Post Job Free
Sign in

Network & Security Engineer - Palo Alto, ACI, Zero Trust

Location:
Ashburn, VA
Salary:
110000
Posted:
October 08, 2026

Contact this candidate

Resume:

Naveen Kumar Talluri

Network & Security Engineer Palo Alto, Cisco ACI, SD-WAN & Zero Trust Multi Cloud Network& Security

Phone: 571-***-****

Email: **********@*****.***

SUMMARY

Network & Security Engineer with 5+ years of hands-on experience designing, implementing, migrating, securing, automating and troubleshooting enterprise LAN/WAN, data center, hybrid and multi-cloud (AWS, Azure, GCP) network infrastructures across telecommunications, energy and enterprise environments.

Expert in enterprise firewall administration across Palo Alto Networks (PAN-OS, Panorama M-Series, PA-3K/5K/7K, VM-Series), Fortinet FortiGate/FortiManager, Cisco Secure Firewall FTD/FMC, Cisco ASA, Juniper SRX and Check Point R80, including centralized policy lifecycle management for 150+ firewalls, App-ID/User-ID, SSL decryption, threat prevention, URL filtering, NAT and IPsec/SSL VPN.

Strong data center expertise with Cisco ACI (APIC, Tenants, VRFs, Bridge Domains, EPGs, Contracts), Cisco Nexus 2K/5K/7K/9K, Arista EOS, VXLAN/EVPN Spine-Leaf fabrics, vPC/VDC and Nexus 7K-to-9K migrations supporting thousands of physical and virtual workloads with 99.99%+ availability.

Advanced routing and switching across Cisco IOS/IOS-XE/NX-OS, Juniper Junos and Arista EOS: BGP (EVPN, route reflection, traffic engineering), OSPF, EIGRP, MPLS L3VPN, MP-BGP, VRF, HSRP/VRRP, STP/RSTP/MSTP, LACP/EtherChannel, 802.1Q, QoS, ACLs and NAT/PAT.

Zero Trust and SASE specialist: Zscaler ZIA/ZPA/ZTNA, Palo Alto Prisma Access and GlobalProtect, Illumio micro-segmentation, Cisco ISE/TrustSec (SGTs), Aruba ClearPass, 802.1X/MAB and CyberArk PAM, enforcing identity- and posture-based least-privilege access across campus, data center and cloud.

Hands-on cloud networking with AWS (VPC, Transit Gateway, Direct Connect, PrivateLink, Route 53, VPC Flow Logs, Network Firewall, WAF, Shield, ALB/NLB), Azure (VNet, NSGs, UDRs, ExpressRoute, Virtual WAN, Private Link, Azure Firewall) and GCP (VPC, Cloud Router, Interconnect), delivering secure hybrid and multi-cloud connectivity through Terraform.

Experienced with Cisco Catalyst SD-WAN/Viptela (vManage, vBond, vSmart, vEdge/cEdge), VMware VeloCloud and Fortinet Secure SD-WAN, leading MPLS-to-SD-WAN migrations, application-aware policies, OMP/TLOC/BFD troubleshooting and SASE integration for 100+ branch sites.

Network automation and Infrastructure as Code with Python (Netmiko, NAPALM, REST APIs), Ansible (playbooks, dynamic inventories, AWX/Tower), Terraform modules, Git and Jenkins/GitLab CI/CD pipelines, automating firewall policy deployment, configuration backups, compliance validation and cloud provisioning and cutting deployment time from days to hours.

Application delivery expertise with F5 BIG-IP LTM/GTM/AFM/ASM (VIPRION, rSeries, vCMP), iRules, SSL offload, GSLB, Citrix NetScaler ADC, AWS ALB/ELB and Azure Load Balancer, including automated SSL certificate lifecycle management with Venafi.

Enterprise wireless design and operations across Cisco Catalyst 9800, Aruba Mobility Conductor/AirWave and Cisco Meraki, including Wi-Fi 6/6E design, Ekahau predictive and on-site surveys, RF optimization, 802.11r/k/v roaming and 802.1X/RADIUS authentication.

Network services and observability with Infoblox DDI, BlueCat, DNS/DHCP/IPAM, DNSSEC, Splunk, QRadar, SolarWinds Orion/NTA, ThousandEyes, Datadog, Grafana/Prometheus, ELK, NetFlow/sFlow/IPFIX, SNMPv3 and Wireshark/TCPdump packet-level analysis.

Security and compliance experience aligned with NIST, CIS Benchmarks, SOC 2, ISO 27001, HIPAA and PCI-DSS, including vulnerability management (Nessus/Qualys), firewall rule-base optimization (AlgoSec/Tufin), IDS/IPS, DDoS mitigation and SIEM-driven incident response.

Proven P1/P2 incident commander and Tier 3 escalation point, leading root-cause analysis, post-mortem RCAs, formal change management (MOP/CAB), ITIL/ServiceNow workflows, DR/BCP testing, on-call rotations, vendor/ISP coordination and mentoring of junior and NOC engineers.

Experience supporting telecommunications, unified communications and physical infrastructure, including VoIP/video systems, fiber network infrastructure, rack-and-stack, structured cabling, IDF/MDF cable management and Cisco switch refresh projects.

TECHNICAL SKILLS:

Firewalls & NGFW

Palo Alto PA-7000/5450/5250/3220, VM-Series (AWS, Azure), PAN-OS, Panorama M-Series, GlobalProtect, Fortinet FortiGate 1000F/200F, FortiManager, FortiAnalyzer, Cisco Secure Firewall FTD 1150/3105/3100/4100, FMC, Cisco ASA 5500-X, Juniper SRX, Check Point R77/R80 (SmartConsole, Gaia), Sourcefire IPS

PAN-OS / NGFW Features

App-ID, User-ID, Content-ID, Threat Prevention, WildFire, URL Filtering, DNS Security, SSL Decryption (Forward Proxy / Inbound), NAT, PBF, Zone/DoS Protection, HA A/P & A/A, Templates & Device Groups, Log Forwarding, IPsec/SSL VPN (IKEv1/IKEv2), Security Profiles

Zero Trust / SASE

Zscaler ZIA/ZPA/ZTNA/ZCC, Palo Alto Prisma Access, Prisma Cloud, Cato Networks SASE, Illumio ASP/VEN micro-segmentation, Cisco TrustSec/SGTs, CASB, SWG, Identity-Based Access, Device Posture (HIP), Least-Privilege Access

Data Center & SDN

Cisco ACI (APIC, Tenants, VRFs, Bridge Domains, EPGs, Contracts, L3Outs), Cisco Nexus 2K/5K/7K/9K, Spine-Leaf, VXLAN/EVPN, vPC, VDC, Arista EOS, Cisco UCS, Cisco MDS SAN (VSANs, Zoning, FC/FCoE), VMware NSX, Nexus 7K-to-9K Migration

Routing & Switching

BGP (EVPN, RR, traffic engineering), OSPF, EIGRP, MPLS L3VPN, MP-BGP, VRF, HSRP/VRRP, STP/RSTP/MSTP, LACP/EtherChannel, 802.1Q, QoS, ACL, NAT/PAT, Cisco Catalyst 9K/3850/3750/2960, ISR/ASR, Juniper MX480/MX10003, EX3400/4300/4400, Arista 7000, Extreme Networks

SD-WAN

Cisco Catalyst SD-WAN/Viptela (vManage, vBond, vSmart, vEdge/cEdge, OMP, TLOC, BFD, Templates, Policies), VMware VeloCloud (VCO, Edge, AppQoE), Fortinet Secure SD-WAN, MPLS-to-SD-WAN Migration, Application-Aware Routing

Cloud Networking

AWS (VPC, Transit Gateway, Direct Connect, PrivateLink, VPN, Route 53, VPC Flow Logs, CloudWatch, Network Firewall, WAF, Shield, ALB/NLB, ACM, CloudFormation), Azure (VNet, NSGs, UDRs, ExpressRoute, Virtual WAN, Private Link, Azure Firewall, Load Balancer, Azure AD), GCP (VPC, Cloud Router, Cloud VPN, Interconnect)

Automation / IaC

Python (Netmiko, NAPALM, Paramiko, Requests, PAN-OS XML/REST API), Ansible (Playbooks, Roles, AWX/Tower, paloaltonetworks.panos), Terraform (Modules, State), Git/GitHub/GitLab, Jenkins, GitLab CI, Bash, PowerShell, YAML/JSON, Policy-as-Code, Cisco DNA Center, ACI/Meraki/Panorama APIs

NAC & Identity

Cisco ISE (802.1X, MAB, Profiling, Posture, Guest, TrustSec), Aruba ClearPass, RADIUS, TACACS+, Active Directory, Azure AD, LDAP, Okta/SSO, SAML, MFA/2FA, CyberArk PAM, Certificate-Based Authentication, RBAC

Load Balancing & ADC

F5 BIG-IP LTM/GTM(DNS)/AFM/ASM, VIPRION, rSeries, vCMP, iRules, SSL/TLS Offload, GSLB, OneConnect, Citrix NetScaler ADC, AWS ALB/ELB, Azure Load Balancer, Venafi Certificate Lifecycle Automation

Wireless

Cisco Catalyst 9800 WLC, Cisco Meraki MR, Aruba Mobility Conductor, Aruba AirWave, Extreme Wireless, Wi-Fi 6/6E (802.11ax), Ekahau Site Surveys, RF Planning & Optimization, 802.11r/k/v, WPA3/802.1X

DNS / DHCP / IPAM

Infoblox DDI (DNS, DHCP, IPAM, Grid, HA/Failover), BlueCat Address Manager, AWS Route 53, DNSSEC, NTP, DNS Failover & Traffic Policies

Monitoring / SIEM / Packet Analysis

Splunk, QRadar, SolarWinds Orion/NPM/NTA, ThousandEyes, Datadog, Grafana, Prometheus, ELK, Cisco DNA Assurance, HP OpenView, SNMPv3, NetFlow/sFlow/IPFIX, Syslog, Wireshark, TCPdump, PCAP Analysis, Streaming Telemetry

Security & Compliance

NIST, CIS Benchmarks, SOC 2, ISO 27001, HIPAA, PCI-DSS, GDPR, Nessus, Qualys, AlgoSec/Tufin Rule-Base Optimization, IDS/IPS, SSL/TLS PKI, Vulnerability Assessments, Firewall Audits, DLP, CrowdStrike EDR, Microsoft Intune/Defender, Tanium

Telecom & Physical Infrastructure

VoIP Phone Systems, Video Conferencing, Fiber Optic Infrastructure, Clock Synchronization, Emergency Notification / Mass-Messaging Platforms, Rack & Stack, Structured/Fiber Cabling, IDF/MDF Cable Management, Switch Refresh & Migration

ITSM / Change / Virtualization

ITIL, ServiceNow (Incident, Change, CMDB), MOP/CAB Change Management, P1/P2 Incident Command, RCA/Post-Mortems, DR/BCP Testing, Vendor/ISP Coordination, Runbooks, Visio Diagrams, VMware vSphere/vCenter/ESXi/NSX, Hyper-V, MDM

Certifications

CCNP – Cisco Certified Network Professional, CCNA – Cisco Certified Network Associate

CERTIFICATIONS

CCNP – Cisco Certified Network Professional

CCNA – Cisco Certified Network Associate

PROFESSIONAL EXPERIENCE

Verizon, Dallas, TX Mar 2025 - Present

Network Security Engineer

Responsibilities:

Administered Palo Alto Panorama (M-Series) for centralized management of 150+ PA-3K/5K/7K and VM-Series firewalls, managing Device Groups, Templates and Template Stacks, RBAC, SSL decryption profiles, App-ID, User-ID, URL filtering and threat prevention profiles across data center, perimeter and cloud deployments.

Migrated security policies, NAT rules and IPsec VPN configurations from PA-5000 to PA-7000/PA-5450 series, performing in-place PAN-OS upgrades, HA validation and hardening prior to production cutover with zero unplanned downtime.

Integrated Palo Alto User-ID with Active Directory and Azure AD to enforce identity-based security policies, and tuned security profiles (Anti-Virus, Anti-Spyware, Vulnerability Protection, WildFire) to reduce false positives while maintaining threat coverage.

Designed, configured and troubleshot IPsec site-to-site and remote-access VPNs (IKEv2, third-party interoperability with AWS/Azure and partner firewalls) and managed GlobalProtect gateways for Zero Trust remote connectivity.

Configured and managed FortiGate 1000F/200F firewalls through FortiManager and FortiAnalyzer, enforcing IPS, application control, web filtering, SSL inspection and IPsec/SSL VPN with MFA for remote sites and controlled internet breakout.

Supported Cisco Secure Firewall FTD 3100/4100 and Firepower Management Center (FMC) for access control and intrusion policy deployment, SSL decryption rules, health/performance monitoring and traffic-flow analysis; optimized security intelligence policies to strengthen perimeter and internal segmentation.

Designed and configured Cisco ACI objects including Tenants, VRFs, Bridge Domains, Application Profiles, EPGs, Contracts and L3Outs to support application segmentation and data center connectivity; monitored fabric health and resolved APIC faults.

Led Cisco Nexus 7K-to-9K migration for core and aggregation layers, migrating VLANs, SVIs, vPC/port channels, trunk links and routing dependencies with pre/post-migration validation and rollback plans, completing cutovers within approved change windows.

Deployed VXLAN/EVPN spine-leaf fabric on Cisco Nexus 9K with BGP EVPN route reflection, ECMP and active-active uplinks, supporting 1,000+ physical servers and 4,000+ virtual workloads with sub-second failover during leaf failures.

Implemented OSPF-to-BGP redistribution with route filtering, prefix lists and route maps, and optimized BGP traffic engineering using local preference, MED, AS-path prepending and communities to control primary and backup paths across ISPs and data centers.

Troubleshot complex Layer 2/Layer 3 issues across Nexus and Catalyst environments using STP, VLAN, routing table, MAC/ARP, interface and forwarding-table analysis, and performed packet-level troubleshooting with Wireshark, TCPdump and ERSPAN captures.

Integrated Zscaler ZIA/ZPA with Active Directory and Azure AD via SAML/SCIM to implement identity-aware access, SSL inspection, URL filtering and Zero Trust application access without exposing internal applications to the internet.

Implemented ZTNA segmentation policies based on user identity, application requirements and device posture to restrict lateral movement and isolate sensitive applications from unauthorized users and devices.

Designed Zero Trust micro-segmentation using Illumio and Cisco ISE TrustSec Security Group Tags (SGTs) across 150+ application workloads, reducing east-west attack surface and supporting SOC 2/ISO 27001 controls.

Designed and deployed AWS Transit Gateway with Direct Connect and Site-to-Site VPN for hybrid cloud connectivity, centralizing routing across 12+ VPCs and on-premises data centers and reducing inter-VPC latency by 25% through route table optimization.

Built reusable Terraform modules for AWS Transit Gateway, VPC attachments, route tables, Route 53 private hosted zones, Network Firewall and security groups, cutting provisioning time from days to hours and eliminating configuration drift.

Deployed AWS Network Firewall, WAF and Shield for deep packet inspection, application-layer and DDoS protection, and enabled VPC Flow Logs integrated with CloudWatch and Splunk for real-time traffic analysis and anomaly detection.

Configured Azure Network Security Groups (NSGs), User-Defined Routes and Azure Virtual WAN connectivity to extend Zero Trust controls into hybrid cloud environments, and deployed Palo Alto VM-Series firewalls in AWS and Azure for consistent policy enforcement.

Performed Cisco SD-WAN (Viptela) circuit migrations, controller upgrades and device/feature template updates on vManage, established IPsec data-plane tunnels between vEdge/cEdge routers and monitored tunnel health using BFD and OMP.

Integrated Cisco SD-WAN with Zscaler ZIA for direct internet access at branch sites, enforcing consistent security policies at the edge, eliminating backhaul traffic and improving SaaS application performance.

Developed Ansible playbooks and Python scripts to automate configuration changes, compliance checks and configuration backups across Cisco Nexus, Palo Alto, FortiGate and F5 devices, and pushed policy changes through Jenkins CI/CD pipelines, reducing policy deployment time from hours to minutes.

Built Python automation with Netmiko and REST APIs (Panorama, ACI, Meraki) for bulk VLAN provisioning, firewall rule audits and log parsing, reducing manual effort by 60% during incident response and change execution.

Configured F5 BIG-IP LTM/GTM virtual servers, pools, health monitors, iRules, SSL/TLS offloading and GSLB for application traffic distribution, and automated SSL certificate renewal across F5 and Palo Alto platforms with Venafi and Python, eliminating expired-certificate incidents.

Designed and deployed enterprise Wi-Fi 6 networks across 40+ locations using Cisco Meraki MR and Cisco Catalyst 9800, performing Ekahau site surveys, RF planning, channel/power optimization and 802.11r/k/v roaming for high-density environments.

Implemented 802.1X certificate-based authentication with Cisco ISE and Aruba ClearPass integrated with Active Directory for role-based SSID access, guest segmentation and dynamic VLAN assignment; automated WLAN changes via the Meraki API.

Administered Infoblox DDI for DNS records (A, CNAME, MX, SPF, TXT), DHCP scopes, IPAM and Grid HA/failover, and orchestrated DNS failover between Infoblox and AWS Route 53 with DNSSEC-signed zones.

Integrated Palo Alto, F5 and Cisco telemetry with Splunk SIEM and ThousandEyes, building dashboards and correlation rules for security operations and reducing mean time to resolution (MTTR) by 35%.

Served as Tier 3 escalation point and incident lead for P1/P2 network and firewall incidents, performing advanced root-cause analysis using traffic, threat and system logs and delivering post-incident RCAs to leadership.

Led formal change management, authoring Method of Procedure (MOP) documents, presenting to the Change Advisory Board (CAB) and executing authorized changes during scheduled after-hours windows with zero failed implementations.

Maintained network architecture diagrams, configuration baselines, capacity forecasts and runbooks in ServiceNow CMDB, and participated in team-based on-call rotations for after-hours and emergency incidents.

Supported SSO/identity provider (Okta, Azure AD) integration to enforce identity-aware access policies across enterprise SaaS applications, and mentored junior and NOC engineers on structured troubleshooting and diagnostic workflows.

Marathon Petroleum, Findlay, OH Oct 2023 - Feb 2025

Network Engineer

Responsibilities:

Deployed and administered Palo Alto PA-5420/PA-3440 NGFWs, implementing security policies, NAT, SSL decryption, App-ID/User-ID and security profiles for enterprise perimeter and data center protection, and managed Panorama device groups, templates and RBAC for consistent multi-firewall enforcement.

Developed Ansible playbooks for Palo Alto Panorama device groups and templates, pushing policy changes, SSL decryption profiles and GlobalProtect configurations to 100+ firewalls through Jenkins CI/CD integration and eliminating manual configuration drift.

Configured Panorama log forwarding for traffic, threat, URL and system logs and integrated firewall telemetry with Splunk SIEM and QRadar for centralized visibility, correlation and incident response.

Performed firewall rule-base optimization using AlgoSec/Tufin-style audit traceability, reducing stale and shadowed rules by 30% across 100+ firewalls and strengthening PCI/SOX-aligned segmentation.

Supported Cisco Secure Firewall/FTD 1150 and 3105 with FMC, including software upgrades, access control and intrusion policy deployment, NAT/PAT analysis, configuration backup and operational troubleshooting.

Configured and supported Juniper MX480/MX10003 core routers with BGP and OSPF, including route policies, prefix lists, BGP communities and MPLS L3VPN for enterprise and refinery-site routing.

Administered Juniper EX3400/4300/4400 and Cisco Catalyst switching, including VLANs, 802.1Q trunking, LACP, STP/RSTP/MSTP, HSRP/VRRP and port security for Layer 2 resiliency and access-layer hardening.

Designed and supported Azure VNet, NSGs, User-Defined Routes, Private Link and ExpressRoute connectivity between cloud workloads and on-premises networks, and automated Azure network resources and security policies with Terraform.

Built Terraform and CloudFormation modules for AWS Transit Gateway, VPC peering and Azure Virtual Network/ExpressRoute connectivity, reducing hybrid connectivity provisioning time from days to hours.

Managed Cisco SD-WAN (Viptela) vSmart controllers as the centralized control plane, maintained OMP routing, centralized/localized policies and device/feature templates, and executed MPLS-to-SD-WAN migrations for 60+ remote and refinery sites.

Troubleshot vEdge-to-vSmart control connections, OMP sessions, TLOC advertisements, BFD sessions and IPsec tunnels, and converted WAN routing from OSPF/EIGRP to BGP for elastic multi-transport WAN connectivity.

Evaluated Cisco Catalyst SD-WAN, VMware VeloCloud and Fortinet Secure SD-WAN in a structured proof of concept as part of WAN modernization, documenting TCO, application performance and failover results for leadership.

Supported Palo Alto Prisma Access and GlobalProtect for secure remote access, enforcing Zero Trust access policies, HIP-based device posture checks and SSL inspection for remote and third-party users.

Designed and supported Cisco ISE policies for 802.1X/MAB-based network access control across wired and wireless endpoints, integrating with Active Directory and certificate authorities for dynamic VLAN assignment, profiling and guest onboarding for 10,000+ endpoints.

Supported F5 BIG-IP VIPRION and LTM/GTM, including virtual servers, pools, iRules, SSL/TLS offloading, HTTP compression and OneConnect optimization, reducing backend server CPU load by 30%; automated F5 configuration and health checks with Ansible and Python.

Established automated health monitoring, firmware upgrades and patch management for F5 and Palo Alto platforms using Ansible and Python, reducing maintenance windows by 50%.

Monitored wireless performance using Aruba AirWave and Cisco Meraki dashboards, analyzing client health, AP utilization, channel utilization and latency, and performed RF tuning and AP placement optimization for plant and office environments.

Developed Python scripts (Netmiko, REST APIs) for configuration backups, compliance validation and bulk changes, and Ansible playbooks for repeatable multi-vendor network configuration deployment across Juniper, Cisco, Palo Alto and F5.

Performed proactive bandwidth trend analysis and capacity forecasting using NetFlow and SolarWinds NTA, executing timely circuit and hardware upgrades and publishing SLA conformance reports to stakeholders.

Acted as primary incident lead for P1/P2 network emergencies, resolving critical incidents within SLA, leading post-mortem RCAs and implementing permanent fixes; maintained adherence to severity-based response SLAs.

Participated in quarterly disaster recovery and business continuity tests, validating failover of firewalls, ExpressRoute/MPLS circuits and data center links to secondary sites and updating BCP runbooks.

Provided Tier 3 escalation support for complex firewall and network security issues, including NAT/PAT configuration analysis, VPN and traffic-flow troubleshooting with packet captures and log analysis.

Coordinated with circuit and ISP vendors on WAN link installations, upgrades, outage escalations and capacity planning, and managed vendor TAC cases through resolution to maintain network availability.

Maintained technical documentation, Visio network diagrams, configuration baselines and operational runbooks in ServiceNow to support change management, audits (SOX, NERC CIP-aligned controls) and knowledge sharing.

Supported VMware vSphere/vCenter/ESXi networking (vSwitch/vDS, port groups, VLAN tagging) and NSX segmentation for virtualized workloads in the data center.

Overlake Health, India Aug 2021 - July 2022

Network Engineer

Responsibilities:

Supported enterprise network infrastructure for Overlake Health, a regional healthcare provider, managing LAN/WAN connectivity across hospital campuses, outpatient clinics and administrative offices to ensure uninterrupted access to clinical systems.

Administered Cisco Catalyst switches and Cisco ISR routers supporting nurse stations, clinical workstations, biomedical devices and hospital IT infrastructure across core, distribution and access layers.

Designed and enforced VLAN segmentation to isolate medical devices, patient monitoring systems, EHR (Epic/Cerner) traffic and guest/patient Wi-Fi from clinical and administrative networks, supporting HIPAA-compliant network security.

Configured and maintained Cisco ASA and Check Point firewalls to secure connectivity for Electronic Health Record (EHR) systems, PACS/imaging servers and lab systems, implementing NAT, access rules and site-to-site VPN for inter-facility connectivity.

Supported hospital-wide wireless network (Cisco/Aruba) for clinical mobility carts, tablets, nurse call systems and Wi-Fi-enabled patient monitoring devices, performing RF troubleshooting and coverage validation across patient-care areas.

Configured and troubleshot VoIP telephony and nurse call/emergency communication systems, ensuring reliable connectivity for code alerts, rapid-response communication and clinician paging.

Administered TACACS+/RADIUS authentication integrated with Active Directory for role-based access control to clinical and administrative network resources, supporting HIPAA access-control requirements.

Monitored network performance and availability across hospital and clinic locations using SolarWinds and Wireshark, proactively identifying and resolving issues impacting clinical applications and patient-care systems.

Performed vulnerability assessments, security patching and CIS/HIPAA-aligned hardening of network devices supporting Protected Health Information (PHI) systems, coordinating remediation with compliance and security teams.

Supported MPLS and site-to-site VPN connectivity between hospital, clinic and data-center locations for centralized EHR access, imaging-archive replication and telehealth application traffic.

Provided Tier 1/2/3 network support for clinical and administrative staff, resolving connectivity incidents affecting EHR, nurse call and biomedical device systems with minimal disruption to patient care.

Assisted with network readiness and cabling for new clinical equipment rollouts, imaging suites and telehealth carts, coordinating with biomedical engineering and clinical IT teams.

Maintained network documentation, IP address schemas and configuration backups for hospital network infrastructure to support audits, disaster recovery and HIPAA compliance reporting.

Wipro, India May 2020 - July 2021

Network Administrator

Responsibilities:

Installed, configured and supported Cisco 3750/3850/2960 switches and Cisco 2900/3900/4400 ISR routers across core, distribution and access layers in enterprise LAN/WAN environments.

Configured and troubleshot BGP, OSPF and EIGRP routing protocols and HSRP/VRRP first-hop redundancy to maintain reliable, resilient network connectivity.

Administered VLANs, 802.1Q trunking, VTP, inter-VLAN routing, STP/RSTP/MSTP, port security and EtherChannel/LACP across enterprise switching infrastructure.

Supported Check Point firewalls (R77/R80, SmartConsole, Gaia), including security policy changes, NAT, VPN communities, policy installation and connectivity troubleshooting; analyzed change requests and performed firewall upgrades.

Configured Cisco ASA 5500-X firewalls, including Static/Dynamic NAT, PAT, access rules, object groups and site-to-site IPsec VPNs, and installed Juniper SRX firewalls with remote-access IPsec VPN.

Supported MPLS Layer 3 VPN environments using VRF and MP-BGP for customer network segmentation and WAN connectivity, and coordinated with service providers on circuit turn-ups and troubleshooting.

Configured and supported TACACS+ and RADIUS (Cisco ISE/ACS) integrated with Active Directory for centralized authentication, authorization and accounting.

Deployed and tuned Sourcefire/Cisco Firepower IPS sensors across data center and web-hosting environments, and conducted regular security audits and CIS hardening benchmark checks.

Monitored network availability and performance using SolarWinds, HP OpenView and Wireshark, investigating alerts, interface utilization, NetFlow data and connectivity issues.

Troubleshot TCP/IP, ACL, routing, switching, DNS/DHCP, VPN and network performance incidents in production environments, providing Tier 1/2 support and documenting resolutions in an internal knowledge base.

Performed rack-and-stack, cabling and staging of Cisco switches, including structured cable management and labeling within IDF/MDF network closets, and validated endpoint connectivity post-migration.

Installed, configured and supported network hardware including switches, routers, firewalls and Cisco/Aruba wireless access points across LAN, WAN and WLAN environments.

Maintained and troubleshot fiber network infrastructure and related physical-layer systems supporting enterprise connectivity.

Administered telecommunications systems, including VoIP phone infrastructure, video conferencing systems and clock synchronization platforms, and supported enterprise mass-notification and emergency messaging platforms.

Responded to and resolved service desk tickets and connectivity requests, coordinating with vendors and internal IT staff on system upgrades, installations and change management.

Supported Extreme Networks and Fortinet devices as part of network security and access-layer refresh initiatives.

Assisted with endpoint provisioning and management using Microsoft Intune and CrowdStrike EDR for Windows-based systems, supporting user onboarding and offboarding.

Developed Python and Bash scripts for configuration backups and repetitive operational tasks, and assisted with root-cause analysis, risk identification and hardware lifecycle planning.



Contact this candidate