Work Preference
Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic
Open To Work

Santhan Cheviti

Bangalore

Work Preference

Job Search Status

Open to work

Work Type

Full Time

Summary

  • Network Security Engineer with 10 years of experience driving enterprise security operations across multi‑region infrastructures, specializing in Zscaler Zero Trust Exchange (ZIA/ZPA), firewall security, VPN implementations, and SSL inspection.
  • Expert in firewall administration (Palo Alto, Panorama, Check Point) with deep knowledge of NAT, ACLs, and IPsec VPN deployments, ensuring compliance with organizational security standards.
  • Strong foundation in routing & switching (BGP, OSPF, EIGRP, STP, RSTP, MSTP) and enterprise‑grade platforms (Cisco Nexus, Catalyst), enabling resilient and scalable network operations.
  • Hands‑on with automation & cloud — Cisco DNAC, AWS networking, and Cisco ISE — integrating hybrid infrastructures and streamlining enterprise network management.
  • Proven incident response leader, adept at managing P1/P2 critical incidents, SLA‑driven support, RCA analysis, and proactive monitoring using SolarWinds, Splunk, ServiceNow, Infoblox, and Thousand Eyes.

Overview

1
1
Certification
11
11
years of professional experience

Work History

Network Security Engineer

Accenture
Bangalore
11.2023 - Current
  • Firewall & Security Operations: Managing firewall access policies and NAT configurations, administering Palo Alto environments with VPN connectivity, SSL inspection, and threat prevention capabilities according to business requirements.
  • IPSEC VPN Deployment: Implementing secure Site-to-Site IPSEC VPN solutions to enable protected enterprise communication channels.
  • Zscaler Zero Trust Exchange Administration: Administered and supported the Zscaler Zero Trust Exchange platform including ZIA, ZPA, and ZCC for enterprise users across multiple locations.
  • ZIA Security Policy Management: Configured and managed ZIA security policies including URL filtering, SSL inspection, bandwidth control, and cloud application policies to enhance security posture.
  • Firewall Rule Optimization: Optimized firewall rules and security objects to improve operational efficiency and minimize policy duplication.
  • Incident Management & Network Support: Managed P1/P2 incidents within SLA commitments, conducted RCA for recurring issues, and provided L2/L3 support for multi-region network environments.
  • Troubleshooting & Incident Resolution: Troubleshot web access issues, SSL handshake failures, and application access problems using Zscaler logs and packet captures while coordinating with Zscaler support for P1/P2 incident resolution, log analysis & defect escalations.
  • Cisco DNAC Automation: Utilizing Cisco DNAC for automated provisioning and policy-based network management across enterprise infrastructure environments.
  • Switching & Routing Administration: Configuring and troubleshooting Cisco Nexus and Catalyst switches for Layer 2/Layer 3 operations while resolving routing issues within BGP and OSPF networks.
  • Analyzed vulnerabilities in systems to enhance overall security posture.
  • Conducted security assessments to identify risks and recommend improvements.

Senior Network Engineer

TCS
Bangalore
09.2021 - 11.2023
  • Monitored client network for security breaches, investigating violations across applications to enhance overall security posture.
  • Implemented security controls on client enterprise network, assisting audit teams in validating and assessing controls to ensure compliance and security effectiveness.
  • Delivered administration, troubleshooting and security services for enterprise network ((3 Data centers & 60+ Remote sites)).
  • Implemented troubleshooting and fixed issues, recommending improvements for client application security and network problems to enhance system integrity across converged technology solutions.
  • Supported system and application teams in identifying and resolving functional issues, helping to identify or rule out network and security issues.
  • Used Splunk and SolarWinds for event correlation, Risk assessment (FMEA) and thread modeling (STRIDE).
  • Administration and assessment of PKI certificates for multiple applications to ensure data integrity and security.

NOC Engineer

MindTree
Bangalore
05.2018 - 08.2021
  • Install, configure & manage network connectivity in global network environment.
  • Upgraded Cisco IOS on Routers & Switches (3925,3945,4351 ISR, ASR 1001-X,3700 &3800 stack,4510, Catalyst 6880-x).
  • Monitored network devices and circuits via SolarWinds and Zabbix to ensure optimal performance.
  • Addressed MI and P1/P2 network issues to minimize downtime and maintain service quality through collaboration with carriers, technicians, and engineers.
  • Work with Vendors, ISP's & Field Engineers on Escalated cases. Taking care of all Change Requests (Change Management).
  • Developed standard operating procedures for resolving critical and company-sensitive issues.

Network Engineer

T-Mobile
Bellevue
11.2015 - 10.2017
  • Provisioned Checkpoint Firewall policies and utilized Provider for troubleshooting and implementing rules.
  • Conducted stateful inspection of Firewall rules to filter TCP/IP protocols and troubleshoot issues.
  • Authored and scheduled MOPs for implementing FW rules by creating nodes/groups/networks in Checkpoint's FW management server (Smart Domain Manager).
  • Pushed firewall rules to live production environments during maintenance windows.
  • Develop detailed template-based plans including: implementation, testing and back out procedures for all network implementations, upgrades and modifications.
  • Industry experience in working with IP routing protocols like EIGRP, BGP, OSPF.
  • Implemented Changes on Existing configurations for the applications on F5 load balancer.

Education

Master of Science - Software Engineering

University of Houston-Clear Lake
Houston
08-2015

B. Tech - Electronics and Communications Engineering

GITAM University
Visakhapatnam, AP
07-2012

Skills

  • Firewall and security management: Palo Alto, Check Point, Zscaler
  • VPN configuration: IPSec, site-to-site, remote access
  • Network management: Cisco DNA Center, Meraki, Infoblox
  • Vulnerability management: Qualys
  • Access control management: Cisco ISE
  • Routing and switching: BGP, OSPF, STP, RSTP, Cisco Nexus and Catalyst Switches
  • Load balancer administration: A10, F5
  • Wireless engineering: Cisco Prime, 9800 controllers
  • Network monitoring & ITSM tools: SolarWinds, Grafana, Thousand Eyes, Service Now and Zabbix

Certification

  • Cisco Certified Network Associate (CCNA), CSCO12834059
  • Cisco Certified Network Professional (CCNP-Routing), CSCO12834059
  • Palo Alto Networks - Accredited Configuration Engineer (ACE)

Timeline

Network Security Engineer

Accenture
11.2023 - Current

Senior Network Engineer

TCS
09.2021 - 11.2023

NOC Engineer

MindTree
05.2018 - 08.2021

Network Engineer

T-Mobile
11.2015 - 10.2017

Master of Science - Software Engineering

University of Houston-Clear Lake

B. Tech - Electronics and Communications Engineering

GITAM University
Santhan Cheviti