Network Architecture and Design
- Develop high-level and low-level network designs for segmented enterprise platforms
- Design inbound and outbound DMZs trusted application zones and management operations backup and datanetworks
- Define VLANs subnets gateways route tables firewall boundaries NAT DNS and IP-address allocations
- Apply default-deny segmentation and permit only approved source destination protocol and port combinations
- Prepare architecture diagrams traffic flows communication matrices allocation registers and implementation records
RHEL and KVM Virtualization
- Design and administer RHEL-based KVM environments
- Open vSwitch or Linux bridges and VLAN-backed virtualinterfaces
- Create isolated hypervisor-only networks and map VM interfaces to approved bridges VLANs and port groups
- Implement virtual firewall and Layer 3 routing services while separating management from application traffic
Kubernetes Network and Security Engineering
- Design separate public-facing and private Kubernetes worker groups and enforce appropriate workload placement
- Implement default-deny NetworkPolicies namespace isolation controlled service DNS exposure and explicit ingress andegress
- Protect control-plane and node-management interfaces and prevent workloads from bypassing approved gateways andfirewalls
API Gateway and Proxy Engineering
- Design and operate APISIX gateways for inbound internal and outbound API traffic
- Configure authentication authorization mTLS request validation rate limits allowlists routing policies tracing and auditlogs
- Configure NGINX reverse and egress proxies with approved upstreams methods paths headers and externaldestinations
Network and Platform Security
- Implement layered controls across WAF, firewalls, APISIX, NGINX, Kubernetes, NAT, and DNS
- Prevent direct internet access to Kubernetes nodes, private services, databases, and management interfaces
- Enforce destination, FQDN, IP, protocol, and port allowlists; permit only stateful return traffic for approved outboundsessions
- Apply TLS/mTLS, manage certificate trust and renewal requirements, and protect credentials in approved secrets stores
- Participate in cybersecurity reviews, threat assessments, risk evaluations, and architecture approvals
Firewall, Routing, NAT, and DNS
- Define complete firewall rules, route tables, next hops, subnet associations, routing priorities, and approval records
- Configure NAT policies and pools, capacity monitoring, controlled DNS forwarding, domain allowlists, and event logging
- Review physical trunks and virtual networks to exclude unapproved VLANs, routes, and unintended transit paths
Monitoring and Operational Readiness
- Integrate WAF, firewall, APISIX, NGINX, Kubernetes, NAT, and DNS events with centralized logging or SIEM
- Monitor availability, latency, error rates, rejected requests, firewall denies, DNS failures, NAT utilization, policy violations,and certificate expiry
- Configure health checks, synchronized time, end-to-end correlation IDs, alerts, escalation paths, and support ownership
- Maintain backup, recovery, troubleshooting, and operational runbooks for gateways, proxies, certificates, and policies
Implementation, Validation, and Governance
- Prepare deployment sequences and coordinate switching, KVM networking, firewalls, Kubernetes, and platform services
- Execute positive and negative connectivity tests, security validation, failover tests, and control-bypass checks
- Collect firewall, route, gateway, proxy, Kubernetes, NAT, DNS, and SIEM evidence for approval and handover
- Maintain version-controlled configurations and comply with change, risk, configuration, and approval processes
- Identify availability risks and recomm