Jesus Sandoval
@jesussandoval
Senior network security engineer specializing in cloud security, Zero Trust, and enterprise firewall architecture.
What I'm looking for
I’m a Senior Network Security Engineer with 10+ years designing, deploying, and managing enterprise firewall, cloud security, and Zero Trust architectures across banking, government, telecom, and critical infrastructure environments. I bring deep multi-vendor expertise across Palo Alto, Fortinet, Check Point, Juniper, and Cisco platforms.
I’ve delivered cloud security across AWS, Azure, GCP, and GCVE, including VMware NSX-T micro-segmentation and distributed firewall rule enforcement. I integrate centralized policy management (e.g., Panorama) and align security posture across hybrid cloud environments.
In recent roles, I led NSX-T micro-segmentation design for a large-scale GCVE migration, resolved complex migration firewall/network issues, and created application/user/workload grouping strategies to reduce east-west risk. At the Government of Canada, I deployed and managed FortiGate fleets with FortiManager, integrated FortiAnalyzer with Splunk/QRadar for real-time threat visibility, and supported ongoing vulnerability auditing across cloud accounts.
I work with a delivery mindset—thorough documentation, knowledge transfer, and measurable improvements to security compliance and incident readiness. I also automate and troubleshoot end to end (from segmentation and SIEM visibility to policy change workflows), and I’m available immediately for remote or on-site contract or full-time roles in Canada and the US.
Experience
Work history, roles, and key accomplishments
Cloud Security Engineer
ATB Financial
Oct 2025 - Mar 2026 (5 months)
Led NSX-T micro-segmentation design and implementation for a large-scale GCVE migration, enforcing Zero Trust segmentation with distributed firewall rules. Centralized Palo Alto firewall policy management using Panorama and resolved migration/network firewall issues to reduce downtime.
Cloud Security Engineer
IRCC (Government of Canada)
Jul 2023 - Sep 2025 (2 years 2 months)
Deployed and managed Fortinet FortiGate firewalls across government locations using FortiManager for centralized NGFW policy enforcement. Integrated FortiGate with Splunk/QRadar SIEM via FortiAnalyzer and implemented advanced threat protection (IPS, antivirus, web filtering) for real-time threat visibility.
Security Consultant
TELUS
Sep 2020 - Jul 2023 (2 years 10 months)
Delivered multi-vendor firewall policy provisioning and complex application migrations using Palo Alto Panorama, Check Point Smart Console, Juniper Junos Space, and FortiManager within Zero Trust architectures. Implemented cloud security for AWS/GCP that increased data protection compliance by 80% and reduced breach risk.
Network Security Engineer
TD Bank
Sep 2021 - Jan 2023 (1 year 4 months)
Managed Palo Alto PA-7050/PA-5060 firewalls via Panorama 9.1 alongside Guardicore micro-segmentation and VMware NSX. Conducted incident response and event log monitoring, and reviewed Tufin Orchestration Suite change requests to ensure firewall policy changes met security and business requirements.
Network Security Engineer
Bank of Nova Scotia
Sep 2019 - Aug 2020 (11 months)
Designed and commissioned a newly built data center in Santo Domingo by implementing network and multi-vendor security infrastructure from the ground up. Managed Palo Alto/Check Point/FortiGate operations, SIEM log collection with ArcSight ESM and Splunk, and change accuracy using AlgoSec FireFlow before deployment.
Network Security Engineer
Peel Regional Police
Apr 2018 - Jul 2019 (1 year 3 months)
Migrated 5 sites from remote access VPN to IPsec site-to-site using IKEv2 and certificate-based authentication between Cisco ASAs to improve security and performance. Designed and deployed Microsoft security stack (Azure Sentinel and Microsoft Defender products), upgraded Cisco ISE, and implemented Cisco SD-WAN across sites and data centers.
Network Security Engineer
Equitable Life of Canada
Feb 2017 - Mar 2018 (1 year 1 month)
Built and migrated two data centers (Waterloo to Barrie) using Cisco Nexus switching, Juniper SRX firewalls, and A10 load balancers with minimal downtime. Designed SD-WAN modernization and deployed Juniper vSRX on AWS with full VPC networking (ENI/EIP, routing, NAT, security groups).
Network Specialist
Rogers Communications
May 2016 - Jan 2017 (8 months)
Supported Rogers network engineering projects by developing design alternatives and optimizing network cost and performance. Troubleshot multi-vendor security environments (Juniper, Check Point, Palo Alto, Fortinet, and Cisco) during incidents and implementations.
Network Specialist
Rogers Communications
Nov 2014 - Aug 2015 (9 months)
Provided network engineering support for Rogers national network, developing design/provisioning and capacity plans for IPv4/IPv6 infrastructure. Troubleshot multi-vendor firewall environments and supported incidents using Microsoft Azure.
Education
Degrees, certifications, and relevant coursework
Jesus hasn't added their education
Don't worry, there are 90k+ talented remote workers on Himalayas
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Jesus?
You can contact Jesus and 90k+ other talented remote workers on Himalayas.
Message JesusFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
