Job Title: Network & Security Engineer
Department: IT Infrastructure & Security
Experience: 3 to 5 years
Employment Type: Full-time
We are seeking an experienced Network Security Engineer to design, implement, maintain, and troubleshoot our organization's enterprise network security infrastructure. The ideal candidate will have hands-on expertise with the Fortinet ecosystem (FortiGate, FortiManager, FortiAnalyzer), along with a solid background in network architecture, routing protocols, and multi-vendor firewall environments.
- Deployment & Maintenance: Deploy, configure, and maintain FortiGate Next-Generation Firewalls (NGFW) across enterprise environments and cloud infrastructures.
- Centralized Management: Utilize FortiManager for centralized policy deployment and FortiAnalyzer for log monitoring, analysis, and threat intelligence.
- Policy Management: Design, review, and optimize firewall rule bases, security profiles (IPS, Anti-Virus, Web Filtering, Application Control), and NAT configurations following the principle of least privilege.
- VPN Architecture: Configure, manage, and troubleshoot Site-to-Site (IPsec) and Remote Access (SSL VPN / FortiClient) connections.
- SD-WAN: Implement and optimize Fortinet Secure SD-WAN for distributed enterprise sites.
- Troubleshooting: Perform Layer 2 to Layer 7 network analysis, packet captures, and flow debugs to resolve complex connectivity and security issues.
- Incident Escalation: Monitor security events, investigate potential threats/breaches, and participate in incident response workflows.
- High Availability & Failover: Implement and maintain High Availability (HA) clusters and redundant network links to ensure maximum uptime.
- Policy Audits: Conduct periodic reviews of firewall security policies and network access control lists (ACLs).
- Patching & Upgrades: Plan and execute FortiOS firmware upgrades and patch management aligned with change control processes (ITIL).
- Documentation: Maintain complete, up-to-date network topologies, standard operating procedures (SOPs), and change history logs.
- Core Fortinet Expertise: In-depth knowledge of FortiGate, FortiManager, FortiAnalyzer, and FortiClient.
- Networking Protocols: Strong understanding of TCP/IP, BGP, OSPF, VLANs, VXLAN, IPsec, NAT, DNS, and DHCP.
- Security Technologies: Expertise in IPS/IDS, Web Application Firewalls (WAF), Multi-Factor Authentication (MFA), and Zero Trust Network Access (ZTNA).
- CCNA/CCNP: Routing & Switching
- Automation (Optional/Plus): Familiarity with Ansible, Python, or PowerShell for network automation and repetitive operational tasks.
- Fortinet Certified Professional (FCP) or Fortinet Certified Solution Specialist (FCSS) (formerly Fortinet NSE 4 / NSE 5 / NSE 6 / NSE 7).
- Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
- Experience: 3+ years of dedicated hands-on experience in network security engineering and firewall management.
- Strong analytical and troubleshooting skills under high-pressure situations.
- Excellent verbal and written technical communication skills.
- Ability to work effectively in a collaborative team environment as well as independently.