← Back to Experience

FROM THE FIELD

Sound Transit

Core Cybersecurity team member securing transit and enterprise networks across train stations and King County locations.

Key responsibilities

  • Designed, deployed and supported Juniper SRX4200 firewall clusters with security policies and IPSec VPN tunnels.
  • Configured Palo Alto and Fortinet NGFWs with application-based policy and segmentation across stations and enterprise networks.
  • Supported Azure ExpressRoute — BGP between on-prem, providers and Azure — with traffic logs integrated into SIEM.
  • Deployed Azure-to-on-prem VPN for the EDP Pilot and Databricks environments.
  • Implemented Cisco ISE NAC and secure wireless with endpoint profiling and role-based segmentation.
  • Led onsite and remote break/fix and 24×7 high-severity incident calls through mitigation and restoration.
  • Ran lab validation and production-readiness testing; participated in CRB/ARB change management with rollback planning.
  • Applied IEC 62443 and PCI-DSS controls to transportation and payment environments; authored security runbooks.
Juniper SRXExpressRouteCisco ISE NACIEC 62443