← Back to list
Registration: 17.05.2023

Portfolio

www.seic.com

Security Enterprise Architect

www.pge.com, San Francisco, CA

Network Security Architect

www.cms.com, Jackson, MI

Senior Enterprise Architect

Skills

AWS
Azure
PaaS
SaaS
TCP/IP

Work experience

Network Cloud Architect
07.2015 - 04.2023 |Under NDA
-
Hybrid and Private Cloud implementation for SaaS, IaaS utilizing AWS, GCP, Box, and Azure as cloud providers. SD-WAN implementation for remote locations. Identity Access Management Architecture and implementation within the Enterprise and partners networks for 802.1x, BYOD, MDM with Cisco ISE. Enterprise Security Support (Check Point, Palo Alto, Cisco Firepower)
Security Enterprise Architect
06.2014 - 07.2015 |www.seic.com
-
Review network and security architecture and provide guidance for deployment of new technologies and integration with existing ones. Recommend best practices on all IT initiatives from a security perspective. Implement new security technologies such as Cisco SourceFire IPS (network intrusion protection system - NIPS), Cisco WSA/ IronPort, IBM Qradar, Trustwave McAfee IPS and Cisco ISE, Palo Alto Networks, Cisco Nexus, Cisco ASA, Netscout, SDWAN. Perform detailed analysis of network security infrastructure components (networking, firewalls, servers, IPS/IDS) and assess the effectiveness of its security implementation; End point security design. Track current security advisories, determine core network vulnerability, and provide rapid guidance in order to minimize core network exposure. Identify security gaps and provide mitigation plan and recommend roadmap for deployment of mitigating solution.
Network Security Architect
11.2010 - 05.2014 |www.pge.com, San Francisco, CA
-
Lead various transformative enterprise network initiatives and global deployment plans including preparation for a NERC CIP audit. Complete MPLS network redesign, infrastructure upgrades, data center global load balancing utilizing Cisco OTV. SmartGrid modernization project with Silver Springs Networks AMI infrastructure and transitioning PG&E IPv4 network to IPv6. Implementation of hybrid cloud for SaaS (Software as a service) and PaaS (Platform as a service). Azure, AWS. Implementation of Cisco ISE for Single Sign-On authentication of wireless users accessing corporate network. SIP, ASR9k/XR, Cisco Nexus rollout, new data center build out and migration within a complex highly secured SCADA multi-vendor network environment including nuclear power plants. FERC, NERC-CIP, NIST, HIPAA, SOX, PCI, SCADA, NEI, Infoblox and IPAM
Senior Enterprise Architect
02.2008 - 12.2010 |www.cms.com, Jackson, MI
-
Lead major project for Consumers Energy on AMI (Advanced Metering Infrastructure) as part of Federal Government’s Smart Grid Demonstration Project. Design and implement network infrastructure to allow utilities to evaluate Smart Grid vendors, to discover and address concerns on the security challenges of the Smart Grid and AMI deployments, Deployment and test of various cloud scenarios for utilities – private, public, hybrid, and security overlay for each type of deployment in order to use cloud services in the most effective manner. Built IPv4/IPv6 network infrastructure to accommodate and test interoperability of SmartGrid/ AMI products. FERC, NERC-CIP, NIST, Cisco, Juniper, Aruba Networks, PaloAlto Firewalls, Checkpoint, ArcSight, Q1 Labs (QRadar), Trustwave, SolarWinds, OpNet, Infoblox and IPAM.
Network Architect
03.2006 - 09.2007 |www.cisco.com , San Jose, CA
-
Provide SME expertise for AST, AS and GTA groups on the development of new AST tools such as PELE, I&R, SCH, NLS for comprehensive Unified Communication network care and improvement.
Lead SME
11.2004 - 12.2005 |United Health, Plymouth, MN
-
Consult United Health Group, #17 in Fortune 500, the largest health insurance provider in the US, which serves more than 55 million individual customers, on data and voice national networks. Develop a strategy and implement a transitioning of network management from AT&T to internal resources, ensuring enterprise-wide systems availability, enhancing the quality of IT services delivered for more than 55.000 users, over 500 sites, while driving down costs. Upgrade, replace network equipment (LAN and WAN) and migrate data centers at nearly half of the company’s sites, affecting approximately 70% of United Health Group’s employees that resulted in a savings of more than $10 million a year for the company. Design and implement new WAN architecture scalable for VOIP using MPLS. Develop configuration standards and documentation set for each site. Deploy Unified Communication – VOIP Pilot Project defining the placement on the network and configuring Cisco Call Manager and Call Manager Express, Cisco Unity and Unity Express. Merge recently acquired companies to existing United Health network. Provide Tier 2 and Tier 3 hands on support for NOC utilizing tools such as CiscoWorks, Concord Health and HP Openview.
Enterprise Architect
01.2004 - 08.2004 |Philips, Andover, MA
-
Led major initiatives, develop roadmaps and standards, and oversee all aspects of the Philips corporate, mission critical, global international web hosting network covering over 60 countries including over 100 routers, 200 switches, 190 VLANs, 5 pairs of Cisco Firewall Switching Modules (FWSM) and 4 Cisco Content Switching Modules (CSM) using high-end Cisco Catalyst 6500 switches. Provide management, technical leadership capacity planning, and expertise to global network initiatives and projects, including remote mentoring of IT teams in Europe and Latin America. Delivered a 21% reduction in network operating costs by renegotiating disaster recovery service contracts, evaluating alternative support and maintenance providers and reducing the annual cost through applying new technologies and adept renegotiations with vendors. Manage vendor relationships and together developed solutions to be offered as services using Technology and Product analysis, perform risk assessments against planned milestones, manage capital project expenditures and coordinate external dependencies.
Lead Senior Network Engineer
05.2001 - 05.2003 |Whitehead Institute for Biomedical Research, Cambridge, MA
-
Provided network management for Whitehead Institute for Biomedical Research, - world leader in cancer and HIV research and institute partners such as Harvard University, MIT, Harvard Hospitals, and several pharmaceutical and biotechnology firms. Performed sound independent analysis of network and systems security design and implementation of such designs. In depth knowledge of firewall technologies including configuration and rule set creation. Led the organization through a series of upgrades to capitalize on emerging technologies and application enhancements including the replacement of obsolete systems in all 6 locations with new LAN/WAN technology, linking them with fiber optic connections Planned, coordinated, implemented and supported the 802.11x, VPN over wireless, security, LAN/WAN hardware, software and Internet/Intranet/Extranet integration network connectivity, diagnosed network failures and resolved any problems. Provided leadership and training to the junior level network professionals. Minimized corporate network vulnerability up to the highest DoD and HIPPA standards by installing Cisco PIX firewall and Cisco Intrusion Detection System, Cisco VPN and Layer 2 and 3 implementations. Reduced network-related help desk calls 85% by restructuring and upgrading company network and by deploying highly scalable and reliable DNS, DHCP solution using Cisco Network Registrar 6.0. Executed an IT culture change and transitioned the function from technology-driven to a business-process driven role.
Lead Senior Network Engineer
05.2000 - 05.2001 |OrderTrust, Inc., Lowell, MA
-
Designed, supported and implemented LAN/WAN for financial transaction processing financial / payment processing company, services of which included order capture, routing of separate fulfillment requests to multiple suppliers, real-time credit card authorization and inventory availability checking, financial settlement and order status notification to consumers via e-mail, providing financial services for consumers and businesses. Modernized network infrastructure through systems overhaul to catapult network speed by 100% and introduce state-of-the-art IT system featuring gigabit backbone and clustering designed specifically to provide maximum performance for e-business. Completed three months ahead of schedule and $120K under budget. Redesigned and implemented rapidly deployable, consistent security throughout the enterprise in a comprehensive and layered approach by adopting latest technologies, which reduced network’s vulnerability and prepared the network for a successful IT auditing from VISA Full project life cycle for enterprise-scale Network contingency planning, network configuration, optimization, redundancy and routing design. Integrated network performance tuning capabilities in a multi-protocol, multi operating system environment which increased network performance and stability by 19%. Developed Disaster Recovery procedure that allowed rapid recovery in a mission-critical environment. Implemented organization’s first NOC highly responsive, multi-tiered support system which improved customer satisfaction, increased department-wide productivity and eliminated expensive technical staff during 2nd and 3rd shifts.
Project Manager, Senior Technical Analyst
05.1998 - 05.2000 |Fujitsu Canada (TMC) Regina, Saskatchewan
-
Managed projects in all phases: requirements gathering, design, system integration, user acceptance testing, and implementation. Developed plans for implementation of changes and scheduled/performed testing and contingency procedures as required by business needs and to ensure that business requirements are achieved and documented. Coordinated the process of evaluating current systems functionality and follow up on issues stemming from these tasks. Ensured that adequate support was provided to all project team members so that they had what they needed to complete their project assignments. Implemented a unique library catalogue search engine, first in Canada, which allowed users to perform real time library material searches across Canada and USA. Provided technical expertise to the library grants project of Bill and Melinda Gates Foundation with budget of $636,957 over the year of 2000 to support Saskatchewan’s public libraries, serving low-income communities with a gift of public access computers, Internet access, and training of library staff.
Computer System Analyst
05.1995 - 05.1998 |World of Vacations Ltd., Vancouver, BC
-
Computer System Analyst, Software Developer
05.1988 - 05.1993 |Kishinev Electronics Plant
-

Educational background

Bachelor and Masters of Science in Computer Information Systems
1983 - 1988
Kiev State Engineering and Construction University

Languages

UkrainianNativeEnglishProficient