Sr. Network Engineer - Fortinet

Conexess Group

United States

On-site

USD 120,000 - 180,000

Full time

10 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Conexess Group is seeking a Network Engineer to own the design, deployment, and operational health of our LAN, WAN, and MAN environments, with deep hands-on Fortinet expertise. This individual will operate with minimal oversight, set technical direction, and raise the team’s capabilities through mentoring and collaboration.

The right candidate will reduce manual toil through automation, implement proactive monitoring, and serve as an escalation point for other engineers, bringing 7+ years of

Qualifications

  • 7+ years enterprise network engineering experience.
  • 3+ years at a senior or lead level.
  • Hands-on FortiGate/FortiOS expertise.
  • Experience with FortiManager/FortiAnalyzer at scale.
  • Automation with Python/Ansible and REST APIs.
  • Strong routing/switching fundamentals.

Responsibilities

  • Design, implement, and maintain enterprise LAN, WAN, and MAN infrastructure.
  • Lead architecture and lifecycle planning for routing, switching, wireless, and security platforms.
  • Own complex network changes end to end: design, peer review, test plan, implementation, validation, rollback.
  • Produce and maintain topology docs, IPAM records, runbooks, and diagrams.
  • Partner with security, systems, cloud, and apps teams to meet business/compliance needs.

Skills

Fortinet FortiGate
FortiOS
Networking
LAN/WAN
Automation
Python/Ansible
REST APIs
Monitoring
Documentation
Leadership

Tools

FortiManager
FortiAnalyzer
LibreNMS
SolarWinds
Zabbix
Grafana
Prometheus
Elastic

Job description

From our start in 2009, Conexess has established itself in 3 markets, employing nearly 200+ individuals nationwide. Operating in over 15 states, our client base ranges from Fortune 500/1000 companies to mid-small range companies. For the majority of the mid-small range companies, we are exclusively used due to our outstanding staffing track record

Who We Are:

Conexess is a full-service staffing firm offering contract, contract-to-hire, and direct placements. We have a wide range of recruiting capabilities, from help desk technicians to CIOs. We are also capable of offering project-based work.

Position Summary

We are seeking a Network Engineer to own the design, deployment, and operational health of our LAN, WAN, and metropolitan-area network environments, with deep hands‑on expertise across the Fortinet product portfolio. This is an individual contributor role for an engineer who operates with minimal oversight, sets technical direction, and raises the capability of the team around them.

The right candidate is equally comfortable in a maintenance window cutting over a core firewall pair and writing a playbook that makes the next twenty cutovers routine. You will be expected to reduce manual toil through automation, replace reactive break/fix cycles with proactive monitoring and telemetry, and serve as an escalation point and mentor for other engineers.

Key Responsibilities:
Network Architecture & Engineering
  • Design, implement, and maintain enterprise LAN, WAN, and MAN infrastructure across the enterprise.
  • Lead architecture and lifecycle planning for routing, switching, wireless, and edge security platforms, including capacity modeling and refresh roadmaps.
  • Own complex network changes end to end: design, peer review, test plan, implementation, validation, and rollback.
  • Produce and maintain accurate documentation — physical and logical topologies, IPAM records, circuit inventories, runbooks, and as-built diagrams.
  • Partner with security, systems, cloud, and application teams to ensure network design supports business and compliance requirements.
Fortinet Platform Ownership
  • Serve as the subject matter expert for the Fortinet Security Fabric across the environment.
  • Design, deploy, and operate FortiGate firewalls in HA clusters, VDOMs, and multi-tenant configurations at the data center, campus, and branch edge.
  • Manage Fortinet Secure SD-WAN — overlay design, SLA-based path selection, application steering, ADVPN, and zero‑touch branch provisioning.
  • Centrally administer policy, configuration, and device lifecycle through FortiManager, including policy packages, ADOMs, provisioning templates, and scripted deployments.
  • Leverage FortiAnalyzer for logging, correlation, reporting, and long-term retention; build dashboards and reports for operational and audit consumption.
  • Deploy and support the broader Fortinet stack as applicable: FortiSwitch, FortiAP, FortiClient/FortiClient EMS, FortiAuthenticator, FortiNAC, FortiSASE, FortiExtender, FortiWeb, FortiMail, and FortiToken.
  • Manage firmware lifecycle strategy — release qualification, staged upgrade planning, and coordinated fleet‑wide maintenance.
  • Own vendor relationships with Fortinet and partner resellers, including TAC escalations, RMA handling, and licensing/entitlement tracking.
Automation & Tooling
  • Identify high‑toil, high‑risk manual workflows and replace them with automation where it delivers real value — pragmatism over automation for its own sake.
  • Develop and maintain automation using Python, Ansible, and REST APIs, including the FortiOS and FortiManager JSON‑RPC APIs.
  • Implement configuration standardization, drift detection, and compliance checking across the device fleet.
  • Manage network configuration and automation code in Git with peer review, versioning, and change traceability.
  • Build validation and pre/post‑change verification tooling to reduce human error during maintenance windows.
  • Contribute to infrastructure‑as‑code practices for network and cloud connectivity where applicable [Terraform, CI/CD pipelines].
Proactive Monitoring & Observability
  • Design and mature the network monitoring and observability practice — move the team from reactive ticket response to early detection and trend‑based intervention.
  • Implement and tune monitoring across SNMP, syslog, streaming telemetry, NetFlow/sFlow/IPFIX, and synthetic transaction testing.
  • Build meaningful dashboards, baselines, and alert thresholds that surface real problems and suppress noise; own alert quality as an ongoing responsibility.
  • Establish capacity and performance trending for circuits, interfaces, tunnels, firewall throughput, and session tables to drive proactive upgrades.
  • Define and report on network SLIs/SLOs and contribute to service availability metrics.
  • Lead root cause analysis for major incidents and drive corrective and preventive actions to closure.
Mentorship & Technical Leadership
  • Act as a technical escalation point for Tier 1/2 support and infrastructure engineers.
  • Mentor teammates through pairing, design reviews, structured knowledge transfer, and lab exercises.
  • Develop and maintain internal documentation, standards, and training material that raise the team's baseline competency.
  • Contribute to change advisory processes, design standards, and engineering best practices.
  • Participate in on‑call rotation and after‑hours maintenance windows as required.
Required Qualifications
  • 7+ years of progressive enterprise network engineering experience, including 3+ years at a senior or lead level.
  • Deep, hands‑on production experience with FortiGate and FortiOS — policy design, routing, HA, VDOMs, IPsec/SSL VPN, IPS/UTM profiles, and troubleshooting with CLI diagnostics (diagnose debug flow, sniffer, session table analysis).
  • Demonstrated production experience with FortiManager and FortiAnalyzer at scale.
  • Hands‑on experience designing and operating Fortinet Secure SD‑WAN in a multi‑site environment.
  • Significant LAN experience: enterprise campus switching, VLAN architecture, spanning tree, link aggregation, first‑hop redundancy, QoS, PoE, 802.1X/NAC, and enterprise wireless.
  • Significant WAN experience: BGP and OSPF at scale, IPsec and DMVPN‑style overlays, MPLS/VPLS, broadband and LTE/5G failover, carrier circuit provisioning and troubleshooting, and WAN performance optimization.
  • Significant MAN experience: metro Ethernet, dark fiber, DWDM/CWDM, point‑to‑point and ring topologies, and inter‑site Layer 2/Layer 3 extension.
  • Strong routing and switching fundamentals independent of vendor — TCP/IP, subnetting, route selection, redistribution, packet flow, and structured troubleshooting methodology.
  • Practical automation ability: Python and/or Ansible, REST/JSON API consumption, and Git‑based workflow.
  • Working knowledge of network monitoring platforms and telemetry pipelines [e.g., LibreNMS, SolarWinds, Zabbix, PRTG, Grafana/Prometheus, Elastic, ThousandEyes].
  • Proven ability to work independently — to take an ambiguous requirement, scope it, design it, and deliver it without day‑to‑day direction.
  • Excellent written and verbal communication, including the ability to explain technical tradeoffs to non‑technical stakeholders.
Preferred Qualifications
  • Fortinet certification at the professional level or above — FCP, FCSS (Network Security, Secure Access Service Edge, or Enterprise Firewall), or FCX. Legacy NSE 4‑7 equally considered.
  • Additional vendor certifications: CCNP/CCIE Enterprise, JNCIP, or equivalent.
  • Experience with additional vendor platforms in a mixed environment [Cisco, Arista, Juniper, Palo Alto].
  • Cloud networking experience — AWS Transit Gateway, Azure Virtual WAN, FortiGate‑VM deployments, and hybrid connectivity via Direct Connect/ExpressRoute.
  • Experience with data center fabrics [VXLAN/EVPN, spine‑leaf], load balancing, and DDI platforms [Infoblox, BlueCat].
  • Exposure to regulated environments and associated controls [PCI‑DSS, HIPAA, SOX, NIST CSF, CJIS].
  • Experience building or leading a network automation practice from the ground up.
  • Prior experience mentoring engineers or leading a small technical team.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Architect (remote)
Network Architect (remote)

Fervo • Georgia

Remote
USD 140,000 - 180,000
Network Architect
Network Architect

Fervo Energy • Houston (TX)

On-site
USD 130,000 - 190,000
Network Architect
Network Architect

Stanford Climate Ventures • Houston (TX)

On-site
USD 120,000 - 170,000
Fortinet Network Engineer at MetroSys Long Beach, CA
Fortinet Network Engineer at MetroSys Long Beach, CA

kozmetickesluzby.vecnakraska.sk - Jobboard • Long Beach (CA)

On-site
USD 80,000 - 120,000
Senior Network Engineer
Senior Network Engineer

Teal Drones • Salt Lake City (UT)

On-site
USD 120,000 - 180,000
Director, Network Engineering & Operations
Director, Network Engineering & Operations

PlanIT Group • Northern (KY)

Hybrid
USD 180,000 - 260,000
Fortinet Network Engineer
Fortinet Network Engineer

KCI Telecommunications • Town of Charlotte (NY)

On-site
USD 55,000 - 80,000
401(k)
Health insurance
Dental and vision
+1
Network Engineer
Network Engineer

Kinect • Philadelphia

On-site
USD 90,000 - 130,000
Systems Engineer
Systems Engineer

Fortinet, Inc. • San Juan (PR)

On-site
USD 80,000 - 120,000
Network Engineer
Network Engineer

Zoomcar • Sunnyvale (CA)

On-site
USD 89,000 - 140,000
Medical insurance
Dental insurance
Vision insurance
+5