Senior Network & Security Architect

Alan J. Matson

Round Rock, TX  ·  Greater Austin Area

15+ years designing, securing, and operating enterprise network infrastructure across financial services, state government, and large multi-site environments — with a focus on Zero Trust architecture, WAN modernization, and measurable risk reduction.

ENTERPRISE
WAN
ZERO TRUST
& IDENTITY
SECURITY
OPERATIONS
CLOUD &
VIRTUALIZATION
COMPLIANCE
& RISK

Senior network and security architect with 15+ years designing, securing, and operating enterprise infrastructure across financial services, government, and large-scale multi-site environments. Currently a network administrator for the statewide Texas judicial court network. Known for delivering zero-downtime migrations, hardening inherited security postures, and modernizing legacy architecture at scale — with hands-on depth across MPLS WAN, BGP/VXLAN, SD-WAN, Zero Trust and passwordless authentication, SAN networking, IPSec VPN, cloud networking, and multi-vendor firewall ecosystems (Cisco ASA/FTD, Palo Alto, Fortinet, Aruba, Netgate). Experienced advisor to executive stakeholders on ISO 27001 and PCI compliance programs.

Core Competencies

Network Architecture
SD-WAN · MPLS WAN · BGP · EIGRP · VXLAN · SAN (iSCSI, FCoE) · LAN/WAN campus & branch design
Firewall & Perimeter
Cisco ASA/FTD · Palo Alto NGFW · Fortinet FortiGate · Netgate pfSense · Aruba (switching, Central, ClearPass, SD-WAN)
Security & Identity
Zero Trust architecture · passwordless auth (YubiKey MFA) · IPSec/SSL VPN · DLP · IDS/IPS · threat hunting · IOC detection
Security Operations
SIEM · EDR (Fortinet) · NDR · incident response · root-cause analysis
Cloud & Virtualization
Cloud networking · VMware ESXi · virtualized & hybrid infrastructure
Tools & Platforms
Cisco Umbrella · Forcepoint Web Security & DLP · QualysGuard · Wireshark · SolarWinds
Compliance
ISO 27001/27002 · PCI DSS · NIST · HIPAA · PII handling
Scripting & Automation
Bash · PowerShell · deployment & automation scripting
EC-Council
Certified Ethical Hacker (CEH)
EC-Council
Computer Hacking Forensic Investigator (CHFI)
Cisco
CCNA Routing & Switching
Cisco
CCNA Security
Cisco
CCNA CyberOps Associate
CompTIA
Security+
CompTIA
Network+
Fortinet
NSE4 – Network Security Professional
SonicWall
Security Administrator
Network Administrator Current
Mar 2026 – Present
Texas Judicial Branch, Office of Court Administration — Austin, TX
  • Serve as Tier III engineer for the statewide judicial network, owning design and engineering across multiple remote court locations on an enterprise MPLS WAN backbone.
  • Architect and administer complex routing and switching environments — Layer 2/3 design, VLAN segmentation, and inter-site connectivity — to sustain high availability for mission-critical court operations.
  • Lead Cisco ASA firewall hardening, remediating inherited perimeter gaps and establishing consistent firewall policy governance enterprise-wide.
  • Manage cloud networking integrations and virtualized environments, maintaining consistent policy enforcement across hybrid infrastructure.
  • Administer SAN architecture, including switches and bridges supporting iSCSI and FCoE protocols for critical judicial data systems.
  • Deploy and maintain site-to-site IPSec VPN tunnels across distributed court locations for encrypted, reliable statewide connectivity.
  • Lead the statewide migration from a mixed Cisco/Dell switching environment to a full Aruba stack — switching, Aruba Central for centralized management, ClearPass for NAC and policy enforcement, and Aruba SD-WAN — modernizing branch connectivity and simplifying statewide policy governance.
  • Implement enterprise monitoring with proactive alerting and baselines, reducing mean time to resolution for network incidents.
Senior Network & Security Architect
2024 – Jan 2026
United Heritage Credit Union — Austin, TX
  • Architected and operated enterprise LAN/WAN infrastructure across 20+ branch and corporate locations, maintaining 99.9%+ availability for mission-critical financial systems.
  • Led data center modernization — migrating from EIGRP to BGP with VXLAN overlay — enabling dual-data-center connectivity and cloud-agnostic scalability with zero production downtime.
  • Designed and deployed a Zero Trust VPN using passwordless YubiKey MFA, eliminating credential-based attack surface organization-wide.
  • Led multi-vendor firewall governance (Cisco, Palo Alto, Fortinet, Netgate), consolidating policy hygiene and reducing mean time to diagnose security events by 40%.
  • Deployed Cisco Umbrella DNS-layer protection, blocking malicious domains before they reached the perimeter and improving shadow-IT visibility.
  • Analyzed identity and network telemetry across Fortinet EDR platforms to detect anomalous behavior; led root-cause analysis with SOC teams during incident response.
  • Rebuilt network documentation — topology diagrams, SOPs, and knowledge-base articles — reducing onboarding time and improving operational resilience.
  • Maintained Forcepoint Web Security and DLP platforms to sustain PCI and regulatory compliance for sensitive financial data.
Network Security Architect, Professional Services
2015 – 2023
Insight Enterprises — Texas Health & Human Services · Austin, TX
  • Delivered senior professional-services consulting for large enterprise and state government clients, owning network security architecture and secure WAN connectivity end to end.
  • Led enterprise-scale deployments and migrations of web security proxies and DLP solutions for environments with thousands of endpoints, with near-zero user disruption.
  • Produced executive deliverables — risk assessments, ISMS artifacts, disaster recovery plans, and architecture proposals — consumed by C-suite and agency leadership.
  • Advised clients on LAN/WAN segmentation, secure internet egress, and compliance architecture aligned to ISO 27001/27002, PCI, and PII requirements.
  • Built lab validation environments to de-risk new technology before production rollout, accelerating procurement decisions.
  • Served as senior SME on security product selection, RFP responses, and vendor evaluations, informing multi-million-dollar infrastructure decisions.
Senior Security Engineer
2011 – 2015
Forcepoint / Websense, Inc. — Arizona
  • Administered enterprise network and security infrastructure — firewalls, VPNs, email security, and endpoint protection — across multiple data centers and global offices.
  • Conducted proactive threat hunting to identify malicious activity and indicators of compromise, translating findings into remediation playbooks adopted across the security team.
  • Ran periodic security audits and compliance checks, maintaining regulatory posture across a public-company environment.
  • Core technologies: Juniper SRX · Cisco Catalyst · HP ProCurve · Brocade load balancers · QualysGuard vulnerability management.
Western Governors University
Salt Lake City, UT
M.S., Information Security & Assurance
B.S., Information Technology Security
Chandler-Gilbert Community College
Chandler, AZ
A.A.S., Computer Information Technology
Certificates: Linux Professional · Microsoft Product Specialist

Open to senior network and security engineering or architecture roles in Austin, TX or remote.