Network Engineer - Fortinet
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+37 more
Job description
The right candidate is equally comfortable in a maintenance window cutting over a core firewall pair and writing a playbook that makes the next twenty cutovers routine. You will be expected to reduce manual toil through automation, replace reactive break/fix cycles with proactive monitoring and telemetry, and serve as an escalation point and mentor for other engineers.
Requirements
-
7+ years of progressive enterprise network engineering experience, including 3+ years at a senior or lead level. \n
-
Deep, hands-on production experience with FortiGate and FortiOS - policy design, routing, HA, VDOMs, IPsec/SSL VPN, IPS/UTM profiles, and troubleshooting with CLI diagnostics (diagnose debug flow, sniffer, session table analysis). \n
-
Demonstrated production experience with FortiManager and FortiAnalyzer at scale. \n
-
Hands-on experience designing and operating Fortinet Secure SD-WAN in a multi-site environment. \n
-
Significant LAN experience: enterprise campus switching, VLAN architecture, spanning tree, link aggregation, first-hop redundancy, QoS, PoE, 802.1X/NAC, and enterprise wireless. \n
-
Significant WAN experience: BGP and OSPF at scale, IPsec and DMVPN-style overlays, MPLS/VPLS, broadband and LTE/5G failover, carrier circuit provisioning and troubleshooting, and WAN performance optimization. \n
-
Significant MAN experience: metro Ethernet, dark fiber, DWDM/CWDM, point-to-point and ring topologies, and inter-site Layer 2/Layer 3 extension. \n
-
Strong routing and switching fundamentals independent of vendor - TCP/IP, subnetting, route selection, redistribution, packet flow, and structured troubleshooting methodology. \n
-
Practical automation ability: Python and/or Ansible, REST/JSON API consumption, and Git-based workflow. \n
-
Working knowledge of network monitoring platforms and telemetry pipelines [e.g., LibreNMS, SolarWinds, Zabbix, PRTG, Grafana/Prometheus, Elastic, ThousandEyes]. \n
-
Proven ability to work independently - to take an ambiguous requirement, scope it, design it, and deliver it without day-to-day direction. \n
-
Excellent written and verbal communication, including the ability to explain technical tradeoffs to non-technical stakeholders. \n, * Fortinet certification at the professional level or above - FCP, FCSS (Network Security, Secure Access Service Edge, or Enterprise Firewall), or FCX. Legacy NSE 4-7 equally considered. \n
-
Additional vendor certifications: CCNP/CCIE Enterprise, JNCIP, or equivalent. \n
-
Experience with additional vendor platforms in a mixed environment [Cisco, Arista, Juniper, Palo Alto]. \n
-
Cloud networking experience - AWS Transit Gateway, Azure Virtual WAN, FortiGate-VM deployments, and hybrid connectivity via Direct Connect/ExpressRoute. \n
-
Experience with data center fabrics [VXLAN/EVPN, spine-leaf], load balancing, and DDI platforms [Infoblox, BlueCat]. \n
-
Exposure to regulated environments and associated controls [PCI-DSS, HIPAA, SOX, NIST CSF, CJIS]. \n
-
Experience building or leading a network automation practice from the ground up. \n
-
Prior experience mentoring engineers or leading a small technical team.
Benefits & conditions
n \n
-
Design, implement, and maintain enterprise LAN, WAN, and MAN infrastructure across the enterprise. \n
-
Lead architecture and lifecycle planning for routing, switching, wireless, and edge security platforms, including capacity modeling and refresh roadmaps. \n
-
Own complex network changes end to end: design, peer review, test plan, implementation, validation, and rollback. \n
-
Produce and maintain accurate documentation - physical and logical topologies, IPAM records, circuit inventories, runbooks, and as-built diagrams. \n
-
Partner with security, systems, cloud, and application teams to ensure network design supports business and compliance requirements. \n
\n
Fortinet Platform Ownership
\n \n
-
Serve as the subject matter expert for the Fortinet Security Fabric across the environment. \n
-
Design, deploy, and operate FortiGate firewalls in HA clusters, VDOMs, and multi-tenant configurations at the data center, campus, and branch edge. \n
-
Manage Fortinet Secure SD-WAN - overlay design, SLA-based path selection, application steering, ADVPN, and zero-touch branch provisioning. \n
-
Centrally administer policy, configuration, and device lifecycle through FortiManager, including policy packages, ADOMs, provisioning templates, and scripted deployments. \n
-
Leverage FortiAnalyzer for logging, correlation, reporting, and long-term retention; build dashboards and reports for operational and audit consumption. \n
-
Deploy and support the broader Fortinet stack as applicable: FortiSwitch, FortiAP, FortiClient/FortiClient EMS, FortiAuthenticator, FortiNAC, FortiSASE, FortiExtender, FortiWeb, FortiMail, and FortiToken. \n
-
Manage firmware lifecycle strategy - release qualification, staged upgrade planning, and coordinated fleet-wide maintenance. \n
-
Own vendor relationships with Fortinet and partner resellers, including TAC escalations, RMA handling, and licensing/entitlement tracking. \n
\n
Automation & Tooling
\n \n
-
Identify high-toil, high-risk manual workflows and replace them with automation where it delivers real value - pragmatism over automation for its own sake. \n
-
Develop and maintain automation using Python, Ansible, and REST APIs, including the FortiOS and FortiManager JSON-RPC APIs. \n
-
Implement configuration standardization, drift detection, and compliance checking across the device fleet. \n
-
Manage network configuration and automation code in Git with peer review, versioning, and change traceability. \n
-
Build validation and pre/post-change verification tooling to reduce human error during maintenance windows. \n
-
Contribute to infrastructure-as-code practices for network and cloud connectivity where applicable [Terraform, CI/CD pipelines]. \n
\n
Proactive Monitoring & Observability
\n \n
-
Design and mature the network monitoring and observability practice - move the team from reactive ticket response to early detection and trend-based intervention. \n
-
Implement and tune monitoring across SNMP, syslog, streaming telemetry, NetFlow/sFlow/IPFIX, and synthetic transaction testing. \n
-
Build meaningful dashboards, baselines, and alert thresholds that surface real problems and suppress noise; own alert quality as an ongoing responsibility. \n
-
Establish capacity and performance trending for circuits, interfaces, tunnels, firewall throughput, and session tables to drive proactive upgrades. \n
-
Define and report on network SLIs/SLOs and contribute to service availability metrics. \n
-
Lead root cause analysis for major incidents and drive corrective and preventive actions to closure. \n
\n
Mentorship & Technical Leadership
\n \n
-
Act as a technical escalation point for Tier 1/2 support and infrastructure engineers. \n
-
Mentor teammates through pairing, design reviews, structured knowledge transfer, and lab exercises. \n
-
Develop and maintain internal documentation, standards, and training material that raise the team’s baseline competency. \n
-
Contribute to change advisory processes, design standards, and engineering best practices. \n
-
Participate in on-call rotation and after-hours maintenance windows as required. \n
\n
About the company
From our start in 2009, Conexess has established itself in 3 markets, employing nearly 200+ individuals nationwide. Operating in over 15 states, our client base ranges from Fortune 500/1000 companies to mid-small range companies. For the majority of the mid-small range companies, we are exclusively used due to our outstanding staffing track record, n
Conexess is a full-service staffing firm offering contract, contract-to-hire, and direct placements. We have a wide range of recruiting capabilities, from help desk technicians to CIOs. We are also capable of offering project-based work.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…