Network Security Engineer

Overview

The Network Security Engineer will focus on optimizing and securing a multi-site retailer's Fortinet firewall environment. In this role, the contractor will work directly with a security architect and other network providers to implement segmentation, secure communications between stores and the data center, and enhance firewall governance through FortiManager. This hands-on position requires close collaboration with a third-party network supplier in an MSP-operated setting, aimed at achieving concrete outcomes in network security.

Responsibilities

  • Review and rationalise existing FortiGate policies, removing obsolete rules.
  • Implement segmentation controls and restrict unnecessary east-west traffic.
  • Secure store-to-data-centre communications across the WAN, including site-to-site VPNs.
  • Support the rollout and adoption of FortiManager for improved firewall governance.
  • Validate and test changes using traffic analysis tools like Wireshark.
  • Collaborate with third-party network suppliers to implement necessary changes in an MSP-operated environment.
  • Act on vulnerability management findings to enhance network security.

Requirements

  • Hands-on experience with FortiGate deployment, administration, and policy optimisation, plus FortiManager.
  • Experience in implementing network segmentation with VLANs, ACLs, and security policies.
  • Knowledge of routing, switching, and WAN, including site-to-site and remote-access VPNs.
  • Proficient in network troubleshooting and traffic analysis using tools like Wireshark.
  • Experience with firewall change management and policy lifecycle in MSP-operated environments.
  • Familiarity with Active Directory, Entra ID, and MFA.