Post Job Free
Sign in

Senior Network Security Engineer

Location:
Ashburn, VA
Posted:
October 08, 2026

Contact this candidate

Resume:

Abbas Khan Pathan

Senior Network Security Engineer

Contact No: 469-***-****

Email: *****************@*****.***

Summary:

Network Security Engineer with 7 years of experience managing, implementing, and supporting enterprise network infrastructures across data center, cloud, branch, and security environments using Cisco, Palo Alto, Fortinet, Check Point, F5, Arista, and cloud networking technologies.

Experienced in Palo Alto PA-Series (PA-5430, PA-3420, PA-410, PA-3220, PA-1420, PA-850), FortiGate (1000F, 60F, 200F), and Check Point (R81, R80.20, 12K) firewalls including security policies, rule updates, NAT, VPN, and troubleshooting.

Experienced with Cisco routing and switching platforms including ASR 9910, ASR 9006, ASR 1002, ISR 4331, Nexus 9300, Nexus 9400, Catalyst 9300, Catalyst 9200, Catalyst 6509E, Catalyst 3750, Cisco 2900 Series, and Cisco 3900 Series.

Strong knowledge of routing protocols including BGP and OSPF with experience in route updates, troubleshooting, and WAN connectivity support.

Experienced in Layer 2 technologies including VLAN, STP, RSTP, MSTP, Ether Channel, and LACP.

Hands-on experience with Cisco ACI, APIC, VXLAN, and data center networking.

Experienced in cloud networking with Azure ExpressRoute, Azure VPN Gateway, Azure CDN, AWS VPC, AWS Direct Connect, and AWS Cloud Watch.

Knowledge of SD-WAN technologies including Cisco Viptela vManage, vBond, and Prisma SD-WAN for WAN connectivity and policy management.

Experience supporting F5 BIG-IP 5000i, F5 BIG-IP 1000r, and NetScaler ADC for load balancing and application traffic management.

Skilled in network monitoring and troubleshooting using Splunk, QRadar, Solar Winds, Wireshark, and Infoblox.

Experience with Cisco ISE for authentication, authorization, and endpoint profiling.

Strong experience in incident troubleshooting, change management, firewall migrations, network upgrades, and production support.

Technical Skills:

Networking Protocols & Technologies: TCP/IP, UDP, ICMP, ARP, BGP, OSPF, EIGRP, MPLS, VXLAN, GRE, IPSEC, NAT, PAT, QoS, VRF, DNS, DHCP, and SNMP.

Physical Layer & Wireless Networking: Cabling standards (Cat5e, Cat6, fiber), port provisioning, patch panel mapping, port security, console access, rack & stack procedures, wireless site surveys, Meraki & Aruba access point deployment, SSID broadcasting, RF interference troubleshooting, signal optimization, wireless heat map analysis.

Routing & Switching: Cisco Catalyst, Nexus (5k, 7k, 9k), Arista 7000 series, Layer 2/3 Switching, Spanning Tree

Firewalls: Palo Alto (PA Series, Panorama), Fortinet FortiGate (60D-3000F), Juniper SRX, Checkpoint, VPN (Site-to-Site, Remote Access).

Cloud Technologies: AWS Cloud front cache settings, Direct Connect, Transit Gateway, Azure Firewall, and Azure NSGs

Load Balancers: F5 BIG-IP Load Balancer rSeries, LTM and GTM.

Automation & DevOps: Terraform templates for AWS VPC, Ansible-SOAR integration.

Professional Experience

InterVision, San Francisco, CA Feb 2025 - Present

Senior Network Security Engineer

Responsibilities: -

Enabled deep application visibility and control on Palo Alto 7000, 5000, and 3000 series firewalls, allowing or denying specific applications and services while inspecting encrypted SSL/TLS traffic to detect and prevent hidden threats.

Led the migration from Cisco firewalls to Palo Alto firewalls, including PA-5000 series (5450, 5430), PA (3000), PA 500, and PA 200 firewalls.

Designed and built VMware NSX environments to improve network security and streamline traffic flow across virtual machines.

Deployed NSX-T components like transport nodes, edge clusters, and logical switches in production and DR setup

Set up micro-segmentation and distributed firewall rules to control east-west traffic between workloads.

Upgraded and maintained NSX environments, including patching, policy updates, and regular health checks.

Integrated NSX with vSphere and monitoring tools to improve visibility and support automation.

Provided daily administration of Palo Alto Networks firewalls, managing security NAT, threat prevention, URL filtering, IPsec and SSL VPNs, security rules, zone-based policies, and syslog analysis, while leveraging Wildfire threat intelligence via Panorama 6.7.

Managed the cutover phase of the migration, transitioning traffic from PA-5000 series to PA-7000 series firewalls with minimal downtime, ensuring a smooth handover.

Configured Cloud flare’s DDoS protection to mitigate Layer 3, 4, and 7 attacks, ensuring 99.99% application time.

Deployed and managed Arista EOS-based switches in leaf-spine architecture, enabling high-throughput, low-latency network fabric for data center operations.

Configured EVPN-VXLAN overlays using Arista switches to support multi-tenant segmentation and layer-2/3 mobility across data center environments.

Utilized Cloud Vision Portal (CVP) for centralized automation, configuration compliance, telemetry, and real-time network state streaming.

Integrated Arista switches with network security monitoring tools for Net Flow/sFlow-based traffic analysis and threat detection.

Automated switch provisioning and configuration via eAPI and Ansible, improving consistency and deployment speed.

Managed security certificates and DNSSEC configurations within Cloud flare to prevent man-in-the-middle (MITM) attacks.

Configured routing protocols and policies such as OSPF, BGP, and Static Routing, implementing route redistribution, BGP policies (route tagging, AS-path filters, local preference, MED, and community-based policies).

Coordinated cross-functional war rooms during high-severity incidents, ensuring real-time collaboration between network, cloud, and endpoint teams.

Mentored Tier 1 and Tier 2 SOC analysts, improving analytical capabilities and escalation accuracy.

Performed software upgrades on Cisco ISR 4K, Catalyst 9600, Catalyst 9300, IE3300, Nexus 5K, and Nexus 7K to maintain network stability and performance.

Maintained network IP addressing, created Visio diagrams, and documented project designs to enhance operational efficiency.

Configured and supported MPLS Layer 3 VPN and BGP WAN configurations for customer networks.

Applied route maps in OSPF and BGP to enforce policy-based routing (PBR) on P2P circuits, optimizing traffic flow.

Configured RADIUS and TACACS+ protocols in Cisco ISE for centralized device administration and user authentication.

Integrated Cisco ISE with Active Directory, LDAP, and SAML providers for user identity management and single sign-on (SSO).

Deployed Guest Access Portals through Cisco ISE, enabling secure guest registration, self-service, and sponsorship flows.

Migrated OpenStack underlay networks from standalone Nexus to Cisco ACI, improving scalability and deployment efficiency.

Extensive experience configuring Cisco IOS, IOS-XR, and NX-OS, ensuring seamless network infrastructure management.

Designed, deployed, and optimized Viptela SD-WAN, leading migration efforts from legacy WAN architectures and enhancing network performance and reliability.

Analysed network traffic patterns and leveraged SD-WAN Viptela analytics to make data-driven optimization decisions.

Designed and deployed Arista spine-leaf architectures to enhance network scalability, performance, and reliability in data center environments.

Architected Arista-based EVPN-VXLAN fabric for multi-tenant segmentation and improved Layer 2/3 scalability across data centres.

Implemented Arista Cloud Vision for centralized network automation, monitoring, and telemetry, reducing operational overhead and improving network visibility.

Configured and managed Cisco and Meraki wireless access points, ensuring optimal guest internet infrastructure.

Proficient in configuring and managing Network Intrusion Detection Systems (NIDS) such as Snort, Suricata, and Zeek (Bro)

Designed and implemented Network Intrusion Detection Systems (NIDS) using tools like Snort, Suricata, and Zeek to monitor and analyze network traffic for malicious activity.

Deployed and configured signature-based and anomaly-based detection systems to identify and mitigate potential security threats in real-time

Developed custom intrusion detection rules and signatures to detect emerging threats and zero-day vulnerabilities.

Monitored and analyzed network traffic patterns to identify suspicious behaviour, including DDoS attacks, port scanning, and malware propagation.

Integrated NIDS with SIEM tools (e.g., Splunk, ELK Stack) for centralized logging, alerting, and incident response.

Conducted regular tuning and optimization of NIDS rules to reduce false positives and improve detection accuracy.

Implemented Cisco ISE network segmentation policies, dynamically assigning users and devices to specific network segments based on security posture and access rights.

Worked extensively with Nexus family switches (Nexus 9K, N7K, N5K, and N2K) in Top of Rack (ToR) and Tier 3/Tiered architectures.

Created professional-level documentation using Visio diagrams, configuring and managing Cisco access-layer routers and switches.

Configured and managed DHCP services using INFOBLOX, ensuring efficient IP address allocation, tracking, and compliance.

Configured and managed fore scout policies to enforce security compliance across IT and OT environments.

Integrated Fore scout with SIEM solutions (e.g., Splunk, QRadar) for real-time security monitoring.

Provided technical support for LAN & WAN systems, designing and implementing network architectures using VLAN, OSPF, and BGP.

T- Mobile, Seattle, WA July 2022 – Aug 2024

Senior Network Engineer

Responsibilities

Applied advanced TCP/IP management, including IP addressing, subnetting with VLSM, route summarization, and route redistribution. Designed and configured LAN and WAN networks using OSPF and VLAN architectures.

Configured and managed VMware VeloCloud SD-WAN edge devices for optimized WAN performance.

Designed and implemented SD-WAN architecture, including business policies, link steering, and dynamic path selection.

Designed and implemented high-availability data center network architectures, including dual-core/leaf-spine topology, redundant links, and HSRP/VRRP.

Managed end-to-end data center migrations, including L2/L3 segmentation, security policy replication, and zero-downtime cutovers.

Implemented network segmentation and micro segmentation using VLANs, ACLs, and firewalls to enforce zero-trust within the data center.

Secured east-west and north-south traffic flows through firewalls (Palo Alto/Cisco ASA), inline IPS, and next-gen switches.

Worked with SDN solutions and virtualization platforms (VMware NSX, ACI, and Arista Cloud Vision) to optimize performance and security in virtualized environments.

Performed regular traffic analysis and capacity planning to support growing data workloads and reduce congestion or bottlenecks.

Architected and maintained enterprise-wide SIEM solutions (Splunk / QRadar / Log Rhythm / Microsoft Sentinel) for centralized security monitoring.

Developed custom correlation rules and threat detection logic to identify advanced persistent threats (APTs) and insider threats.

Configured MAC Authentication Bypass (MAB) in Cisco ISE for non-802.1X capable devices like printers and VoIP phones

Enabled profiling services in Cisco ISE to automatically classify endpoints and assign appropriate access policies.

Collaborated with InfoSec teams to align ISE policies with Zero Trust security models and micro segmentation strategies.

Monitored authentication logs and endpoint activity using ISE Monitoring and Troubleshooting (MNT) for rapid incident response.

Integrated Cisco ISE with third-party solutions like Firepower, Palo Alto, Splunk, and Tufin for policy enforcement and visibility.

Participated in NAC (Network Access Control) policy design and lifecycle management using Cisco ISE across multiple campus locations.

Designed and deployed Arista Cloud Vision Portal (CVP) for centralized automation, monitoring, and compliance enforcement across enterprise and data center networks.

Implemented network automation using CVP’s Cloud Vision Configlets and Ansible, reducing manual configuration and ensuring consistency across Arista devices.

Integrated Arista CVP with Terraform for infrastructure-as-code (IaC), enabling automated provisioning and policy enforcement.

Configured and optimized CVP’s streaming telemetry and event-based monitoring, enhancing real-time network visibility and troubleshooting.

Developed compliance and configuration drift detection policies in CVP, ensuring adherence to security and operational standards

Used Ansible and NSX APIs to automate common network tasks and speed up deployments.

Helped improve network security by enforcing segmentation policies and reducing unnecessary communication between systems.

Worked closely with security and app teams to design NSX policies that match business and compliance needs.

Documented NSX designs, processes, and troubleshooting steps for internal teams.

Supported lifecycle management, including version upgrades and clean-up of unused network resources.

Integrated VeloCloud Orchestrator (VCO) and VeloCloud Edge (VCE) for centralized management and monitoring.

Optimized QoS (Quality of Service) and traffic shaping policies to ensure application performance.

Configured Palo Alto firewalls with advanced threat prevention features, including Intrusion Prevention System (IPS), antivirus, anti-spyware, and advanced malware analysis.

Implemented Zero Trust Network Access (ZTNA) principles on Palo Alto PA-5000 series to ensure secure access for authorized users and devices.

Centrally managed multiple Palo Alto firewalls using the Palo Alto Panorama M-500 management appliance.

Administered various Palo Alto firewall models (PA-7000, PA-5000, and PA-3000 series), implementing robust threat prevention mechanisms to enhance network security.

Conducted real-time vulnerability assessments and threat analysis using Fort iGATE’s built-in security tools to proactively mitigate security risks.

Configured and managed Fortinet firewalls, including FortiGate 3000 and 3815 series, according to network architecture requirements.

Established and optimized IPsec and SSL VPN tunnels on FortiGate firewalls, including FortiGate 1500D, 2000E, and 2500E models.

Integrated VeloCloud with cloud services (AWS, Azure, and GCP) for secure cloud access.

Automated SD-WAN deployment and monitoring using APIs and scripting.

Provided support for multi-site SD-WAN deployments, ensuring high availability and redundancy.

Fine-tuned firewall policies and security profiles on Cisco Firepower appliances to enforce granular access controls and threat prevention.

Performed security audits and vulnerability assessments using Cisco Firepower appliances to identify and remediate potential threats.

Worked with Cisco routers (2500, 2600, 2800 series) and switches (1900, 2900, 3560, 3750, 6509 series), as well as Juniper switches (EX4200, EX2200) and Cisco ASR routers (9922, 9912).

Designed and deployed network architectures using Nexus switch families, including Nexus 9k, 5k, 3k, and 2k series.

Configured Nexus 2000 Fabric Extenders (FEX) to function as remote line cards for Nexus 9000 series switches, improving scalability and flexibility.

Deployed and managed ACI Multi-Site solutions for interconnecting distributed data centers and ACI fabrics across multiple locations.

Automated Cisco ACI deployments using RESTful APIs, ACI Toolkit, and Python scripting for infrastructure orchestration.

ADP, India June 2020 – June 2021

Network Engineer

Responsibilities

Provided configuration and technical support for both production and development servers, operating systems and software applications.

Designed and managed the internal Cisco LAN, WAN and Aruba wireless networks for both corporate and retail sites.

Configured, managed and provided technical support for the virtual environment, including hosts, operating systems and storage utilizing VMware.

Involved in day-to-day system administration, support, tracking, and performance monitoring of all internal windows Active Directory/Domain servers, utilizing Solar Winds NCM, APM and NPM.

Installed and configured Cisco routers (1000, 4000 and 9000 series) and Cisco switches (3000, 4000 series).

Responsible for designing, installing, configuring the organization’s local and wide area networks, servers, systems, storage and firewall.

Administered and maintained complicated data center and remote sites involved detailed BGP, HSRP, VRP and VRRP configurations.

Worked on reported problems, including network, VOIP telephone system, and PC, server and application issues in an enterprise NOC environment.

Performed configuration and maintenance of the F5 BIG-IP load balancers to ensure high availability and stability in a complex, large scale environment.

Configured authentication, authorization, accounting access for various customers using, Microsoft and UNIX platforms running TACACS and RADIUS servers.

Accenture, India May 2019 – May 2020

Network Analyst

Responsibilities

Build and maintain all WAN connectivity for remote offices with a global Checkpoint firewall infrastructure.

Troubleshoot and configured connectivity issues related to VPN, DHCP, DNS, Firewall DMZ.

Implemented WAN, LAN, VOIP, Security solutions in health care, retail, manufacturing and financial services.

Configuring IPsec VPNs as per customer requirements with standard encryption and encapsulation.

Reviewed network device configurations and recommend fixes using industry best practices.

Manage edge Firewall/Router to update Policies, Web Filtering, and Application control features to increase security.

Perform WAN Throughput testing (Iperf) to educate the customer on how throughput is affected by high bandwidth, high latency links.

Troubleshot performance issues related to load balancing, SSL/TLS handshakes, and connection persistence.

Configured AVI Service Engines (SEs) for high availability and traffic scalability



Contact this candidate