Senior Network Firewall Engineer / Architect

ECI

Dallas, Northern (TX, KY)

Hybrid

USD 125,000 - 135,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health benefits
Life insurance
401(k)
Flexible PTO

Job summary

ECI is seeking a Senior Network Firewall Engineer/Architect to deliver hands-on firewall administration, policy management, and VPN troubleshooting for a global client network. The role emphasizes ownership of day-to-day firewall work across Palo Alto and Fortinet platforms, with an aim to standardize environments and improve security posture.

The ideal candidate will bring deep expertise in Palo Alto Panorama, FortiGate, site-to-site and remote-access VPNs, and enterprise networking

Qualifications

  • Extensive hands-on experience with enterprise firewalls in production.
  • Proficient with Palo Alto firewalls, policy management, VPN troubleshooting, and Panorama.
  • Hands-on Fortinet FortiGate and VPN experience.
  • Experience with mixed-vendor/legacy environments.
  • Strong communication with clients and documenting findings.

Responsibilities

  • Administer Palo Alto and Fortinet firewalls in production environments.
  • Create, review, modify, and troubleshoot firewall policies, rules, objects, and whitelisting requests.
  • Manage site-to-site and remote-access VPNs (GlobalProtect, FortiClient).
  • Use Panorama and Fortinet tooling for centralized device management and changes.
  • Produce and maintain technical documentation, diagrams, and remediation steps.

Skills

Firewall engineering
VPN troubleshooting
Panorama management
Network fundamentals
Technical documentation

Tools

Palo Alto Networks
Fortinet FortiGate
Cisco (Catalyst/Nexus)
FortiClient/FortiGuard
Panorama

Job description

Senior Network Firewall Engineer / Architect

Primary focus: hands-on firewall engineering and operations, representing approximately 90% of the role.

Position Overview

We are seeking an experienced, hands-on Senior Network Firewall Engineer / Architect to provide dedicated support for a complex, global client network. The role is heavily focused on firewall administration, troubleshooting, security policy management, VPN connectivity, and firewall platform standardization, while also requiring strong enterprise networking fundamentals and architecture-level judgment.

The environment includes a mix of Palo Alto Networks and Fortinet FortiGate firewalls, along with Cisco, Cisco Meraki, Aruba, HP ProCurve, and Ubiquiti networking technologies. The successful candidate will be comfortable taking ownership of day-to-day firewall work, partnering directly with client stakeholders, resolving inherited configuration and security issues, and supporting a longer-term transition toward a more standardized network environment.

Key Responsibilities
  • Perform hands‑on administration and troubleshooting of Palo Alto Networks and Fortinet FortiGate firewalls.
  • Create, review, modify, and troubleshoot firewall security policies, access permissions, rules, objects, and whitelisting requests.
  • Manage and troubleshoot site‑to‑site VPN tunnels and remote‑access VPN services, including Palo Alto GlobalProtect and Fortinet FortiClient.
  • Use Palo Alto Panorama and Fortinet management tooling to manage devices, configurations, policies, and operational changes across the environment.
  • Assess existing firewall configurations for security gaps, inconsistencies, technical debt, and deviations from standards or best practices.
  • Support the gradual migration and standardization of firewall platforms, including movement from Fortinet toward Palo Alto where approved and funded.
  • Provide dedicated technical support and direct communication for a specific global client while collaborating with ECI network services, implementation, NOC, compliance, and principal engineering teams.
  • Support firewall and network integration for newly acquired offices and other merger‑and‑acquisition activity.
  • Plan and execute upgrades, technology refreshes, patching, configuration changes, and remediation activities through established change‑management processes.
  • Troubleshoot network and application connectivity issues across firewalls, routing, switching, wireless, SD‑WAN, circuits, DNS, and adjacent infrastructure.
  • Review traffic flows, logs, packet captures, latency, jitter, packet loss, utilization, and application policies to isolate performance or connectivity problems.
  • Produce and maintain accurate technical documentation, including network diagrams, firewall standards, rule documentation, implementation plans, validation steps, rollback plans, and client‑facing recommendations.
  • Help assess inherited client environments, verify how systems are configured, and recommend practical remediation and modernization priorities.
Technical Environment
  • Palo Alto Networks firewalls and Panorama
  • GlobalProtect remote‑access VPN
  • Fortinet FortiGate firewalls, FortiClient, Fortinet SD‑WAN, and centralized Fortinet management tools
  • Firewall policies, permissions, rule bases, objects, NAT, whitelisting, and VPN tunnels
  • Cisco routing and switching, including Catalyst and Nexus platforms
  • Cisco Meraki switching and wireless
  • Cisco ISE and 802.1X initiatives
  • Aruba, HP ProCurve, and Ubiquiti networking and wireless technologies
  • Enterprise LAN, WAN, wireless, routing, SD‑WAN, DNS, and network security
Required Qualifications
  • Significant hands‑on experience administering and troubleshooting enterprise firewalls in production environments.
  • Strong practical experience with Palo Alto Networks firewalls, including policy and rule management, VPN troubleshooting, and Panorama.
  • Hands‑on experience with Fortinet FortiGate firewalls and related VPN or management technologies.
  • Demonstrated ability to manage firewall permissions, security policies, rule bases, whitelisting, objects, and connectivity requirements.
  • Experience configuring and troubleshooting site‑to‑site VPNs and remote‑access VPN solutions.
  • Strong enterprise networking fundamentals across TCP/IP, routing, switching, VLANs, LAN/WAN, wireless, DNS, and packet flow analysis.
  • Ability to troubleshoot complex connectivity and performance issues using logs, packet captures, traffic analysis, device health data, and systematic fault isolation.
  • Experience working in mixed‑vendor, poorly standardized, or inherited network environments.
  • Experience preparing and executing controlled infrastructure changes, including implementation, validation, rollback, peer review, and stakeholder coordination.
  • Ability to communicate directly with client stakeholders, explain technical findings clearly, and operate with limited day‑to‑day supervision.
  • Strong technical documentation, prioritization, analytical, and collaboration skills.
Preferred Qualifications
  • Advanced Palo Alto Networks experience, certifications, or deep operational expertise.
  • Experience migrating firewalls from Fortinet to Palo Alto.
  • Experience with Fortinet SD‑WAN and potential transition planning toward Palo Alto SD‑WAN.
  • Experience standardizing office networks on Cisco Meraki switching and wireless.
  • Experience with Cisco ISE, 802.1X, network access control, or related security initiatives.
  • Experience supporting global clients, acquisitions, carve‑outs, and newly integrated office locations.
  • Previous managed services, consulting, or customer‑facing infrastructure experience.
  • Relevant advanced networking or security certifications are preferred but not required.
Ideal Candidate Profile

The ideal candidate is a firewall‑first engineer who can work independently across Palo Alto and Fortinet platforms and is comfortable owning the full lifecycle of firewall‑related requests, incidents, changes, and remediation. This individual should be equally capable of working through detailed rule and VPN issues, communicating with client stakeholders, documenting the environment, and contributing to broader network modernization decisions. General network architecture and engineering skills remain important, but deep, current, hands‑on firewall expertise is essential for success in this role.

Work Arrangement and Engagement Type
  • Remote role with Central Time Zone availability preferred.
  • Support will be provided primarily through remote access for sites in the United States, Europe, Asia, and Mexico.
  • The role is initially being considered as a contract-to-hire engagement, with potential conversion to a permanent position based on performance and mutual interest.
Interview Focus
  • Hands‑on depth with Palo Alto and Fortinet firewall administration.
  • Panorama experience and centralized firewall management.
  • Firewall permissions, policies, rules, objects, NAT, and whitelisting.
  • Site‑to‑site and client VPN troubleshooting, including GlobalProtect and FortiClient.
  • Practical troubleshooting scenarios involving traffic flow, logs, packet captures, and connectivity.
  • Ability to document changes, communicate with clients, and operate in a mixed‑vendor global environment.
ECI's culture is all about connection - connection with our clients, our technology and most importantly with each other. In addition to working with an amazing team around the world, ECI also offers a competitive compensation package and the range for this role is $125,000 to $135,000 annually (DOE & location), plus variable with flexible PTO, health benefit eligibility the first of the month, life insurance, pet insurance, 401K and so much more!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Security Engineer — Firewall Team
Senior Network Security Engineer — Firewall Team

Compuquip Technologies, LLC • Town of Florida (NY), Northern (KY)

Hybrid
USD 150,000 - 170,000
Health and dental coverage
On-site in South Florida
Network Implementation - Senior Network Engineer, Implementation
Network Implementation - Senior Network Engineer, Implementation

ECI • United States

Hybrid
USD 126,000 - 154,000
Flexible PTO
Health benefits
Life insurance
+2
Remote Senior Firewall Architect (Palo Alto & Fortinet)
Remote Senior Firewall Architect (Palo Alto & Fortinet)

ECI • Dallas (TX), Northern (KY)

Hybrid
USD 125,000 - 135,000
Health benefits
Life insurance
401(k)
+1
Firewall Engineer
Firewall Engineer

Saigepartners • Iowa City (IA)

On-site
USD 90,000 - 150,000
Mid-Level Network Security Engineer - Palo Alto
Mid-Level Network Security Engineer - Palo Alto

Myriad360 • New York (NY)

On-site
USD 140,000 - 150,000
Unlimited PTO
Incentive compensation
401k contributions
+3
Network/ Firewall Engineer
Network/ Firewall Engineer

Peraton • United States

On-site
USD 80,000 - 128,000
Sr. Firewall/Network Security Administrator
Sr. Firewall/Network Security Administrator

Calance • Tallapoosa (GA)

Hybrid
USD 90,000 - 130,000
EPO/PPO Medical Plans
401K Retirement vesting program
Flex Spending Plan
+1
External Job Posting Title Network/ Firewall Engineer
External Job Posting Title Network/ Firewall Engineer

Peraton • Northern (KY)

Hybrid
USD 80,000 - 128,000
Senior Network Engineer
Senior Network Engineer

Tenth Revolution Group • Menlo Park (CA)

On-site
USD 180,000 - 240,000
Principal-level Firewall Engineer
Principal-level Firewall Engineer

Tata Consultancy Services • Phoenix (AZ)

On-site
USD 110,000 - 125,000