Source description
About the role
L3 Expert in F5 APM and Paloalto Firewalls
-
In depth understanding and experience in Security protocol technologies.
-
Experience designing, deploying and supporting dynamic routing protocols
-
Expertise in PaloAlto and capable in troubleshoot the high critical issue and implement new requirement according to business need.
-
Experience in AWS cloud setup.
-
Hands-on Experience working with F5 - APM
-
In depth understanding in troubleshoot on F5 APM and ability to address complex issues
-
Expertise in Cisco ASA along with the context base platform.
-
Good understanding on solution designing and implementation of Force scout NAC solution.
-
Good hands on exposure on Remote Access VPN - Cisco ASA.
-
Provide production network deployment, configuration, support and upgrades of Cisco/ Palo Alto Firewall and Bluecoat proxy.
-
Experience in Firewall/AV (Trend) within AWS cloud.
-
Thorough understanding of modern service
-
project learning's are documented, responsible to update the runbook.
-
Able to work under pressure in a high-paced customer service environment, and able to prioritize multiple tasks effectively provider TCP/IP data networks using standards and technologies. Experience configuring and managing Cisco ASA Firewalls
-
Experience of managing large scale security network infrastructure and Data Centres kind of network.
-
In depth knowledge of configuring and troubleshooting Cisco/Palo Alto firewalls, like ACL, Remote Access VPN, IPSEC VPN, SSL VPN, NAT, PAT, Clustering, End point security assessment
-
Worked on Network Performance Monitoring and Troubleshooting
-
Communicate effectively, both orally and in writing, including conveying technical subject matter clearly and concisely.
-
Design & Implementation of Data Centre Firewall security
-
Perform RCA for Major Incidents related to his / her tower Follow quality / security process defined for the engagement.
-
Responsible for implementation and administration of network security hardware and software, enforcing the network security policy and complying with requirements of external security audits and recommendations
-
Experience of large DC Network security architecture migration would be an added advantage.
-
Day to day administration of L3 and escalated calls and provide resolution.
-
Be proactive to anticipate issues or situations which impact service quality, as part of Problem management and Capacity Management functions
-
Contributes to knowledge tools and communities, and ensures
Security NAC
· Subject matter expert (SME) for Cisco Identity Services Engine (Client) solution, helping maintain stable operations while enhancing the service.
· Good Understanding on NAC Solution designing and implementation on Force Scout
· Understand the security architecture, implementation and improving security solution for Network Access Control.
· Configure and lead the configuration, policy creation, policy tuning in Cisco Client solution.
· Extensive experience with Cisco Identity Service Engine solution in monitoring mode and enforcing mode, security posturing, compliance assessment.
· Continually assess security controls for deficiencies and drive remediate and improvement efforts.
· Experience with designing and deploying Cisco Client (Network Access Control) infrastructure, creating new device profiles for 802.1X and MAB.
· Experience with establishing network access restrictions using Cisco SGT (Scalable Group Tags).
· Experience with 802.1x, WPA2 Enterprise, authentication and access controls in a mobile environment, and with mobile device security.
· Experience with working in a large enterprise environment, the associated challenges and their inherent security strengths and weaknesses.
· Experience with Cisco switches in configuring, troubleshooting and optimizing Network Access Device (NAD) configurations to ensure proper Client functionality.
· Experience in EAPOL, EAP and PEAP authentication protocol.
· Experience on User and Machine Authentication – Certificate Based and LDAP/AD based.
· Stablishing a baseline Client security rules/policies working with other service lane members
· Implementing redundant/HA Cisco Client solution
· Radius and TACACS+ authentication and authorization methods
· Integrating Cisco Client solution with enterprise PKI architecture
· Implement Client solution for campus LAN, wireless, remote access and guest network environments
· Integrating Client with enterprise patching and anti-virus solutions
· Understanding of Radius and TACACS authentication with Cisco Client
· Understanding of remote access VPNs with PKI authentication
· Understanding of 802.1X authentication process
· Understanding of Cisco Client remediation process
· Understanding of Cisco guest access authentication process
Job type: Contract Division: Darwin Rhodes Reference: 21-04710
More at eTeam