Slow network, unstable VPN, a firewall nobody wants to touch, or an AWS setup that has grown messy? I fix these quickly and document them so they stay fixed.
Network & Cloud Architect with 10+ years of experience designing, deploying, and securing enterprise, data-center, and hybrid-cloud networks.
What I can do for you:
Network design and audit — LAN/WAN, VLANs, Layer 2/3 routing, multi-site and data-center architecture
Firewall setup and hardening — Palo Alto, Fortinet, Sophos, Cisco ASA, pfSense, Huawei USG
VPN — Site-to-Site, Client and SSL VPN, secure on-prem ↔ AWS connectivity
AWS networking — VPC design, subnetting, Security Groups and NACLs, NAT and Internet Gateways, VPC Peering, ALB/NLB, CloudWatch and VPC Flow Logs
Troubleshooting — packet-level diagnosis of latency, routing, and connectivity issues; monitoring with PRTG, Zabbix, SolarWinds, Nagios, OpManager
Servers and virtualization — Active Directory, DNS, VMware ESXi, Hyper-V, SAN/NAS, backup and disaster recovery
Certifications:
- AWS Certified Solutions Architect – Associate
- Cisco Certified Network Professional (CCNP)
- Cisco Certified Network Associate (CCNA)
- Microsoft Certified Solutions Associate (MCSA)
How I work
Every engagement ends with a clear write-up and a network diagram (Visio or Lucidchart) so your team can maintain it without me. I communicate in plain English, give honest timelines, and tell you up front if something is outside my scope.
Message me with what's broken or what you're building and I'll reply within a day with how I'd approach it.
Subin S.
Linux Infrastructure Engineer | Proxmox/Scale Computing | Wazuh SIEM
Coimbatore, India
$25/hr$25 per hour5.0 (13) 28 jobs $10K+ total earnings
Overview:
I secure and segment the infrastructure businesses cannot afford to lose: industrial control networks, production servers, and the boundary between corporate IT and operational technology. 100% Job Success | Top Rated | 1,700+ hours on Upwork.
Most of my recent work is OT/ICS: designing and building the controlled access path between an enterprise network and a manufacturing environment, so engineers and vendors can reach plant systems without exposing them. I also do the underlying Linux work that makes it hold together, identity, DNS, time, storage, monitoring, and I document it to a standard that survives an audit.
OT / ICS security:
- IT-to-OT network segmentation to the Purdue model (Levels 0-5), aligned to IEC 62443 zone-and-conduit principles
- Brokered remote access for OT: Apache Guacamole broker, DMZ jump hosts, session mediation, no direct IT-to-OT reach
- OT DMZ design and build: controlled realm transition, vendor access mediation, deny-by-default firewall posture
- Separate OT identity infrastructure: Samba Active Directory, BIND9 DNS, chrony NTP, Kea DHCP, independent of corporate IT
- Air-gapped and internet-restricted environments: internal package mirrors, offline patching workflows, no-egress operation
- SCADA/historian platforms: Ignition Gateway, Microsoft SQL Server historians, OT-to-IT one-way data push
- Industrial network hardware: Cisco IE-series switches, Sophos XGS firewalls, VLAN segmentation for production lines
- Vendor remote access control: time-bound, logged, restricted to approved systems
What I deliver:
- Wazuh SIEM/XDR deployment: full setup, agent enrollment, custom rules, dashboards, and alerting across Linux and Windows endpoints
- Server monitoring stacks: Wazuh, Zabbix, Nagios, Grafana, deployed and tuned to cut alert noise
- High availability for infrastructure services: keepalived/VRRP virtual IPs, PostgreSQL replication, HAProxy ingress
- Active Directory integration across Linux and Windows: realmd/SSSD, Kerberos, keytabs, group-based authorisation
- Linux server hardening to production-grade standards (Ubuntu, Debian, CentOS)
- Firewall policy design and enforcement (UFW, iptables, pfSense)
- ZFS storage and immutable backup design: snapshot policy, retention, SMB file services, restore validation
- DNS architecture with failover, DNSSEC, and SPF/DKIM/DMARC for email security
- Virtualization platforms: Proxmox VE, Scale Computing HyperCore, VMware
- Windows Server and SQL Server administration: domain join, role-based access, cumulative update management
- Cloud infrastructure security across AWS, Azure, GCP, and DigitalOcean
- NGINX and Apache optimization for high-traffic environments
- CI/CD pipeline security and infrastructure automation with Docker and Bash
- VAPT: vulnerability assessment & penetration testing, with formal reporting and remediation timelines
- Log analysis, threat detection, and incident response
- Build records, runbooks and validation evidence, every change documented, reversible, and auditable
Recent work:
- Built the controlled access path between an enterprise network and a manufacturing plant: Guacamole access broker, IT-side and OT-side jump hosts, dual-realm Active Directory, and the firewall rule set to go with it. Engineers and vendors reach production systems through one audited, revocable path instead of direct connections.
- Deployed an OT file services platform on Debian with OpenZFS and Samba: six access-controlled shares for PLC projects, vendor files, gauge exports and database backups, with snapshot retention and least-privilege service accounts proven by test rather than assumed.
- Found and fixed a realm-wide time service that had never worked: the NTP servers were synchronised but serving no clients, and the build-time validation checked the wrong side. The site firewall and several infrastructure hosts had been silently unsynchronised for months. Kerberos authentication depends on this.
- Migrated an industrial database platform to a segmented OT zone: Windows Server 2022 and SQL Server 2022, domain-joined, with group-based sysadmin delegation replacing shared credentials, and a documented single revocation point per host.
- Deployed and managed Wazuh SIEM across multi-server environments with real-time alerting and compliance monitoring.
- Handled a live credential-exposure incident: hardcoded admin credentials pushed to a public repository. Full key rotation and git history remediation, zero downstream compromise.
- Delivered a full VAPT engagement for a mid-market client with a structured draft-to-final reporting cycle.
- Rebuilt email security posture (SPF, DKIM, DMARC) for a client domain from a failing state to fully compliant.
Experience includes serving as Cybersecurity & Infrastructure Manager for a venture firm, Senior DNS & Network Security Engineer at a security company, and Infrastructure & Security Consultant for a US-based consulting firm.
I respond within 5 hours.
I'm a network and security engineer with 10+ years of experience designing, deploying, and maintaining enterprise network infrastructure. I hold CCNP Security, CCDE, and Cisco Meraki Black Belt certifications, and have direct engagement experience with reputed multinational organizations including Standard Chartered Bank, Maersk Bangladesh, and HSBC — as well as delivery experience through global system integrators such as Dimension Data, Logicalis Hong Kong, NTT, and British Telecom (BT).
I help businesses improve network performance, strengthen security, and reduce downtime — with a focus on clean, well-documented deployments that make long-term maintenance easier for you or your team. I'm also a Visio specialist — I turn complex network environments into clear, simplified diagrams that make it easy for your team to understand, maintain, and troubleshoot your infrastructure.
Hardware & Platforms I Work With:
1. Routers: Cisco 1900, 2600, 2800, 2900, 3745, 7206, ISR 4300 series
2. Switches: Cisco Catalyst 2800, 3650, 3750, 3850, 4500, 6800, 9300 (L2/L3)
3. Security: Cisco FPR 1000/1100/2100/3100, Cisco ASA 5500-X, NGFW, ESA, Check Point
4. NGTP/NGTX, Fortinet FG-80D, WatchGuard
5. Wireless: Cisco AP 1800–9100 series, Aruba AP 535/565 & IAP, Cisco WLC
6. 2504/5504/5520/9800, Aruba 7200 mobility controllers
7. Meraki: MR (wireless), MS (switching), MX (security appliance) — full-stack Meraki deployment
8. Servers: Dell PowerEdge T310, HP ProLiant DL360, HP RX2660
9. WAN Optimization: Riverbed SteelHead CX
10. Video Conferencing: Polycom RealPresence Group Series, Polycom VSX/HDX, Cisco
11. TelePresence SX20, Cisco MX300 G2
12. Network Documentation: Microsoft Visio — clean, simplified network diagrams and topology mapping
Tools: GNS3 for Cisco IOS configuration and testing
Certifications:
1. Cisco CCNP Security
2. Cisco Certified Design Expert (CCDE)
3. Cisco CCNA (Routing & Switching)
4. Cisco CCNA Security
5. Cisco Meraki Black Belt Deployment
6. Cisco Networking: On-Premise and Cloud Solutions (OCSE)
7. Cisco CyberOps Associate
If you need a reliable partner for network design, security hardening, Cisco/Meraki deployment, or clean network documentation — let's talk about your project and how I can help.
Yasir A.
Network Architect CCIE x2 SD-WAN VXLAN ACI AI ML DataCenter
Dubai, United Arab Emirates
$90/hr$90 per hour5.0 (9) 22 jobs $40K+ total earnings
I am Cisco Dual CCIE (Routing & Switching, Service Provider, DC(in process) Network professional with demonstrable experience in the design and delivery of Enterprise, DC, Service provider, and AI/ML Training DataCenter Networks.
I have also worked on AI Architect roles for customers are who are looking to determine hardware requirements for AI training systems, Architect enhancements required for efficient training of AI models, Scale-Out and Scale-Up Architectures, based on Cisco and Arista AI enhanced Spine & Leaf SW.
I have considerable experience in SD-WAN deployments including Cisco iWAN, Cisco Viptela, Velocloud.
I have deployed projects based on Cisco ACI, DCNM, NDFC, and Manual VXLAN Fabric from Cisco, Arista.
I am an advocate of Automation in Network deployment and Operations and have significant commercial Python and Ansible experience.
I am also Network Security Expert, have deployed multiple projects in DC, Cloud, or private Colo with Palo Alto Firewalls, Fortinet, Cisco Firepower, Juniper Firewall with BGP, S2S VPNs, IPS, NAT, Policies and remote-access deployments.
Certifications:
Cisco:
CCIE Routing & Switching (26003)
CCIE Service Provider
CCIE DataCenter (Written)
CCDE Written, CCNP, IOS XR Specialist.
Splunk:
Cert-57763 Splunk Certified Knowledge Manager, Admin, Power User
Cloud:
AWS Certified Solution Associate (Exam Pending)
Skills (Expert Level):
Software Defined Data Center:
Cisco ACI :
Capacity Planning, Design, Deployment
Migration of existing DC to ACI (Brownfield, Greenfield)
Migrating WAN Services to ACI, L3out
Automation the Migration with the help of Ansible
Implementing Multi-Pod or Multi-site ACI
Cisco ACI and Vmware VMM integration
Cisco VXLAN, Single Fabric, Multi Pod Fabric and Multisite Fabric Design, CLI, Nexus Dashboard, NDFC
Arista EVPN VxLAN
Cumulus Linux and White Box Switches
Vmware NSX-T
IP/MPLS/WAN:
Cisco SD-WAN, Viptela/Velocloud Deployments and Troubleshooting
IOS, IOS XR, NX-OS, JunOS, SROS.
Cisco Nexus Platform, CRS, ASR9K, Cisco Adaptive Security Appliance (ASA) 55xx.
OSPF, BGP, Fabrickpath, MPLS, Multicast, EVPN.
Cisco SD-Access SDA DNA Center
Splunk:
Analyzing the customer requirements
Design and implementation of Splunk Architecture
Creating Reports and Dashboard according to the requirements
Troubleshooting the Splunk operations and scalability issues
Security:
Configuration and Troubleshooting Palo Alto, CheckPoint, F5 Appliances, Fortinet, Cisco Firepower Hardware Appliances or Cloud in Azure, AWS.
Network Automation and Programmability with CI/CD
Python
JSON, XML, YAML
Ansible
Jenkins
Git
How it works
Post a job for freePost a job
Tell us what you need. Create your own job post or generate one with AI then filter talent matches.
Hire top talent fast
Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.
Collaborate easily
Use Upwork to chat or video call, share files, and track project progress right from the app.
Payment simplified
Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.
Don't just take our word for it
“Upwork provides an umbrella-level of security. I can see a talent’s work history and ratings. I can hold payments in escrow. I can communicate through Upwork Messages instead of working through my email address.”
KD
Kim Darling
Verified
Emerald Tiger
“Upwork is the best platform to hire skilled professionals when we're not looking for a full-time employee. All the companies in our portfolio use Upwork to find talent across a wide range of fields.”
DM
David Merry
Verified
Kinetic Investments
“Our very specific requirements can be a challenge—With Upwork, we’re able to access a bigger community to ensure the success of our projects.”
KK
Katja Krohn
Verified
Summa Linguae
How do I hire a NetBSD Specialist on Upwork?
You can hire a NetBSD Specialist on Upwork in four simple steps:
Create a job post tailored to your NetBSD Specialist project scope. We’ll walk you through the process step by step.
Browse top NetBSD Specialist talent on Upwork and invite them to your project.
Once the proposals start flowing in, create a shortlist of top NetBSD Specialist profiles and interview.
Hire the right NetBSD Specialist for your project from Upwork, the world’s largest work marketplace.
At Upwork, we believe talent staffing should be easy.
How much does it cost to hire a NetBSD Specialist?
Rates charged by NetBSD Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.
Why hire a NetBSD Specialist on Upwork?
As the world’s work marketplace, we connect highly-skilled freelance NetBSD Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream NetBSD Specialist team you need to succeed.
Can I hire a NetBSD Specialist within 24 hours on Upwork?
Depending on availability and the quality of your job post, it’s entirely possible to sign up for Upwork and receive NetBSD Specialist proposals within 24 hours of posting a job description.