Mateo Velez Network Administrator
McLean, VA • netadmin@gmail.com • +1 703-555-0148
Profile Summary
- Network Administrator with 11 years of experience operating multi-site enterprise networks across hospitality, healthcare, and corporate IT, specializing in LAN/WAN administration, firewall operations, and enterprise wireless.
- Solid technical background across switching and routing (Cisco, VLAN trunking, OSPF), wireless (Meraki, 802.1X with WPA3 Enterprise), perimeter security (Palo Alto), monitoring (SolarWinds, NetFlow with Wireshark), and IPAM on Infoblox, with strong fundamentals in change-management discipline, monitoring rigor, and structured OSI-layer troubleshooting.
- Deep expertise in multi-site LAN/WAN administration, firewall and VPN operations, enterprise wireless management, and monitoring and incident response, applying practices such as OSI-layer troubleshooting and ITIL change management to deliver reliable, secure, and well-documented networks.
- Engaged collaborator working cross-functionally with Security, Server, Helpdesk, and Site IT teams in ITIL-driven IT operations, contributing to change advisory boards, post-incident reviews, and refresh planning with a pragmatic, ownership-first mindset.
- Senior operator who shares technical excellence and fosters a culture of runbook discipline and post-incident review rigor through after-action reviews and peer coaching, while leading network operations weekly review sessions and authoring widely adopted runbooks and SOPs.
Technical Skills
- Routing & Switching:
- Cisco Catalyst, Cisco Nexus, VLAN trunking, inter-VLAN routing, OSPF, EIGRP, BGP, spanning tree (RSTP/MST), LACP/EtherChannel, HSRP/VRRP
- Firewalls & Security:
- Palo Alto PAN-OS, Fortinet FortiGate, Cisco ASA, ACL design, NAT, IPsec and SSL VPN, Zero Trust patterns, 802.1X with RADIUS
- Wireless:
- Cisco Meraki, Aruba Central, Ruckus, RF site surveys, WPA2/3 Enterprise, 802.1X authentication, guest SSID and captive portal, channel and power tuning
- WAN & SD-WAN:
- MPLS, Metro Ethernet, dedicated internet access (DIA), Cisco SD-WAN (Viptela), Meraki SD-WAN, site-to-site VPN, QoS for voice and video
- Monitoring & Performance:
- SolarWinds NPM/NCM, PRTG, Nagios, Zabbix, LibreNMS, NetFlow / sFlow analyzers, Wireshark, SNMPv3, syslog and trap collection
- DNS, DHCP & IPAM:
- Infoblox, BlueCat, Microsoft DNS and DHCP, BIND, phpIPAM, subnetting, DNS zones (forward and reverse), DHCP scopes and reservations
- Protocols & Troubleshooting:
- TCP/IP, OSPF, BGP, EIGRP, STP, ARP, ICMP, packet capture (Wireshark, tcpdump), ping/traceroute/nslookup, OSI-layer troubleshooting
- Certifications & Methodologies:
- Cisco CCNA, Cisco CCNP Enterprise, CompTIA Network+, Palo Alto PCNSA, ITIL Foundation, change management, Visio / Lucidchart / draw.io documentation
Education
Work Experience
- Own the day-to-day administration of the corporate IT and brand-network environment across 850+ Cisco and Meraki devices, covering corporate HQ LAN, 40+ branch sites over SD-WAN, and enterprise wireless for 9,000+ corporate users.
- Administer the LAN, WAN, and VLAN fabric across 320 access and core switches at 42 sites, handling VLAN trunking, inter-VLAN routing, spanning tree, and link aggregation across 180 production VLANs.
- Run IPAM, DNS, and DHCP on Infoblox across 62k IP addresses, including forward and reverse DNS zones, scope design, and reservation hygiene, sustaining DNS resolution under 20 ms at the branch edge.
- Manage perimeter security on Palo Alto PAN-OS, maintaining 1,400+ firewall rules across ACLs, NAT, and site-to-site and remote-access VPN, terminating 2,200 concurrent VPN tunnels for hybrid users.
- Run the enterprise wireless fabric across 1,100 Meraki MR access points, including SSID strategy, RF tuning, guest captive portal, and 802.1X authentication, supporting 14,000 peak concurrent clients at 98.4% client connect rate.
- Operate network monitoring on SolarWinds with NetFlow and Wireshark for deep dives, cutting MTTR on network incidents from 2 hr 40 min to 48 min and sustaining 99.98% on tier-1 circuits.
- Triage and resolve 1,600+ network tickets per year using OSI-layer troubleshooting, CLI tools (ping, traceroute, nslookup), and packet captures, holding escalations to under 4% and recording 92% first-touch resolution.
- Drove network change management and firmware patching across the property estate, processing 220+ network changes with planned maintenance windows shrinking from 6 hr to 90 min and zero failed firmware rollbacks.
- Owned network documentation on Visio and the team's IPAM and asset inventory, maintaining 60+ network diagrams and runbooks and clearing clean PCI and SOX audits in back-to-back years.
- Coordinated with 4 ISPs and 2 carriers on circuit installs, escalations, and RMAs, handling 300+ vendor and ISP tickets and closing them with zero billing disputes left open over 30 days.
- Worked closely with Security, Server, Helpdesk, and Property IT teams across 11 resort properties, authoring 35 runbooks and SOPs that shaped the team's operating baseline and onboarding 6 new-hire network administrators.