Senior Network Engineer in Allentown
Role details
Job location
Tech stack
Job description
The Senior Network Engineer will design, implement, and support advanced network security infrastructure solutions for enterprise and mid-market clients. This role serves as both a technical leader and trusted client advisor, with a concentrated focus on Fortinet Security Fabric solutions, including FortiGate Next- Firewalls, FortiNAC, and associated ecosystem tools. The Senior Network Engineer will drive end-to-end project delivery, provide expert-level troubleshooting and escalation support, mentor junior and mid-level engineers, and actively collaborate with pre-sales and project teams to develop scalable, secure, and future-ready network environments. This individual will also contribute to the strategic growth of the security practice by evaluating emerging technologies and helping define engineering standards and best practices., Network Security Design & Implementation
· Lead the end-to-end design, deployment, and optimization of Fortinet-based security solutions, including FortiGate NGFWs, FortiManager, FortiAnalyzer, FortiSwitch, FortiAP, and FortiNAC
· Architect and implement Network Access Control (NAC) solutions, including device profiling, posture assessment, endpoint compliance enforcement, and guest access workflows
· Design and deploy advanced firewall policies, security zones, NAT rules, IPS/IDS profiles, SSL inspection, web filtering, and application control policies aligned with Zero Trust principles
· Configure and maintain SD-WAN solutions leveraging the Fortinet Security Fabric for WAN optimization, path selection, and traffic steering
· Design and implement segmentation strategies utilizing VLANs and firewall zone policies to enforce least-privilege access across enterprise environments
· Deploy and manage site-to-site and client-based VPN solutions (IPsec and SSL-VPN) for secure remote access and branch connectivity
Routing, Switching & WAN
· Design and implement enterprise LAN, WAN, and SD-WAN environments including advanced routing protocol configurations (BGP, OSPF) in production-scale deployments
· Support high availability architectures including FGCP (FortiGate Clustering Protocol) Active/Active and Active/Passive failover designs
· Troubleshoot and resolve Layer 2 and Layer 3 network issues across multi-vendor environments
NAC & -Based Access
· Design and implement FortiNAC or equivalent NAC platforms for automated device discovery, classification, and enforcement
· Develop and maintain network access policies based on user , device type, posture compliance, and location context
· Integrate NAC solutions with Active Directory, LDAP, RADIUS, and SAML-based providers for policy-driven access control
· Manage wired, wireless, and VPN-based onboarding workflows for corporate, BYOD, and IoT/OT endpoints
· Support incident response workflows that leverage NAC for dynamic device quarantine and remediation
Client Engagement & Project Delivery
· Serve as a technical escalation point for complex Fortinet and NAC-related incidents, service requests, and change implementations
· Conduct network security assessments, health checks, and technology roadmap reviews for clients, providing actionable recommendations
· Collaborate with project managers and pre-sales teams on solution scoping, proposals, Bills of Materials (BOMs), and Statements of Work (SOWs)
· Communicate complex technical concepts clearly to both technical and non-technical client stakeholders
· Oversee staging, installation, validation, and testing of engineered solutions from kickoff through project closeout
Mentorship & Standards Development
· Provide technical guidance and mentorship to junior and mid-level network engineers, fostering skill development in Fortinet technologies and NAC
· Develop and maintain engineering standards, runbooks, implementation playbooks, and best practice documentation to ensure consistency across deployments
· Stay ahead of Fortinet product roadmaps, firmware releases, and emerging security technologies to advise clients and leadership
· Participate in on-call rotation for after-hours support as required, This role offers the opportunity to work across diverse enterprise environments, lead meaningful security transformation projects, and grow within a team that values technical excellence, continuous learning, and client impact. You will have access to vendor training resources, lab environments, and a collaborative team of experienced engineers who are passionate about delivering best-in-class solutions.
Requirements
· Minimum of 5 years of experience in network engineering, network security, infrastructure consulting, or related technical roles
· Hands-on expertise with Fortinet Security Fabric, including FortiGate firewall policy management, FortiManager centralized administration, FortiAnalyzer log management and reporting, and FortiNAC
· Demonstrated experience designing and implementing NAC solutions, including endpoint profiling, dynamic VLAN assignment, posture assessment, and remediation workflows
· Advanced knowledge of enterprise networking principles including routing, switching, segmentation, redundancy, and high availability
· Proven experience with routing protocols - BGP and OSPF - in production environments
· Strong understanding of network security concepts including firewall policy design, Zero Trust architecture, access control, and secure remote access
· Experience designing and deploying enterprise LAN, WAN, SD-WAN, and wireless solutions
· Proficiency in VPN technologies - both IPsec and SSL-VPN - for site-to-site and remote access use cases
· Working knowledge of RADIUS, LDAP, Active Directory, and -based policy enforcement
· Proven ability to lead technical projects, manage client-facing engagements, and deliver under defined timelines
· Strong documentation, analytical, troubleshooting, and organizational skills with the ability to produce clear network diagrams, design documents, and change records
· Active Professional-level industry certification in networking or security (CCNP, Fortinet NSE 4 or higher, ACSP), · Fortinet NSE 5, NSE 6, or NSE 7 certification, specifically in FortiNAC, FortiManager, or enterprise firewall tracks
· CCNP, CCIE, or equivalent vendor-neutral or vendor-specific expert-level certification
· Experience in a managed services, consulting, or professional services environment supporting multiple clients simultaneously
· Experience across multiple networking and security vendors - Cisco, Meraki, Aruba, Juniper, Palo Alto, Fortinet
· Familiarity with SIEM integration, syslog pipelines, and SOC workflows leveraging FortiAnalyzer or third-party platforms
· Experience with IoT/OT segmentation and NAC-based enforcement in industrial or healthcare environments
· Familiarity with vendor management platforms and centralized administration tools (FortiManager, Cisco DNA Center, Aruba Central)
· Exposure to cloud networking concepts and hybrid connectivity, including SD-WAN integration with cloud platforms (AWS, Azure)
· Experience managing multiple concurrent tasks and priorities in a fast-paced, client-focused environment