Ross Fisher
Network Engineer | Cloud Security

20 years in telecommunications, the last four provisioning and troubleshooting enterprise Layer 2 and Layer 3 services on Nokia carrier-grade MPLS platforms across a four-state footprint. GIAC-certified in incident handling and security essentials. Runs a self-operated cloud security research lab and documents active attack campaigns from live sensor data. Comfortable at the intersection of network engineering, security operations, and infrastructure automation.

Certifications
GCIH
GIAC Certified Incident Handler
Active — expires Apr 2029
GSEC
GIAC Security Essentials
Active — expires Dec 2028
GISF
GIAC Information Security Fundamentals
Active — expires Sep 2028
GFACT
GIAC Foundational Cybersecurity Technologies
Active — expires Mar 2028
Advisory Board
GIAC Advisory Board Member
Active — expires Dec 2028
AWS SAA-C03
AWS Solutions Architect Associate
In progress — 2026

Previously held: ISC² CC (exp. Jan 2026) · Cisco CCNA (exp. Jul 2024) · Nokia NRS-I (exp. May 2025)

Experience
Field Engineering Operations Technician II
Cox Business — Access Transport, San Diego, CA
Mar 2022 — Present
  • Provision end-to-end Layer 2 and Layer 3 customer services on Nokia production MPLS routing infrastructure spanning California, Nevada, Arizona, and Idaho, across a fleet of thousands of carrier-grade devices
  • Build and execute service configuration scripts using in-house automation tooling to deploy and modify services across the Nokia router fleet; averaged 2–3 circuit builds and cutovers per working day with zero outages across hundreds of deployments
  • Staged, provisioned, and led the hot cut migration of a 23-site school district VPLS network from Nokia FP3 to FP4 platform, completing all 23 sites in under 60 minutes with zero service disruption
  • Led and coordinated a carrier-to-carrier network-to-network interface (NNI) upgrade from 1G to 10G, cutting over 24 circuits in under three hours with no major service interruptions
  • Diagnosed and resolved a failed geo-redundant SIP circuit transfer that had stumped prior escalations
  • Monitor network performance and service quality using Skylight with Accedian Network Interface Devices at carrier-to-customer demarcation points
  • Coordinate equipment migrations and service re-provisioning during maintenance windows, updating router configurations to move services from legacy to replacement hardware
  • Provide real-time provisioning support to field technicians during installations, escalations, and live maintenance windows; trained and mentored two new hires, one of whom has since advanced to a management role
Business Technology Technician II
Cox Business — San Diego, CA
Aug 2018 — Mar 2022
  • Installed, configured, and troubleshot enterprise Cox Business services including Metro-Ethernet, SIP trunks, IP Centrex, Business Voice Manager, and surveillance systems for SOHO, multi-campus enterprises, schools, hospitals, and military installations including US Navy and USMC facilities in San Diego
  • Deployed and maintained IP telephony environments built on Edgewater Networks Edgemark devices, PoE switching, and Cisco and Polycom endpoints, from initial build through troubleshooting
  • Subject matter expert for detection and surveillance systems and security panel configuration; primary escalation technician for complex voice, data, and security issues across the San Diego region
  • Led small teams as senior technician on multi-site surveillance installs, including a 40+ camera rebuild across two campuses
Field Service Supervisor
Cox Communications — San Diego, CA
Sep 2015 — Aug 2018
  • Supervised a team of 14 field technicians across residential and commercial service operations, covering quality inspections, safety training, and customer escalations
  • Tracked and drove team performance across four scorecards: quality checks, points per hour, home certification pass rates, and net promoter scores
  • Achieved quarterly NPS regional top performer by focusing on first-time fix rates and technician coaching; coached multiple team members into promotions, one into a leadership role
Universal Home Technician
Cox Communications — Santa Barbara & San Diego, CA
May 2006 — Sep 2015
  • Installed and serviced Cox residential broadband, digital telephone, home networking, and home security and automation systems across two markets over nine years
  • Specialized in repeat-visit resolution, permanently fixing chronic signal and wiring issues that prior technicians had missed or worked around; selected as one of the first technicians trained on Cox Home Security at launch
Security Projects & Research
Terrapot — Cloud-Native Honeypot and Threat Intelligence Platform
  • Built an AWS honeypot and threat intelligence platform provisioned entirely as code: 42 resources in modular Terraform with S3 remote state, Docker Compose services, and a GitHub Actions pipeline gating every merge on Checkov policy scanning
  • Designed the network and IAM layer from scratch: VPC, subnetting, security group segmentation, and least-privilege instance roles, with threat intelligence enrichment via Lambda and AbuseIPDB and canary alerting on CloudTrail and EventBridge
  • Log aggregation and dashboards in Grafana, Loki, and Promtail with automated TLS via Certbot; validated through full destroy-and-rebuild cycles with zero configuration drift, holding monthly cost under $5
Security Research — DShield / SANS ISC Honeypot
  • Raspberry Pi 4 running Cowrie SSH/Telnet honeypot and Suricata 7.0 IDS with the Emerging Threats ruleset, reporting continuously to the SANS Internet Storm Center (sensor ID 3000055796)
  • Documented active attack campaigns observed on live sensor data, including Redtail cryptominer and Outlaw/mdrfckr IRC botnet activity (May 2026)
Technical Skills
Network Infra Nokia 7750 SR/IXR, Nokia NFMP, MPLS/VPLS, Metro-Ethernet, SIP, ELAN, Layer 2/3 services, TCP/IP, BGP fundamentals, WAN circuit provisioning
Cloud AWS (EC2, S3, Lambda, DynamoDB, CloudTrail, EventBridge, CloudWatch, GuardDuty, IAM, API Gateway, Route53, CloudFront, SSM Parameter Store)
Infra as Code Terraform, Docker, GitHub Actions CI/CD, Checkov policy scanning, Git, S3 remote state
Security Tools Suricata, Cowrie, DShield, Grafana, Loki, Promtail, Wireshark, nmap, gobuster, Burp Suite, Caido, Metasploit, Responder, Hashcat
Security Concepts Incident handling, threat intelligence, network security, MITRE ATT&CK, OWASP Top 10, cyber kill chain, deception technology, canary tokens
Platforms Linux (Kali, Raspberry Pi OS, Ubuntu), Windows, SecureCRT, Skylight, UET/Remedy
Education
AS, Computer Network Engineering
Santa Barbara City College
AA, General Studies
Santa Barbara City College