Summary
Overview
Work History
Education
Skills
Areas of Technical Expertise
Certification
Education and Training
Websites
Timeline
Generic

Rooein Faghieh Nasiri

Roseville,CA

Summary

Active CCIE Routing & Switching and Security #22672 since 2008 and CISA (Certified Information Systems Auditor), with over 16 years of experience designing, securing, auditing, and automating complex enterprise network infrastructures across the education, government, healthcare, and corporate sectors.

Specialized in network architecture, security engineering, audit and compliance readiness, routing protocols, VPN technologies, SDN, and data center modernization. Trusted technical lead for numerous large-scale deployments, infrastructure migrations, and network redesign projects.

Extensive hands-on experience in multi-vendor environments including Cisco, Palo Alto, Meraki, Check Point, Juniper, Arista, HP, and Huawei. Skilled in firewall management and migration using Palo Alto Panorama, Expedition, and GlobalProtect VPN. Strong background in network automation using Python, as well as advanced monitoring, orchestration, and compliance-driven operations.

Well-versed in bridging the gap between technical implementation and regulatory alignment, ensuring that networks meet both business and security standards. Known for deep protocol expertise, resilience under pressure, and technical leadership. A proactive team mentor and clear communicator with a passion for continuous learning and staying ahead of evolving technologies.

Overview

19
19
years of professional experience
1
1
Certification

Work History

Senior Network Engineer/Architect

Portola Systems
09.2017 - Current
  • Led full lifecycle design, implementation, and troubleshooting of enterprise, data center, and multi-site network infrastructures across education, healthcare, government, and retail sectors.
  • Served as Project Lead, managing technical teams and overseeing complex deployments from planning through delivery.
  • Acted as a Tier 3 escalation engineer, resolving high-severity incidents and mentoring junior staff.
  • Provided day-to-day operational support including advanced troubleshooting, change requests, upgrades, and performance monitoring.
  • Designed secure, scalable network topologies using core, distribution, access, and data center spine-leaf architectures.
  • Extensive hands-on experience with routing protocols such as EIGRP, OSPF (multi-area), and BGP, including route redistribution, summarization, and policy-based routing.
  • Deployed and supported MPLS, VPLS, and VXLAN overlays in multi-tenant and hybrid environments.
  • Used Python for network automation tasks including bulk configuration, compliance checks, device inventory, and CLI template generation.
  • Conducted vulnerability assessments and penetration testing; implemented mitigation strategies in coordination with security teams.
  • Created detailed network documentation: physical and logical diagrams, IP schemas, ACLs, VLANs, and firewall rules.
  • Managed backups, patching, firmware upgrades, and disaster recovery planning.
  • Supported and integrated multi-vendor environments: Cisco, Meraki, Palo Alto, Check Point, Juniper, Arista, HP, Aruba.
  • Worked with various professional network monitoring systems and applications (e.g., SolarWinds, PRTG, Cisco Prime, NetFlow analyzers, LogicMonitor) for proactive performance monitoring, alerting, and capacity planning.


  • List of the Projects:

    1. Transbay Cable Project
    2. University of San Francisco
    3. Peet’s Coffee
    4. Town of Windsor
    5. Sonoma Marin Area Rail Transit (SMART)
    6. Mountain View–Los Altos High School District
    7. Northern California Medical Associates
    8. City of Healdsburg
    9. Sonoma Valley Hospital
    10. Sonoma County Fire District
    11. Sacramento City Unified School District
    12. Roseville Joint Union High School District
    13. Grammarly
    14. Fastly Inc.

Senior Network Engineer/Leader

NetXperts LLC
09.2016 - 09.2017

San Francisco International Airport – Terminals T1/T2/T3


  • Served as part of the core design team responsible for architecting the network infrastructure across SFO terminals.
  • Designed and configured core, distribution, access, and firewall devices to support mission-critical airport operations.
  • Configured and maintained routers, switches, firewalls, and load balancers to ensure high availability and performance.
  • Monitored performance and availability using enterprise-grade tools and conducted log reviews to identify and resolve inefficiencies.
  • Evaluated emerging networking technologies to enhance system reliability and performance.
  • Ensured compliance with SLAs and fulfilled all client network requirements.
  • Provided technical support to users and mentorship to junior engineers to improve team capacity and knowledge.
  • Implemented and validated networking services according to detailed solution designs and change control processes.


ClearCaptions


  • Designed and configured a Cisco ACI spine-and-leaf architecture for high-performance and scalable data center networking.
  • Troubleshot complex issues in ACI environments, significantly reducing downtime and improving network responsiveness.
  • Monitored system metrics to ensure speed, availability, and reliability across environments.
  • Configured and installed routers, switches, and firewalls to enhance overall security posture and operational performance.
  • Implemented secure remote access using firewalls and VPNs, strengthening network perimeter defenses.


Alameda Unified School District


  • Designed, deployed, and maintained LAN and WAN infrastructure across multiple campuses and administrative offices.
  • Configured Cisco ASA firewalls to provide advanced security, antivirus protection, and remote access capabilities.
  • Collaborated with cross-functional teams to align network infrastructure with district-wide educational and administrative initiatives.
  • Deployed and maintained wireless access points and controllers to ensure robust connectivity in high-density environments.
  • Met with stakeholders to advise on hardware/software decisions and deliver project updates.
  • Used network monitoring tools to optimize and upgrade infrastructure, ensuring minimal disruption and proactive maintenance.
  • Conducted scheduled maintenance during off-hours to preserve service availability.

Senior Network Engineer

RAF Co
01.2010 - 08.2016
  • Designed, implemented, and maintained a secure multi-branch MPLS intranet network, enabling seamless and encrypted interoffice communication and collaboration.
  • Configured and managed over 30 Cisco routers, 20 Catalyst switches, and 4 VPN routers, ensuring reliable WAN and LAN connectivity across all sites.
  • Maintained and monitored 3 Cisco ASA firewalls in collaboration with the Network Security team, enhancing security posture and enforcing access control policies.
  • Delivered 24x7 support, consistently achieving >99% network uptime across all critical business locations.
  • Actively participated in network redesign projects to improve segmentation, redundancy, scalability, and encryption.
  • Configured and supported WAN links including MPLS, Point-to-Point, and Point-to-Multipoint topologies.
  • Consolidated legacy routing protocols (RIP, IGRP, EIGRP) into a unified OSPF domain, improving route convergence and network scalability.
  • Deployed redundant network architectures using HSRP, VRRP, and dual-homed switches to ensure high availability and fault tolerance.
  • Designed and installed robust enterprise networks with Cisco routers, Catalyst 6509 switches, and Firewall Services Module (FWSM) in HA mode with OSPF.
  • Used SolarWinds for network monitoring and performance optimization, proactively resolving latency and throughput issues.
  • Collaborated with cross-functional teams to plan and implement new networks or modify existing designs based on evolving business needs.
  • Identified, analyzed, and resolved network performance bottlenecks, ensuring consistent and secure connectivity.

Network Engineer

TekData
01.2007 - 12.2010
  • Designed and implemented customized network solutions for new clients, ensuring scalability, performance, and alignment with business needs.
  • Worked closely with the sales team to scope technical requirements, propose solutions, and deliver successful post-sales implementations.
  • Installed and configured Cisco routers and switches across small to mid-sized customer environments, following project-specific topology and security guidelines.
  • Configured network services and infrastructure including DHCP, DNS, and Active Directory on Microsoft Server 2003 platforms.
  • Installed, configured, and supported network monitoring tools such as SolarWinds, enabling visibility into performance metrics and alerts.
  • Provided hands-on support for Huawei routers in client environments where alternative vendor solutions were required.
  • Applied OS and firmware updates across servers, routers, switches, and firewalls to maintain stability and security.
  • Replaced or upgraded faulty hardware components to restore and enhance network performance with minimal disruption.

Education

Master of Arts - Management

UOFTehr
08-2014

Skills

  • Data center networking
  • Network architecture design
  • ITIL framework
  • Network security implementation
  • SD-WAN implementation
  • Network automation tools
  • Data center architecture
  • Network troubleshooting expertise
  • Layer-2/3 protocols
  • Network troubleshooting
  • Networking and routing protocol expertise
  • Project management experience

Areas of Technical Expertise

Routing & WAN Technologies

Protocols: BGP (expert), OSPF (multi-area), EIGRP, IS-IS, RIP, Policy-Based Routing, Redistribution

Transport: MPLS, VPLS, VXLAN (expert), GRE, DMVPN, Frame Relay, PPP, PtP/PtMP

Redundancy: HSRP, VRRP, GLBP, EtherChannel, ECMP, StackWise, VSS

Security & Firewall Management

Cisco ASA 5500-X, Firepower NGFW, FTD, FMC, PIX, IPS/IDS

Palo Alto Networks: GlobalProtect VPN, Panorama, Expedition

Cisco ISE (2.x+), ACS, RADIUS, TACACS+, IPsec/SSL VPNs

Check Point firewalls, DUO MFA, Cisco AnyConnect (Remote Access VPN)

Switching & Data Center

Cisco Catalyst: 1800–9000 Series, C9300/C9500, 6500, 4500

Nexus NX-OS 2K/3K/5K/7K/9K (vPC expert)

Cisco ACI, Cisco DNA Center, spine-leaf architectures

High Availability: vPC, StackWise, SSO, HA firewall pairs

Network Automation & Monitoring

Python scripting (config automation, compliance, audits)

Tools: SolarWinds, PRTG, LogicMonitor, Cisco Prime, NetFlow, SNMP, Syslog

Orchestration: Ansible, REST APIs, Cisco DNA workflows

Visualization: Microsoft Visio, Draw.io

Cloud, Virtualization & Systems

Hybrid integration: Azure/AWS VPN, cloud route management

Microsoft Server 2003–2019: DHCP, DNS, Active Directory

VMware vSphere/ESXi, Load Balancers, clustering

IT Operations & Documentation Platforms

Datto (BCDR), Autotask PSA, IT Glue (documentation),

IPAM (IP Address Management tools)

Atlassian tools: Confluence, Jira (ITSM & project tracking)

Professional & Interpersonal

Project leadership, customer-facing delivery, pre-sales engineering

Team mentoring, escalation handling (Tier 3), technical presentations

Compliance awareness (CISA), documentation, continuous learning

Certification

  • CCIE#22672 Routing and Switching
  • CCIE#22672 Security
  • CISA Certified
  • CCNP Enterprise Infrastructure
  • Cisco Certified Specialist - Enterprise Advanced Infrastructure Implementation
  • Cisco Certified Specialist - Security Identity Management Implementation
  • Cisco Certified Specialist - Enterprise Core certificate
  • Cisco Certified Specialist - Security Core certificate
  • Palo Alto Certified Network Security Engineer
  • IPv6 Network Engineer (Gold)

Education and Training

Project Management (PMP)

Timeline

Senior Network Engineer/Architect

Portola Systems
09.2017 - Current

Senior Network Engineer/Leader

NetXperts LLC
09.2016 - 09.2017

Senior Network Engineer

RAF Co
01.2010 - 08.2016

Network Engineer

TekData
01.2007 - 12.2010

Master of Arts - Management

UOFTehr