Network Architect
Current2021 - Present(updated 2024): Cybersecurity Transformation• Deployed EDR endpoint system for enhanced defense posture and incident investigation. Conduct root cause analysis during incident response to fine-tune endpoint policies.• Engaged SOC/MDR vendor to enhance our internal team and for more rapid incident response.• Implemented segmentation at various levels to minimize lateral movement. Strict internet access on servers. Strengthened Azure environment with strict traffic controls and least privilege design.• Proactively hunt threats using EDR SQL queries, packet traces, logs, etc.• Streamlined applications and reduced attack surface on endpoints. Enhanced visibility by reducing noise in logs and EDR queries.• Collaborate across IT teams to balance security and functionality. Foster a security-aware culture across all IT levels. Mentor junior engineers and field technicians.2019 - 2021: Stabilization and Network EnhancementRescued a struggling datacenter by addressing server crashes within the VM environment, caused by design flaws/changes. Evaluated and optimized access layer network design, eliminating undesirable connections and enhancing HQ network reliability. Transitioned from a legacy network MSP to in-house management of 150 sites, resulting in cost savings, fast resolution time, increased efficiency, and improved resilience. Redesigned corporate Wi-Fi for enhanced security across all sites. Designed and successfully migrated the entire infrastructure for a new NYC HQ datacenter within a tight 3-month timeline. • Infrastructure components included Nexus 9k dual core switches, 4-node c-series Hyperflex, UCS 6332-16UP, PureStorage arrays, and Cohesity backup. • Implemented Meraki MX250\MX68 for IPS, VPN access, and SD-WAN across 150 remote sites. • Upgraded closets with Meraki MS250 stacks and wireless access points.