Summary
Overview
Work History
Education
Skills
Certification
Professional Training
Interests
Work Availability
Quote
Timeline
Generic
Kazi Islam

Kazi Islam

CyberSecurity Engineer/Architect
Haymarket,VA

Summary

Computer security professional with 15 years of progressive experience in CyberSecurity industry. Demonstrated skill identifying business risks and compliance issues and designing proactive solutions. Background designing and implementing layered network security approaches.

Overview

16
16
years of professional experience
11
11
years of post-secondary education
3
3
Certifications
4
4
Languages

Work History

Senior Security Engineer/Architect

ECS Federal, LLC
Fairfax, VA
10.2017 - Current
  • Federal Contractor for House of Representatives
  • Oversee operations, management and administration of the following systems and functions to protect the integrity, confidentiality, and availability of information assets and technology infrastructures of the organization: IDS/IPS , Firewalls, Anti-Virus, Event Log Analysis, Risk analysis for vulnerabilities, incidents and change requests, Data Classification and encryption of data, Manage/perform security audits, Develop security awareness instructional material, Coordinate or assist with the management and resolution of security related incidents Event Management/SIEM Management
  • Counseled senior-level management on current privacy and security trends and recommendations to mitigate risk.
  • Provided technical leadership focused on Next Generation Firewalls (NGFW)/Web Application Firewalls (WAFs) and Security orchestration, automation and response (SOAR) Tools.
  • Represented company's technical security interests to partners to provide bi-directional flow of technical information and best practices in information security.
  • Strong knowledge of Cloud technologies and architectures, including Amazon Web Services and Microsoft Azure - Broad experience building cloud infrastructure using infrastructure-as-code tools like AWS CloudFormation or Terraform
  • Built Amazon Web Services (AWS) Infrastructure from ground-up in order to deploy security tools in the cloud. Used VPC-Peering tunnel to create a fully redundant configuration which provided high-availability and business continuity protection. Experience in deploying and monitoring applications on various platforms using Elastic Beanstalk, setting up the life cycle policies to back the data from Amazon Web Services AWS S3 to AWS Glacier, various AWS EC2 and S3 CLI tools
  • Architected new RSA Netwitness infrastructure to provide organization 30% cost savings over previous implementation. Reduced the number of decoders in half (from 12 to 6), while cutting down the total number of concentrators from 7 to 4. Increased storage to allow 60 days of log retention facilitating better event correlation by analysts.
  • SME for Firewall Optimization Tools. Replaced Firemon with Tufin Orchestration Suite, including SecureTrack & SecureChange modules used for cleanup, optimization and automation of Enterprise-wide Network Security Policy. Helped meet audit requirements by Inspector General (IG)
  • Administered both on-prem (960) and CloudGen Barracuda Web Application Firewall (WAF) as a proxy server in order to protect internal and external websites in a Hybrid environment. Working on transitioning to Akamai Security Center pushing WAF functionality to the edge.
  • Assisted in taking Cloud Access Security Broker (CASB) from Proof of Concept to production. Assessed top Magic quadrant solutions from McAfee, Netskope and Symantec. Helped implement McAfee MVISION (now Trellix SkyHigh).
  • Championed process improvement of organization wide Enterprise Firewall Change Requests to include System Owner approval for increased accountability.
  • Upgraded HA implementation of FireEye CMS to latest version.
  • Implemented 4 Principles of Servant Leadership to foster a vibrant work environment.

Firewall Engineer

Trowbridge & Trowbridge LLC
McLean, VA
11.2015 - 10.2017
  • Federal Contractor for U.S Bureau of Labor Statistics (BLS)
  • Applied leading theories and concepts to development, maintenance and implementation of information security standards, procedures and guidelines.
  • Leading a team of four security engineers who were responsible for building and deploying security devices in customer networks
  • Responsible for Checkpoint Firewall Administration and Operational Support and Checkpoint Firewall Appliances in Clustered Configuration (Active/Passive)
  • SME and main administrator for McAfee Web Gateway (MWG) used for Enterprise-wide URL Filtering. Managed Proxy Server Upgrade Project including rewriting the PAC file, configuring Central Management and Proxy HA
  • Configuring New Client connectivity via Site2Site/Remote/SSL VPN, clustering and ISP redundancy on Checkpoint firewall
  • Researched and implemented a process for migrating all customer terminating VPNs from CheckPoint to Cisco ASA
  • Managing 200+ Firewalls deployed across the site, primarily Checkpoint Firewall on 4400/4800 & Nokia IPSO
  • Responsible for upgrading UTM-1 Edge appliances to CheckPoint 1100/1430 Firewalls for All 50 States & U.S Territories
  • In charge of creating SOPs covering all operational procedures
  • Provide Tier-3 troubleshooting support on all managed devices and supported technologies
  • Utilized AlgoSec AFA 6.9 to assist in drafting rules/policies and performing forensics analysis
  • Monitored network via Solarwinds NPM and maintained it as Source of Truth (SOT) for all Firewall related data.
  • Planned and oversaw configuration changes for security infrastructure platforms. Helped implement Managed Trusted Internet Protocol Service (MTIPS).

Engineer, IT Administrator

VERISIGN INC
Reston, VA
06.2007 - 06.2015
  • As a member of NOC/SOC, in a team of 20, working in 3 shifts to provide 24/7 coverage while meeting our 99.998% SLA for TLD .COM & .NET 16-year uptime
  • Administered Cisco/Juniper/Brocade/Arista routers & switches, F5 Load Balancers
  • Possess solid understanding of Network Fundamentals, Windows Server & VoIP Architecture, TCP/IP Protocol suite and default TCP/UDP ports. Also experienced in NAT and PAT
  • Good understanding of SNMP and other Network management protocols, ISO and TCP Models
  • Adept at using ping, arp, netstat, curl, wget, dig etc to troubleshoot and resolve access issues
  • Experience in Web Content Filtering through internal platform as well as Arbor Networks Peakflow, Procera and other tools
  • Used Splunk, Thousand-Eyes, Pingdom and many 3rd-party tools for monitoring and investigating
  • Support critical infrastructure for registry operations & Global DNS by pushing Root and ARPA Zone to organizations worldwide
  • Possess SOX compliant knowledge of Security issues
  • Performed DDoS Mitigation for Managed Services Dept. Planned and created Site-to-Site Tunnels
  • Monitor system & network alarms via Netcool, Nagios & Naemon
  • Spearheaded ITIL-based CIS Dept Initiative to provide one-on-one in-person concierge support through the Technical Support Service Center (TSSC). Improved customer satisfaction by 50% and reduced support center calls by 35%
  • Deployed and administered Trusted Platform Module (TPM) via Wave Systems ERAS Full Disk Encryption (FDE). SME for Wave Systems EMBASSY Remote Administration Server FDE & SED Solution
  • Installed and managed Checkpoint PointSec FDE
  • Trained employees across multiple departments on network operations including log-in procedures, network management software, permissions, printing issues, security and use of software
  • Managed Active Directory, ADP, Oracle, Service-Now, MS SMS/SCCM

Education

Bachelor of Science - Information Technology

Strayer University
09.2009 - 06.2015

Associate of Applied Science (A.A.S) - Computer Information Systems

Queensborough Community College (CUNY), CIS
Bayside, NY
09.1995 - 01.2001

Skills

    Designing security controls

Implementing security programs

Security infrastructure architecture

Cloud implementation

Internet-facing project

Erecting firewalls

Certification

ITILv3 Foundation

Professional Training

Anchor Technologies, Inc. - Columbia, MD

Check Point Certified Security Expert (CCSE) R80.30  Jul 2019

Check Point Certified Security Admin (CCSA) R80.20  Jun 2019

ExitCertified Corporation - Reston, VA

Architecting on AWS  Sep 2018

Checkpoint – Las Vegas, NV

Advanced Threat Management  Sep 2016

Stanly Community College / VMware IT Academy, Online

VMWare vSphere 5.5  May 2016

Intellectual Point – Reston, VA

CISSP Preparatory Course  Dec 2015

Learning Tree International — Reston, VA 

Linux Administration and Support  Dec 2014

CCNA Boot Camp (CCNAX)  Jul 2013

CompTIA Security+ Certification Exam Prep  Jun 2012

Integrating Mac OS X into a Windows Environment             Aug 2011

Mac Essential for PC Users: Hands-On               Mar 2010 

Interests

Building Custom PCs

Movies

The Great Outdoors/Travel

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Quote

Life shrinks or expands in proportion to one’s courage.
AnaÏs Nin

Timeline

Senior Security Engineer/Architect

ECS Federal, LLC
10.2017 - Current

ITILv3 Foundation

12-2015

Firewall Engineer

Trowbridge & Trowbridge LLC
11.2015 - 10.2017

SOASTA Foundation Exam

06-2014

CompTIA Security+

06-2013

Bachelor of Science - Information Technology

Strayer University
09.2009 - 06.2015

Engineer, IT Administrator

VERISIGN INC
06.2007 - 06.2015

Associate of Applied Science (A.A.S) - Computer Information Systems

Queensborough Community College (CUNY), CIS
09.1995 - 01.2001
Kazi IslamCyberSecurity Engineer/Architect