Evolution Cloud Services (EVOCS)
Senior Network Security Engineer
Denver, CO · Senior
Sponsorship not specified$75k-$90kDetected 8 days ago
PythonAWSGCPAzureCloud PlatformsTerraformAnsibleCybersecurityNetwork SecuritySIEMSOC OperationsDetection EngineeringIncident ResponseComplianceFirewallVPNCiscoBGP/OSPFSD-WANZero TrustHIPAACommunicationCollaboration
About the role
- Administer FortiManager for centralized policy management, device provisioning, and configuration consistency across all regional firewall deployments
- Conduct regular firewall audits and rule-base reviews to identify and remediate policy bloat, misconfiguration, and unnecessary exposure
- Participate in security incident response activities, including firewall log analysis, traffic forensics, containment actions, and post-incident remediation
Responsibilities
- Operate and maintain FortiAnalyzer for log aggregation, threat correlation, security event analysis, and compliance reporting across the global environment
- Architect and implement Fortinet Security Fabric integrations including FortiSIEM, FortiEDR, FortiNAC, and FortiSandbox to deliver cohesive, end-to-end threat detection and response capabilities
- Design and manage SD-WAN solutions using Fortinet SD-WAN, optimizing performance, resilience, and security for multi-site connectivity
- Develop, maintain, and enforce firewall security policies, access control lists, NAT rules, application control profiles, and SSL/TLS inspection policies
- Lead the planning and execution of multi-region firewall migrations, upgrades, and new site deployments with minimal business disruption
- Partner with network, cloud, and security operations teams to integrate perimeter security controls with cloud-native security services (AWS, Azure, GCP) and zero trust architecture initiatives
- Develop and maintain network security documentation including architecture diagrams, standard operating procedures, runbooks, and change management records
- Collaborate with compliance and risk teams to ensure firewall configurations meet regulatory requirements (e.g., PCI-DSS, HIPAA, SOC 2, ISO 27001)
- We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success.
- We strive to deliver exceptional quality and consistency through a white-glove approach.
Requirements
- 7+ years of enterprise network security engineering experience, including 4+ years of hands-on Fortinet firewall administration and architecture
- Deep expertise in FortiGate firewall configuration, policy management, HA clustering, and multi-VDOM environments
- Proven experience managing Fortinet deployments across multiple geographic regions or data centers with FortiManager centralized management
- Strong experience with FortiAnalyzer for log management, security event correlation, and compliance reporting
- Experience designing and implementing Fortinet SD-WAN solutions for enterprise multi-site connectivity
- Familiarity with zero trust network access (ZTNA) principles and implementation within the Fortinet Security Fabric
- Experience integrating firewall environments with cloud platforms (AWS, Azure, or GCP), including FortiGate-VM and cloud-native security group management
- Strong understanding of network security frameworks, threat modeling, and defense-in-depth architecture
- Experience supporting compliance and audit activities related to firewall configuration (PCI-DSS, SOC 2, HIPAA, or similar)
- Design, deploy, and manage enterprise-grade Fortinet firewall infrastructure (FortiGate) across multiple geographic regions, ensuring standardized policy frameworks and localized compliance where required
Nice to have
- Fortinet NSE 7 - Enterprise Firewall, SD-WAN, or Network Security Architect certifications
- Experience with Fortinet Security Operations Center (SOC) tools including FortiSIEM and FortiSOAR
- Background supporting global template or network standardization programs across diverse regional environments
- Experience with network automation and infrastructure-as-code tooling (Ansible, Terraform, Python scripting for Fortinet APIs)
- Familiarity with SASE architecture and cloud-delivered security services
- Additional vendor certifications (CCNP Security, Palo Alto PCNSE, or equivalent) demonstrating broad network security breadth
- Background in incident response and threat hunting using network traffic analysis and firewall telemetry
- Firewall uptime and availability SLAs are consistently met across all regional deployments
Compensation
- Pay Range for jobs in the US.
Apply directly at Evolution Cloud Services (EVOCS) →Create a free account for alerts like thisView Evolution Cloud Services (EVOCS) immigration profile
This listing is sourced directly from Evolution Cloud Services (EVOCS)'s careers page and normalized into a canonical job model.