Summary
Overview
Work History
Education
Skills
Certification
Timeline
EDUCATION AND TRAINING
Generic

Saif Alani

Tomball,TX

Summary

Senior Network Engineer with 20 years of comprehensive experience in the design, implementation, and management of robust network infrastructures in both cloud and on-premises environments. Possesses strong expertise in network security, switching technologies, and architectural design, with a demonstrated ability to optimize network performance and enhance security measures. Skilled in collaborating with cross-functional teams to create innovative solutions that foster operational efficiency and adapt to changing business requirements. Committed to utilizing advanced technical knowledge and industry best practices to achieve resilient, secure, and scalable network systems.

Overview

20
20
years of professional experience
1
1
Certification

Work History

Sr.Network Engineer ( AWS)

Parexel-Goverments Accounts
Roseville, California
09.2019 - Current
  • Achieved efficient management of 15 AWS accounts through successful setup of EC2 instances, RDS databases, and VPCs. Delivered streamlined configurations of Elastic Load Balancers (ELBs) and Amazon Elastic Kubernetes Service (EKS). Optimized DNS record management using Route 53 on AWS cloud.
  • Configured GCP's Identity-Aware Proxy to implement a comprehensive zero-trust security framework, ensuring secure access controls.
  • Administered databases, VPC Elastic Load Balancers (ELBs), and Route 53 for effective DNS record management on AWS government infrastructure.
  • Spearheaded engineering and refinement of data ingestion indexing and search solutions utilizing Elasticsearch for enhanced real-time data analysis.
  • Diagnosed and rectified SD-WAN connectivity issues to enhance performance of critical business applications.
  • Configured and managed IPSec VPN tunnels to facilitate secure communication between hub data centers and remote branch locations.
  • Monitored and managed Elasticsearch clusters and Apache Airflow environments, ensuring optimal performance, scalability, and data integrity. This emphasizes operational and maintenance skills.
  • Conducted vulnerability scans using Tenable Nessus to identify security weaknesses.
  • Configured and managed Tenable Nessus scanners for network security assessments.
  • Implemented workflows to automatically manage user access to applications based on group membership, reducing security risks associated with stale access privileges.
  • Managed and maintained VMware NSX distributed environments, including configuration, troubleshooting, and policy enforcement.
  • Responded quickly to incidents reported by customers regarding outages or service degradation issues.
  • Utilize AWS CloudWatch and other monitoring tools to track the performance and health of cloud-based applications and infrastructure
  • Orchestrated deployment and operations for production DC and RDC remote data center networks infrastructure.
  • Experience with infrastructure as code using AWS CloudFormation or Terraform for deploying Airflow and related services.
  • Experience with configuring Fortinet's Secure SD-WAN, including setting up SD-WAN zones, defining SD-WAN rules, and integrating it with other Fortinet products (like FortiSwitch and FortiAP).
  • Managing various components such as PE Tier, CE Tier, CC Connector, PSW POD Switches, CR Cluster Switches, etc.
  • Configured and implemented Composite Network models consist of Cisco Nexus 9K, 7K, 5K, 2K, and Arista L2/L3 S7010, 7050's, and 7060's, Cisco 2950, 3500, 5000, and 6500 Series switches.
  • Implemented and maintained LAN configurations, EVPN, ACLs, VXLAN, VTP, and Spanning Tree protocols on Cisco and IOS switches in the DC environment.
  • Directed vulnerability assessments or analysis of information security systems.
  • Monitored systems for indications of threats, security breaches or intrusions.
  • Performed scheduled maintenance tasks on servers and databases, ensuring optimal performance and functionality.
  • Design, implement, and maintain Cisco ACI fabric, including APIC, Spine, and Leaf components.
  • Investigated information security breaches to identify vulnerabilities and evaluate damage.
  • Support and troubleshooting of security mechanisms, such as SSL/TLS,
  • Configure and support L2/L3 switching, dynamic protocols, routing protocols, and technologies (IP, MPLS, BGP, EBGP, IBGP, Ethernet, spine/leaf architectures, ACI, etc.).
  • Collaborated with the IRS Network Team to analyze and refine network security safeguards, ensuring compliance with evolving regulatory requirements, and industry best practices.
  • Experience working collaboratively across teams in a hybrid, multi-cloud environment. Experience with the design and implementation of data center migration involving access, distribution, and core layers.
  • Deployed and managed Dynatrace agents across diverse cloud environments (AWS, Azure, GCP), enabling comprehensive, end-to-end application performance monitoring.
  • Created custom dashboards and alerts in Dynatrace and SolarWinds to provide real-time visibility into application health, performance metrics, and potential issues.
  • Management of both remote-access and site-to-site VPN tunnels in a primarily Palo Alto Networks environment.
  • Cloud Engineer with three years of experience architecting and implementing solutions on the Google Cloud Platform. Proficient in Compute Engine, Kubernetes Engine, and Cloud Storage.
  • Configured and deployed STP, RSTP, and MSTP on Cisco switches to ensure network loop prevention and high availability.
  • Implemented a service mesh using Istio within a Kubernetes environment to enable advanced traffic management (A/B testing, canary deployments), circuit breaking, and mTLS, significantly improving microservice resilience and observability.
  • Troubleshot and resolved complex STP-related issues, such as duplicate MAC addresses and flapping interfaces, minimizing network downtime and improving network stability.
  • Managed on-call rotation with global team to ensure continuous support for regional network infrastructure.
  • Configured and maintained routing and switching equipment to enhance network efficiency.
  • Troubleshot network performance issues, ensuring optimal connectivity and uptime.
  • Self-motivated, with a strong sense of personal responsibility.
  • Worked effectively in fast-paced environments.
  • Managed complex routing and switching configurations to ensure optimal performance.
  • Designed and implemented secure network architectures for military communications.
  • Analyzed deployment processes to identify areas for improvement and enhance operational efficiency.

Network Engineer- IS&T Team

Apple.Inc
Elk-Grove, USA
07.2019 - 12.2020
  • Configure and support deep design of routing, switching, and firewall technologies, system design, implementation, and troubleshooting complex DC networks.
  • Experience in network design, implementation, and deployment of Nexus 9K, 7K, 5K, 2K, and Arista 7010, 7050, and 7060 on Apple AODC, RDC, and GDCS.
  • Network configuration for server apps and app migrations support.
  • Monitor performance and analysis tools the network used, the tools like Capri, Cielo, Net tools, DC tools, and experience in configuring and troubleshooting protocols BGP, IBGP, EBGP, and OSPF.
  • Support and configure HSRP, VRRP, ICMP, and SNMP.
  • Design, implement, and maintain Cisco ACI fabric, including APIC, Spine, and Leaf components.
  • Worked on installing and configuring DNS and DHCP servers.
  • Hands on FTD and FMC components Cisco's Firepower security platform.
  • Manage and support firewalls (ASA, Palo Alto) during the project requirements.
  • Using SD-Access managed through Cisco DNA Center as a centralized management system to apply policies, manage workflows, and gain visibility into the Apple networks DC and RDC.
  • Build and implement VLAN and ACL L2/L3 in overlay and underlay environments.
  • Create and manage automated deployments across various technologies, such as Unicorn, Capri, and Splunk, Grafana.
  • Configure and maintain AAA architecture, TACACS+, RADIUS, and Cisco ACS and ICE.
  • Maintained network documentation for hardware, configuration, and licensing.
  • Install, maintain, and support the customer transit. Core, edge, and access network devices.
  • Provide support in troubleshooting the complicated routing networks issue in the underlay and overlay layers.
  • Provided that the MOP (Verification and Validation) for all MOPs is required. required.
  • Developed Python scripts to automate data processing tasks.
  • Physical and logical network infrastructure design. And design documents for LAN connectivity.
  • With L2-L3 layer troubleshooting, routers and switches from Cisco, Juniper, Nexus, and Arista, provide technical assistance in analyzing packet traces of TCP/IP and UDP traffic.
  • Provide support in preparing documents such as High-Level Design, Low-Level Design, NIP (Network Infrastructure), planning and coordination skills, and automation/scripting skills.
  • Managed multiple projects simultaneously while meeting tight deadlines without compromising quality.
  • Collaborated with cross-functional teams (including development, operations, and security) to address complex network issues in a hybrid environment.
  • Configured and managed network devices (Cisco routers, switches, firewalls), ensuring optimal network performance and security.
  • Familiar with the DNAC automation suite and experience with edge and network services to solve challenges related to the demand for new compute and networking technologies at Apple data centers.
  • Assist with process improvements and best practices in data center operations. Support for the network hardware platforms and their specifications in the data center space and remote data center.
  • Support for the network hardware platforms and their specifications in the data center space and remote data center.
  • Experience on Cisco Identity Services Engine (ISE) to network access control and policy enforcement platfor and enhances network security by providing centralized control over network access.
  • Responded to and resolved Prime-based incidents and service disruptions within defined SLA timeframes.
  • Participate in an on-call rotation to support the regional network infrastructure 24/7.
  • Analyzed deployment processes to identify areas for improvement and enhance operational efficiency.

SD-WAN Network Engineer

Century Link
Tulsa, USA
08.2018 - 07.2019
  • Orchestrated the delivery of 15 integrated network solutions, aligning hardware platforms with specific client requirements for optimal functionality.
  • Managed firewalls, including Forcepoint and Firepower NGFW, resulted in a 25% decrease in security incidents and unauthorized access attempts.
  • Architected and led the implementation of a global SD-WAN solution for a multinational corporation. This option emphasizes leadership and project management skills related to SD-WAN.
  • Administered routers (Juniper, Cisco, HP), load balancers (F5), and firewalls (ASA, SSLVPN), leading to a 20% increase in network speed and data transfer efficiency.
  • Proven ability to manage complex WAN environments, including the deployment and optimization of hybrid SD-WAN networks, utilizing MPLS and DIA for enhanced traffic steering and reliability.
  • Experienced network engineer with a strong background in designing and implementing SD-WAN solutions, leveraging both Dedicated Internet Access (DIA) and MPLS circuits to optimize network performance and reduce costs.
  • Implemented SD-WAN technology to optimize traffic flow and improve application performance by 50% across geographically dispersed locations.
  • Developed 10 detailed physical and logical infrastructure design documents for WAN connectivity, specializing in SD-WAN technologies like Viptela, IOS XE, and Versa SD-WAN.
  • SD-WAN can utilize both Dedicated Internet Access (DIA) and Multi-Protocol Label Switching (MPLS) circuits within its underlay network.
  • Conducted system analysis and testing to identify and resolve technical issues or inefficiencies.
  • Conducted testing of software and systems to ensure quality and reliability.
  • Configured and managed SD-WAN devices to intelligently route traffic based on application needs, leveraging both MPLS and DIA connections for failover and load balancing.
  • Design expertise for SD-WAN (Versa), SD-LAN, and WAN optimization technologies. This specifies a particular SD-WAN vendor and related technologies.
  • Led the successful deployment of a global SD-WAN solution across 100+ sites, improving network agility and reducing WAN costs by 40%.

Q A Network Engineer III

Sprint Communications Provider
Kansas, USA
03.2017 - 08.2018
  • Increased overall network performance by 15% through upgrades and optimized monitoring tools.
  • Recommended network equipment that led to 20% cost savings while improving operational efficiency.
  • Identified vulnerabilities in existing systems, significantly reducing security incidents through enhanced measures.
  • Maintained VoIP and VTC devices to achieve 10% improvement in call quality metrics.
  • Configured routers and firewalls across departments, contributing to decreased unauthorized access attempts.
  • Expertly troubleshot L2-L3 layers on Cisco, Alcatel, Juniper devices within data center environments.
  • Created network documentation including architecture diagrams and topology layouts to streamline processes.
  • Acted as last-tier support for high-severity business-impacting issues in a large-scale network.
  • Installed software updates on servers, routers, firewalls, and other network devices.
  • Created documentation detailing all aspects of the network infrastructure and its configuration.
  • Assisted in the design of local area networks and wide area networks.
  • Configured and maintained network hardware, including routers, switches, firewalls, and wireless access points.

Transport Network Engineer

Windstream Communications
Little Rock, USA
12.2015 - 03.2017
  • Managed provisioning and troubleshooting of transport equipment within a NOC, ensuring 99.9% network.
  • Led commissioning tests and turn-ups of new equipment, contributing to the seamless integration of the network.additions. Proficiently provisioned DWDM and optical transport, including Cisco, ROADM, and crossponders.Cyan and Fujitsu technologies.
  • Demonstrated expertise in tools such as CTC/CTM, NetSmart, CyMS, DSL, ADSL, and the ability to interpret circuit layout records.
  • Executed tasks associated with circuit conversions and disconnect orders, maintaining a proactive approach to order/provisioning plan steps.
  • Implement complex communication solutions that can be deployed to field or remote locations to connect.
  • Secure facilities and support the exchange of required data within a cloud environment.
  • Involved in the design and implementation of approved networking and transport solutions to support long-term Information System (IS) management goals, which include installing and configuring network equipment, and providing support to systems administrators.
  • Monitor computer systems to improve network performance, and lead troubleshooting efforts to resolve networking issues between local and external sites. Manage and maintain a library of network engineering tools to be used for system testing and diagnosis. Network-related system issues, both locally and abroad.
  • Apply leading-edge principles, theories, and concepts to the development, maintenance, and implementation of network engineering standards, procedures, and guidelines.
  • Maintain current knowledge and implement best practices in network security to offer the best solutions and protection to information systems.
  • Produce documentation to support installation, configuration, troubleshooting, and operator usage of systems.
  • Contribute technical content and tutorials to product documentation.
  • Work directly with customers to plan and strategize.

Network Engineer

US Military - Coalition Forces -IMOD
Baghdad, Iraq
11.2005 - 02.2015
  • Successfully addressed IDN network issues by identifying root causes, and implementing effective solutions.
  • Administered and constructed networks, focusing on security across routers, switches, and various networking devices.
  • Managed the security landscape, selecting.
  • Deploying, and troubleshooting various networking protocols and technologies.
  • Implemented, tested, validated and maintained networking services according to solution designs.
  • Configured routers, switches, firewalls and other hardware to deploy and manage LAN, WAN and wireless networks.
  • Corrected network faults and malfunctions to restore connectivity to individual users and entire facilities.
  • Provided technical support to users experiencing difficulties with their networks.
  • Installed software updates on servers, routers, firewalls, and other network devices.
  • Created documentation detailing all aspects of the network infrastructure and its configuration.
  • Provided technical support for queries related to networks, computer systems, software, and hardware equipment.
  • Optimized network performance through ongoing tuning, hardware upgrades, and bandwidth optimization techniques.
  • Contributed innovative ideas and solutions to enhance team performance and outcomes.
  • Demonstrated strong problem-solving skills, resolving issues efficiently and effectively.
  • Designed, implemented, and maintained a robust Cisco-based network infrastructure, resulting in a 25% increase in network efficiency.
  • Troubleshot and resolved over 200 complex network issues, minimizing downtime.
  • Collaborated with software development teams to define network requirements for three major software releases.
  • Network device configuration and troubleshooting (e.g., Cisco IOS/IOS-XE).
  • Advanced features like IPv4, GRE, IPsec, Quality of Service, VLANs, and multicast.
  • Network security features, like IP access lists and stateful protocol inspections.
    Network management protocols like SNMP, SSH, syslog, and RADIUS/TACACS.
    Experience with various operating systems (Windows, Linux, VMWare).
    Network monitoring tools (e.g., NetScout, Wireshark).
  • Provided 24/7 on-call support for critical data infrastructure and workflow systems, ensuring high availability, and rapid issue resolution. This explicitly addresses the 24/7 support requirement.

Education

Bachelor of Science - Network Infrastructure And Security

• Academic Achievements
US Military Assistance Program EZCOM
07.2013

Bachelor of Electrical Engineer -

University of Technology
Baghdad, Iraq
01.2006

Skills

  • Firewall management and security FMC-Fortimanager - Panoramic (Palo Alto)
  • Network protocols: BGP, OSPF, EIGRP
  • NOC, SOC, and OPS collaboration
  • SD-WAN, MPLS, DIA, WAN optimization, dynamic path selection, policy-based routing
  • Data center operations
  • Technical troubleshooting
  • Documentation writing
  • DDoS detection and attack analysis
  • Identity and access management (IAM)
  • Multi-factor authentication (MFA)
  • Network monitoring tools: SolarWinds, Dynatrace, Splunk, Kentik, and Grafana
  • Microsegmentation for containerized environments (Kubernetes, OpenShift)
  • Team collaboration
  • Effective communication, project management
  • Operating system security, incursion tracking
  • Security incident response and threat analysis, data loss prevention
  • VXLAN designs and troubleshooting, patch management, encryption techniques
  • IP addressing and subnetting
  • Security awareness training
  • Virtual private networks, firewall configuration
  • Istio, Kubernetes, Terraform
  • Database security

Certification

  • CCNP Routing (300-101)
  • CCNA Routing & Switching
  • CCNA Wireless
  • CCNP Security (CISSP)
  • CCNA Security
  • (IINS) CompTIA A+ Hardware

Timeline

Sr.Network Engineer ( AWS)

Parexel-Goverments Accounts
09.2019 - Current

Network Engineer- IS&T Team

Apple.Inc
07.2019 - 12.2020

SD-WAN Network Engineer

Century Link
08.2018 - 07.2019

Q A Network Engineer III

Sprint Communications Provider
03.2017 - 08.2018

Transport Network Engineer

Windstream Communications
12.2015 - 03.2017

Network Engineer

US Military - Coalition Forces -IMOD
11.2005 - 02.2015

Bachelor of Electrical Engineer -

University of Technology

Bachelor of Science - Network Infrastructure And Security

• Academic Achievements

EDUCATION AND TRAINING

true,true,other
Saif Alani