Sai Prasanna Gandi
Network Security Engineer
+1-469-***-**** ************@*****.***
PROFESSIONAL SUMMARY
Data Center Network Engineer with 7+ years of experience designing, implementing, troubleshooting, and supporting enterprise and mission-critical data center networks. Strong hands-on expertise with Cisco Nexus and Arista switching, BGP, OSPF, VLANs, STP, EtherChannel, vPC, VRFs, and Layer 2/Layer 3 networking, with experience supporting highly available and resilient network fabrics. Skilled in troubleshooting complex routing, switching, connectivity, and performance issues across data center, cloud, firewall, and load-balancing environments. Experienced with high-availability designs, network migrations, production changes, incident response, RCA, and 24x7 operational support. Proven ability to work independently with minimal supervision while collaborating effectively with cross-functional engineering teams to maintain reliable and scalable data center infrastructure.
TECHNICAL SKILLS
Palo Alto & Network Security: Palo Alto PA-7000/PA-5000/PA-850/PA-3220, PAN-OS, Panorama, App-ID, User-ID, NAT, Security Policies, Security Zones, SSL Decryption/Inspection, FortiGate 1800F/1000F, FortiManager, FortiAnalyzer, Cisco ASA, Check Point, Zscaler ZIA/ZPA
F5 & Application Delivery: F5 BIG-IP LTM, GTM/DNS, APM, ASM, iRules, iControl REST API, Virtual Servers, Pools, Pool Members, Health Monitors, Persistence Profiles, Traffic Management Policies, SSL Offload, SSL Profiles, TCP Optimization, Web Acceleration, Application Switching, High Availability, Failover, SNAT, NAT, F5 DNS.
Load Balancing / Application Services: VMware Avi Load Balancer, Application Delivery, Global Server Load Balancing (GSLB), DNS Load Balancing, Application Traffic Management, HTTP/HTTPS, TCP/IP, SSL/TLS, Certificate Management, PKI, Private Keys, Certificate Rollover.
Routing & Switching: BGP, MP-BGP, OSPF, EIGRP, Static Routing, VLANs, STP, EtherChannel, Cisco Nexus 9000, ASR 9000/8300, Layer 2/Layer 3 Networking
Data Center: Cisco ACI, APIC, VRFs, Bridge Domains, EPGs, Contracts, VXLAN EVPN, Spine-Leaf, ECMP
SD-WAN & Cloud: Cisco Viptela, vManage, vSmart, vEdge, AWS VPC, Azure, ExpressRoute, VPN, Hybrid Cloud, Terraform
Monitoring & Troubleshooting: SolarWinds, Splunk, Wireshark, Packet Captures, Traffic Analysis, Protocol Analysis, L2/L3 Troubleshooting, VPN Troubleshooting, Network Performance Monitoring
Automation: Python, Bash, F5 iControl REST API, Ansible, Terraform, PowerShell.
Operations: ITIL/ITSM, Service Request Fulfillment (SRF), Incident Management, Problem Management, Change Management, P1/P2 Incident Response, RCA, Risk Mitigation, SOPs, Knowledge Management.
PROFESSIONAL EXPERIENCE
Network Security Engineer
CVS Health, Dallas, TX May 2026 – Present
Responsibilities:
Automated repetitive Palo Alto firewall administration activities across PA-7000/PA-5000 platforms and Panorama, improving consistency and reducing manual configuration effort.
Implemented and maintained Palo Alto security policies using App-ID, User-ID, NAT, SSL Decryption, URL Filtering, DLP, WildFire, and Advanced Threat Protection while validating policy behavior against application requirements.
Administered and supported Cisco Nexus 9000 data center switching, including VLANs, 802.1Q trunking, STP, EtherChannel, vPC, Layer 2/Layer 3 connectivity, and high-availability network designs.
Designed, implemented, maintained, and supported enterprise data center network infrastructure supporting business-critical applications and security services.
Administered Cisco Nexus 9000 switches across data center environments, including VLANs, 802.1Q trunking, STP, EtherChannel, vPC, Layer 2/Layer 3 connectivity, and high-availability designs.
Supported highly available data center network fabrics by maintaining redundant switching, uplink, vPC, and Layer 3 connectivity between application servers, firewalls, load balancers, and core network infrastructure.
Configured and troubleshot BGP, OSPF, VRFs, static routing, route redistribution, VLANs, STP, EtherChannel, and Layer 2/Layer 3 connectivity across enterprise data center environments.
Supported Arista switching infrastructure and performed configuration, troubleshooting, and operational support for high-performance data center networks.
Worked with Arista EOS and Cisco Nexus platforms to support resilient spine-leaf/data center switching architectures and maintain application connectivity.
Performed advanced troubleshooting of routing adjacencies, route advertisements, VLAN connectivity, STP issues, vPC consistency, interface failures, packet loss, latency, and end-to-end traffic paths.
Supported high-availability network designs with redundant paths, resilient uplinks, first-hop redundancy, and failover mechanisms to maintain continuous connectivity for mission-critical applications.
Troubleshot end-to-end traffic flows across Cisco Nexus, Arista switches, Palo Alto firewalls, F5 BIG-IP, SD-WAN, Internet circuits, AWS, Azure, and backend application environments.
Used Wireshark, packet captures, routing tables, MTR, cURL, Splunk, SolarWinds, and device-level diagnostics to isolate complex network and application connectivity issues.
Supported data center connectivity between servers, application platforms, load balancers, firewalls, and cloud environments while validating routing and Layer 2/Layer 3 reachability.
Participated in network migrations, data center changes, and infrastructure implementations by assessing existing configurations, validating dependencies, developing rollback plans, and performing post-change verification.
Performed P1/P2 incident response and root-cause analysis for critical data center networking, routing, switching, firewall, load-balancing, and application-connectivity issues.
Independently handled complex production network escalations, coordinating with Network Engineering, Security, Cloud, Infrastructure, Application, and Operations teams when cross-functional support was required.
Automated network operational activities using Python, Ansible, Bash, PowerShell, and Terraform to improve configuration validation, operational checks, and repeatable network changes.
Maintained network diagrams, configuration records, SOPs, implementation documentation, RCA reports, and troubleshooting procedures for data center infrastructure.
Participated in 24x7 production support and change-management activities for enterprise data center environments, including implementation validation and post-change monitoring.
Senior Network Engineer
T-Mobile, Bellevue, WA Nov 2025 – Apr 2026
Responsibilities:
Designed, configured, implemented, tested, and supported enterprise data center networking infrastructure across complex, highly available production environments.
Administered Cisco Nexus data center switching infrastructure supporting application servers, firewalls, load balancers, and enterprise network services.
Supported Arista switching environments and performed configuration, troubleshooting, and operational support across high-performance data center network infrastructure.
Configured and troubleshot BGP, OSPF, VRF, VLANs, STP, EtherChannel, vPC, Layer 2/Layer 3 routing, and redundant network paths.
Supported high-availability data center fabrics by maintaining redundant switching paths, resilient uplinks, vPC configurations, routing adjacencies, and failover connectivity.
Troubleshot BGP neighbor relationships, route advertisements, route selection, OSPF adjacencies, routing loops, asymmetric paths, VLAN issues, STP events, and Layer 2/Layer 3 connectivity problems.
Supported mission-critical production environments requiring controlled implementation, continuous availability, rapid incident response, and detailed post-change validation.
Troubleshot application traffic flows across Cisco Nexus, Arista switches, F5 BIG-IP load balancers, Palo Alto firewalls, WAN/SD-WAN infrastructure, cloud networks, and backend applications.
Performed deep packet analysis using Wireshark, packet captures, MTR, cURL, routing tables, device logs, Splunk, and application-flow analysis to identify performance and connectivity issues.
Supported F5 BIG-IP LTM environments and validated connectivity between data center switching infrastructure, load balancers, application servers, and security platforms.
Supported AWS VPC and Azure VNet connectivity, including subnets, route tables, VPN gateways, Direct Connect, ExpressRoute, and hybrid-cloud traffic flows.
Participated in data center network implementations, migrations, upgrades, and production changes, including configuration validation, dependency analysis, rollback planning, and post-implementation testing.
Performed P1/P2 incident response and root-cause analysis for critical routing, switching, data center, load-balancing, firewall, SD-WAN, and application-connectivity incidents.
Independently investigated and resolved complex production network issues with minimal supervision, escalating to specialized engineering teams only when required.
Collaborated with Network Engineering, Security, Cloud, Infrastructure, Application, and Operations teams to resolve cross-domain connectivity issues and improve data center reliability.
Developed Python and Ansible automation for configuration validation, operational checks, troubleshooting workflows, and repeatable network configuration activities.
Applied Terraform and Infrastructure as Code practices for controlled and repeatable network and cloud infrastructure change
Created and maintained network diagrams, implementation records, SOPs, troubleshooting guides, RCA documentation, and knowledge-base material.
Participated in 24x7 production support and change-management activities for highly available enterprise data center infrastructure.
Network Engineer
TCS, India Dec 2021 – Nov 2024
Responsibilities:
Supported enterprise LAN/WAN, core, data center and hybrid-cloud networks for US and German clients, troubleshooting routing, and troubleshot BGP, OSPF and static routing, analyzing route advertisements, neighbor relationships, routing tables and end-to-end traffic paths.
Managed Cisco SD-WAN Viptela through vManage, supporting VPN/VRF configuration, WAN connectivity, tunnel monitoring and application-performance troubleshooting.
Supported AWS VPC networking, including subnets, route tables, security groups and VPN connectivity between AWS resources and on-premises enterprise networks.
Administered Palo Alto firewalls and Panorama, implementing security-policy and NAT changes and troubleshooting application connectivity using traffic logs, sessions and routing information.
Supported FortiGate/FortiManager environments, implementing firewall policies and NAT changes and troubleshooting blocked application traffic.
Used Wireshark and packet captures to analyze TCP failures, retransmissions, resets and application connectivity issues.
Developed Python automation for repetitive network-administration activities and configuration tasks.
Used Ansible for multi-device network configuration and operational tasks.
Collaborated with DevOps teams on Terraform-based network/cloud infrastructure changes, validating connectivity after implementation.
Supported production changes, incident troubleshooting and post-change validation, maintaining technical documentation and operational procedures.
Network Support Analyst
ADP, India Dec 2018 – Nov 2021
Responsibilities:
Supported LAN/WAN, core networking and AWS connectivity for an Australian enterprise client, resolving network availability and connectivity incidents.
Configured and troubleshot Cisco routing and switching, including VLANs, trunking, inter-VLAN routing, OSPF, BGP and static routing.
Monitored network devices and WAN links, investigating interface errors, link failures, device availability and connectivity incidents.
Supported AWS network connectivity between cloud resources and enterprise infrastructure.
Supported Cisco ASA firewalls, implementing access-rule and NAT changes and troubleshooting application connectivity.
Assisted with firewall rulebase cleanup by identifying unused and duplicate ACL entries and consolidating policies.
Performed network changes, configuration backups and technical documentation while supporting senior engineers during production incidents.
CERTIFICATIONS
CCNA – Routing and Switching Cisco Certified Network Associate
Educational Details:
Bachelor’s in Mechanical engineering, University college of Engineering Narasaraopet, JNTUK