Evolution Cloud Services (EVOCS)

Evolution Cloud Services (EVOCS)

Senior Network Security Engineer

Denver, CO · Senior

Sponsorship not specified$75k-$90kDetected 8 days ago
PythonAWSGCPAzureCloud PlatformsTerraformAnsibleCybersecurityNetwork SecuritySIEMSOC OperationsDetection EngineeringIncident ResponseComplianceFirewallVPNCiscoBGP/OSPFSD-WANZero TrustHIPAACommunicationCollaboration

About the role

  • Administer FortiManager for centralized policy management, device provisioning, and configuration consistency across all regional firewall deployments
  • Conduct regular firewall audits and rule-base reviews to identify and remediate policy bloat, misconfiguration, and unnecessary exposure
  • Participate in security incident response activities, including firewall log analysis, traffic forensics, containment actions, and post-incident remediation

Responsibilities

  • Operate and maintain FortiAnalyzer for log aggregation, threat correlation, security event analysis, and compliance reporting across the global environment
  • Architect and implement Fortinet Security Fabric integrations including FortiSIEM, FortiEDR, FortiNAC, and FortiSandbox to deliver cohesive, end-to-end threat detection and response capabilities
  • Design and manage SD-WAN solutions using Fortinet SD-WAN, optimizing performance, resilience, and security for multi-site connectivity
  • Develop, maintain, and enforce firewall security policies, access control lists, NAT rules, application control profiles, and SSL/TLS inspection policies
  • Lead the planning and execution of multi-region firewall migrations, upgrades, and new site deployments with minimal business disruption
  • Partner with network, cloud, and security operations teams to integrate perimeter security controls with cloud-native security services (AWS, Azure, GCP) and zero trust architecture initiatives
  • Develop and maintain network security documentation including architecture diagrams, standard operating procedures, runbooks, and change management records
  • Collaborate with compliance and risk teams to ensure firewall configurations meet regulatory requirements (e.g., PCI-DSS, HIPAA, SOC 2, ISO 27001)
  • We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success.
  • We strive to deliver exceptional quality and consistency through a white-glove approach.

Requirements

  • 7+ years of enterprise network security engineering experience, including 4+ years of hands-on Fortinet firewall administration and architecture
  • Deep expertise in FortiGate firewall configuration, policy management, HA clustering, and multi-VDOM environments
  • Proven experience managing Fortinet deployments across multiple geographic regions or data centers with FortiManager centralized management
  • Strong experience with FortiAnalyzer for log management, security event correlation, and compliance reporting
  • Experience designing and implementing Fortinet SD-WAN solutions for enterprise multi-site connectivity
  • Familiarity with zero trust network access (ZTNA) principles and implementation within the Fortinet Security Fabric
  • Experience integrating firewall environments with cloud platforms (AWS, Azure, or GCP), including FortiGate-VM and cloud-native security group management
  • Strong understanding of network security frameworks, threat modeling, and defense-in-depth architecture
  • Experience supporting compliance and audit activities related to firewall configuration (PCI-DSS, SOC 2, HIPAA, or similar)
  • Design, deploy, and manage enterprise-grade Fortinet firewall infrastructure (FortiGate) across multiple geographic regions, ensuring standardized policy frameworks and localized compliance where required

Nice to have

  • Fortinet NSE 7 - Enterprise Firewall, SD-WAN, or Network Security Architect certifications
  • Experience with Fortinet Security Operations Center (SOC) tools including FortiSIEM and FortiSOAR
  • Background supporting global template or network standardization programs across diverse regional environments
  • Experience with network automation and infrastructure-as-code tooling (Ansible, Terraform, Python scripting for Fortinet APIs)
  • Familiarity with SASE architecture and cloud-delivered security services
  • Additional vendor certifications (CCNP Security, Palo Alto PCNSE, or equivalent) demonstrating broad network security breadth
  • Background in incident response and threat hunting using network traffic analysis and firewall telemetry
  • Firewall uptime and availability SLAs are consistently met across all regional deployments

Compensation

  • Pay Range for jobs in the US.

This listing is sourced directly from Evolution Cloud Services (EVOCS)'s careers page and normalized into a canonical job model.