| PRAVALIKA P - Network Security Engineer |
| [email protected] |
| Location: Dallas, Texas, USA |
| Relocation: YES |
| Visa: EAD |
| Resume file: Pravalika_S_Network Engineer_1788289362280.docx Please check the file(s) for viruses. Files are checked manually and then made available for download. |
|
PRAVALIKA P
Network Security Engineer | CCNA, PCNSE, PSSE Plano, TX | (224) 252-5162 | [email protected] | linkedin.com/in/pravalika-pullannagaari-a790b6145 PROFESSIONAL SUMMARY Network Engineer with 7+ years of experience in major internet routing protocols (BGP, OSPF/EIGRP) and hands-on Linux/Unix systems environments, supporting datacenter and provider network operations across a 500K+ subscriber ISP network and enterprise cloud customer environments. Builds automation via Bash/shell scripting and Python programming to deliver simple, sustainable, and repeatable operational solutions, reducing MTTR by 40% and manual overhead by 25%. Experienced diagnosing, mitigating, and resolving large-scale networking events, operating and troubleshooting routing, interconnectivity, and configuration issues from Top of Rack to network border. Creates and maintains technical documentation, standard operating procedures, and knowledge transfer material, and partners with cross-functional network/systems/software engineering teams to support fast, smooth rollout of new designs and tools. Comfortable operating in a 24x7 on-call rotation and under pressure during customer-impacting events. CERTIFICATIONS Cisco Certified Network Associate (CCNA) Active Palo Alto Networks Certified Network Security Engineer (PCNSE) Active Palo Alto Network Security Service Edge Engineer (PSSE) -Active CORE TECHNICAL SKILLS Internet Routing Protocols: BGP, OSPF/EIGRP, TCP/IP, IPv4/IPv6, MPLS WAN circuits, VLANs, subnetting, Internet peering & inter-domain routing (4+ years, ISP environment) Linux/Unix Systems: 4+ years hands-on Linux/Unix systems environment experience, shell environment operations, command-line diagnostics and troubleshooting Automation & Scripting: Bash/shell scripting and Python programming for network automation, monitoring, and operational tooling Network Hardware: Cisco routers & switches (350+ device environment), Cisco ASA, Palo Alto NGFW, VMware SD-WAN (VeloCloud) Monitoring & Telemetry: SolarWinds, Splunk, Prometheus, Grafana, real-time alarm surveillance and performance/fault management, Wireshark, tcpdump, ping/traceroute diagnostics Operations & Incident Response: Large-scale network event diagnosis and mitigation, incident lifecycle management and escalation, change management, 24x7 on-call operations Documentation & Process: Runbooks, SOPs, standard operating procedures, knowledge transfer material, change and approval process adherence Cloud & Azure Networking: Microsoft Azure, VNets, NSGs, Azure Firewall, ExpressRoute, Site-to-Site VPN, Hub-and-Spoke, VNet Peering, Azure Private Link, Azure Virtual WAN, Hybrid Connectivity, Azure Routing, BGP. Cloud Security: Azure Firewall, Azure NSGs, Azure Private Link, Azure Virtual WAN, Hybrid Cloud Security Compliance: Security Architecture Reviews, Security Standards, Audit Support, Control Validation, Risk Assessment Firewalls & Security: Palo Alto PA-3000/PA-5000 (Panorama, Wildfire, SSL forward proxy/decryption, zone-based policies, IPSec/SSL VPN); Checkpoint R55 R77.20 Gaia (ClusterXL, Provider-1/MDM); Cisco ASA 5500/5500-X/5580/5540/5520; Juniper SRX 100/240; firewall migration tooling (Cisco ASA Checkpoint/Palo Alto). Load Balancing (ADC): F5 BIG-IP LTM, GTM, APM, ASM; iRules scripting (TCL); virtual servers, pools, SNAT, persistence profiles, monitors, and Wide IPs; one-arm and two-arm architectures. Proxy & Web Security: Zscaler (ZIA, cloud-based proxy design and support), Bluecoat, WebSense, McAfee Web Gateway (MWG), policy management, content filtering, and URL/application inspection. Network Access & AAA: Cisco ISE, ACS, Aruba ClearPass; RADIUS, TACACS+; Infoblox DNS/DHCP/IPAM; Active Directory/ADFS integration. Wireless (WLAN): Cisco and Aruba WLAN AP groups/profiles, SSIDs, authentication rules, RTLS, RF planning, WPA2/WPA3, 802.11 and Mesh design. Cloud & Virtualization: Microsoft Azure (ExpressRoute, site-to-site VPN, hub-and-spoke topology, VNets, NSGs, VNet peering); VMware vCenter, NSX-T, vMotion, vSphere/ESXi; NSX-to-Azure workload migration. Network Automation: Python, Ansible, Terraform, REST APIs, Cisco DNA Center, Cisco SD-WAN (Viptela), Itential, Netmiko, NAPALM, Nornir, Git, GitHub, Jenkins, YAML, JSON, Jinja2, Postman, Linux, Automation Framework Development, Configuration Compliance, Network Orchestration, Infrastructure as Code (IaC) PROFESSIONAL EXPERIENCE Client: Palo Alto Networks, Plano, TX Apr 2025 Present Network Security Engineer Responsibilities: Directed network security initiatives focused on regulatory compliance and high-availability for mission-critical financial systems, supporting thousands of users across multi-region data centers and hybrid cloud environments. Designed and maintained secure routing architectures using BGP, OSPF, and MPLS to deliver resilient and low-latency WAN transport, ensuring uninterrupted access to business-critical applications. Conducted extensive network segmentation across core and edge networks using Cisco ACI and VRFs to enforce data protection and reduce attack surfaces. Designed and implemented Azure ExpressRoute for secure, private connectivity between on-prem data centers and Azure VNets. Configured and maintained Fortinet FortiGate firewalls including IPSec VPNs, security zones, NAT policies, IPS profiles, and web filtering services. Managed Check Point firewall rule lifecycle, including policy deployment, audit remediation, change validation, and compliance reporting. Supported F5 BIG-IP LTM/GTM solutions for enterprise banking applications, ensuring high availability and optimal traffic distribution. Implemented firewall hardening standards and security best practices to reduce attack surface and strengthen perimeter defenses. Participated in after-hours maintenance windows, firewall upgrades, and emergency incident response activities supporting 24x7 banking operations. Developed and enforced Conditional Access policies in Microsoft Azure AD/Entra, applying risk-based authentication logic and real-time user behaviour analytics. Managed full-cycle implementation of Global Protect VPNs integrated with Entra MFA, enhancing remote workforce security while maintaining seamless user access. Led cross-functional coordination with security, compliance, and application teams to deploy identity-aware access policies and zero-trust enforcement. Worked with telecom providers to provision and troubleshoot ExpressRoute cross-connects. Spearheaded migration projects involving hybrid cloud identity federation using Azure AD Connect and SAML/OAuth integrations. Designed and executed tabletop simulations for high-severity incidents including phishing campaigns and insider threats, producing detailed RCA documentation. Automated security infrastructure tasks using Python and Ansible, streamlining patch management, configuration checks, and compliance validations. Implemented DNS filtering and DDoS protection via Cloudflare and Umbrella, significantly reducing inbound attack vectors. Delivered identity lifecycle governance by integrating Entra workflows with HR and onboarding systems, improving access provisioning and deprovisioning efficiency. Configured Forcepoint Web Security for granular content filtering, malware scanning, and endpoint protection against shadow IT. Integrated SIEM telemetry with Conditional Access logs to track privilege escalation attempts and unauthorized login patterns. Monitored authentication flows and enforced session security using token lifetimes, sign-in frequency policies, and device state evaluations. Conducted application risk assessments before onboarding to Azure AD, enforcing SSO policies, SAML integration, and claims mapping. Maintained firewall rule governance using Palo Alto Panorama, conducting quarterly policy reviews and cleanup audits. Client: Global Tel Link (GTL)| Dallas TX Feb 2024 Mar 2025 Network Engineer Responsibilities: Configured Cisco 2800/3800 routers and 3650/3850/4500/6500 switches as part of network implementation projects. Configured LAN switches (Cisco Catalyst 2900, 3550, 4500, 6509) and access-layer switches (3560, 3850) for VLAN, STP, RSTP, MSTP, and EtherChannel. Reviewed and approved firewall requests, ACL modifications, NAT changes, and network connectivity requirements to ensure compliance with enterprise security standards. Designed and implemented network segmentation strategies using VLANs, VRFs, firewall zones, and security policies to reduce lateral movement. Collaborated with security architecture, infrastructure, and application teams to define secure network architecture patterns for hybrid cloud deployments. Designed trust boundaries and ingress/egress security controls for enterprise applications deployed across Azure and on-premises environments. Participated in architecture review meetings and provided technical guidance for network security design decisions. Documented security architecture standards, design decisions, HLDs, LLDs, and implementation procedures for enterprise deployments. Supported enterprise network modernization initiatives involving firewall migration, segmentation, and secure cloud connectivity. Developed Python automation scripts to automate network configuration, health checks, and compliance validation across Cisco and Juniper devices. Built Ansible playbooks for automated provisioning, software upgrades, configuration backups, and standard change deployments. Integrated Infoblox IPAM with automation workflows to dynamically allocate IP addresses during network provisioning. Monitored enterprise network health using SolarWinds, SNMP, ICMP, and Wireshark to proactively identify and resolve network issues. Client: PepsiCo, Frisco TX, USA March 2023-Jan 2024 Network Engineer Responsibilities: Analyze, troubleshoot, and investigate security-related, information systems' anomalies based on security platform reporting, network traffic, log files, host-based and automated security alerts Monitor and analyze output and performance of network and host-based security platforms including: Vulnerability scanning systems and tools, Network-based Intrusion Detection/Prevention Systems (IDS/IPS), Host-based Intrusion Detection/Prevention Systems (HIDS/HIPS), File integrity verification and monitoring software (FIM), Security Information & Event Management (SIEM) platform, Data Loss Prevention (DLP), Log Indexing and Correlation tools, Anti-virus and anti-spyware logs and events, Web proxy and filtering systems Execute routine and ad-hoc vulnerability scans and other tests to verify system security settings and configurations. Built Python-based automation pipelines for cloud networking (AWS/GCP/Azure) using Boto3 and SDKs. Automated firewall rule audits and reporting using Python and REST APIs across on-prem and cloud environments Collaborated with stakeholders to align Brinqa's risk scoring metrics with organizational risk management frameworks, ensuring consistent and accurate reporting. Created scripts to validate IaC deployments using Python and TestInfra, ensuring post-deployment compliance. Refactored legacy network configurations into modular IaC templates, reducing manual rework and drift. Facilitated red team/blue team exercises simulating product-level security incidents. Maintained detailed incident response documentation and improved playbooks based on lessons learned. Built cross-functional relationships with DevSecOps, legal, marketing, and customer support for efficient PSIRT operations. Monitored and analyzed security metrics through Brinqa, providing monthly reports that highlighted trends and informed proactive security measures. Developed PowerShell scripts to automate IAM tasks, including user provisioning, access reviews, role assignments, and automated certificate renewals. Integrated Microsoft Graph API for advanced IAM operations. Code review with the help of SonarQuber and HP Fortify tools Designed Threat Model (STRIDE/DREAD) to SDLC process. Capgemini (Client COX communications), Hyderabad, India Feb 2020 Aug 2022 Network Engineer Responsibilities: Operated and troubleshot major internet routing protocols (BGP peering, OSPF/EIGRP fundamentals) and MPLS-based WAN circuits across a production ISP network of 350+ Cisco routers and switches serving 500K+ customers, in a Linux/Unix systems environment. Built Bash/shell and Python scripting for monitoring automation, reducing manual troubleshooting overhead and supporting real-time detection of network anomalies alongside senior engineers. Diagnosed and mitigated large-scale network outages through packet-level diagnostics (Wireshark, tcpdump, ping, traceroute), partnering with senior engineers on root-cause analysis to restore service quickly. Supported route advertisement checks, path/label troubleshooting, and circuit turn-up validation for BGP peering and MPLS WAN circuits across the provider network. Supported network deployment, scaling, and technology refresh activity including SD-WAN rollouts and upgrades across corporate, manufacturing, and field environments, following established change management processes. Created and maintained technical documentation, SOPs, and knowledge transfer material authoring 30+ runbooks and knowledge base articles to standardize operational procedures. Performed periodic health checks, patching, and post-change validation across distributed sites; supported firewall/NAT connectivity and VPN configuration across Cisco ASA and Palo Alto NGFW platforms. Directed network security initiatives focused on regulatory compliance and high-availability for mission-critical financial systems, supporting thousands of users across multi-region data centers and hybrid cloud environments. Client: Sonata Software, India Aug 2019 - Jan 2020 Network Engineer Responsibilities: Created, updated, and maintained incident documentation, operational procedures, and network runbooks. Performed connectivity validation using SSH, Telnet, Traceroute, Ping, and CLI diagnostics across routers, switches, and firewalls. Participated in 24x7 on-call support, maintenance windows, and emergency production changes. Automated firewall policy deployment and configuration validation using REST APIs and Python. Used Git for version control of network automation scripts and infrastructure configurations. Worked with Terraform to automate Azure network resource provisioning including VNets, NSGs, route tables, and VPN gateways. Reduced manual configuration efforts by automating repetitive network operational tasks across enterprise environments. Collaborated with engineering teams to implement Infrastructure as Code (IaC) standards for network deployments. Implemented, configured, and troubleshot OSPF and BGP routing on Cisco and Juniper routers and firewalls. Performed upgrades and maintenance on production Juniper, Cisco, and Palo Alto firewall devices. Migrated IPSec tunnels from Juniper SRX 3600 firewalls to Palo Alto 7080 appliances. Implemented high-availability pairs with multiple virtual routers per chassis. Upgraded and configured Cisco Wireless LAN Controllers (5520) to integrate WLAN access control with Cisco ISE. Configured Cisco WLC with ISE to perform 802.1X authentication for wireless users. Troubleshot WLAN, LAN, and WAN issues; currently implementing Catalyst 9800-40 WLC. Developed engineering documentation for the F5 environment (LTM and GTM) and related change processes. Applied F5 TMOS architecture expertise across LTM/GTM environments. Managed DNS and DHCP configurations across multiple network views via Infoblox and MS DNS/DHCP consoles. Provided operational support for the network underlying running on Juniper QFX 10008, QFX 5100, EX 4300, and EX 2200 switches. Implemented Wi-Fi security measures (WPA2/WPA3, MAC filtering, VLAN segmentation, firewall rules) to protect against unauthorized access. Designed, implemented, and optimized wireless networks for coverage and performance across diverse environments. TECHNICAL PROJECTS Infrastructure Monitoring & Automated Triage System: Built a Python/Bash monitoring system integrated with Prometheus and Splunk to detect network anomalies in real time, automating alert triage and reducing MTTR by 40% and manual overhead by 25% directly applicable to delivering sustainable, repeatable network automation solutions. Network Fundamentals Practice Lab: Built a GNS3/EVE-NG lab replicating enterprise LAN/WAN topologies (OSPF/BGP routing scenarios, link-down events, VPN tunnel failures) in a Linux-based environment to practice structured incident triage and SOP execution; documented findings in runbooks and KB articles. EDUCATION Master of Science, Management Information Systems University of Houston Clear Lake (May 2024) Keywords: active directory information technology ffive hewlett packard microsoft mississippi Pennsylvania South Dakota Texas Wisconsin |