A
Aman Singh
Aman Singh
About
Detail
United States
Senior Network & Cyber Security Engineer with 11+ years of progressive hands-on experience designing, securing, and operating large-scale enterprise, data center, and multi-cloud network environments supporting mission-critical workloads. Proven background spanning network engineering, network security, and information security, with deep expertise in next-generation firewalls, routing and switching, hybrid cloud connectivity, Zero Trust architecture, and end-to-end observability. Extensive experience working in highly regulated industries (banking, healthcare, and enterprise), consistently balancing strong security controls with high availability, performance, and operational stability. Engineered and troubleshot InfiniBand and ROCE (RDMA) fabrics supporting GPU compute clusters. Architected network readiness validation for GPU training clusters operating on InfiniBand-enabled leaf-spine fabrics. Demonstrated success leading complex packet-flow investigations across firewalls, CDNs, cloud edges, and core routing domains to rapidly distinguish application issues from true network faults. Advanced hands-on expertise with Palo Alto, Fortinet, Check Point VSX, Juniper SRX, and Cisco security platforms, including HA design, deep traffic analysis, policy optimization, and large-scale rule lifecycle management. Strong background in internet-edge security and application protection using Akamai, Cloudflare, and upstream DDoS controls, including traffic analysis, anomaly detection, and mitigation validation. Deep experience designing and operating hybrid connectivity across AWS, Azure, and GCP using Transit Gateway, Direct Connect, VPN, and cloud-native routing constructs. Built continuous synthetic tests for critical banking and SaaS apps, using ThousandEyes Al insights to justify routing changes with carriers when external hops degraded user experience. Fed Selector Al with logs from firewalls, cloud gateways, and SD-WAN, then used its correlation output to propose a simplified alerting model that cut noisy tickets for the on-call team. Used Selector Al service dependency maps to prove when network slowness was actually caused by inefficient database calls, helping application owners focus on code fixes instead of firewall changes. Combined Cortex XDR AI analytics with NGFW logs to spot high-risk service accounts abusing network paths. Used FireMon Al analytics to map firewall policies to specific applications and owners, enabling a formal review process where unused or risky rules were retired with clear business sign-off. Proven ability to implement and tune Zero Trust and SASE solutions (Prisma Access, Zscaler, Netskope) with close attention to real user experience and remote workforce reliability. Skilled in BGP traffic engineering, asymmetric routing analysis, MTU/fragmentation troubleshooting, and latency-sensitive transaction network optimization. Heavy user of ThousandEyes, NetBrain, Prometheus, Grafana, and Splunk to deliver actionable network visibility, accelerate root cause analysis, and reduce MTTR during high-severity incidents. Automation-focused engineer with practical experience using Python and Ansible to validate firewall health, VPN status, and routing behavior, improving consistency and reducing manual effort. Recognized for driving firewall and segmentation cleanups, eliminating legacy risk exposures while maintaining business continuity through careful stakeholder coordination. Trusted technical partner to SOC, fraud, IAM, cloud, and application teams, providing network-level threat context and grounded operational insight during security events and architecture reviews. Experienced in PCI-DSS, NIST 800-53, ISO 27001, HIPAA, and FFIEC-aligned environments, producing audit-ready evidence and implementing compliant network security controls.