Professional Summary
Senior Network Security Engineer with 10+ years securing large-scale hybrid cloud and on-premises infrastructure, including 6+ years administering an enterprise environment of 3,500+ firewalls at a Fortune 50 retailer. Led enterprise-wide Zero Trust Network Access (ZTNA/SASE) deployments, and currently driving microsegmentation with Akamai Guardicore, cloud firewall automation in GCP, and identity-based access integration with Entra ID. MS in Cybersecurity and Information Assurance; U.S. Air Force veteran with a proven record of leading teams, authoring documentation, and operating independently in remote, cross-functional settings.
Core Technical Skills
Firewalls & Network Security
Palo Alto NGFW / Panorama, Fortinet FortiGate, Cisco ASA, Check Point, microsegmentation (Akamai Guardicore), firewall policy design, network segmentation, SSL inspection, DLP
Zero Trust / SASE / VPN
FortiSASE, Atmos by Axis (HPE), Zscaler ZPA/ZIA, GlobalProtect, FortiClient, Cisco AnyConnect, clientless ZTNA
Cloud & Automation
GCP, Azure, OCI; cloud-native firewall deployment, Panorama automation, Python (scripting familiarity), Linux
Identity & Access
Microsoft Entra ID, identity-based access control, least-privilege enforcement, IAM collaboration
Security Operations
SIEM analysis (Splunk, OpenSearch), EDR telemetry, incident response support, threat hunting / IOC analysis, vulnerability mitigation
Infrastructure Services
Infoblox DNS/DHCP, DNS sinkholing, F5 LTM/WAF (iRules, VIP management), Cisco routing/switching (NX-OS, Catalyst)
Governance & Frameworks
NIST SP 800-53, NIST SP 800-207 (Zero Trust), ISO 27001, FedRAMP environments, security documentation & runbooks
Professional Experience
- Administer and maintain enterprise firewall infrastructure of 3,500+ Palo Alto and Fortinet firewalls across centralized and decentralized deployments, including full lifecycle upgrades, patching, and hardware refresh cycles.
- Led the enterprise rollout of Zero Trust Network Access, deploying Atmos by Axis and later migrating the environment to FortiSASE, integrated with IAM, EDR, and SSE platforms to reduce attack surface.
- Implementing an enterprise microsegmentation initiative using Akamai Guardicore, designing segmentation policies that restrict lateral movement and reduce attack surface across enterprise workloads.
- Architected and implemented Atmos Air, a clientless ZTNA web solution built from the ground up to give third-party partners secure access to enterprise systems without endpoint agents.
- Scaled Palo Alto NGFWs in GCP using cloud-native deployment methods and Panorama integration, enabling automated, consistent policy enforcement across cloud workloads.
- Evaluate and implement risk-based, non-standard firewall change requests for complex enterprise applications while maintaining compliance with segmentation strategy and NIST SP 800-53-aligned policy governance.
- Integrate identity-based access controls with Microsoft Entra ID, enforcing least-privilege access in partnership with IAM and security architecture teams.
- Analyze SIEM (Splunk, OpenSearch) and EDR telemetry to support incident response, APT investigations, IOC identification, and enterprise hardening initiatives.
- Administer Infoblox DNS/DHCP services, including DNS sinkholing and blocklist enforcement supporting threat containment.
- Tune F5 WAF rule sets with application teams to reduce false positives; author operational runbooks and lead internal training for security and operations teams.
- Redesigned a FedRAMP-secure network environment, improving segmentation, routing, and overall firewall posture for regulated workloads.
- Reduced firewall rule complexity by approximately 25%, improving operational efficiency and audit readiness.
- Administered Infoblox DNS/DHCP and supported F5 WAF rule tuning; escalated and resolved network and vendor issues under strict SLA and change-management processes.
- Maintained LAN/WAN security and availability across enterprise systems, diagnosing and resolving critical performance and security incidents in real time.
- Performed day-to-day network administration, monitoring, and alert response, including DNS/DHCP operations and DNS sinkhole enforcement.
- Troubleshot and resolved hardware, software, and network issues; supported end users locally and remotely.
- Configured and supported workstations and network infrastructure; assisted with firewall configurations, B2B network integrations, and backup operations.
- Led teams of 4–16 personnel in high-risk operational environments, assigning workloads and priorities under strict safety and quality compliance.
- Developed process improvements that reduced job completion time while increasing inspection pass rates by 20%.