Joseph Hannah III

Joseph Hannah III

Network security engineer, New Jersey

I build and secure networks for regulated production environments, where an outage or a failed audit is expensive. I have 5+ years in networking. Most recently I owned the network for both US sites of a PCI CPP and ISO 27001 production environment, including a new site I designed, cabled, configured, and walked the auditor through. My background includes PCI CPP card production environments, where the network has to satisfy auditors as well as operations.

Available now. Open to remote, hybrid, or on-site roles in New Jersey.

Joseph Hannah III

Certifications CompTIA and Fortinet

  • CompTIA Security+
  • CompTIA Network+
  • CompTIA A+
  • CompTIA ITF+
  • CompTIA Secure Infrastructure Specialist (CSIS)
  • Fortinet NSE 3
  • Fortinet NSE 2
  • Fortinet NSE 1

Selected work

A compliant production site, empty room to passed audit

Regulated card-production environment

The problem
A new production facility needed a network that would pass PCI CPP and ISO 27001 audits from day one, with secure remote access back to the existing site.
What I did
  • Handled the design, equipment selection, physical build, and logical configuration myself
  • 5 security zones, segmented VLANs and subnets, and a default-deny firewall policy with explicit allow rules between zones
  • Compliant encrypted remote access between sites
  • Hardened every switch with Dynamic ARP Inspection, port security, and IPv6 RA/DHCPv6 Guard
  • Cabled and dressed it myself
Result
I stood in front of the auditor for the site's network and answered every question. He also complimented the cable management, which is the part I'm proudest of.
Internet edgeperimeter
DMZinspected
Productionsegmented
High-security zonemost restricted
Simplified. Each boundary is a firewall layer, and traffic only moves inward where a rule allows it.

Other projects

  • Segmenting a flat production network

    Replaced a flat network with dedicated subnets per zone and explicit-allow rules on a default-deny firewall. 50+ devices re-addressed and documented, with cutovers staged inside scheduled maintenance windows and a rollback point at each step.

  • Firewall migrations across four vendors

    Moved full security policy and site connectivity between platforms: Cisco to Check Point and pfSense, SonicWall to FortiGate, and Palo Alto to FortiGate. Each one got reference documentation and a staged cutover plan with a way back at every step. I also reprovisioned firewalls so two sites shared one topology.

  • PCI CPP and ISO 27001 audit lead for the network

    Network and systems lead for 3 PCI CPP and ISO 27001 audits, and the primary contact for the assessors on 2. I led the infrastructure review, built the evidence packages, and helped redefine and enforce the change management process so the records were always audit-ready.

  • Replacing end-of-life switching

    Aging switches were running outdated cryptography, which was a real audit exposure. I compared replacement platforms on power, stacking and security capability, then recommended a migration path.

Experience

I started fixing arcade machines at 14 and have been working in technical roles since 2017.

  1. Aug 2024 to Aug 2026Eatontown, NJ

    Network Security Engineer

    TAG Systems (AustriaCard)

    • Designed and deployed the network for a new production facility, including security zones, equipment, addressing and compliant remote administration
    • Replaced a flat production network with a microsegmented design: dedicated subnets per zone, explicit-allow rules on a default-deny firewall, 50+ devices re-addressed and documented
    • Designed a layered firewall architecture with least-privilege routing between zones
    • Network and systems lead for 3 PCI CPP and ISO 27001 audits; coordinated with teams in 17 countries
    • Helped redefine and enforce change management for network and firewall changes across both sites
    • Migrated firewall policy and site connectivity from Cisco to Check Point and pfSense, then reprovisioned 3 firewalls to align topology across sites
    • Hardened 10+ switches with DAI, port security, and IPv6 RA/DHCPv6 Guard
  2. Sep 2022 to Aug 2024Brick Township, NJ

    Network Administrator

    Monmouth Cyber, promoted from IT Technician

    • Network and firewall lead for about 15 recurring clients, from small businesses to industrial operations and enterprise campuses
    • Led 10+ complete network redesigns covering cabling, firewall policy, and wireless, including firewall migrations from SonicWall and Palo Alto to FortiGate
    • Handled escalations on-site and remotely, and covered on-call emergencies
  3. Feb 2022 to Sep 2022Point Pleasant, NJ

    IT Manager

    Jenkinson's South, promoted from IT Technician

    • Ran IT for a boardwalk entertainment campus with 300+ endpoints (more than a /24 could hold), including 100+ point-of-sale terminals
  4. Sep 2021 to Jan 2022Toms River, NJ

    Fulfillment Expert

    Target

  5. May 2017 to Sep 2020Seaside Heights, NJ

    Arcade Technician

    Casino Beach Pier. My first paid technical job, diagnosing hardware faults across a large arcade floor.

Skills

Grouped by the kind of work, each with where I've done it.

Firewalls and segmentation

Designed layered firewall zones for PCI CPP production environments, and migrated firewalls between Cisco, Check Point, pfSense, SonicWall, Palo Alto, and FortiGate.

  • Fortinet FortiGate
  • Cisco Firepower
  • Check Point
  • pfSense
  • SonicWall
  • Palo Alto
  • Network segmentation
  • Microsegmentation
  • Firewall policy design
  • NAT
  • IDS / IPS
  • Firewall migration

Switching and routing

Hardened access switching across production zones, and led the evaluation for replacing end-of-life switches.

  • Cisco Catalyst
  • Cisco IOS
  • VLANs
  • Spanning tree
  • Link aggregation
  • Layer 2 security
  • IPv6
  • QoS
  • Wireless

Compliance and audit

Network and systems lead for PCI CPP and ISO 27001 audits in card production environments: infrastructure review, evidence packages, findings and change records.

  • PCI CPP
  • ISO 27001
  • Audit evidence
  • Change management
  • Risk assessment
  • HSM integration
  • Technical documentation

Secure remote access

Built compliant remote administration between production sites, and run my own lab with separate internal and public access behind single sign-on.

  • Site-to-site VPN
  • IPsec
  • Zero trust access
  • Single sign-on
  • Identity-aware access

Infrastructure and virtualization

Servers and virtualization across client environments, plus a home lab running more than 50 self-hosted services.

  • VMware
  • Virtualization
  • Containers
  • Windows Server
  • Linux
  • Backup and recovery
  • Structured cabling

Monitoring and operations

MSP ticketing, documentation and remote management, plus logging and vulnerability scanning.

  • Splunk
  • Nessus
  • Centralized logging
  • Vulnerability scanning
  • ConnectWise
  • IT Glue
  • RMM tools
  • Jira

Home lab

Where every change gets broken and rebuilt before it goes anywhere near production.

Full-height server rack with its front doors closed, lit blue from inside
The rack, doors closed, running.

My home lab is not VLAN 1 on a consumer router. It's a full rack in my home office that runs around the clock and did not fit through the doorway without a brief moment of regret.

My real estate agent mentioned "home office potential." She did not specify what kind. I did not mention I'd be looking up floor joist load ratings before moving in a 7-foot rack. We have both chosen not to discuss it further.

Open source first: I reach for open-source tools before commercial ones, and I have to understand anything I run.

I use it so the first time I try something is never on production equipment.

Network
Segmented into isolated zones, with intrusion detection at the edge. Multi-gig switching with QoS
Access
Internal and public access kept separate, with every service behind single sign-on
Compute
Virtualization hosts running more than 50 self-hosted services
Storage
Redundant storage pools across multiple nodes
Backup
3-2-1, with scheduled restore tests
Visibility
Centralized logging, monitoring and alerting