Job Summary:
The Senior Network Design & Implementation Engineer is responsible for architecting, designing, deploying and testing end-to-end enterprise network, edge security and SD-WAN solutions centered around the Fortinet Security Fabric. This role requires advanced knowledge and experience in FortiGate Secure SD-WAN with advanced next-generation firewalling (NGFW), zero-trust architecture, and cloud connectivity. This position will also require familiarity with other SD-WAN solutions such as Arista Velocloud and Cisco SD-WAN.
As a senior technical lead, this position converts complex enterprise connectivity and compliance requirements into validated Low-Level Designs (LLDs), automated configuration templates, structured migration cutover plans, and seamless operational handoffs.
Key Responsibilities:
1. Architecture & Low-Level Design (LLD)
· Secure SD-WAN Design: Architect scalable FortiGate Secure SD-WAN topologies across multi-region environments, including Hub-and-Spoke, Full Mesh, and Dynamic Mesh VPN (ADVPN) structures with automated BGP routing.
· SLA & Steering Profiles: Design SD-WAN rules, Performance SLAs, link health monitoring probes, and application control steering policies using Dynamic Application Steering to optimize voice, SaaS, and critical business traffic over diverse underlays (DIA, MPLS, 5G/LTE).
· Fortinet Security Fabric Integration: Build comprehensive edge and core security layouts incorporating FortiGate NGFWs, FortiManager, FortiAnalyzer, FortiSwitch, and FortiAP (FortiLAN Cloud/Fabric extensions).
· Zero Trust & Edge Security: Design and integrate Zero Trust Network Access (ZTNA), FortiSASE, SSL/TLS deep inspection, IPS, Web/URL filtering, and inline malware prevention profiles across local and remote access tiers.
· Underlay & Overlay Integration: Standardize complex BGP (iBGP/eBGP), OSPF, VRF, NAT, and IPsec tunnel architectures integrating SD-WAN overlays with existing enterprise data centers, core switching backbones, and legacy WANs.
· Design Documentation: Develop complete High-Level Designs (HLDs), Low-Level Designs (LLDs), IP/VLAN schemes, network topology diagrams (Visio/Lucidchart/draw.io), and Bill of Materials (BOMs).
2. Staging, Migration, & Hands-On Implementation:
· Deployment Engineering: Configure, stage, and deploy physical and virtual FortiGate appliances utilizing FortiManager for centralized policy management, device mapping, and revision tracking.
· Migration Execution: Author detailed Method of Procedure (MOP) documents, cutover playbooks, rollback strategies, and maintenance window schedules for migrating legacy firewalls and WAN circuits to Fortinet Secure SD-WAN.
· Hybrid & Multi-Cloud Connectivity: Implement secure cloud edge connectivity, deploying virtual FortiGate instances (FortiGate-VM) in Azure using Cloud On-Ramp methodologies and Transit Gateways.
· LAN/WLAN Integration: Configure FortiSwitch and FortiAP deployments using FortiLink to deliver unified, single-pane-of-glass management through FortiGate controllers.
3. Automation & Deployment Standardization:
· Template Standardization: Build and maintain standardized CLI scripts, FortiManager Meta-Fields, Normalized Interfaces, and Jinja2 templates to enable zero-touch provisioning (ZTP) for global site rollouts.
· Infrastructure as Code (IaC): Automate policy pushes, object creation, and compliance checks using Python, Ansible, or Terraform (FortiOS/FortiManager providers).
4. Validation, Operational Handoff, & Escalation:
· Acceptance & Failover Testing: Execute rigorous post-implementation testing (failover validation, link brownout/blackout simulations, throughput benchmarking, and HA cluster state verification).
· Operational Enablement: Author Standard Operating Procedures (SOPs), knowledge-base articles, and operational runbooks; conduct formal training and handoff sessions for Tier-2/3 operations and NOC teams.
· Tier-4 Escalation: Serve as the ultimate technical authority during complex cutovers, critical outage recoveries, and escalated Fortinet TAC engagements.
Required Qualifications & Experience:
Technical Expertise
· Fortinet Ecosystem: 6+ years of hands-on architectural and implementation experience with Fortinet solutions, including FortiGate (FortiOS), FortiManager, FortiAnalyzer, FortiSwitch, FortiAP, and FortiClient.
· Fortinet Secure SD-WAN: Deep expertise in ADVPN, SD-WAN rules, Performance SLAs, BGP over IPsec overlays, and centralized orchestration via FortiManager.
· Routing & Networking Protocols: Expert-level understanding of BGP (path selection, communities, route reflection), OSPF, VRFs, VXLAN, EVPN, IPsec, NAT, IPv6, and QoS models.
· Network Automation: Practical proficiency in scripting and automation using Python, Ansible, Terraform, or REST APIs.
· Arista Velocloud: Familiarity with Arista Velocloud solutions in order to integrate with, and eventually migrate off of the current network based on Velocloud.
Education & Experience:
· Bachelor’s degree in Computer Science, Network Engineering, Information Technology, or equivalent industry experience.
· 8+ years of experience in enterprise network engineering, with a focus on enterprise security design and multi-site WAN transformations to SD-WAN.
Preferred Certifications
· Fortinet: Fortinet Certified Solution Specialist (FCSS) in Network Security or Secure SD-WAN; Fortinet Certified Expert (FCX) / NSE 8 highly valued.
· Industry Certifications: CCIE (Enterprise Infrastructure or Security), CCNP Enterprise/Security, or equivalent expert-level network engineering credentials