Network & Cloud Security Engineer
Arlington, Virginia Β· US Citizen Β· FranΓ§ais / English
Open to remote
LinkedIn TechVernia SankaraShield
I build network and security infrastructure from the ground up β routing, segmentation, firewall policy, secure remote access β then attack it, detect the attack, and audit the configuration that allowed it. Everything below is published: the configurations, the detections, the tooling, and the parts that do not work.
Focus on cloud-delivered security: SASE, firewall policy, detection engineering, and network automation in Python.
| Project | What it is |
|---|---|
| network-config-compliance CI | A Python tool that audits Cisco IOS configurations against CIS Benchmark and DISA STIG controls and fails a CI pipeline when a non-compliant configuration is about to ship. 16 tests, structured parser, three output formats. |
| soc-tier1-detection-lab | A home SOC run end to end: Sysmon telemetry, six Sigma detections translated to Wazuh, each technique triggered on purpose with Atomic Red Team, then triaged with a written runbook. Mapped to MITRE ATT&CK, including the gaps. |
| l2-attacks-and-mitigations | Six Layer 2 attacks β ARP spoofing, DHCP starvation, rogue DHCP, CAM overflow, VLAN hopping, STP takeover β each paired with the switch configuration that stops it and the capture that proves it. |
| palo-alto-segmentation-lab | Zone-based segmentation on PAN-OS: least-privilege policy, App-ID instead of port rules, and East-West control between segments most networks leave flat. |
| fortigate-secure-remote-access | FortiGate SSL VPN and IPsec IKEv2, built least-privilege β access tied to identity and role rather than a flat tunnel into the LAN. |
| zero-trust-sase-architecture | Reference architecture for replacing perimeter VPN with identity-based access: NIST SP 800-207, ZTNA versus VPN, SASE, and a migration roadmap. |
| Lab | What it demonstrates |
|---|---|
| Cisco NSO Network Automation | Service orchestration across a multi-vendor estate β IOS, IOS-XE, IOS-XR and NX-OS β with device onboarding and service templates |
| Multi-Area OSPF Routing | Two-site topology with redundant WAN links, authenticated OSPF adjacencies, QoS for voice and HSRP gateway redundancy |
| Enterprise Network Simulation | Full enterprise build β VLANs, inter-VLAN routing, DHCP, NAT β with a hardened management plane and Layer 2 protections on every device |
| NAT Scenarios | Static NAT, dynamic NAT, PAT, port forwarding and NAT Virtual Interface, with verification |
No credential, key or real address appears in any of these repositories. Every configuration uses placeholders and documentation ranges (RFC 5737, RFC 1918), and the labs score 100% against the compliance tool above.
SankaraShield β networking and security: protocol behaviour, vendor releases, and what breaks in practice.
techvernia.com β hands-on technical reviews and guides, published in ten languages. 256 tools tested, 50+ guides.
- Preparing CompTIA Security+
- Extending the compliance tool to NX-OS and PAN-OS configurations
- Publishing lab write-ups on SankaraShield
Open to network and security engineering roles β remote, and the DC metro area.