Network Engineer I — Miami, FL

I own network changes from design to CAB to done

Contract Network Engineer executing enterprise change management across routing, firewalls, and hybrid-cloud connectivity — with CCNA and CompTIA Security+ in progress.

40%
Reduction in manual backup/config time
20+
Employee systems supported & monitored
2
Certifications actively in progress
Core Competencies

Where I add value on day one

Hands-on contract experience across routing, security, and hybrid-cloud connectivity, backed by a full change-management workflow.

01

Routing & Switching

Cisco IOS/IOS-XE environments — OSPF, EIGRP, BGP fundamentals, VLANs, 802.1Q trunking, and HSRP-based gateway redundancy.

02

Network Security

Palo Alto Networks NGFW and Cisco Firepower change execution, including site-to-site IPsec VPN builds and policy hardening.

03

Hybrid Cloud Connectivity

Designed and documented on-prem/AWS site-to-site VPN connectivity, including diagramming and implementation MOPs.

04

Change Management

Own MOP authorship, backout planning, and CAB presentation end-to-end for network infrastructure changes.

05

Directory & Name Services

Migrated DHCP services from router-based pools to centralized Windows Server DHCP integrated with Active Directory and DNS.

06

SD-WAN (in progress)

Self-directed lab study on Cisco Viptela/SD-WAN architecture — underlay/overlay design and controller-based management.

Experience & Projects

What I've actually shipped

Contract change-management work at Aston Technologies, expanded into case studies. Client specifics are withheld per NDA — process and outcomes are real.

Case Studies

Network Engineer I — Aston Technologies

Contract · Mar 2026 – Present · Remote / Multiple Client Environments
Current Role
01

DHCP Migration: Distributed Cisco Pools → Centralized Windows DHCP

Cisco IOS · Windows Server DHCP · Active Directory · CAB/MOP
+

Problem

DHCP was administered locally on individual Cisco routers across a multi-site VLAN environment, with no centralized failover — a single router failure could take DHCP offline for that site, and scope changes had to be repeated router-by-router as VLANs grew.

Process

Authored the full MOP and CAB change packet: backed up existing Cisco configs, documented every existing DHCP pool (scopes, exclusions, lease terms), built matching scopes on Windows DHCP with AD/DNS integration, and staged a phased per-VLAN cutover — migrating one VLAN first to validate before touching production-wide traffic.

Solution

Migrated DHCP services to centralized Windows Server DHCP with 50/50 load-balanced failover, reconfigured Cisco helper-addresses to forward requests, and validated lease assignment, DNS registration, and connectivity at each stage before disabling the legacy router pools.

Rollback Plan

Documented a full backout path — reactivate Cisco DHCP pools, remove helper-address changes, and restore prior config — so the change could be reversed within the maintenance window if validation failed.

Outcome

Eliminated DHCP as a single-router point of failure, centralized administration into one console instead of per-router configs, and left a documentation package detailed enough for another engineer to execute or roll back independently.

02

Perimeter Hardening: Palo Alto Firewall + Site-to-Site IPsec VPN

Palo Alto NGFW · IPsec VPN · Cisco Firepower · CAB/MOP
+

Problem

Existing firewall policy included overly broad rules built up over time, and a new site needed secure, encrypted connectivity back to the core network without adding a costly dedicated circuit.

Process

Reviewed and CAB-documented proposed rule changes on both Palo Alto NGFW and Cisco Firepower, defined pre- and post-change validation steps, and designed a site-to-site IPsec tunnel to carry the new site's traffic securely over existing internet transport.

Solution

Configured and validated the IPsec tunnel end-to-end, then tightened firewall policy in tandem — replacing broad allow rules with scoped ones matched to actual traffic patterns identified during review.

Verification

Confirmed tunnel stability, correct traffic routing through the new policy set, and no unintended access loss for legitimate traffic before closing out the change window.

Outcome

Delivered secure site connectivity without new circuit costs, and measurably reduced the number of overly permissive "any-any" style rules as part of an ongoing security hardening initiative.

03

Hybrid Connectivity: On-Prem to AWS Site-to-Site VPN

AWS VPC · Site-to-Site VPN · Network Diagramming · CAB/MOP
+

Problem

On-prem infrastructure needed a secure, repeatable path into an AWS VPC for a cloud-connected workload, with no existing hybrid connectivity pattern documented for future builds.

Process

Diagrammed the target topology, wrote the change request and implementation MOP, and configured VPN termination on both the on-prem and AWS sides, including routing to make the VPC subnet reachable from the internal network.

Solution

Established and validated the site-to-site VPN tunnel, confirmed routing in both directions, and packaged the diagrams and MOP as a reusable template rather than a one-off build.

Outcome

Delivered working hybrid connectivity and left behind a documented, repeatable pattern for future on-prem/AWS builds instead of tribal knowledge.

Additional Experience & Self-Directed Projects

04

Junior Systems Admin — Odessa Realty

Jan 2025 – Jan 2026 · Atlanta, GA

Automated server backup and database processes, cutting manual configuration time 40% and eliminating downtime incidents. Configured and monitored internal systems for 20+ employees.

Resume for detail
05

Multi-Site SD-WAN Lab

Self-Directed · Cisco Viptela

Built and documented a simulated Cisco SD-WAN environment (vManage/vSmart/vEdge) with a full IP addressing plan, to build hands-on SD-WAN expertise beyond production change work.

View writeup
Cisco CCNAIn Progress
CompTIA Security+In Progress
B.S. Information, Communication & TechnologyFlorida State University · Dec 2024

Let's talk about your network.

Open to Network Engineer I/II roles in Miami or remote.

Get In Touch
JustinBowden14@gmail.com · linkedin.com/in/justinbowden · Miami, FL