Senior Network Security Engineer
Evocs OverviewEVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with idealtechnologies to provide them with comprehensive solutions to grow and prosper.Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let’s talk!Position SummaryWe are seeking an experienced Senior Network Security Engineer with deep, hands-on expertise in Fortinet technologies and multi-region network security architecture. This role is responsible for the design, implementation, management, and continuous improvement of our global network security infrastructure, ensuring consistent policy enforcement, threat visibility, and operational resilience across all regional environments. The ideal candidate brings strong Fortinet platform mastery — including FortiGate, FortiManager, FortiAnalyzer, and the broader Fortinet Security Fabric — combined with broad enterprise network security experience and a security-first mindset.Key ResponsibilitiesDesign, deploy, and manage enterprise-grade Fortinet firewall infrastructure (FortiGate) across multiple geographic regions, ensuring standardized policy frameworks and localized compliance where requiredAdminister FortiManager for centralized policy management, device provisioning, and configuration consistency across all regional firewall deploymentsOperate and maintain FortiAnalyzer for log aggregation, threat correlation, security event analysis, and compliance reporting across the global environmentArchitect and implement Fortinet Security Fabric integrations including FortiSIEM, FortiEDR, FortiNAC, and FortiSandbox to deliver cohesive, end-to-end threat detection and response capabilitiesDesign and manage SD-WAN solutions using Fortinet SD-WAN, optimizing performance, resilience, and security for multi-site connectivityDevelop, maintain, and enforce firewall security policies, access control lists, NAT rules, application control profiles, and SSL/TLS inspection policiesLead the planning and execution of multi-region firewall migrations, upgrades, and new site deployments with minimal business disruptionConduct regular firewall audits and rule-base reviews to identify and remediate policy bloat, misconfiguration, and unnecessary exposurePartner with network, cloud, and security operations teams to integrate perimeter security controls with cloud-native security services (AWS, Azure, GCP) and zero trust architecture initiativesDevelop and maintain network security documentation including architecture diagrams, standard operating procedures, runbooks, and change management recordsParticipate in security incident response activities, including firewall log analysis, traffic forensics, containment actions, and post-incident remediationMonitor network security posture through threat intelligence feeds, vulnerability assessments, and proactive tuning of IPS/IDS, web filtering, and antivirus profilesCollaborate with compliance and risk teams to ensure firewall configurations meet regulatory requirements (e.g., PCI-DSS, HIPAA, SOC 2, ISO 27001)Mentor junior network security engineers and serve as a subject matter expert for escalations and architectural decisionsEvaluate and recommend new Fortinet capabilities, firmware releases, and adjacent technologies to strengthen the organization's security postureRequired Qualifications7+ years of enterprise network security engineering experience, including 4+ years of hands-on Fortinet firewall administration and architectureDeep expertise in FortiGate firewall configuration, policy management, HA clustering, and multi-VDOM environmentsProven experience managing Fortinet deployments across multiple geographic regions or data centers with FortiManager centralized managementStrong experience with FortiAnalyzer for log management, security event correlation, and compliance reportingSolid understanding of networking fundamentals: BGP, OSPF, VLAN, VPN (IPSec/SSL), QoS, and routing protocols in a multi-site environmentExperience designing and implementing Fortinet SD-WAN solutions for enterprise multi-site connectivityFamiliarity with zero trust network access (ZTNA) principles and implementation within the Fortinet Security FabricExperience integrating firewall environments with cloud platforms (AWS, Azure, or GCP), including FortiGate-VM and cloud-native security group managementStrong understanding of network security frameworks, threat modeling, and defense-in-depth architectureExperience supporting compliance and audit activities related to firewall configuration (PCI-DSS, SOC 2, HIPAA, or similar)Fortinet NSE 4 certification (minimum); NSE 5, NSE 6, or NSE 7 strongly preferredExcellent documentation, communication, and cross-functional collaboration skillsPreferred QualificationsFortinet NSE 7 — Enterprise Firewall, SD-WAN, or Network Security Architect certificationsExperience with Fortinet Security Operations Center (SOC) tools including FortiSIEM and FortiSOARBackground supporting global template or network standardization programs across diverse regional environmentsExperience with network automation and infrastructure-as-code tooling (Ansible, Terraform, Python scripting for Fortinet APIs)Familiarity with SASE architecture and cloud-delivered security servicesAdditional vendor certifications (CCNP Security, Palo Alto PCNSE, or equivalent) demonstrating broad network security breadthExperience in regulated industries (financial services, healthcare, manufacturing) with associated compliance obligationsBackground in incident response and threat hunting using network traffic analysis and firewall telemetrySuccess MetricsFirewall uptime and availability SLAs are consistently met across all regional deploymentsPolicy audit findings result in measurable reduction in rule-base risk exposure and unnecessary firewall openingsMulti-region deployments and migrations are executed on schedule with zero unplanned production outagesSecurity event detection and response times improve through FortiAnalyzer tuning and integration with SIEM/SOC toolsCompliance audit findings related to firewall configuration are reduced year-over-yearDocumentation and runbooks are current, complete, and sufficient to support knowledge transfer and operational continuityPay Range for jobs in the US.Pay Range$75 - $90 USD👥 Our ValuesWe are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.The Values We Live ByCustomer-centric SolutionsInnovation & ExcellenceIntegrity & TransparencyData-driven Decision Making📝 Need to KnowThe posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.