WAN/LAN Netzwerk Architekt / Network Architect / UNIX/WINDOWS Engineer
Aktualisiert am 24.02.2025
Profilbild
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 01.04.2025
Verfügbar zu: 100%
davon vor Ort: 50%
IT-Architekt
IT-Security
Network Security
Unix System Engineer
VPN Interconnectivity
PKI Infrastructure
Firewalls
Proxy Server
Mail Server
Samba AD
Deutsch
Muttersprache
Englisch
fliessend

Einsatzorte

Einsatzorte

Österreich, Schweiz, Deutschland

Deutschland: bevorzugter Bereich: D6

möglich

Projekte

Projekte

Network Security Engineer and Architect
  • Global IP and VLAN Network Re-Design for German/Swiss Chemistry, biochemistry
  • and Pharmaceuticals Company
  • Inventory taking and documentation of existing network infrastructure
  • Installation of network management system
  • Harmonization of network infrastructure device congurations
  • Implementation of central network device conguration backup system
  • IT/OT separation
  • Introdcution of OT-Network Purdue model
  • IT-Network security zone separation
Sophos Firewalls Netgear Switches Aruba Switches LibreNMS UNIFI
Switching Routing VLAN Linux Webserver Active Directory SNMP Remote Logging
German/Swiss Chemistry, biochemistry and Pharmaceuticals Company
Remote, Germany and Switzerland
Senior Network and UNIX/Linux Engineer
Security review for new flow opening requests
Mentoring on network support for applications
Engineering support for application and network incidents
Firewall openings analysis and audit support
Training new team members
Commercial Bank
Senior Network Security Architect
  • Network design review for IT- and OT-networks in Europe and US
  • Implementation NetFlow data collection
  • NetFlow based traffic flow/matrix analysis
  • IT- / OT-segregation support
  • Security-Zoning design
Pharmaceuticals Company
Remote and CH
Senior Network Security Architect
  • Status-Quo Analysis
  • Workshops
  • Project discontinued due to project planning misconception
Commercial Bank
Senior Network Security Auditor
  • Focus on Disaster Recovery and Business Continuity
  • F5 Load-Balancer
  • Barracuda Firewalls
  • Fortigate Firewalls
  • RSA Authentication Manager
  • LAN and WAN Routing and Switching Infrastructure
Insurance
Senior Network Security Architect
  • Security assessement for the setup of network applications:
  • Linux Install Services (Apache Web Server)
  • LDAP (389ds)
  • DNS (ISC BIND, Infoblox)
  • DHCP (ISC DHCPD, Infoblox)
  • VMWare vSphere
Insurance
Senior Network Security Architect
  • Financial institute data center migration network design
  • Existing Data Center network analysis
  • Data Center redesign network security zone and segmentation design
  • Network communication rules design and implementation (Firewalls, Security Zones)
  • Oracle Exadata and ZFS database infrastructure network design
  • Infrastructure, Application and Database Team mentoring
Commercial Bank
Senior Network Security Architect
  • Network communication rules review and approval
  • Infrastructure, Application and Database Team mentoring
Commercial Bank
Senior Network Security Architect
  • Analysis current MPLS attached locations
  • Traffic site-to-site analysis plus application and volume assessment
  • Provider quotes assessment
Automation Industry
  • Network Security Engineering and 3rd level support
  • Design backup and recovery network on converged infrastructure switches (mixed FibreChannel and 10GB Ethernet infrastructure)
  • Implementation file based server backup strategy
  • Implementation backup tape archiving solution
  • Implementation/extension VPN based remote user access due to Corona based increased demand of remote/mobile work with world wide regional VPN access gateways
Commercial Bank
Rhein-Main Area
  • Concept for firewall renewal and new firewall implementation with ruleset migration
  • Concept and implemenation of intranet mailserver replacement
Corporate Design and Media Concept
  • Concept and Implemementation for sandbox secured malware analysis VM infrastructure
  • Implementation encrypted/tunneled malware traffic routing for "real world" traffic observation
  • Provisioning of tunneled malware routing template VM
Commercial Bank
  • Renewal of SSL/TLS PKI infrastructure with expiring root CA certificate
  • Network security engineering and 3rd level network support
  • Site wide firewall consolidation and migration in Germany
  • Lastline malware analysis platform upgrade/extension
Commercial Bank
  • Network security engineering and 3rd level network support
  • Concept and implementation of multiple multi-stage malware information sharing platforms based on MISP
Commercial Bank
  • Site wide firewall consolidation and migration in Singapore
  • Fireeye malware analysis platform upgrade/extension
Commercial Bank
  • Automation network administration tasks
  • Implementation automated PKI certificate handling/management
Commercial Bank
  • Automation network administration tasks
  • Implementation automated PKI certificate handling/management
Commercial Bank
  • Site firewall consolidation and migration
  • Fireeye analysis platform extension
  • Re-build of "lost" site in North America (major outage due to environmental impact)
  • Setup of PXE based boot server environments for automated workstation installation and package distribution in 3 global sites
  • Setup of distributed malware analysis platform VMRay
Commercial Bank
Concept "Secure Network Access Control"
  • Concept for roaming user authentication based network access control with fixed IP reservervation/assignment per user
Cyber-Security
Concept for transparent tunneling of malicious network traffic from customer to cyber security provider for analysis
Cyber-Security
Setup Secure Malware Analysis Network
  • Network setup of segregated analysis network
  • Planning an implementation of site network core services (DNS, DHCP, NTP)
  • Implementation multi-tier PKI
  • Implementation roaming user VPN access
Commercial Bank
Senior Network Security Architect
  • Concept for highly segregated and secured network for safe malware analysis and software
  • development
  • Pilot site network implementation of system of interconnected analysis network environments
  • Planning an implementation of site network core services (DNS, DHCP, NTP)
  • Setup cross platform single-sign-on environment (Kerberos v5)
  • Implementation network access control with 802.1x and HA RADIUS servers
  • Implementation multi-tier PKI
  • Implementation roaming user VPN access
  • Setup and integration of additional site in Asia
  • Setup and integration of additional site in North America
Commercial Bank
Technical Project Lead SW Engineering
Technical project lead for new distributed global maritime cargo vessel data-transfer solution
Development
Pilot vessel implementation
Global coastal radio station migriation
PPPoE test environment setup for satellite data transmission proof-of-concept
Concept for international HF-based emergency communication network for governmental use
Telecommunication
Bern
Technical Project Lead SW Engineering
  • Concept for international HF-based emergency communication network for governmental use
  • Implementation arbitrary HF band allocation for encrypted radio based voice and data communication
  • Documentation and handover of international HF communication solution for cargo vessels
Telecommunication
Bern
  • Network security assessment for platform change to new groupware solution
  • Migration network internet firewall
  • Setup customer owned PKI for SSL/TLS certificate maintenance
  • VPN implementation for mobile users
Metal Manufacturing
Technical Project Lead SW Engineering
  • Stabilization and bug fixing exisiting global amateur-radio based IT communication solution for cargo vessels
  • Re-Design of amateur-radio based IT communication solution for cargo vessels (with GSM and
  • satellite backup)
  • Technical project management and development team lead for re-implementation of amateur-radio
  • based IT communication solution for cargo vessels (with GSM and satellite backup)
Telecommunication
bern
Technical Project Lead SW Engineering
? Broadcast service provider management system extension
? Analysis of existing solution for amateur-radio based world-wide mail system for Cargo ships
Telecommunication
bern
Senior Network Security Architect
  • DHCP service migration rollout to centralized HA IPAM appliances (redundant per site)
  • Network design for 10G TSM storage server attachment
  • Evaluation network attachment for IBM n-Series storage gateway
  • Pilot implementation of netflow based network monitoring
European Institute
Senior Network Security Architect
  • LAN Layer-2 and Layer-3 segmentation and firewall implementation
Senior Network Security Architect
  • DHCP pilot service migration to centralized HA IPAM appliances (redundant per site)
  • DNS pilot service migration to centralized HA IPAM appliances (redundant per site)
  • Active-Directory support pilot implementation on central IPAM appliances
  • Evaluation and re-design enterprise-wide LAN network security zone concept
European Institute
Senior Network Security Architect
  • Evalution and conceptual design of data-center migration from single server to blade server environment
  • Concept for implementation of distributed LDAP based user database on monitoring and management satellite servers
  • 3rd level network support and network engineering
European Institute
Senior Network Security Architect
  • Re-design an implementation of a Small-Office internet connection solution
Senior Network Security Architect
  • Requirements analysis for centralized load-balancing solution
  • Data-center security concept
  • Implementation HA load-balancer
  • 3rd level network support
  • Network management enhancement (automation)
  • Implementation centralized WAN and FW security management server
European Institute
Senior Network Security Architect
  • Evaluation of various IPAM solutions
  • Concept for consolidation of distributed DNS and DHCP services into a enterprise wide HA solution
  • Evaluation of Active-Directory DHCP migration to HA IPAM solution
European Institute
Senior Network Security Architect
  • Consolidation heterogeneous DNS services
  • Network design and implmenetation for high density blade server in HA LAN environment
  • Re-design network monitoring and management for HA LAN environment
European Institute
  • Implementation of dual-stage mail routing solution with virus- and spam-filtering
Corporate Design and Media Concept
Setup Samba Active Directory server pair
Setup HA Fileserver and enterprise directory server
Firewall migration/replacement
Semiconductor Industry
Consolidation heterogeneous DNS services
Evaluation and concept for network attachment for high density blade servers
Evaluation HA and Load-Balancing services
European Institute
Evaluation and design mobile user VPN connectivity
Evaluation and design external supplier VPN connectivity
Semiconductor Industry
Project coordination for network technology migration from ATM core LAN to switched Ethernet core
Analysis existing home-grown network monitoring solution
Evaluation of possible migration paths for network monitoring replacement
European Institute
  • Implementation of business customer internet access firewalls for an ISP
  • Design an implementation of redundant ISP sites with HA availability of network core services
Internet Service Provider
  • Implementation of HA samba file server pair with AD services
Semiconductor Industry
  • Implementation of business customer internet access firewalls for an ISP
  • Implementation HA network authentication server (RADIUS)
  • Implementation internet service provider proxy and load-balancer service
  • Implementation mail server solution with built-in encryption support
Internet Service Provider
  • Setup, maintenance and integration of Cognos PowerPowerPlay Enterprise Solution Server
  • Maintenance CLS/MTS (Continuous Linked Settlement) gateway for a financial institution
  • Maintenance Swiftnet Alliance gateway for a financial institution
Commercial Bank
Implementation and administration CLS/MTS (Continuous Linked Settlement) gateway for a financial institution
Implementation and adminsitration of Swiftnet Alliance gateway for a financial institution
Commercial Bank
  • Network security consulting for ISP customers
  • Implememtation Autonomous System (AS) for an Internet Service Provider (ISP) with peering to multiple global internet network providers
  • Implementation firewalls and site-to-site VPNs for multiple ISP customers
  • Implementation of internet dial-in gateways with pre-paid access cards; application layer proxying of available/permitted internet resources for multiple global internet network providers
  • Implementation firewalls and site-to-site VPNs for multiple ISP customers
  • Implementation of internet dial-in gateways with pre-paid access cards; application layer proxying of available/permitted internet resources
Internet Service Provider
  • Network security consulting for an Internet Service Provider (ISP)
  • Implementation of transparent proxying with Layer-7 online time accounting
Internet Service Provider
  • Setup of Support- and Operations-Group for Remote Access Services
  • Remote access server administration and maintenance
Commercial Bank
  • Network security consulting for local internet service provider
Internet Service Provider
  • WAN engineering and administration
  • Re-Design WAN interconnection; technology switch-over and regional relocation of WAN hub site
  • Introduction of new Unix based WAN encryption management system
Global Semiconductor Industry
Network Engineer
  • WAN engineering and administration
  • Regional (EMA) Implementation of intranet VoIP
  • Implementation centralized routing network device logging
Global Semiconductor Industry
Implementation Secure Commerce Web Server Infrastructure
  • WAN engineering and administration
  • Implementation Reverse Web Proxy for Secure Commerce Web Server
  • Finalisation of network management migration to new platform
Network Engineer
  • WAN engineering and administration
  • VoIP setup evaluation and planning (routing, traffic volume, traffic priorities, traffic queueing ...)
  • Administration and maintenance for pilot implementation of distributed network monitoring system
Global Semiconductor Industry
Network and UNIX/Linux Engineer

  • WAN interconnection design and implementation
  • Implementation dual-stage firewall architecture
  • Implementation web-proxy server

Global Semiconductor Industry
Network Engineer
WAN interconnection design and implementation
Implementation firewall secured interconnections to business partners
Pilot implemention of distributed network monitoring system
Global Semiconductor Industry
Network and UNIX/Linux Engineer
  • WAN interconnection design and implementation
  • Design and implementation of fault-tolerant switched data-center infrastructure
Global Semiconductor Industry
Network and UNIX/Linux Engineer
WAN interconnection design and implementation
Introduction Frame-Relay data encryption
Setup of WAN network encryption master controller
Routing protocol migration from IGRP to EIGRP
Introduction network performance monitoring
Unix administration
Global Semiconductor Industry
Network and UNIX/Linux Engineer
  • Design WAN interconnection expansion
  • Implementation WAN network performance and fault monitoring
  • Secure Dial-In administration
  • Unix system and application administration
Global Semiconductor Industry
  • Administration and engineering of global player enterprise WAN
    • - regional focus on EMEA
    • ?- global responsibility according to the Follow-The-Sun approach
  • Unix administration
  • Unix application support for network management system
Global Semiconductor Industry
Team Lead Network and PC Support
* Head of PC user support
* Design of new switched LAN and server infrastrcture in new premises
* Planning and implementation of smooth switch-over for LAN users moved to new site with two
actively used sites
Telecommunication Manufacturer
Team Lead Network and PC Support
  • Head of PC user support
  • Implementation of LAN <-> SNA network gateway
  • Setup of new production UNIX application server for database- and project planning
Telecommunication Manufacturer
Team Lead Network and PC Support
  • Head of PC user support
  • Desgin and implementation of LAN to BS2000 network gateway
  • Implementation of remote access dial-in gateway
  • Implementation of electronic data transmission gateway to public telephony services
  • Implementation sendmail <-> ms-mail gateway
Team Lead Network and PC Support
  • Head of PC user support
  • Design and setup of Unix based environment for database- and project planning development
  • Unix support for developers
Telecommunication Manufacturer
PC User and Network Support
Design and implementation of Ethernet PC LAN Infrastructure
Consolidation of isolated/standalone network implementations
Setup of network file and login server
Telecommunication Manufacturer
PC User and Network Support
  • PC hardware and software support
  • PC interconnection support to BS2000 network
Telecommunication Manufacturer
Software Developer and VAX Administrator
IT infrastructure support
IT system administration and support on a DECnet based mid range VAX 8650 VMS system and IBM PCs used for ASIC design (Application Specific Integrated Circuit).
Custom SW maintenance and development
User support
Telecommunication Manufacturer

Aus- und Weiterbildung

Aus- und Weiterbildung

1986-1989: Studium Elektrotechnik/Nachrichtentechnik BA Stuttgart
Abschluss als Diplom Ingenieur (BA)



Kompetenzen

Kompetenzen

Top-Skills

IT-Architekt IT-Security Network Security Unix System Engineer VPN Interconnectivity PKI Infrastructure Firewalls Proxy Server Mail Server Samba AD

Produkte / Standards / Erfahrungen / Methoden

Hardware

  • PC (versch. Hersteller), Sun SparcServer/SparcStation UltraSparc, IBM RS/6000, Motorola Powerstack
  • X-Terminals (versch. Hersteller)
  • Printserver (versch. Hersteller)
  • Cisco Router, Cisco Switches
  • BinTec ISDN Router
  • Cabletron Hubs

Software

  • MS DOS, MS Windows, MS WindowsNT, Windows 2000
  • Sun OS, Sun Solaris, Sun OpenWindows
  • IBM AIX
  • Linux
  • X11
  • Novell Netware
  • KDE, GNOME
  • Motorola Unix
  • MS Office, OpenOffice
  • MS Exchange Server
  • Unix Sendmail, QMail, OpenLDAP, Squid, FreeRadius
  • SunNet Manager, Cabletron Spectrum, HP OpenView
  • MTRG
  • MS IIS (Internet Information Server), Apache Web Server
  • Netscape Proxy Server, Netscape Directory Server, SunONE/iPlanet Directory Server
  • MySQL, MS SQL
  • Sun Solstice/Checkpoint Firewall-1, Raptor Eagle Firewall
  • Cylink SecureManager, Cylink PrivaCy Manager
  • Ipchains Packet Filter, Iptables/Netfilter Packet Filter
  • Squid Proxy Server
  • Swiftnet Link, Swiftnet Alliance Gateway (SAG)
  • CLS/MTS Gateway
  • Cognose Enterprise BI / PowerPlay Server / Transformation Server

 

Netzwerk

  • Ethernet, FastEthernet, FDDI, Token Ring, Gigabit Ethernet, 10 Gigabit Ethernet, ATM, LANE
  • Leased Lines (DDV), Frame-Relay, ISDN
  • Voice Dial-In
  • IP, IPX/SPX, AppleTalk
  • RIP, IGRP, EIGRP, BGP
  • SNMP, SMTP, LDAP, NNTP, DHCP, DNS
  • Cisco IOS
  • BinTec OS

Sonstiges

  • sh (Bourne Shell), csh (C Shell), ksh (Korn Shell), bash (Bourne Again Shell), Perl
  • Pascal, C, Visual Basic, Windows Scripting Host
  • HTML, JavaScript, PHP

Betriebssysteme

BS2000
Cisco IOS
Sehr gute Kenntnisse
Cisco IOS XE
Cisco Nexus
HPUX
Linux
Sehr gute Kenntnisse
Mac OS
MS-DOS
sehr gute Kenntisse
Novell
SUN OS, Solaris
sehr gute Kenntnisse
Unix
sehr gute Kenntnisse
VMS
vSphere ESXi
Windows
sehr gute Kenntnisse
XenServer

Programmiersprachen

Basic
C
Grundwissen
C++
Grundwissen
HPGL, HP PCL
Java
JavaScript
Pascal
Perl
PHP
Python
Scriptsprachen
Shell
SQL
Ansible

Datenbanken

Informix
ISAM
MariaDB
MS SQL Server
MySQL
Postgres
Sybase

Datenkommunikation

AppleTalk
ATM
Ethernet
Fax
FDDI
Firewall
HDLC
Internet, Intranet
ISDN
ISO/OSI
LAN, LAN Manager
Message Queuing
Network-Security
Novell
Packet-Radio
Proxy Server
Router
RPC
RS232
SMTP
SNA
SNMP
TCP/IP
Token Ring
Voice
Voice over IP
X.400 X.25 X.225 X.75...

Hardware

BlueCoat MAA-S Appliances
Cisco Converged Switches
gute Kenntnisse
Cisco Router
sehr gute Kenntnisse
Cisco Switches
gute Kenntnisse
Cylink Leitungs-Encrypter
embedded Systeme
FireEye MAS Appliances
genugate Firewalls
HP ProLiant Rack Server
gute Kenntnisse
IBM RS6000
Mikrocontroller
Modem
Prozessrechner
Siemens Großrechner
SUN
gute Kenntnisse

Design / Entwicklung / Konstruktion

EAGLE

Branchen

Branchen

  • Banken
  • Versicherungen
  • Internet Service Provider
  • Nachrichtentechnik
  • Elektrotechnik
  • Telekommunikation, Broadcasting
  • Metallbau
  • Presse und Werbedesign
  • Medizinische Forschungsinstitute / Kliniken

Einsatzorte

Österreich, Schweiz, Deutschland

Deutschland: bevorzugter Bereich: D6

möglich

Projekte

Network Security Engineer and Architect
  • Global IP and VLAN Network Re-Design for German/Swiss Chemistry, biochemistry
  • and Pharmaceuticals Company
  • Inventory taking and documentation of existing network infrastructure
  • Installation of network management system
  • Harmonization of network infrastructure device congurations
  • Implementation of central network device conguration backup system
  • IT/OT separation
  • Introdcution of OT-Network Purdue model
  • IT-Network security zone separation
Sophos Firewalls Netgear Switches Aruba Switches LibreNMS UNIFI
Switching Routing VLAN Linux Webserver Active Directory SNMP Remote Logging
German/Swiss Chemistry, biochemistry and Pharmaceuticals Company
Remote, Germany and Switzerland
Senior Network and UNIX/Linux Engineer
Security review for new flow opening requests
Mentoring on network support for applications
Engineering support for application and network incidents
Firewall openings analysis and audit support
Training new team members
Commercial Bank
Senior Network Security Architect
  • Network design review for IT- and OT-networks in Europe and US
  • Implementation NetFlow data collection
  • NetFlow based traffic flow/matrix analysis
  • IT- / OT-segregation support
  • Security-Zoning design
Pharmaceuticals Company
Remote and CH
Senior Network Security Architect
  • Status-Quo Analysis
  • Workshops
  • Project discontinued due to project planning misconception
Commercial Bank
Senior Network Security Auditor
  • Focus on Disaster Recovery and Business Continuity
  • F5 Load-Balancer
  • Barracuda Firewalls
  • Fortigate Firewalls
  • RSA Authentication Manager
  • LAN and WAN Routing and Switching Infrastructure
Insurance
Senior Network Security Architect
  • Security assessement for the setup of network applications:
  • Linux Install Services (Apache Web Server)
  • LDAP (389ds)
  • DNS (ISC BIND, Infoblox)
  • DHCP (ISC DHCPD, Infoblox)
  • VMWare vSphere
Insurance
Senior Network Security Architect
  • Financial institute data center migration network design
  • Existing Data Center network analysis
  • Data Center redesign network security zone and segmentation design
  • Network communication rules design and implementation (Firewalls, Security Zones)
  • Oracle Exadata and ZFS database infrastructure network design
  • Infrastructure, Application and Database Team mentoring
Commercial Bank
Senior Network Security Architect
  • Network communication rules review and approval
  • Infrastructure, Application and Database Team mentoring
Commercial Bank
Senior Network Security Architect
  • Analysis current MPLS attached locations
  • Traffic site-to-site analysis plus application and volume assessment
  • Provider quotes assessment
Automation Industry
  • Network Security Engineering and 3rd level support
  • Design backup and recovery network on converged infrastructure switches (mixed FibreChannel and 10GB Ethernet infrastructure)
  • Implementation file based server backup strategy
  • Implementation backup tape archiving solution
  • Implementation/extension VPN based remote user access due to Corona based increased demand of remote/mobile work with world wide regional VPN access gateways
Commercial Bank
Rhein-Main Area
  • Concept for firewall renewal and new firewall implementation with ruleset migration
  • Concept and implemenation of intranet mailserver replacement
Corporate Design and Media Concept
  • Concept and Implemementation for sandbox secured malware analysis VM infrastructure
  • Implementation encrypted/tunneled malware traffic routing for "real world" traffic observation
  • Provisioning of tunneled malware routing template VM
Commercial Bank
  • Renewal of SSL/TLS PKI infrastructure with expiring root CA certificate
  • Network security engineering and 3rd level network support
  • Site wide firewall consolidation and migration in Germany
  • Lastline malware analysis platform upgrade/extension
Commercial Bank
  • Network security engineering and 3rd level network support
  • Concept and implementation of multiple multi-stage malware information sharing platforms based on MISP
Commercial Bank
  • Site wide firewall consolidation and migration in Singapore
  • Fireeye malware analysis platform upgrade/extension
Commercial Bank
  • Automation network administration tasks
  • Implementation automated PKI certificate handling/management
Commercial Bank
  • Automation network administration tasks
  • Implementation automated PKI certificate handling/management
Commercial Bank
  • Site firewall consolidation and migration
  • Fireeye analysis platform extension
  • Re-build of "lost" site in North America (major outage due to environmental impact)
  • Setup of PXE based boot server environments for automated workstation installation and package distribution in 3 global sites
  • Setup of distributed malware analysis platform VMRay
Commercial Bank
Concept "Secure Network Access Control"
  • Concept for roaming user authentication based network access control with fixed IP reservervation/assignment per user
Cyber-Security
Concept for transparent tunneling of malicious network traffic from customer to cyber security provider for analysis
Cyber-Security
Setup Secure Malware Analysis Network
  • Network setup of segregated analysis network
  • Planning an implementation of site network core services (DNS, DHCP, NTP)
  • Implementation multi-tier PKI
  • Implementation roaming user VPN access
Commercial Bank
Senior Network Security Architect
  • Concept for highly segregated and secured network for safe malware analysis and software
  • development
  • Pilot site network implementation of system of interconnected analysis network environments
  • Planning an implementation of site network core services (DNS, DHCP, NTP)
  • Setup cross platform single-sign-on environment (Kerberos v5)
  • Implementation network access control with 802.1x and HA RADIUS servers
  • Implementation multi-tier PKI
  • Implementation roaming user VPN access
  • Setup and integration of additional site in Asia
  • Setup and integration of additional site in North America
Commercial Bank
Technical Project Lead SW Engineering
Technical project lead for new distributed global maritime cargo vessel data-transfer solution
Development
Pilot vessel implementation
Global coastal radio station migriation
PPPoE test environment setup for satellite data transmission proof-of-concept
Concept for international HF-based emergency communication network for governmental use
Telecommunication
Bern
Technical Project Lead SW Engineering
  • Concept for international HF-based emergency communication network for governmental use
  • Implementation arbitrary HF band allocation for encrypted radio based voice and data communication
  • Documentation and handover of international HF communication solution for cargo vessels
Telecommunication
Bern
  • Network security assessment for platform change to new groupware solution
  • Migration network internet firewall
  • Setup customer owned PKI for SSL/TLS certificate maintenance
  • VPN implementation for mobile users
Metal Manufacturing
Technical Project Lead SW Engineering
  • Stabilization and bug fixing exisiting global amateur-radio based IT communication solution for cargo vessels
  • Re-Design of amateur-radio based IT communication solution for cargo vessels (with GSM and
  • satellite backup)
  • Technical project management and development team lead for re-implementation of amateur-radio
  • based IT communication solution for cargo vessels (with GSM and satellite backup)
Telecommunication
bern
Technical Project Lead SW Engineering
? Broadcast service provider management system extension
? Analysis of existing solution for amateur-radio based world-wide mail system for Cargo ships
Telecommunication
bern
Senior Network Security Architect
  • DHCP service migration rollout to centralized HA IPAM appliances (redundant per site)
  • Network design for 10G TSM storage server attachment
  • Evaluation network attachment for IBM n-Series storage gateway
  • Pilot implementation of netflow based network monitoring
European Institute
Senior Network Security Architect
  • LAN Layer-2 and Layer-3 segmentation and firewall implementation
Senior Network Security Architect
  • DHCP pilot service migration to centralized HA IPAM appliances (redundant per site)
  • DNS pilot service migration to centralized HA IPAM appliances (redundant per site)
  • Active-Directory support pilot implementation on central IPAM appliances
  • Evaluation and re-design enterprise-wide LAN network security zone concept
European Institute
Senior Network Security Architect
  • Evalution and conceptual design of data-center migration from single server to blade server environment
  • Concept for implementation of distributed LDAP based user database on monitoring and management satellite servers
  • 3rd level network support and network engineering
European Institute
Senior Network Security Architect
  • Re-design an implementation of a Small-Office internet connection solution
Senior Network Security Architect
  • Requirements analysis for centralized load-balancing solution
  • Data-center security concept
  • Implementation HA load-balancer
  • 3rd level network support
  • Network management enhancement (automation)
  • Implementation centralized WAN and FW security management server
European Institute
Senior Network Security Architect
  • Evaluation of various IPAM solutions
  • Concept for consolidation of distributed DNS and DHCP services into a enterprise wide HA solution
  • Evaluation of Active-Directory DHCP migration to HA IPAM solution
European Institute
Senior Network Security Architect
  • Consolidation heterogeneous DNS services
  • Network design and implmenetation for high density blade server in HA LAN environment
  • Re-design network monitoring and management for HA LAN environment
European Institute
  • Implementation of dual-stage mail routing solution with virus- and spam-filtering
Corporate Design and Media Concept
Setup Samba Active Directory server pair
Setup HA Fileserver and enterprise directory server
Firewall migration/replacement
Semiconductor Industry
Consolidation heterogeneous DNS services
Evaluation and concept for network attachment for high density blade servers
Evaluation HA and Load-Balancing services
European Institute
Evaluation and design mobile user VPN connectivity
Evaluation and design external supplier VPN connectivity
Semiconductor Industry
Project coordination for network technology migration from ATM core LAN to switched Ethernet core
Analysis existing home-grown network monitoring solution
Evaluation of possible migration paths for network monitoring replacement
European Institute
  • Implementation of business customer internet access firewalls for an ISP
  • Design an implementation of redundant ISP sites with HA availability of network core services
Internet Service Provider
  • Implementation of HA samba file server pair with AD services
Semiconductor Industry
  • Implementation of business customer internet access firewalls for an ISP
  • Implementation HA network authentication server (RADIUS)
  • Implementation internet service provider proxy and load-balancer service
  • Implementation mail server solution with built-in encryption support
Internet Service Provider
  • Setup, maintenance and integration of Cognos PowerPowerPlay Enterprise Solution Server
  • Maintenance CLS/MTS (Continuous Linked Settlement) gateway for a financial institution
  • Maintenance Swiftnet Alliance gateway for a financial institution
Commercial Bank
Implementation and administration CLS/MTS (Continuous Linked Settlement) gateway for a financial institution
Implementation and adminsitration of Swiftnet Alliance gateway for a financial institution
Commercial Bank
  • Network security consulting for ISP customers
  • Implememtation Autonomous System (AS) for an Internet Service Provider (ISP) with peering to multiple global internet network providers
  • Implementation firewalls and site-to-site VPNs for multiple ISP customers
  • Implementation of internet dial-in gateways with pre-paid access cards; application layer proxying of available/permitted internet resources for multiple global internet network providers
  • Implementation firewalls and site-to-site VPNs for multiple ISP customers
  • Implementation of internet dial-in gateways with pre-paid access cards; application layer proxying of available/permitted internet resources
Internet Service Provider
  • Network security consulting for an Internet Service Provider (ISP)
  • Implementation of transparent proxying with Layer-7 online time accounting
Internet Service Provider
  • Setup of Support- and Operations-Group for Remote Access Services
  • Remote access server administration and maintenance
Commercial Bank
  • Network security consulting for local internet service provider
Internet Service Provider
  • WAN engineering and administration
  • Re-Design WAN interconnection; technology switch-over and regional relocation of WAN hub site
  • Introduction of new Unix based WAN encryption management system
Global Semiconductor Industry
Network Engineer
  • WAN engineering and administration
  • Regional (EMA) Implementation of intranet VoIP
  • Implementation centralized routing network device logging
Global Semiconductor Industry
Implementation Secure Commerce Web Server Infrastructure
  • WAN engineering and administration
  • Implementation Reverse Web Proxy for Secure Commerce Web Server
  • Finalisation of network management migration to new platform
Network Engineer
  • WAN engineering and administration
  • VoIP setup evaluation and planning (routing, traffic volume, traffic priorities, traffic queueing ...)
  • Administration and maintenance for pilot implementation of distributed network monitoring system
Global Semiconductor Industry
Network and UNIX/Linux Engineer

  • WAN interconnection design and implementation
  • Implementation dual-stage firewall architecture
  • Implementation web-proxy server

Global Semiconductor Industry
Network Engineer
WAN interconnection design and implementation
Implementation firewall secured interconnections to business partners
Pilot implemention of distributed network monitoring system
Global Semiconductor Industry
Network and UNIX/Linux Engineer
  • WAN interconnection design and implementation
  • Design and implementation of fault-tolerant switched data-center infrastructure
Global Semiconductor Industry
Network and UNIX/Linux Engineer
WAN interconnection design and implementation
Introduction Frame-Relay data encryption
Setup of WAN network encryption master controller
Routing protocol migration from IGRP to EIGRP
Introduction network performance monitoring
Unix administration
Global Semiconductor Industry
Network and UNIX/Linux Engineer
  • Design WAN interconnection expansion
  • Implementation WAN network performance and fault monitoring
  • Secure Dial-In administration
  • Unix system and application administration
Global Semiconductor Industry
  • Administration and engineering of global player enterprise WAN
    • - regional focus on EMEA
    • ?- global responsibility according to the Follow-The-Sun approach
  • Unix administration
  • Unix application support for network management system
Global Semiconductor Industry
Team Lead Network and PC Support
* Head of PC user support
* Design of new switched LAN and server infrastrcture in new premises
* Planning and implementation of smooth switch-over for LAN users moved to new site with two
actively used sites
Telecommunication Manufacturer
Team Lead Network and PC Support
  • Head of PC user support
  • Implementation of LAN <-> SNA network gateway
  • Setup of new production UNIX application server for database- and project planning
Telecommunication Manufacturer
Team Lead Network and PC Support
  • Head of PC user support
  • Desgin and implementation of LAN to BS2000 network gateway
  • Implementation of remote access dial-in gateway
  • Implementation of electronic data transmission gateway to public telephony services
  • Implementation sendmail <-> ms-mail gateway
Team Lead Network and PC Support
  • Head of PC user support
  • Design and setup of Unix based environment for database- and project planning development
  • Unix support for developers
Telecommunication Manufacturer
PC User and Network Support
Design and implementation of Ethernet PC LAN Infrastructure
Consolidation of isolated/standalone network implementations
Setup of network file and login server
Telecommunication Manufacturer
PC User and Network Support
  • PC hardware and software support
  • PC interconnection support to BS2000 network
Telecommunication Manufacturer
Software Developer and VAX Administrator
IT infrastructure support
IT system administration and support on a DECnet based mid range VAX 8650 VMS system and IBM PCs used for ASIC design (Application Specific Integrated Circuit).
Custom SW maintenance and development
User support
Telecommunication Manufacturer

Aus- und Weiterbildung

1986-1989: Studium Elektrotechnik/Nachrichtentechnik BA Stuttgart
Abschluss als Diplom Ingenieur (BA)



Kompetenzen

Top-Skills

IT-Architekt IT-Security Network Security Unix System Engineer VPN Interconnectivity PKI Infrastructure Firewalls Proxy Server Mail Server Samba AD

Produkte / Standards / Erfahrungen / Methoden

Hardware

  • PC (versch. Hersteller), Sun SparcServer/SparcStation UltraSparc, IBM RS/6000, Motorola Powerstack
  • X-Terminals (versch. Hersteller)
  • Printserver (versch. Hersteller)
  • Cisco Router, Cisco Switches
  • BinTec ISDN Router
  • Cabletron Hubs

Software

  • MS DOS, MS Windows, MS WindowsNT, Windows 2000
  • Sun OS, Sun Solaris, Sun OpenWindows
  • IBM AIX
  • Linux
  • X11
  • Novell Netware
  • KDE, GNOME
  • Motorola Unix
  • MS Office, OpenOffice
  • MS Exchange Server
  • Unix Sendmail, QMail, OpenLDAP, Squid, FreeRadius
  • SunNet Manager, Cabletron Spectrum, HP OpenView
  • MTRG
  • MS IIS (Internet Information Server), Apache Web Server
  • Netscape Proxy Server, Netscape Directory Server, SunONE/iPlanet Directory Server
  • MySQL, MS SQL
  • Sun Solstice/Checkpoint Firewall-1, Raptor Eagle Firewall
  • Cylink SecureManager, Cylink PrivaCy Manager
  • Ipchains Packet Filter, Iptables/Netfilter Packet Filter
  • Squid Proxy Server
  • Swiftnet Link, Swiftnet Alliance Gateway (SAG)
  • CLS/MTS Gateway
  • Cognose Enterprise BI / PowerPlay Server / Transformation Server

 

Netzwerk

  • Ethernet, FastEthernet, FDDI, Token Ring, Gigabit Ethernet, 10 Gigabit Ethernet, ATM, LANE
  • Leased Lines (DDV), Frame-Relay, ISDN
  • Voice Dial-In
  • IP, IPX/SPX, AppleTalk
  • RIP, IGRP, EIGRP, BGP
  • SNMP, SMTP, LDAP, NNTP, DHCP, DNS
  • Cisco IOS
  • BinTec OS

Sonstiges

  • sh (Bourne Shell), csh (C Shell), ksh (Korn Shell), bash (Bourne Again Shell), Perl
  • Pascal, C, Visual Basic, Windows Scripting Host
  • HTML, JavaScript, PHP

Betriebssysteme

BS2000
Cisco IOS
Sehr gute Kenntnisse
Cisco IOS XE
Cisco Nexus
HPUX
Linux
Sehr gute Kenntnisse
Mac OS
MS-DOS
sehr gute Kenntisse
Novell
SUN OS, Solaris
sehr gute Kenntnisse
Unix
sehr gute Kenntnisse
VMS
vSphere ESXi
Windows
sehr gute Kenntnisse
XenServer

Programmiersprachen

Basic
C
Grundwissen
C++
Grundwissen
HPGL, HP PCL
Java
JavaScript
Pascal
Perl
PHP
Python
Scriptsprachen
Shell
SQL
Ansible

Datenbanken

Informix
ISAM
MariaDB
MS SQL Server
MySQL
Postgres
Sybase

Datenkommunikation

AppleTalk
ATM
Ethernet
Fax
FDDI
Firewall
HDLC
Internet, Intranet
ISDN
ISO/OSI
LAN, LAN Manager
Message Queuing
Network-Security
Novell
Packet-Radio
Proxy Server
Router
RPC
RS232
SMTP
SNA
SNMP
TCP/IP
Token Ring
Voice
Voice over IP
X.400 X.25 X.225 X.75...

Hardware

BlueCoat MAA-S Appliances
Cisco Converged Switches
gute Kenntnisse
Cisco Router
sehr gute Kenntnisse
Cisco Switches
gute Kenntnisse
Cylink Leitungs-Encrypter
embedded Systeme
FireEye MAS Appliances
genugate Firewalls
HP ProLiant Rack Server
gute Kenntnisse
IBM RS6000
Mikrocontroller
Modem
Prozessrechner
Siemens Großrechner
SUN
gute Kenntnisse

Design / Entwicklung / Konstruktion

EAGLE

Branchen

  • Banken
  • Versicherungen
  • Internet Service Provider
  • Nachrichtentechnik
  • Elektrotechnik
  • Telekommunikation, Broadcasting
  • Metallbau
  • Presse und Werbedesign
  • Medizinische Forschungsinstitute / Kliniken

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.