Contract Network Engineer executing enterprise change management across routing, firewalls, and hybrid-cloud connectivity — with CCNA and CompTIA Security+ in progress.
Hands-on contract experience across routing, security, and hybrid-cloud connectivity, backed by a full change-management workflow.
Cisco IOS/IOS-XE environments — OSPF, EIGRP, BGP fundamentals, VLANs, 802.1Q trunking, and HSRP-based gateway redundancy.
Palo Alto Networks NGFW and Cisco Firepower change execution, including site-to-site IPsec VPN builds and policy hardening.
Designed and documented on-prem/AWS site-to-site VPN connectivity, including diagramming and implementation MOPs.
Own MOP authorship, backout planning, and CAB presentation end-to-end for network infrastructure changes.
Migrated DHCP services from router-based pools to centralized Windows Server DHCP integrated with Active Directory and DNS.
Self-directed lab study on Cisco Viptela/SD-WAN architecture — underlay/overlay design and controller-based management.
Contract change-management work at Aston Technologies, expanded into case studies. Client specifics are withheld per NDA — process and outcomes are real.
Case Studies
DHCP was administered locally on individual Cisco routers across a multi-site VLAN environment, with no centralized failover — a single router failure could take DHCP offline for that site, and scope changes had to be repeated router-by-router as VLANs grew.
Authored the full MOP and CAB change packet: backed up existing Cisco configs, documented every existing DHCP pool (scopes, exclusions, lease terms), built matching scopes on Windows DHCP with AD/DNS integration, and staged a phased per-VLAN cutover — migrating one VLAN first to validate before touching production-wide traffic.
Migrated DHCP services to centralized Windows Server DHCP with 50/50 load-balanced failover, reconfigured Cisco helper-addresses to forward requests, and validated lease assignment, DNS registration, and connectivity at each stage before disabling the legacy router pools.
Documented a full backout path — reactivate Cisco DHCP pools, remove helper-address changes, and restore prior config — so the change could be reversed within the maintenance window if validation failed.
Eliminated DHCP as a single-router point of failure, centralized administration into one console instead of per-router configs, and left a documentation package detailed enough for another engineer to execute or roll back independently.
Existing firewall policy included overly broad rules built up over time, and a new site needed secure, encrypted connectivity back to the core network without adding a costly dedicated circuit.
Reviewed and CAB-documented proposed rule changes on both Palo Alto NGFW and Cisco Firepower, defined pre- and post-change validation steps, and designed a site-to-site IPsec tunnel to carry the new site's traffic securely over existing internet transport.
Configured and validated the IPsec tunnel end-to-end, then tightened firewall policy in tandem — replacing broad allow rules with scoped ones matched to actual traffic patterns identified during review.
Confirmed tunnel stability, correct traffic routing through the new policy set, and no unintended access loss for legitimate traffic before closing out the change window.
Delivered secure site connectivity without new circuit costs, and measurably reduced the number of overly permissive "any-any" style rules as part of an ongoing security hardening initiative.
On-prem infrastructure needed a secure, repeatable path into an AWS VPC for a cloud-connected workload, with no existing hybrid connectivity pattern documented for future builds.
Diagrammed the target topology, wrote the change request and implementation MOP, and configured VPN termination on both the on-prem and AWS sides, including routing to make the VPC subnet reachable from the internal network.
Established and validated the site-to-site VPN tunnel, confirmed routing in both directions, and packaged the diagrams and MOP as a reusable template rather than a one-off build.
Delivered working hybrid connectivity and left behind a documented, repeatable pattern for future on-prem/AWS builds instead of tribal knowledge.
Additional Experience & Self-Directed Projects
Automated server backup and database processes, cutting manual configuration time 40% and eliminating downtime incidents. Configured and monitored internal systems for 20+ employees.
Built and documented a simulated Cisco SD-WAN environment (vManage/vSmart/vEdge) with a full IP addressing plan, to build hands-on SD-WAN expertise beyond production change work.
Open to Network Engineer I/II roles in Miami or remote.
Get In Touch