
A creative and energetic IT professional with over 20 years experience focusing in network infrastructure and security. Committed to designing and building robust data communication networks.
• System administration and configuration Linux (Ubuntu, Redhat, Centos, Cumulus) and Windows (Window Server).
• Active Directory administration.
• Azure AD (Microsoft Entra ID) administration.
• Office 365 administration.
• Systems administration of Cisco ACI and Cisco Firepower – upgrades and policy configuration.
• Configuration of Cisco Nexus\Catalyst, Juniper EX series and NVIDIA switches.
• Configuration of Cisco ASA\FTD and Palo Alto firewalls.
• Advanced configuration of AWS, Azure and Gcloud infrastructure.
• Configuration of BGP\OSPF and EIGRP.
• Network monitoring with Zabbix and Nagios: configuration of custom scripts for monitoring and host and service discovery.
• Azure: designed and configured Azure Virtual Networks, subnets, Azure network settings, DHCP address blocks, DNS settings, NSGs, deployed Azure IaaS virtual machines (VMs) and cloud services (PaaS role instances) into secure VNets and subnets.
• Creation of Python scripts to automate switch and firewall configuration.
• Network device support: responsible for the maintenance and configuration of Cumulus, Nexus 5000, Cisco 6500, Cisco 3650, Juniper EX 4200, Palo Alto 5060 devices.
• Configuration of F5 Big IP load balancers: integration into Azure DevOps pipelines, configuration of virtual servers, server pools, certificates, upgrades and ASM security policies.
• Configured VMware in clustered environment, implemented migration of virtual machines using VMotion, virtualized Windows and Linux servers using VMware Converter and Platespin PowerConvert.
• Windows: support, administration, update and configuration of Windows 2016\2019, Active Directory administration
• Create and maintain fully automated CI/CD pipelines for code deployment using Octopus Deploy and PowerShell
• Actively manage, improve, and monitor cloud infrastructure on AWS, EC2, S3, and RDS, including backups, patches, and scaling.
• Configuration and administration of F5 LTM, NGINX and HAPROXY.
• Advanced configuration of Azure\on premise hybrid infrastructure.
• Configuration of Cisco Nexus\Catalyst and NVIDIA switches.
• Configuration of Microsoft HCI, Vmware and Docker.
• Python, Golang and Powershell scripting for network automation.
• Use of automation tools such as Azure Devops and Git.
• Configuration of Zabbix and Sumologic.
• Configuration Postfix, Foreman.
• Remediate discovered security issues per PCI requirements.
• Maintained, monitored and configured nodes on a WAN comprised of Cisco ASA 5545\Astaro\Sonicwall firewalls, Cisco Catalyst 4500\6500 and Nexus 5000 switches.
• Configuration and implementation of firewall security policies on Cisco ASA 5545\Astaro\Sonicwall firewalls.
• Configuration and troubleshooting of routing protocols (BGP\OSPF\EIGRP).
• Network monitoring with Nagios, Cacti and Solarwinds.
• Configuration (VLANS\802.1x\security policies) and deployment of wireless infrastructure based on Aruba\Cisco Mobility Express.
• Windows system administration (configuration of group policies, login scripts) in a 2012\2016 Active Directory domain.
• Linux (Centos, Ubuntu, RedHat) systems administration, configuration and patching.
• In depth knowledge of AWS cloud compute, network, storage and identity and access management services.
• Deployment and configuration of on premise and AWS infrastructure (VPC, subnets, Internet gateway, NAT, route tables, instances) utilizing Cloud Formation, AWS OpsWorks and Chef.
• Experience creating and managing playbooks in Ansible.
• Experience with versioning tools like GitHub (GIT), Subversion (SVN) and software builds tools like Apache Maven, Apache Ant.
• RHEV\VMWare administration and configuration.
• Email administration: Office 365, Postfix configuration, DKIM, SPF and DMARC configuration.
• Python scripting to automate the configuration of switches, firewalls and Linux servers.
• Installation, configuration and deployment of Docker containers for deploying cloud native applications.
• Installation and configuration of Cisco UCS.
· Engineering team lead supporting and designing enterprise networks of multiple Eden Technology commercial clients.
· Installed, configured and administered VOIP infrastructures (Asterisk, Cisco and Avaya)
· Microsoft Exchange migrations to Office 365 and or Exchange 2010\2013
· provisioning messaging security via spam filtering, DKIM\Domain Keys, SPF and DMARC
· software, package deployment and systems management utilizing Altiris, WSUS and SCCM
· designed and implemented cloud based and on premise backup and DR solutions (Vembu, Acronis, Veeam, Datto)
· performed network penetration testing and security audits (NMAP, Network Security Toolkit, Metasploit, OpenVAS)
· deployed and configured intrusion detection and SIEM systems (Alien Vault, OSSIM, Event log Analyzer)
· Cisco firewall router install and configuration
· deployed and supported virtual environments based on VMware, Hyper-V or Linux KVM; virtualization of existing physical environments
· Puppet, Ansible and\or Chef rollouts and configuration.
· Aruba, Cisco and Mist AP support and deployment.
· Active directory deployments, migrations and administration
· Configuration of Juniper M320s and PEs.
· Installed and configured 40 Microsoft Exchange infrastructures including DNS (SPF, DKIM and DMARC)
· Python scripting to automate the configuration of switches, firewalls and Linux servers.
· Installation, configuration and deployment of Docker containers for deploying cloud native applications.
· Solely supported users on a global mixed Windows 2003 Active Directory\Linux infrastructure across six regions (Brussels, London, Moscow, New York, Washington and Geneva), implementation of ITIL best practices, email and data access polices.
· Installed, configured and administered a global, SIP trunked, Asterisk PBX infrastructure; configure Polycom, SNOM and Aastra IP phones, troubleshoot T1\ISDN-E issues
· Installation and configuration of Snort IDS, Web sense and Spam Titan mail filtering appliances; encryption of laptops utilizing McAfee Security suite; ensure that all server, laptop and PC operating systems are updated and properly patched
· Responsible for the maintenance and configuration of Cisco ASA 5520 and Cisco 2600, HP Procure switches, Linux routers\firewalls, site to site IPSEC VPNs; VLANs; troubleshooting connectivity issues; administration of core network services (DNS, DHCP)
· Migrated a single Exchange 2003 server to a five site Exchange 2007 environment (administration of mail accounts groups); Exchange 2007 server maintenance; implementation of an instant messaging platform based on Open fire Real Time Collaboration Server; support Blackberry Enterprise 4.1 and mobile devices (Blackberry and I Phone)
· Application installation and support, VPN and remote access issues,
· Implemented disaster recovery solution with Backup Exec 12, Acronis Universal Restore and VMware ESX
· Developed a flash based video conferencing system, maintained the company website, Active Directory administration, implemented Nagios and Cacti for event notification and performance monitoring.
· Engineering team member supporting and designing enterprise networks of multiple Computer Troubleshooters commercial clients.
· Installations\upgrades of SBS 2000\2003 networks; configuration of core network services (DNS, DHCP, RRAS, RADIUS); patch management utilizing WSUS\ Level Platforms; network administration (creation of login scripts, modification of group policy)
· Installation of Exchange 2003; Exchange migrations; installation and configuration of Blackberry Enterprise servers; support of Sendmail.
· configuration of various wireless hardware (Proxim, Net gear)
· utilizing Level Platforms and\or Nagios provided monitoring and event notification for nodes on client LAN\WAN infrastructures
· Support of BlackBerry and Palm devices: configuration of web interface, mail forwarding
· Firewall\Router\Switch support: configuration of ASA 5500, Catalyst 4900, Sonic Wall, Linux routers (VLAN configurations, BGP, OSPF, VPN)
· Network migration\design: migrated 5 sites international WAN consisting of 5 sites (Hong Kong, Beijing, New York, Shanghai, Shenzhen) from Windows NT to Window s 2003 Active directory, migrated Exchange 5.5 organizations to Exchange 2003, configuration of site to site VPNs;
· Telephony support: responsible for the implementation of Asterisk PBX systems throughout the enterprise: support for roaming users, migration of existing PBX dial plans, etc;
· Network administration: responsible for the network administration of an international WAN comprising 450 users in a Windows 2003 Active Directory
· Linux\Unix support: setup and configured Nagios to provide performance data and notifications from any node in the international WAN environment, configuration of SNORT appliances throughout the enterprise;
· Patch management and software testing: responsible for the testing of operating system patches, updates and software utilizing virtual machines (Microsoft Virtual PC and VMWare) in a test environment;
· Messaging support: supported Exchange 5.5\2000\2003, migration of Exchange 5.5 to Exchange 2003 in 450 user environment;
· Router\firewall support: configure, maintain and troubleshoot Cisco 2600\2520, Checkpoint 4\TNG, Netscreen 5\5XP firewalls (IOS upgrades, traffic management, routing configuration and policy management);
· Windows NT\2000\2003 support: responsibilities include the administration \ support of a mixed Windows Active Directory environment comprising 20 NT 4 servers, 125 Windows 2000 servers and 30 Windows 2003 servers (creation\ maintenance of user accounts, DNS, DHCP, print service, patch \ software management and hardware upgrades, support of Citrix MetaFrame XP and Windows terminal services and RAS) on a global WAN, operating system upgrades, configuration of Active Directory policies;
· Linux\Unix support: setup and configured Linux (Fedora Core 2 and 3) IPsec VPN concentrators based on FreeSWAN, firewalls based on IPtables and the installation and configuration of proxy servers (Safe Squid); created custom, diskless thin terminals based on FreeBSD 5.0; kernel configuration of Redhat\Fedora Core servers (configuration of X Windows and kernel parameters to allow diskless operation), compilation of software from source and administration of user accounts;
· Patch management and software testing: responsible for the testing of operating system patches, updates and software utilizing virtual machines (Microsoft Virtual PC and VMWare) in a test environment;
· Web development: utilizing Apache, PERL, PHP and MySQL created portals for the use of file sharing with outside vendors;
· Messaging support: support of Exchange 5.5\2000\2003, lotus domino 6.54 and Sendmail 8-9 (database maintenance, configuration and performance tuning) and mail account administration;
· Router\firewall support: configure, maintain and troubleshoot Cisco 2600\2520, Checkpoint 4\TNG, Netscreen 5\5XP firewalls (IOS upgrades, traffic management, routing configuration and policy management);
· Data backup and disaster recovery: utilizing Veritas NetBackup, Arcserve, Backup Exec and sync designed and implemented a backup\restore strategy for over 60 sites
· Network infrastructure design\planning: as a member of the Global Network Services team maintained, installed, configured and planned the deployment and placement of Windows 2000 \ 2003 and Fedora Core 2 servers throughout the enterprise; creation of a single sign on method for users of Debian workstations in an Active Directory environment utilizing OpenLDAP and Kerberos;
· Network monitoring\security\virus control: setup monitoring of network nodes and services on a global WAN comprised of over 60 sites utilizing NAGIOS and HP Open View, performed network vulnerability assessments of routers and firewalls on a monthly basis utilizing Open source tools (Nmap, Ettercap, Nessus) , implementation of SPAM filtering \ virus detection Linux email filters utilizing Spam Assassin and Kaspersky Antivirus; also implemented a public key infrastructure for sensitive email transmissions
· Server migrations \ upgrades: migration of Windows NT 4 Servers to Windows 2000 Active Directory, migration of Exchange 5.5 accounts to Exchange 2000, desktop migrations from Windows NT 4 \ Intranetware to Windows 2000\XP
· IP Telephony: implementation of Asterisk PBX on a Redhat platform to migrate existing POTS based PBX system to IP telephony (migration of existing dial plan, configuration of call routing and DID)
· Installation and configuration of Compaq, HP and Dell servers: RAID configuration, firmware updates, installation\upgrades of Linux, Windows NT \2000 and Novell
· Network administration\engineering in Active Directory, Linux, Novell and\or mixed platform environments: creation and maintenance of user\group accounts, definition and application of network access policies and procedures, IPv4\v6 address and service (DHCP, DNS, WINS) management, print queue management , patch and software distribution, scripting
· Desktop support: Windows 95\NT workstation to Windows 2000\XP roll outs, support of all end user requests;
· Configuration and management of network devices: routers (Cisco 2621\4500\7125\3725) and firewalls (PIX 515\520, Check Point, Linux IPTABLES), VPN \ RAS concentrators (FreeS/WAN, Intel Net Structure), DSL routers;
· Application support: Microsoft Office 2000\XP , Act 7\2000, PC Payroll for Windows, RSWIN\RSSQL, MSSQL 7\2000, Apache, AOL Server, IIS
· Introducing new technologies in server and infrastructure areas: implemented a Linux based dumb terminal solution in warehouse areas to provide real time storage data and statistics, provided VPN capability to remote offices and users via FreeS/WAN IPsec concentrators.
· Messaging support: supported Exchange 5.5\2000 in an Active Directory environment, designed an instant messaging infrastructure based on Jabber
· Network monitoring and security\integrity: SPAM control and removal (Mail Sweeper, SPAMASASSIN), virus detection and removal (Symantec Antivirus Corporate, McAfee, AMAVIS), intrusion detection and network forensics (SNORT, Encase), network vulnerability testing (Nessus, NMAP), node\service monitoring (HP Open View, Net Saint), web proxying (Squid) and content filtering\auditing (Web sense)
CCNA