Sr. Security Engineer
Job Description – Network Security Engineer
Role Overview
The Network Security Engineer is responsible for implementing, supporting, and operating enterprise network security platforms, with a primary focus on Fortinet and Zscaler technologies. This role ensures secure connectivity, threat prevention, and policy enforcement across on-premises, cloud, and remote user environments, aligned with Zero Trust security principles.
Key Responsibilities
- Configure, manage, and support Fortinet firewalls (FortiGate), including security policies, NAT, VPNs, and security profiles.
- Support and administer Zscaler platforms (ZIA and/or ZPA) for secure internet and private application access.
- Perform day-to-day operational support and troubleshooting for network security controls.
- Handle L2/L3 incidents related to firewall, VPN, and secure access issues.
- Support Zero Trust Network Access (ZTNA) and secure remote access solutions.
- Monitor and analyze firewall and Zscaler logs to identify security and performance issues.
- Optimize firewall rules and access policies to reduce risk and improve performance.
- Participate in change management, implementation, and maintenance activities.
- Create and maintain network security documentation, SOPs, and runbooks.
- Collaborate with SOC, Cloud, IAM, and Infrastructure teams to support integrated security solutions.
Required Skills & Experience
- 3–5 years of experience in Network Security or Network Engineering roles.
- Hands-on experience with Fortinet technologies (FortiGate, FortiManager, FortiAnalyzer).
- Experience working with Zscaler ZIA and/or ZPA.
- Strong understanding of firewall concepts, routing, switching, and VPN technologies.
- Good knowledge of TCP/IP, DNS, DHCP, and network protocols.
- Experience with network troubleshooting and log analysis.
- Familiarity with ITSM processes such as incident, change, and problem management.
Preferred Qualifications
- Experience working in large enterprise or regulated environments such as healthcare or finance.
- Exposure to cloud networking and security (Azure or AWS).
- Knowledge of Zero Trust, SASE, and modern network security architectures.