Senior Network Firewall Engineer / Architect
ECISenior Network Firewall Engineer / Architect
|
Primary focus: hands-on firewall engineering and operations, representing approximately 90% of the role. |
Position Overview
We are seeking an experienced, hands-on Senior Network Firewall Engineer / Architect to provide dedicated support for a complex, global client network. The role is heavily focused on firewall administration, troubleshooting, security policy management, VPN connectivity, and firewall platform standardization, while also requiring strong enterprise networking fundamentals and architecture-level judgment.
The environment includes a mix of Palo Alto Networks and Fortinet FortiGate firewalls, along with Cisco, Cisco Meraki, Aruba, HP ProCurve, and Ubiquiti networking technologies. The successful candidate will be comfortable taking ownership of day-to-day firewall work, partnering directly with client stakeholders, resolving inherited configuration and security issues, and supporting a longer-term transition toward a more standardized network environment.
Key Responsibilities
- Perform hands-on administration and troubleshooting of Palo Alto Networks and Fortinet FortiGate firewalls.
- Create, review, modify, and troubleshoot firewall security policies, access permissions, rules, objects, and whitelisting requests.
- Manage and troubleshoot site-to-site VPN tunnels and remote-access VPN services, including Palo Alto GlobalProtect and Fortinet FortiClient.
- Use Palo Alto Panorama and Fortinet management tooling to manage devices, configurations, policies, and operational changes across the environment.
- Assess existing firewall configurations for security gaps, inconsistencies, technical debt, and deviations from standards or best practices.
- Support the gradual migration and standardization of firewall platforms, including movement from Fortinet toward Palo Alto where approved and funded.
- Provide dedicated technical support and direct communication for a specific global client while collaborating with ECI network services, implementation, NOC, compliance, and principal engineering teams.
- Support firewall and network integration for newly acquired offices and other merger-and-acquisition activity.
- Plan and execute upgrades, technology refreshes, patching, configuration changes, and remediation activities through established change-management processes.
- Troubleshoot network and application connectivity issues across firewalls, routing, switching, wireless, SD-WAN, circuits, DNS, and adjacent infrastructure.
- Review traffic flows, logs, packet captures, latency, jitter, packet loss, utilization, and application policies to isolate performance or connectivity problems.
- Produce and maintain accurate technical documentation, including network diagrams, firewall standards, rule documentation, implementation plans, validation steps, rollback plans, and client-facing recommendations.
- Help assess inherited client environments, verify how systems are configured, and recommend practical remediation and modernization priorities.
Technical Environment
- Palo Alto Networks firewalls and Panorama
- GlobalProtect remote-access VPN
- Fortinet FortiGate firewalls, FortiClient, Fortinet SD-WAN, and centralized Fortinet management tools
- Firewall policies, permissions, rule bases, objects, NAT, whitelisting, and VPN tunnels
- Cisco routing and switching, including Catalyst and Nexus platforms
- Cisco Meraki switching and wireless
- Cisco ISE and 802.1X initiatives
- Aruba, HP ProCurve, and Ubiquiti networking and wireless technologies
- Enterprise LAN, WAN, wireless, routing, SD-WAN, DNS, and network security
Required Qualifications
- Significant hands-on experience administering and troubleshooting enterprise firewalls in production environments.
- Strong practical experience with Palo Alto Networks firewalls, including policy and rule management, VPN troubleshooting, and Panorama.
- Hands-on experience with Fortinet FortiGate firewalls and related VPN or management technologies.
- Demonstrated ability to manage firewall permissions, security policies, rule bases, whitelisting, objects, and connectivity requirements.
- Experience configuring and troubleshooting site-to-site VPNs and remote-access VPN solutions.
- Strong enterprise networking fundamentals across TCP/IP, routing, switching, VLANs, LAN/WAN, wireless, DNS, and packet flow analysis.
- Ability to troubleshoot complex connectivity and performance issues using logs, packet captures, traffic analysis, device health data, and systematic fault isolation.
- Experience working in mixed-vendor, poorly standardized, or inherited network environments.
- Experience preparing and executing controlled infrastructure changes, including implementation, validation, rollback, peer review, and stakeholder coordination.
- Ability to communicate directly with client stakeholders, explain technical findings clearly, and operate with limited day-to-day supervision.
- Strong technical documentation, prioritization, analytical, and collaboration skills.
Preferred Qualifications
- Advanced Palo Alto Networks experience, certifications, or deep operational expertise.
- Experience migrating firewalls from Fortinet to Palo Alto.
- Experience with Fortinet SD-WAN and potential transition planning toward Palo Alto SD-WAN.
- Experience standardizing office networks on Cisco Meraki switching and wireless.
- Experience with Cisco ISE, 802.1X, network access control, or related security initiatives.
- Experience supporting global clients, acquisitions, carve-outs, and newly integrated office locations.
- Previous managed services, consulting, or customer-facing infrastructure experience.
- Relevant advanced networking or security certifications are preferred but not required.
Ideal Candidate Profile
The ideal candidate is a firewall-first engineer who can work independently across Palo Alto and Fortinet platforms and is comfortable owning the full lifecycle of firewall-related requests, incidents, changes, and remediation. This individual should be equally capable of working through detailed rule and VPN issues, communicating with client stakeholders, documenting the environment, and contributing to broader network modernization decisions. General network architecture and engineering skills remain important, but deep, current, hands-on firewall expertise is essential for success in this role.
Work Arrangement and Engagement Type
- Remote role with Central Time Zone availability preferred.
- Support will be provided primarily through remote access for sites in the United States, Europe, Asia, and Mexico.
- The role is initially being considered as a contract-to-hire engagement, with potential conversion to a permanent position based on performance and mutual interest.
Interview Focus
- Hands-on depth with Palo Alto and Fortinet firewall administration.
- Panorama experience and centralized firewall management.
- Firewall permissions, policies, rules, objects, NAT, and whitelisting.
- Site-to-site and client VPN troubleshooting, including GlobalProtect and FortiClient.
- Practical troubleshooting scenarios involving traffic flow, logs, packet captures, and connectivity.
- Ability to document changes, communicate with clients, and operate in a mixed-vendor global environment.
ECI’s culture is all about connection - connection with our clients, our technology and most importantly with each other. In addition to working with an amazing team around the world, ECI also offers a competitive compensation package and the range for this role is $125,000 to $135,000 annually (DOE & location), plus variable with flexible PTO, health benefit eligibility the first of the month, life insurance, pet insurance, 401K and so much more! If you believe you’d be a great fit and are ready for your best job ever, we’d like to hear from you!!
Love Your Job, Share Your Technology Passion, Create Your Future Here!