A journey across industries, building and securing networks that keep people moving, businesses growing and services running.
Feb 2026 – Present
F5 Networks
Sr. Network Engineer · Seattle, WA
Managing and troubleshooting a global security environment of 100+ Palo Alto firewalls, ~80 centrally managed through Panorama HA across data centers, branches and cloud.
Key responsibilities
- Advanced Layer 3–7 troubleshooting of production incidents — BGP, route propagation, asymmetric traffic, NAT, DNS, TCP/SSL and VPNs — using packet captures, session analysis and CLI diagnostics.
- Administer Panorama: Device Groups, Templates, VSYS, shared/inherited policies, commits, policy pushes and configuration sync.
- Troubleshoot Azure/AWS hybrid networking: VNets, peering, NSGs, UDRs, Azure Firewall, Load Balancers, Private Endpoints, Private DNS and Application Gateway.
- Support firewall lifecycle work: Panorama onboarding, policy migration, decommissioning, PA-5200/5400 hardware refreshes.
- Conduct SOX firewall rule reviews — identifying unused, duplicate, temporary and overly permissive rules and driving remediation.
- Validate HA/DR failover and routing convergence during production changes and maintenance windows.
- Troubleshoot site-to-site IPSec VPNs end to end: IKE/IPSec negotiation, routing, NAT, policy and bidirectional flows.
- Work in Linux and Terraform-based environments to diagnose routing, DNS and cloud connectivity issues.
Palo Alto / Panorama HAAzure & AWSBGP & RoutingSOX Governance
Jan 2025 – Jan 2026
Sound Transit
Sr. Network Engineer · Seattle, WA
Core Cybersecurity team member securing transit and enterprise networks across train stations and King County locations.
Key responsibilities
- Designed, deployed and supported Juniper SRX4200 firewall clusters with security policies and IPSec VPN tunnels.
- Configured Palo Alto and Fortinet NGFWs with application-based policy and segmentation across stations and enterprise networks.
- Supported Azure ExpressRoute — BGP between on-prem, providers and Azure — with traffic logs integrated into SIEM.
- Deployed Azure-to-on-prem VPN for the EDP Pilot and Databricks environments.
- Implemented Cisco ISE NAC and secure wireless with endpoint profiling and role-based segmentation.
- Led onsite and remote break/fix and 24×7 high-severity incident calls through mitigation and restoration.
- Ran lab validation and production-readiness testing; participated in CRB/ARB change management with rollback planning.
- Applied IEC 62443 and PCI-DSS controls to transportation and payment environments; authored security runbooks.
Juniper SRXExpressRouteCisco ISE NACIEC 62443
Jul 2024 – Dec 2024
Olympus of Americas
Sr. Network Engineer · Center Valley, PA
Designed and supported LAN/WAN and network security across data centers and branch sites.
Key responsibilities
- Managed Catalyst 9600/6500/4500/9300 and Nexus 7K/9K with VLANs, STP, trunking, inter-VLAN routing and HA.
- Configured Palo Alto and Fortinet NGFWs, Fortinet WAF policies, NAT and segmentation for critical applications.
- Engineered BGP, OSPF and EIGRP — including an EIGRP-to-OSPF migration, SP peering, QoS and PBR.
- Delivered IPSec/SSL VPN, DMVPN and SD-WAN connectivity for remote sites and branches.
- Built Cisco ISE NAC with profiling, RADIUS/TACACS+ and Zero Trust segmentation.
- Deployed Cisco WLC 9800 wireless integrated with ISE for secure onboarding.
- Supported IoT/OT network integration and compliance with cybersecurity, facilities and engineering teams.
- Authored HLDs, LLDs, security runbooks, risk assessments and backout plans.
Catalyst & NexusSD-WAN / DMVPNFortinet WAFCisco WLC 9800
Jan 2020 – Jun 2024
Barclays
Sr. Network Security Engineer · Seattle, WA
Four-plus years securing data centers, branches and hybrid cloud for business-critical financial services.
Key responsibilities
- Deployed Palo Alto NGFW/Panorama and Cisco FTD/FMC with app-aware policy, NAT, IPS/IDS and threat prevention.
- Managed F5 ASM/WAF to protect web applications against OWASP Top 10 threats.
- Configured Cisco ISE NAC with endpoint profiling, role-based access and Zero Trust policies.
- Managed and optimized Azure ExpressRoute connectivity and resolved end-to-end hybrid issues.
- Integrated firewall, VPN, WAF and ISE logs into SIEM; used Nessus, FortiAnalyzer, Wireshark and SolarWinds for threat monitoring.
- Supported SOC operations and incident response aligned to NIST, PCI-DSS and HIPAA.
- Led firewall standardization and micro-segmentation / Zero Trust initiatives.
- Maintained HLDs, LLDs, runbooks and operational procedures.
Palo Alto & Cisco FTDF5 ASM/WAFExpressRouteSOC & IR
Jan 2017 – Nov 2019
Nokia
System Network Engineer · Dallas, TX
On-site data center and security monitoring support, protecting availability and integrity of enterprise infrastructure.
Key responsibilities
- Configured Cisco switches, routers and firewalls for secure LAN/WAN and inter-site connectivity.
- Managed Palo Alto, Cisco ASA/FTD and Fortinet NGFWs enforcing application-level policy.
- Deployed IPsec and SSL VPN for remote users and branches; tuned OSPF and BGP.
- Worked with the SOC on event monitoring, anomaly investigation and escalation.
- Integrated firewall and VPN logs into syslog for better threat visibility.
- Performed Wireshark traffic analysis and Nessus-driven vulnerability remediation.
- Enforced AD-integrated access control and MFA for privileged accounts.
- Monitored infrastructure with SolarWinds and PRTG for early outage detection.
Cisco Routing & SwitchingNGFW OperationsVPNMonitoring