Résumé

Security Architect with 11+ years designing and operating enterprise security infrastructure across telecom, MSSP, and Fortune 500 environments. Deep expertise in zero-trust architecture, SASE/SSE (Prisma Access), and cloud security on AWS and Azure. Proven track record translating security requirements into scalable, auditable designs — reducing DR deployment time by 92% and accelerating firewall migration timelines by up to 50% through automation. ISC2 CISSP certified; active Palo Alto Networks and AWS certifications.

Experience

Nov 2022 – Present

Senior Security Consultant & Security Architect

Orange Cyberdefense · Atlanta, GA

  • Architected zero-trust security solutions for large-scale enterprise clients — defining security boundaries, access policies, and segmentation strategies aligned to NIST CSF and CIS Controls.
  • Designed and delivered SASE/SSE strategy leveraging Palo Alto Networks Prisma Access, enabling consistent policy enforcement for hybrid and remote workforces across client environments.
  • Eliminated a 4-hour manual DR process — re-architected Azure Disaster Recovery infrastructure and automated provisioning via ARM templates and GitHub Actions, cutting deployment to under 20 minutes (92% reduction).
  • Scaled the cloud firewall fleet from zero to 30+ PA-VM instances in Azure, fully automated via bootstrap configurations, Panorama templates, and Device Groups, with zero post-deployment manual intervention.
  • Automated firewall migration workflows using vendor tooling and custom scripting, compressing deployment timelines by 30–50% and reducing human error exposure.
  • Hardened enterprise security posture by implementing SSL/TLS inspection and phishing-resistant MFA — capabilities previously absent from client environments.
  • Led and mentored two security teams (10+ engineers), owning hiring, performance reviews, and skills development aligned to current threat frameworks.

Aug 2015 – Oct 2022

Security Engineer

Orange Cyberdefense · Atlanta, GA

  • Managed security and network operations for a diverse MSSP portfolio — resolving complex L2/L3 incidents and serving as escalation point for advanced troubleshooting across multi-vendor environments.
  • Designed and delivered firewall policy architectures (Palo Alto, Fortinet) ensuring least-privilege access and compliance with client security standards.
  • Conducted capacity and performance assessments using FortiSIEM and FortiAnalyzer, translating telemetry into actionable hardening recommendations.
  • Secured third-party vendor access via IPsec tunnels, maintaining auditability and enforcing vendor access control policies.
  • Performed network packet analysis (Wireshark, tcpdump) and protocol-level troubleshooting across TCP/IP, DNS, BGP, and routing environments to isolate complex incidents.

Core Competencies

Architecture & Strategy

  • Zero Trust Architecture
  • SASE / SSE
  • Prisma Access
  • Security Boundary Design
  • Network Segmentation
  • Risk Assessment

Cloud

  • AWS
  • Azure
  • Identity & Access Management
  • Infrastructure as Code
  • ARM Templates
  • GitHub Actions
  • CloudFormation

Network Security

  • Palo Alto Networks
  • Fortinet
  • Check Point
  • Cisco ASA
  • Panorama
  • IPsec / SSL VPN
  • SSL/TLS Inspection

Operations & Analysis

  • SIEM & Threat Management
  • FortiSIEM / FortiAnalyzer
  • Wireshark / tcpdump
  • TCP/IP · BGP · DNS
  • Incident Response
  • Routing & Switching

Governance

  • NIST CSF
  • CIS Controls
  • ISO 27001
  • ITIL
  • Compliance Auditing
  • Team Leadership

Certifications

Professional Development

Education

2009 – 2012

Bachelor of Science — Network & Telecommunications

Ecole Pratique des Hautes Etudes Commerciales (EPHEC) · Belgium

Languages