firewalls: Palo Alto, Check Point, Fortinet
Zero Trust: Zscaler (ZIA, ZPA)
Data Loss Prevention: Microsoft Purview, Zscaler DLP, Forcepoint
Cloud Security Posture Management (CSPM ): Wiz
Cloud Security: AWS, Azure, GCP
Endpoint Security (CrowdStrike, Defender, Carbon Black)
SIEM & Monitoring (Splunk)
Vulnerability Management (Tenable)
Experience
Senior Security Engineer – New York Power Authority (Jul 2024 – Present)
Lead security engineering initiatives across hybrid cloud and on-prem environments aligned with Zero Trust principles
Implement Zscaler (ZIA/ZPA) policies to enforce secure user access and trafϐic inspection
Manage and optimize Check Point ϐirewall policies to enhance network security and compliance
Identify and remediate cloud vulnerabilities using cloud security posture management
(CSPM) tools such as Wiz
Optimize and tune DLP policies to signiϐicantly reduce false positives and improve detection accuracy
Implement security controls across AWS, Azure, and GCP
Monitor and respond to endpoint threats using CrowdStrike EDR
Perform vulnerability management using Tenable and prioritize remediation based on risk
Security Engineer – Amalgamated Bank (Nov 2021 – Feb 2024)
Designed and implemented DLP solutions to safeguard sensitive ϐinancial data
Deployed and supported EDR tools (Carbon Black, Defender, Microsoft E5)
Managed Fortinet ϐirewall policies and Proofpoint email security solutions
Investigated and resolved security incidents, improving response time Network Security Engineer – Equinix (Mar 2018 – Aug 2021)
Managed and maintained ϐirewall policies across 500+ Palo Alto devices in a global environment
Utilized Panorama for centralized ϐirewall management and policy enforcement
Troubleshot complex network trafϐic issues and optimized ϐirewall conϐigurations for performance and security
Network Support II – Sprint NOC (Mar 2017 – Mar 2018)
Monitored and supported MPLS backbone networks in a high-availability NOC environment
Performed root cause analysis on network incidents to ensure rapid resolution
Troubleshot routing protocols including BGP and OSPF to maintain network stability EducaƟon & CerƟficaƟons
B.S. Information Technology (Cyber Security), Strayer University (GPA: 4.0)
CCNA (Routing & Switching)
CompTIA Security+
Palo Alto Networks EDU-210, EDU-220
F5 BIG-IP (LTM, DNS, APM)
SANS SEC488 (Cloud Security)