Overview
The Network Security Engineer will focus on optimizing and securing a multi-site retailer's Fortinet firewall environment. In this role, the contractor will work directly with a security architect and other network providers to implement segmentation, secure communications between stores and the data center, and enhance firewall governance through FortiManager. This hands-on position requires close collaboration with a third-party network supplier in an MSP-operated setting, aimed at achieving concrete outcomes in network security.
Responsibilities
- Review and rationalise existing FortiGate policies, removing obsolete rules.
- Implement segmentation controls and restrict unnecessary east-west traffic.
- Secure store-to-data-centre communications across the WAN, including site-to-site VPNs.
- Support the rollout and adoption of FortiManager for improved firewall governance.
- Validate and test changes using traffic analysis tools like Wireshark.
- Collaborate with third-party network suppliers to implement necessary changes in an MSP-operated environment.
- Act on vulnerability management findings to enhance network security.
Requirements
- Hands-on experience with FortiGate deployment, administration, and policy optimisation, plus FortiManager.
- Experience in implementing network segmentation with VLANs, ACLs, and security policies.
- Knowledge of routing, switching, and WAN, including site-to-site and remote-access VPNs.
- Proficient in network troubleshooting and traffic analysis using tools like Wireshark.
- Experience with firewall change management and policy lifecycle in MSP-operated environments.
- Familiarity with Active Directory, Entra ID, and MFA.