Please give us some details about the role you want to fill and let us know why you think our client might be the perfect candidate for you.
What happens next?
Our Job Search Specialist Mark Beltran will facilitate the next steps:
Mark will let our client know that you have shown an interest in their professional skills.
You will receive a full job application from our client and might want to offer them a formal job interview if you see the right potential in this candidate.
If you decide that you would like to offer the role to our client, we will help to make the next steps as smooth as possible.
You will be supported by our Licensed Immigration Advisers, who will take care of all visa related aspects of the process of offering our client a job.
Offering a job to our client will be straight forward.
CCIE Security-certified network security professional with 20+ years of progressive IT experience, including extensive enterprise security engineering, operations and transformation work across telecommunications, banking and managed services environments.
Experienced in leading large-scale firewall technology refreshes, mission-critical production cutovers, Fortinet SASE On-Prem operations, secure remote access, Zero Trust-aligned controls and multi-vendor security platforms. Combines hands-on engineering depth with technical leadership, Level-3 troubleshooting, vendor/Professional Services coordination and disciplined change execution in complex, high-availability environments.
• Enterprise Network Security
• Fortinet Security Fabric & SASE On-Prem
• Fortinet, Cisco, Palo Alto & Juniper
• Firewall Lifecycle & Technology Refresh
• IPsec / SSL VPN, IPS, NAT & HA
• Routing: BGP, OSPF, EIGRP & MPLS L3 VPN
• Zero Trust & Secure Remote Access
• Production Cutovers & Change Management
• NDR / EDR Security Solutions
• Incident Response, RCA & L3 Support
• Vendor / Professional Services Coordination
• Security Standards, SOPs & Baselines
Expert Engineer / Network Security | Etisalat by e& Dubai, UAE| Sep 2019 - Present
• Manage the operations, administration and lifecycle of enterprise security infrastructure spanning Fortinet, Cisco, Palo Alto and Juniper firewall platforms.
• Administer enterprise security services including firewall policy, IPsec VPN, IPS, High Availability, NAT, routing and secure remote access across production environments.
• Lead firewall technology refresh initiatives, software upgrades, infrastructure migrations and production cutovers, with focus on service continuity and controlled business impact.
• Serve as Enterprise Technical SPOC for strategic security implementations, coordinating internal stakeholders, vendors and Fortinet Professional Services from integration through operational handover.
• Own operational management of the Fortinet SASE On-Prem platform, including security policy administration, platform maintenance and integration with FortiClient EMS, FortiAuthenticator and FortiAnalyzer.
• Provide Level-3 technical support, root-cause analysis, platform optimisation and continuous service improvement for complex network security incidents.
• Fortinet SASE (On-Prem): supported enterprise deployment and integration with core components including EMS, FortiAnalyzer, FortiManager and Forti Portal, and subsequently assumed operational management of the platform.
• IDC Firewall Technology Refresh: delivered replacement of legacy FortiGate 1000C/600C platforms with 21 FortiGate 600E High Availability clusters across the IDC infrastructure zone.
• Service & Cloud Firewall Technology Refresh: led deployment of 28 FortiGate 3400E High Availability clusters replacing FortiGate 3200D/1500D platforms across Service Layer, Private Cloud and Public Cloud environments.
• Satellite Firewall Technology Refresh: migrated FortiGate 1500D platforms to FortiGate 1100E, supporting lifecycle modernisation of the satellite firewall environment.
• DI/DPI Security Gateway & Automation: played a key role in deployment and management of the Fortinet Security Gateway and implemented Co-Manage automation to improve operational efficiency.
• NDR & EDR: contributed in a leading technical role to deployment of NDR and EDR solutions protecting mobile signalling and O&M environments.
• IPsec VPN Automation: led automation of Co-Manage DI/DPI customer onboarding and deployment workflows across FortiGate and FortiAuthenticator.
Manager Network Security | Allied Bank Limited, Lahore Pakistan | May 2016 - Sep 2019
• Managed enterprise network security engineering and operations across Cisco firewall, VPN, identity, data-centre and security management platforms.
• Evaluated, deployed and operated Cisco FTD/FMC, Threat Grid, ISE, AnyConnect SSL VPN, IPsec/IKEv2 VPN, DMVPN/GetVPN and NGFW services including AMP, AVC, URL filtering and IPS.
• Implemented Cisco ISE capabilities including 802.1X, MAB, WebAuth/CWA and AAA migration, strengthening network access control across campus, VPN and infrastructure administration use cases.
• Supported data-centre security and network transformation using Cisco Nexus 7K/5K/2K, OTV and enterprise routing technologies including BGP, OSPF, EIGRP and MPLS L3 VPN.
• Developed security hardening controls, technology SOPs, security baselines, DR technical documentation and project plans aligned with business and regulatory requirements.
• Led technology evaluations and POCs and supported vendor management, BoQ/RFP preparation, procurement, budget forecasting, project planning and implementation strategy with senior management.
• Cisco ISE (2018): implemented profiling and Microsoft AD-backed authentication, migrated network-device AAA from Cisco ACS, enabled 802.1X/MAB controls and deployed a two-node PSN model across primary and secondary data centres.
• Cisco OTV / Service-Based DR (2017): deployed OTV between data centres, enabling MAC-in-IP extension and reducing DR turnaround time by up to 70%.
• DR Data Centre Integration (2016): migrated VPN and DMZ firewall segments from Catalyst 6500 to Nexus 7010 with no downtime and replaced legacy FWSM with ASA 5585-X integrated into the Nexus core/server-farm environment.
Manager Network Operations / Team Lead | Cyber Internet Services, Lahore Pakistan | 2010 - 2016
• Led the Enterprise Data Network Operations Centre supporting nationwide telecom infrastructure and mission-critical business services, while managing and mentoring engineers providing 24x7 operational support.
• Planned, implemented and maintained enterprise routing, switching, firewall, VPN and network security infrastructure; led BGP dual-multihoming to improve Internet resilience and traffic separation.
• Developed operational standards, SOPs and security baseline documentation and coordinated customer management, vendors and engineering teams for incident resolution and infrastructure planning.
• Led network staging, Cisco LLD configuration-template development, configuration-management/backup/compliance automation initiatives, technology evaluations, POCs and procurement support.
• Oversaw operational budgeting, resource planning, service delivery and team development while supporting Cisco ASA, PIX, FWSM, VPN Concentrators, IDS/IPS, CS-MARS and authentication platforms.
Senior Network & Security Engineer | Cyber Internet Services, Lahore Pakistan | 2008 - 2010
• Provided senior engineering support within Warid Telecom’s 24x7 Enterprise Data Network NOC, managing security components (CS-MARS, ACS, VPN Concentrators, PIX, IDS), coordinating penetration-testing remediation and network audits, and working with Cisco TAC on installation, configuration and optimisation of routers, switches, firewalls and VPN infrastructure to meet operational SLAs.
Network & Security Engineer | Cyber Internet Services, Lahore Pakistan | 2006 - 2008
• Performed resident network and security operations for Warid Telecom’s 24x7 NOC, troubleshooting routing, switching, firewall, VPN, redundancy and AAA services; supported data-centre capacity and high-availability planning (including SolarWinds Network Performance Monitor deployment and vulnerability-assessment remediation); and produced HLD/LLD documentation, coordinating with Cisco TAC on technical assistance and configuration support.
• Warid Telecom Primary Data Centre Relocation (2012): contributed to project planning, capacity planning, migration planning, resource coordination, system integration and service restoration with minimal network-service degradation.
• Warid Telecom Secondary Data Centre Deployment & Integration (2008): contributed to HLD/LLD development and configuration templates, supervised on-site Cisco deployment resources and integrated the secondary data centre with the primary site for Active/Standby services.
CCIE Security #55472 | CCNP Security | Fortinet NSE 4 | Fortinet NSE 5 (FortiManager/FortiAnalyzer) | JNCIS-SEC | JNCIA-SEC
FortiGate • FortiClient EMS • FortiAuthenticator • FortiAnalyzer • FortiManager • Cisco FTD/FMC • Cisco ISE • Cisco Threat Grid • AnyConnect • Cisco ASA/FWSM/PIX • Nexus • Palo Alto Networks • Juniper Security • BGP • OSPF • EIGRP • MPLS L3 VPN • IPsec • SSL VPN • IPS • NAT • HA • NDR • EDR
Available on request.