Network Security (Firewalls, IDS, IPS, Network devices)
Policy updates
Risk Analysis & mitigation (using ISO 2700x series, NIST SP framework)
Log Analysis-using Wireshark & SIEM Tools
Reporting & Documenting Weekly and monthly.
Team Communication
My Technical Skills in detail:
Resolved critical system and network issues on a 24/7 basis including complete network outages effecting many client networks throughout Ontario, AB and BC regions in Canada by remote access from India
Reviewing and implementation of core and edge device configuration on network architecture devices as per customer services like VPN, EIGRP, OSPF and Carrier Ethernet Service’s.
Provisioning of services on the customer/Service provider network.
Responsible for Designing, Migrating and Decommissioning of various data service types such as CES, L3 VPN and HOT CUT & parallel CUT based on Customer Managed services.
Responding immediately to escalations in 24*7 shift roles without missing SLA.
Design task include customer specific configuration from core and edge devices.
Co-coordinating with the End (enterprise Customer) and Technicians to ascertain smooth transition of the services.
Designing, implementing and maintaining IPsec VPN, RADIUS and 802.1x , MAB, ISE
Worked on AAA, Cisco ASA & NG Firewalls, routers and switches, IDS,IPS and vulnerability management with Knowledge on packet capturing logs in Wireshark.
Review log-based data, both in raw form and utilizing SIEM or aggregation tools and ability to interpret logs , events and identify patterns of behaviour, indications of compromise
Strong knowledge base with legacy and enterprise networking platforms
Good understanding and working experience on ISP routing policies and technologies.
Strong knowledge on developing and implementation of new system security plans, conducted risk assessments (NIST SP 800 30, 37, 39,51A) and drafted new information security policies and procedures using ISO 27000 series.
Strong understanding and hands on working with SIEM, SOAR Tools such as IBM QRadar, LogRhythm, Arcsight & Splunk by Monitoring, responding to security incident Alerts and can analyse & identify basic indicators of compromise on hosts.
Incident handling, monitor security access, analyses security breaches to identify the root cause and prepare risk advisories.
Strong Understanding on IR Team playbooks for use cases.
Able to perform basic forensic analysis using FTK Tools and live triage of hosts to include examining running processes, network connections, system logs, file system activity, and more for signs of anomalous behaviour.
Strong understanding of Network Security concepts, Security Operations, Analysis of Event Logs.
Experience working in an IT outsource environment.
Excellent communication skills both written and verbal.
Client engagement skills, time management, expectation management etc.,
Alacrity to learn new technologies.
Ability to work under pressurized situations 24*7 to serve the escalations within SLA’s.
Experience of balancing security risk versus specific business\client requirements