You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Nadir KhenakNK

Nadir Khenak

Network and Security Architect / Engineer

€760/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Nadir

Network and Security Architect / Engineer with solid experience in critical banking environments with high demands.
I specialize in network and security, with expertise in Check Point, Fortinet, Palo Alto, Cisco ASA firewall solutions, and also in F5 Network and Netscaler load balancing.
  • French

    Native or bilingual

  • English

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • BNP Paribas
    Network Security Architect
    BANKING AND INSURANCE
    May 2023 - May 2026 (3 years)
    Montreuil, France
    Technologies: Cisco Nexus 9K, ASR, Arista switches, Check Point appliances/VSX firewalls, Fortinet Firewalls, Palo Alto Firewall and IPS, F5 BIG-IP LTM, APM, GTM, ASM WAF load balancers, F5 rSeries, vCMP Host/Guest functionality and physical appliances.
    • • Contribution to the telecom infrastructure redesign program, migration from a legacy environment (VDC/VPC) to a VXLAN/EVPN Fabric architecture, including: Migration and redesign of different VRFs, Deployment and integration of new Fortinet 1801 F, 1101 E firewalls with multi-vdom functionality and Check Point SG9000, SG6700 and N9K switches, Analysis of impacts and implementation of VS migration to dedicated clusters.
    • • Redesign of BNP partner core routing, design, study, and implementation of a new VXLAN fabric with Fortinet 1801 F clusters and Palo Alto PAN5200 IPS environment for bank interconnections and partner LS (BNPPARIBAS). Configuration and production deployment of firewalls and IPS sensors, implementation of partner migration batches.
    • • Deployment of Palo Alto IPS sensors, strengthening the security of traffic between the group environment and bank subsidiaries.
    • • Obsolescence management program: hardware refresh of various Fortinet, Check Point, and Palo Alto firewall ranges, as well as F5 load balancers identified as nearing EOS (End of Support), qualification of new ranges.
    • • Replacement program for F5 Viprions with the F5 rSeries 10800 solution. Installation, massive deployment of F5 rSeries assets on new VXLAN Fabrics, scratch configuration, vCPU distribution management, and tenant implementation. Adaptation of the target configuration for migrating vCMP Guests to target tenants on the F5 rSeries. Migration plan for hundreds of vCMP Guests to the new solution, implemented via HNO operations. Migration of WAF policies, all GTMs for the bank's DNS services, and LTMs.
  • Société Générale
    Network Security Engineer
    BANKING AND INSURANCE
    July 2019 - May 2023 (3 years and 10 months)
    Fontenay-sous-Bois, France
    Technologies: Cisco Nexus 9K, 5K, 3K, 2K fex fabric, ASR1004, 1001-X, ASR9000, Check Point 21400, 15600 appliances/VM/VSX firewalls, Fortinet Firewalls, Cisco IPS/IDS Sourcefire, Citrix Netscaler Load Balancers, F5 BIG-IP LTM, APM, GTM, ASM WAF.
    • • Project for modernizing Data Center urbanization in the EU, migrating ICN infrastructures from old DCs to target locations at Equinix. Preparation of BoMs/orders for assets, hardware deployment and staging, creation of cabling matrices, supervision of DC teams. HNO migration process for services, study of technical migration strategies, and business validation tests.
    • • Implementation of Cisco N9K switches under the 2-layer infrastructure standard for secure traffic chaining. Configuration of Check Point, Fortinet firewalls, clustering, HA and routing settings, CPU performance tuning, acceleration, strengthening redundancy and bandwidth via bond/ether-channel. Deployment of L2 HSRP, STP, vPC, vDC infrastructure, priorities, convergence management.
    • • Remediation: technical optimizations within the scope of capacity planning monitoring, creation of L2DCI links, Nexus under vPC subdomains. Nexus 3K to 9K refresh program, Check Point cluster VSLS HA Load sharing for active/active distribution of the bank's BAD application hosting environment.
    • • Deployment of a Cisco SDWAN core for bank branch networks. Design of SDWAN Control Plane infrastructures, deployment of VRFs, Check Point VS, and Fortinet VDOMs, N9K switches. Configuration of VMANAGE routing on MAN and BGP announcements to ISPs, RIPE registration.
    • • Commissioning of Microsoft TEAMS infrastructures: study of the deployment strategy across the bank's corporate infrastructures, design of the target infrastructure, creation of technical environments: installation of Check Point firewalls in VSX, Netscaler load balancers, and N9K switches.
  • Réseau et Sécurité Banque SOCIETE GENERALE
    Engineer
    BANKING AND INSURANCE
    July 2019 - May 2023 (3 years and 10 months)
    Fontenay-sous-Bois, France
    Within the ICN Internet Connectivity team, responsible for internet-facing infrastructures, designing new architectures, HLD/LLD documentation, and deployment. Remediation and capacity planning for critical and vital bank infrastructures, as well as their operational maintenance.

    Technologies: Check Point 21400, 15600 appliances/VM/VSX firewalls, Fortinet Firewalls, Cisco IPS/IDS Sourcefire, Citrix Netscaler Load Balancers, F5 BIG-IP LTM, APM, GTM, ASM WAF. Cisco Nexus 9K, 5K, 3K, 2K fex fabric, ASR1004, 1001-X, ASR9000

Recommendations

Be the first to recommend Nadir

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Skill set

Categories