Michael J. Ferguson

Firewall Engineer · NSX-T and Firewall Automation

Summary

20+ years of IT infrastructure experience in security and architecture. Currently focused on VMware NSX-T automation and Palo Alto policy engineering. Hands-on developer in Python, JavaScript/React, and PostgreSQL, building firewall self-service and automation platforms. Experience with AWS and Azure virtual networking, VMware, and OpenStack. Extensive knowledge of IP routing, in particular BGP and OSPF. Well-rounded and experienced from the ground up.

Technical Skills

Development

React, Python, FastAPI, Flask, PostgreSQL, pan-os-python, REST APIs, Streamlit

DevOps

Docker, Kubernetes, Ansible, Terraform, Jenkins and GitHub Actions (CI/CD), Agile/Kanban, Jira, Confluence

Security

Palo Alto (Panorama, GlobalProtect, User-ID, HSM), FortiGate/FortiManager, Check Point, VMware NSX-T, Zscaler, Cisco ASA, VPN, AWS VPN, AlgoSec, Firemon, Wireshark, Rapid7, threat detection and vulnerability analysis

Network

LAN/WAN, BGP/OSPF, Cisco Nexus/ASR/ISR, Arista, Cisco Wireless, F5 and NetScaler load balancers, DNS (Infoblox, Bluecat), MPLS

Platforms & Cloud

Linux, VMware, OpenStack, Windows Server, Microsoft Azure, AWS networking/VPC

Auth & Storage

LDAP, OAuth2, OIDC, JWT, Redis, PingFederate, Duo; iSCSI, RAID

Certifications & Training

  • AlgoSec Firewall Analyzer Expert and FireFlow Expert, 2025
  • Terraform, 2024
  • Python / Ansible / Jenkins / Docker, 2024
  • Aruba ClearPass, 2024
  • Palo Alto ACE Accreditation v6.0, 7.0, 8.0, 2016 to 2018
  • Cisco CCNP, 2011; CCNA, 2009
  • Federal (GSA) security clearance, 2017 (expired)

Experience

Dec 2025 to present

First Citizens Bank

Firewall Engineer (contract)

  • Primary responsibility: VMware NSX-T automation.
  • Palo Alto firewall rule engineering and administration.
  • Zscaler policy and connectivity.
Mar 2024 to Jul 2025

G Research

Senior Network Security Engineer, Automation

  • AlgoSec deployment lead: designed and deployed six physical servers in a DR configuration covering 2,000+ Layer 3 devices and 150+ firewalls.
  • Learned the full campus network (three data centers, six offices) and updated all SSH ACLs.
  • Added Layer 3 firewall interfaces, BGP connectivity, and firewall policies for new subnets.
  • Designed and built an extensive firewall test lab with BGP and multiple VLANs: Cisco, Arista, Palo Alto/Panorama, FortiGate/FortiManager, Check Point/SmartCenter.
  • Ansible at engineering level for all network configuration; supported the operations team.
  • Terraform for new FortiGate deployment designs (proof of concept).
  • PostgreSQL DR failover: analyzed and redesigned the database structure for new data center nodes and updated existing automation to use the failover structure.
  • Built Panorama, FortiManager, and multiple logging servers on OpenStack.
  • Began building internal tooling with Streamlit, Python, and React.
Mar 2020 to Mar 2024

American Airlines

Senior Network Security Engineer + Automation

Developer of firewall automation and self-service platforms alongside Palo Alto engineering.

  • Firewall Self-Service Portal and Firewall Rule Request Portal v2.0: React frontend, Python/FastAPI backend, PostgreSQL schema, pan-os-python against Panorama; approval and compliance logic; Kubernetes; CI/CD with GitHub Actions.
  • Firewall Rule Request Portal v1.0: Flask, Python, MySQL, Celery/Socket backend.
  • PingFederate migration: proof of concept converting legacy LDAP/JWT/Redis tokens to OAuth2/OIDC.
  • DNS Automation v1.0 (A records) and automated port security with Ansible, Netmiko, and Paramiko.
  • Palo Alto: new interfaces with BGP/OSPF, captive portal, Panorama rules, HSM connectivity for certificate keys, VPN testing to AWS.
  • NSX-T training and proof of concept including Layer 3 dynamic route advertisement with BGP.
  • Network troubleshooting by subnet location using BGP and OSPF routing-table analysis.
Dec 2018 to Feb 2020

First American Payment Systems

Sr. Network Security Engineer, Network Engineering

  • Daily Palo Alto administration: rules, upgrades, VPN creation.
  • Projects: firewall upgrades, Duo authentication redesign, User-ID redesign.
  • NSX firewall administration, VIP analysis, NSX load balancing for HSM.
  • Design and implementation of HSM including routing documentation and cabling.
  • Routing and switching administration; Wireshark and PCAP analysis.
Sep 2017 to Oct 2018

Telos Corp.

Sr. Network Security Engineer, Security Operations

  • Co-lead, Carbon Black Protection/Bit9 migration to new servers and software upgrade; Microsoft SQL Server installation; Dell DRAC and RAID 1/10 configuration.
  • Co-lead, Security Onion IDS migration: pilot plus ten production sensor servers.
  • Palo Alto upgrades, rules, and DoS protection; Cisco ASA rules; Bluecat DNS.
  • Security incident troubleshooting with Wireshark and PCAP analysis.
Mar 2015 to Sep 2017

Torchmark Inc.

Sr. Network Engineer, Network Design

  • Lead: designed and built Palo Alto User-ID across four Windows domains; User-ID became the standard for security policy.
  • Lead: corporate MPLS network upgrade with remote hardware refresh and BGP/OSPF dynamic routing.
  • Lead: new Palo Alto DMZ zone (OSPF + User-ID) for database, Exchange, and Oracle Exadata/Exalogic infrastructure.
  • Co-lead: disaster recovery site with Palo Alto 5060s and Nexus 7k/5k/2k.
  • Cisco AnyConnect upgrade to LDAP with Duo two-factor; ASA segregation and migration to 5545-X; contractor VPN.
  • Built AWS and Azure connectivity to the corporate network including VPNs and AWS routing.
  • Other leads: secure Bloomberg connection, 6509 to Nexus 7k core cutover, 9k deployments, Firemon and NetBrain proofs of concept, Panorama VM.
Apr 2014 to Feb 2015

Mary Kay Inc.

Sr. Network Engineer, Implementation

Configured and deployed Palo Alto branch firewalls using BGP and OSPF with VPN failover, and assisted with branch network refreshes.

  • Data center: two Palo Alto 3050s as VPN concentrator backup with OSPF to Nexus VDCs.
  • Brazil main office and Minas Gerais, and Mexico main office plus warehouse: Palo Alto 3020/500 as the site Layer 3 device with dual MPLS or VPN backup, BGP/OSPF, and local internet offload.
  • US branches and MK Manufacturing: staged and tested Palo Alto 3020/3050 deployments; ASR 1002 BGP redesign for the plant.
  • WAN redesign converting IPsec VPN routing from OSPF to BGP; Cisco 4500 and 2960 refresh; Visio and Office documentation.
Jul 2012 to Apr 2014

JC Penney

Network Engineer, Network Security

Central point of contact for 2,200 store ASA 5525-X firewalls; deployed 300+ ASAs plus Cisco 2900 routers, 3560/2960 stacks, MPLS, Nexus 7k/5k/2k/1k, wireless, and UCS.

  • Lead firewall engineer: four UCS C-260 servers for centralized management of 2,000+ firewalls; scripted conversion of 2,200 firewalls from Active/Active to Active/Standby; discovery of 4,400+ contexts and IPS sensors.
  • Lead: store firewall/IPS upgrade of 2,270 devices, 10,000 feature licenses, NetFlow and IPS configuration, scripted context access.
  • Lead: store QA lab upgrade with a dozen full-scale test environments.
  • Store network refresh (Cisco's largest wireless project, 2012): controllers, routers, switches, vendor coordination.
May 2011 to Jun 2012

Citigroup

Network Analyst 2, Network Change Implementation

  • Configuration implementation across 40,000+ network devices in scheduled maintenance windows under ITIL.
  • Cisco router and switch changes and upgrades, DNS operations, VPN and QoS, NetScaler and F5 VIPs, Cisco wireless controller and AP configuration.
2003 to 2009

North Texas Medical Consultants

Systems and Network Support Engineer

  • Ran all servers and networks across several offices.
1998 to 2002

Fidelity Investments Systems Company

Senior Systems Programmer

  • Implementation and support of production Solaris/AIX systems for Fidelity front-end web and application servers.
  • Designed and built a content delivery/distribution system for 2,000+ web servers.