Summary
Overview
Work History
Education
Skills
Certification
Project Work
Languages
Timeline
Generic

Sampreet Bagchi

Kolkata

Summary

Proficient in leading end-to-end datacenter migration & platform migration projects; skilled at providing technical support involving security architecting On-prem and Cloud infrastructure and mitigation of vulnerabilities to ensure continual delivery operations.

Overview

9
9
years of professional experience
1
1
Certification

Work History

Network Security Specialist

Cognizant Technology Solutions, CTS
06.2023 - Current
  • Handled major incident escalations and critical troubleshooting as an L3 network security engineer, diagnosing and resolving complex security and connectivity issues across Zscaler ZIA/ZPA, Citrix Netscaler, multi-vendor firewalls (Checkpoint, Palo Alto, Cisco FTD), VPN tunnels, and load balancers. Conducted deep-dive packet analysis, SSL decryption troubleshooting, and RCA to restore services within SLA.
  • Designed and deployed advanced network security architectures, implementing firewall security policies, SSL certificate management, TLS offloading, IDS/IPS configurations, NAT rules, and web filtering policies. Engineered secure cloud access and segmentation using Zscaler Private Access (ZPA) and Zscaler Internet Access (ZIA) while optimizing Zero Trust security models.
  • Led network security migrations and high-availability configurations, including disaster recovery (DR) setups, BGP/MPLS failover testing, and multi-cloud security enforcement. Configured backup tunnels for S2S/IPSec VPNs, HA firewall pairs, Citrix Netscaler GSLB for redundancy, and Layer 7 traffic control to ensure uninterrupted service during failover events.
  • Acted as the senior technical escalation point, coordinating with vendors and internal teams to optimize proxy policies, deep packet inspection (DPI) rules, application-layer security, and WAF protections. Conducted in-depth log analysis (PCAP, Syslog, SIEM) for security incident investigations, refining security baselines and improving response times.

Network Operations Engineer

Tata Consultancy Services, TCS
02.2016 - 05.2023
  • Managed a team of 7 members, conducting knowledge transfer sessions, updating SOPs, and organizing team engagement meetings to enhance operational efficiency and technical expertise.
  • Configured, managed, and upgraded Cisco Routing & Switching infrastructure, including LAN, WAN, VLAN, VTP, and HSRP on Cisco L2/L3 devices. Implemented STP/RSTP, RIP, OSPF, BGP, and VRF routing protocols while performing firmware and hardware upgrades to ensure optimal network performance, security, and reliability.
  • Led critical incident management, device monitoring, and service request resolution, ensuring SLA adherence by coordinating with multi-functional teams for rapid troubleshooting, network device upgrades, business continuity, and post-incident technical recovery processes.

Education

B.Tech - Information Technology

Netaji Subhash Engineering College
Kolkata, India
08-2015

Skills

  • NETWORK INFRASTRUCTURE

CISCO ROUTING & SWITCHING, MPLS, IP PROTOCOL, VPN, HTTP, SSL, FTP, DNS, DHCP

  • NETWORK SECURITY FIREWALL

CISCO (ASA, FIREPOWER THREAT DEFENCE, FIREPOWER MANAGEMENT CENTER, CSM), PALOALTO NETWORKS, CHECKPOINT TECHNOLOGIES, FORTIGATE

  • LOAD BALANCER

CITRIX NETSCALER, F5 LTM

  • FORWARD PROXY

ZSCALER-ZIA, ZPA, ZTNA

  • CLOUD INFRASTRUCTURE

AZURE NETWORKING & AZURE NETWORK SECURITY, POWERSHELL

  • NETWORK TOOLS

ALGOSEC, SOLARWINDS, WIRESHARK, TCPDUMP, SPLUNK, QRADAR, ENTUITY, MX-TOOLBOX, INFLOBOX

Certification

  • Microsoft:

Azure Fundamentals AZ-900

Azure Data Fundamentals DP-900

  • Zscaler:

Zscaler Digital Transformation Administrator (ZDTA)

Zero Trust Certified Associate (ZTCA)

  • Palo Alto Networks:

Network Security Fundamentals

Palo Alto Networks Certified Network Security Engineer (PCNSE)

  • ITILv3 Foundation

Project Work

Data Center Transition:

  • Led the brownfield migration from Cisco Nexus legacy architecture to Cisco ACI, including APIC configuration, VRF creation, Application Profiles, Bridge Domains, and Contracts to ensure seamless policy-driven network automation and security segmentation.
  • Executed VLAN cutover strategy to transition VLAN-based policies to EPGs, enable inter-VRF routing, and optimize application connectivity, ensuring minimal downtime and seamless workload migration within the ACI fabric.
  • Managed the migration of Cisco ASA to Cisco FTD and Check Point to Palo Alto next-generation firewalls, implementing HA (High Availability) build, security zone configuration, NAT policies, IPS/IDS policies, and tag-based rule mapping. Designed and deployed template and template stacks for device groups structured per location, ensuring standardized security policies and efficient policy management across multiple sites.


Proxy Transformation:

  • Led the migration from a legacy on-premises proxy to Zscaler Internet Access (ZIA), implementing explicit and transparent proxy modes with PAC file management, Z-Tunnel 1.0/2.0 traffic forwarding, and SSL inspection with custom certificate pinning exceptions. Configured GRE/IPSec tunnels for optimized egress routing, enforced Cloud Firewall policies with advanced Layer 7 application control, and integrated identity-based authentication using SAML and SCIM with Azure AD. Migrated and optimized security policies, including URL filtering, DNS security, sandboxing, and data loss prevention (DLP), to enhance cloud-based threat protection.
  • Designed and deployed Zscaler Private Access (ZPA) to replace traditional VPN solutions, implementing application segmentation and least-privilege access using micro-tunnels. Configured ZPA App Connectors for secure application publishing, integrated SAML authentication with Azure AD for identity-aware access, and enabled posture-based policies using device trust settings. Optimized ZPA traffic flow by implementing Bypass, FQDN, and IP-based access policies, ensuring secure, low-latency connectivity for remote users accessing private applications without exposing internal networks to the public internet.


VPN Migration:

  • Led the Site-to-Site (S2S) VPN migration project, managing end-to-end coordination between third-party vendors, customers, and internal stakeholders to ensure a seamless transition. Conducted technical assessments of existing VPN tunnels, restructured IPsec Phase 1/2 configurations, and optimized encryption algorithms to enhance security and performance. Facilitated project planning meetings, defined migration timelines, and implemented a phased cutover approach to minimize downtime. Performed rigorous pre- and post-migration testing, ensuring compliance with customer security policies and industry standards.


Public Cloud Migration:

  • Configured Azure networking components for cloud migration through Azure Portal and automated deployments using JSON scripts via Azure PowerShell. Provisioned ExpressRoute circuits, generated authorization keys for private peering, and deployed Virtual Network Gateways (VNGs) with BGP peering. Created and managed Resource Groups, Virtual Networks (VNETs), and subnets while implementing User-Defined Routes (UDRs) for traffic control. Deployed Azure Firewalls with DNAT, SNAT, and application rule policies for secure traffic filtering, enforcing Network Security Groups (NSGs) at subnet and NIC levels to optimize network security and performance.
  • Executed a phased network migration to Azure by establishing ExpressRoute private peering and validating BGP route advertisements. Conducted pre-migration network mapping, ensuring on-premises subnet-to-Azure subnet alignment with UDR adjustments. Deployed VNET-to-VNET peering for cross-region connectivity, applied NSG and Azure Firewall policies for layered security, and performed controlled cutovers for critical workloads. Utilized Azure Network Watcher for real-time packet tracing, flow log analysis, and end-to-end connectivity validation, ensuring a seamless transition with minimal downtime.


Network Refresh Project:

  • Designed and deployed network infrastructure across multiple client sites, configuring switches, routers, and MPLS routing to establish secure and redundant data center connectivity. Engineered BGP and OSPF-based dynamic routing policies for MPLS integration, optimizing traffic flow, failover mechanisms, and high availability. Configured Layer 2/Layer 3 components, including VLANs, STP, EtherChannel, and QoS policies, ensuring efficient bandwidth utilization and network segmentation. Served as the techno-functional lead, overseeing project planning, vendor coordination, and risk assessments while managing end-to-end implementation, change control, and post-deployment validation to ensure seamless enterprise integration across all sites.

Languages

English
Bilingual or Proficient (C2)
Hindi
Advanced (C1)
Bengali
Bilingual or Proficient (C2)

Timeline

Network Security Specialist

Cognizant Technology Solutions, CTS
06.2023 - Current

Network Operations Engineer

Tata Consultancy Services, TCS
02.2016 - 05.2023

B.Tech - Information Technology

Netaji Subhash Engineering College
Sampreet Bagchi