Multi‑Site Network Core
Designing and operating Cisco‑based WAN/LAN across 40+ distributed enterprise locations with BGP, OSPF, MPLS, and QoS.
Lead Network Engineer with deep experience in Cisco Nexus/IOS, ASA, AWS networking, and security frameworks (CIS Hardening, DISA STIG). I design and migrate multi‑site networks, enforce compliance, and use Python/Ansible and AI‑driven tooling to keep environments resilient.
From core routing and Nexus datacenter fabrics to Juniper Mist wireless and virtualization, I treat the network and systems stack as one integrated platform—designed for uptime, security, and scale.
Designing and operating Cisco‑based WAN/LAN across 40+ distributed enterprise locations with BGP, OSPF, MPLS, and QoS.
RF‑driven Wi‑Fi design with secure access, RADIUS, WPA2/WPA3, and predictive surveys using Ekahau.
Integrating Windows Server, Linux (Red Hat, Ubuntu), VMware, and Hyper‑V into resilient network designs.
Designing monitoring to hit 99.9%+ SLAs with fast troubleshooting, clear runbooks, and proactive alerting.
Building cloud-native infrastructure with Kubernetes, Terraform, and CI/CD pipelines for automated deployments.
Developing network automation with Python (Netmiko, Paramiko, Requests), Ansible, and REST APIs for config management.
Senior cloud infrastructure security with expertise in Kubernetes hardening, AWS security architecture, and cloud-native threat mitigation.
I help teams refactor legacy architectures into cloud‑aware, compliance‑aligned designs with AWS VPCs, Direct Connect, VPNs, and hardened Cisco infrastructure following CIS and DISA STIG standards.
Designed multi‑site Cisco infrastructure integrated with AWS VPCs, Direct Connect, and Transit Gateway, enforcing segmentation and secure hybrid connectivity across campus and cloud.
Led CIS Hardening and DISA STIG standards implementation for Cisco Nexus, IOS, and ASA platforms, achieving 100% compliance validation with repeatable checklists, audits, and remediation workflows.
Built IPSec/SSL VPN designs, RBAC policies, and segmented access to enforce least privilege and Zero Trust‑aligned architectures across distributed sites.
Executed zero‑downtime network migrations with rigorous change control, testing, and vendor coordination across multi‑phase data center modernization efforts.
Deployed enterprise‑grade wireless with WPA2/WPA3, RADIUS authentication, and predictive RF surveys supporting seamless roaming and mobility across 40+ sites.
Developed automated network compliance validation aligned with CIS Hardening and DISA STIG requirements, reducing drift and human error through infrastructure‑as‑code.
Designed and deployed Kubernetes-based container orchestration platform with Terraform IaC and CI/CD pipelines, enabling automated application deployments with Git-based workflows.
Built comprehensive Python automation suite using Netmiko, Paramiko, and Requests libraries for device configuration, API integrations, and network state validation across multi-vendor environments.
Designed and implemented senior-level cloud security architectures including Kubernetes cluster hardening, AWS security controls, IAM policies, and Cloud Security Alliance best practices for enterprise workloads.
I capture architectures as living blueprints: from Python/Ansible‑driven config generation to AI‑assisted troubleshooting with Mist Marvis and intelligent monitoring—reducing MTTR and provisioning time.
Automated configuration generation for Cisco and Juniper using Python (Netmiko, Paramiko, Requests), Ansible, Terraform, and CI/CD pipelines, creating reusable blueprints for VLANs, routing, and firewall policies with Git version control.
Combined Mist Marvis AI‑driven troubleshooting with SolarWinds and custom Python tooling to cut MTTR by 60%, using intelligent insights and automated checks across 40+ sites.
Built reusable automation runbooks using Python, Ansible, Bash, and Git that standardize provisioning and compliance validation, reducing device deployment time by 70% across Cisco Nexus, IOS, and ASA environments.
Logical and physical network diagrams with VLAN segmentation, routing protocols, and security zones.
Firewall policies, VPN tunnels, RBAC models, and Zero Trust segmentation aligned with CIS/DISA STIG.
AWS VPC architecture, Direct Connect, Transit Gateway, and hybrid connectivity blueprints.
Python (Netmiko, Paramiko, Requests), Ansible, Terraform, Git, Bash, REST APIs, Jinja2 templates, and CI/CD pipelines for config management.
Mist Marvis AI troubleshooting, predictive analytics, and intelligent alerting for proactive ops.
CIS Hardening checklists, DISA STIG validation, and audit‑ready documentation for federal standards.
Kubernetes Security (CKS), AWS Security Specialty, CCSK frameworks, and senior cloud infrastructure protection.
Whether you need a security‑aligned rebuild, a hybrid network design, or automation and AI/ML‑driven operations, I can help design and deliver a resilient blueprint.
Assessment & Discovery:
Audit current network, wireless, and cloud connectivity to surface risk, technical debt, and opportunities.
Blueprint & Roadmap:
Propose a phased blueprint for security‑aligned, automated, cloud‑ready architecture with clear milestones.
Implementation & Transfer:
Lead or support implementation, documentation, and knowledge transfer for your team to own and operate.