> Markdown version of [/jobs/ext/3629390-network-engineer-fortinet](https://www.wearedevelopers.com/jobs/ext/3629390-network-engineer-fortinet). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Engineer - Fortinet - **Company:** Conexess Group - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** LTE (Telecommunication), IEEE 802.1X, Link Aggregation (Ethernet), Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Border Gateway Protocol, Spanning Tree Protocols, Cloud Computing, Wavelength-Division Multiplexing, Data Centers, Software Debugging, Dynamic Multipoint Virtual Private Networks, Failover, Virtual Private LAN Services, Internet Protocol Security (IP SEC), Subnetting, Multi-protocol Systems, JSON, Python (Programming Language), Network Security, Network Layer, Network Architecture, Network Monitoring, Routing, Open Shortest Path First (OSPF), Paessler Router Traffic Grapher, PCI Data Security Standards, Performance Tuning, Ansible, Prometheus, Sniffers, TCP/IP, Virtual Local Area Networks, Wide Area Networks, Wireless Networks, Zabbix, Load Balancing, Grafana, Firewalls (Computer Science), Juniper, Git, National Institute of Standards and Technology Cybersecurity Framework, SolarWinds (Software), Performance Monitor, Fortinet, Open Network Automation Platform, Cisco, SSL VPN - **Published:** October 8, 2026 - **Apply:** https://www.thejobnetwork.com/job/42b53d1e-97dd-4159-af52-d8231a822d87/sr-network-engineer-fortinet ## About the Role * 7+ years of progressive enterprise network engineering experience, including 3+ years at a senior or lead level. \n * Deep, hands-on production experience with FortiGate and FortiOS - policy design, routing, HA, VDOMs, IPsec/SSL VPN, IPS/UTM profiles, and troubleshooting with CLI diagnostics (diagnose debug flow, sniffer, session table analysis). \n * Demonstrated production experience with FortiManager and FortiAnalyzer at scale. \n * Hands-on experience designing and operating Fortinet Secure SD-WAN in a multi-site environment. \n * Significant LAN experience: enterprise campus switching, VLAN architecture, spanning tree, link aggregation, first-hop redundancy, QoS, PoE, 802.1X/NAC, and enterprise wireless. \n * Significant WAN experience: BGP and OSPF at scale, IPsec and DMVPN-style overlays, MPLS/VPLS, broadband and LTE/5G failover, carrier circuit provisioning and troubleshooting, and WAN performance optimization. \n * Significant MAN experience: metro Ethernet, dark fiber, DWDM/CWDM, point-to-point and ring topologies, and inter-site Layer 2/Layer 3 extension. \n * Strong routing and switching fundamentals independent of vendor - TCP/IP, subnetting, route selection, redistribution, packet flow, and structured troubleshooting methodology. \n * Practical automation ability: Python and/or Ansible, REST/JSON API consumption, and Git-based workflow. \n * Working knowledge of network monitoring platforms and telemetry pipelines [e.g., LibreNMS, SolarWinds, Zabbix, PRTG, Grafana/Prometheus, Elastic, ThousandEyes]. \n * Proven ability to work independently - to take an ambiguous requirement, scope it, design it, and deliver it without day-to-day direction. \n * Excellent written and verbal communication, including the ability to explain technical tradeoffs to non-technical stakeholders. \n, * Fortinet certification at the professional level or above - FCP, FCSS (Network Security, Secure Access Service Edge, or Enterprise Firewall), or FCX. Legacy NSE 4-7 equally considered. \n * Additional vendor certifications: CCNP/CCIE Enterprise, JNCIP, or equivalent. \n * Experience with additional vendor platforms in a mixed environment [Cisco, Arista, Juniper, Palo Alto]. \n * Cloud networking experience - AWS Transit Gateway, Azure Virtual WAN, FortiGate-VM deployments, and hybrid connectivity via Direct Connect/ExpressRoute. \n * Experience with data center fabrics [VXLAN/EVPN, spine-leaf], load balancing, and DDI platforms [Infoblox, BlueCat]. \n * Exposure to regulated environments and associated controls [PCI-DSS, HIPAA, SOX, NIST CSF, CJIS]. \n * Experience building or leading a network automation practice from the ground up. \n * Prior experience mentoring engineers or leading a small technical team. ## Description The right candidate is equally comfortable in a maintenance window cutting over a core firewall pair and writing a playbook that makes the next twenty cutovers routine. You will be expected to reduce manual toil through automation, replace reactive break/fix cycles with proactive monitoring and telemetry, and serve as an escalation point and mentor for other engineers.