

Insightful Network and Security Architecture/SME dedicated to providing strategic and technical leadership to technical teams. Skilled in Project Capex Costing, Opex Saving, Interconnecting Large Network Mergers, On-perm to Cloud Migration, Optimized and Cost Effective solution with critical BAU/Operation support and resolving complex information technology problems by performing technical root cause analysis. Quadruple CCIE Certified in R&S,Security,DC and Service Provider.
Zscaler
Owns the lifecycle management of GRE/IPSEC tunnels for secure data transport to/from all new site locations.
Provides technical expertise during P1/P2 calls for Zscaler client related troubleshooting.
Responsible for configuring and calibrating security controls like file blocking, bandwidth control, URL filtering, firewall policies, and SSL inspection to ensure optimal security posture.
Manages internal services and applications using Zero Trust principles through ZPA Application Management.
Supervise App Connectors for optimal performance across diverse regions (AMER, EMEA and APAC).
Integrating OKTA to provide differentiated authentication based on user profiles.
Infloblox
Managing IPAM for Company's IPv4 (public/private) CIDR blocks allocation.
Aligning and Implementing DDI infrastructure (DNS, DHCP, NTP) according to business needs.
Management of multiple Grid Masters (GMC & GM) in the company's 3-region grid architecture.
Paloalto:
Participated in designing and deploying a secure CNF, MCX, Cloud and DC firewalls with various layer (L2, L3) and deployment options (inline, multi-Vsys).
Implement a configuration management strategy with global templates and environment-based device groups for centralized control and efficiency.
Responsible for configuring, maintaining, and troubleshooting Panoramas and log collectors for efficient log management across cloud, on-premises, and manufacturing environments.
Utilize Skybox in collaboration with the Internal Security Audit team to align with compliance mandates.
Implementing NGFW features such as App-ID, URL-Filtering, User-ID, DNS-Security and AIOPS along with PANOS Code upgrades.
Contribute to the process of identifying and removing unauthorized firewall rules following established SOPs for each environment.
Provides technical expertise during P1/P2 calls for firewall and traffic flow related troubleshooting.
Migration of Data Center Cisco ASAs to Palo Alto leveraging the Expedition tool.
Contribution in building a framework for managing iDMZ and mDMZ firewall rules within a manufacturing environment.
File and vulnerability checks.
Fortinet:
Participate in building a test environment (PoC lab) to demonstrate Fortinet SDWAN capabilities.
Setting up a scalable network using regional hubs and branch offices, managed by FortiManager and FortiAnalyzer.
Enabling intelligent traffic routing scenarios across a global SD-WAN network through BGP
Configuring and Testing global policies and create IPSEC/GRE tunnels by using pre-define templates.
Cisco ASA/ISE
Building and configuring redundant Cisco ASAs (ASA 5585) and Multi Context Data Center Firewall Segmented 4 data centers in AMER, EMEA and Singapore.
Cisco Anyconnect Remote Access VPN deployment in 5 Datacenters of NA, EMEA and APAC.
TCACAs Authentication and onboarding on Cisco ISE globally.
Managed Web Proxy and URL Filtering using Onperm Web Security Appliances across the three region.
Multi Cloud Exchange / CNF Architecture and Deployment:
Architect and deployed 8 CNFs / MCX in AMER, EMEA and APAC to provide Global Connectivity to Takeda Enterprise Cloud in AWS.
Technical lead of the deploying 20+ Nexus 9504s, PA 7050s, PA5450s, Cisco ASRs1001HX and C8500-12X
Technical lead of migrating Application/Services from Lagacy AWS environments to Takeda Enterprise Cloud Globally via Overlay Transport Virtualization and loop free redundant 10G Direct Connects in Regional AWS Cloud.
Technical lead of decommissioning and migration of Network Services from 5 Data Centers in USA.
Planning, roadmap development, Configuration and troubleshooting of Routing and Switching Network infrastructurefor Data Centers, manufacturing plants and office facilities. Features include BGP, MPLS, OSPF Routing Protocols onCisco IOS/IOS XE Router, Nexus Switching, Layer3 Redundancy, Inter VLANs, Ether channel, VPC, STP configuration on Nexus 7K, 5K/2K and Catalyst VSS/Stackable Switches
WAN integration and Inter-regional routing designing/implementation for Companies merger with IP Remediation within NA/EMEA/APEC Regional Data Centers in 18 locations over 10 Gig CNF Links and 700 Overlapped subnets without a single network disruption.
Contributed IP Overlap remediation across company global network during two acquisitions.
Contributing in Architecting and deploying Cisco Wireless LAN for centralized switching and Flex Connect.
• Routine troubleshooting activities using Network Monitoring and Logging tolls including SPLUNK, LiveNX and
Aternity.
• Firewall traffic flow Investigation and Remediation task through regular expression strings on SPLUNK 6.5.3.
• Configuring Web security access policies, Identity Profiles, Allowed/Block Domains List, CLI packet logs on 12 Web Security Appliances S680 (WSA – 9.1.2-022 GD) through M680 SMA – 10.1.0-052 MD, Configuration Master 9.0.
• Designing and commissioning of more than 25 Site to Site IPSEC VPN setups between Data Centers and Business Partners and multivendor VPN Peer Appliances includes IPSEC parameters, NAT/PAT and Firewall access
permissions.