Senior network and security architect with 15+ years designing, securing, and operating enterprise infrastructure across financial services, government, and large-scale multi-site environments. Currently a network administrator for the statewide Texas judicial court network. Known for delivering zero-downtime migrations, hardening inherited security postures, and modernizing legacy architecture at scale — with hands-on depth across MPLS WAN, BGP/VXLAN, SD-WAN, Zero Trust and passwordless authentication, SAN networking, IPSec VPN, cloud networking, and multi-vendor firewall ecosystems (Cisco ASA/FTD, Palo Alto, Fortinet, Aruba, Netgate). Experienced advisor to executive stakeholders on ISO 27001 and PCI compliance programs.
Core Competencies
- Serve as Tier III engineer for the statewide judicial network, owning design and engineering across multiple remote court locations on an enterprise MPLS WAN backbone.
- Architect and administer complex routing and switching environments — Layer 2/3 design, VLAN segmentation, and inter-site connectivity — to sustain high availability for mission-critical court operations.
- Lead Cisco ASA firewall hardening, remediating inherited perimeter gaps and establishing consistent firewall policy governance enterprise-wide.
- Manage cloud networking integrations and virtualized environments, maintaining consistent policy enforcement across hybrid infrastructure.
- Administer SAN architecture, including switches and bridges supporting iSCSI and FCoE protocols for critical judicial data systems.
- Deploy and maintain site-to-site IPSec VPN tunnels across distributed court locations for encrypted, reliable statewide connectivity.
- Lead the statewide migration from a mixed Cisco/Dell switching environment to a full Aruba stack — switching, Aruba Central for centralized management, ClearPass for NAC and policy enforcement, and Aruba SD-WAN — modernizing branch connectivity and simplifying statewide policy governance.
- Implement enterprise monitoring with proactive alerting and baselines, reducing mean time to resolution for network incidents.
- Architected and operated enterprise LAN/WAN infrastructure across 20+ branch and corporate locations, maintaining 99.9%+ availability for mission-critical financial systems.
- Led data center modernization — migrating from EIGRP to BGP with VXLAN overlay — enabling dual-data-center connectivity and cloud-agnostic scalability with zero production downtime.
- Designed and deployed a Zero Trust VPN using passwordless YubiKey MFA, eliminating credential-based attack surface organization-wide.
- Led multi-vendor firewall governance (Cisco, Palo Alto, Fortinet, Netgate), consolidating policy hygiene and reducing mean time to diagnose security events by 40%.
- Deployed Cisco Umbrella DNS-layer protection, blocking malicious domains before they reached the perimeter and improving shadow-IT visibility.
- Analyzed identity and network telemetry across Fortinet EDR platforms to detect anomalous behavior; led root-cause analysis with SOC teams during incident response.
- Rebuilt network documentation — topology diagrams, SOPs, and knowledge-base articles — reducing onboarding time and improving operational resilience.
- Maintained Forcepoint Web Security and DLP platforms to sustain PCI and regulatory compliance for sensitive financial data.
- Delivered senior professional-services consulting for large enterprise and state government clients, owning network security architecture and secure WAN connectivity end to end.
- Led enterprise-scale deployments and migrations of web security proxies and DLP solutions for environments with thousands of endpoints, with near-zero user disruption.
- Produced executive deliverables — risk assessments, ISMS artifacts, disaster recovery plans, and architecture proposals — consumed by C-suite and agency leadership.
- Advised clients on LAN/WAN segmentation, secure internet egress, and compliance architecture aligned to ISO 27001/27002, PCI, and PII requirements.
- Built lab validation environments to de-risk new technology before production rollout, accelerating procurement decisions.
- Served as senior SME on security product selection, RFP responses, and vendor evaluations, informing multi-million-dollar infrastructure decisions.
- Administered enterprise network and security infrastructure — firewalls, VPNs, email security, and endpoint protection — across multiple data centers and global offices.
- Conducted proactive threat hunting to identify malicious activity and indicators of compromise, translating findings into remediation playbooks adopted across the security team.
- Ran periodic security audits and compliance checks, maintaining regulatory posture across a public-company environment.
- Core technologies: Juniper SRX · Cisco Catalyst · HP ProCurve · Brocade load balancers · QualysGuard vulnerability management.
B.S., Information Technology Security
Certificates: Linux Professional · Microsoft Product Specialist
Open to senior network and security engineering or architecture roles in Austin, TX or remote.