Senior Network Engineer (Aruba + Fortinet FortiGate Focus
Listed on 2026-08-14
-
IT/Tech
Network Engineer, Systems Engineer, Cybersecurity, Network Security
Senior Network Engineer
We’re hiring a Senior Network Engineer to lead the design, implementation, and ongoing support of secure, scalable enterprise networks with a strong emphasis on HPE Aruba switching/wireless and Fortinet Forti Gate (WAN/SD-WAN + security).
This is a senior, hands-on role responsible for network architecture, operational excellence, troubleshooting complex incidents, and driving standards across LAN/WAN/WLAN and perimeter/edge security.
Travel:
Up to 50% travel for the first 6 months (site assessments, deployments, cutovers), then reduced travel as the environment stabilizes.
Environment scope: ~50 sites, 4 data centers, ~1,600 staff.
Key ResponsibilitiesOwn end-to-end network delivery: architecture, design, implementation, and support of enterprise LAN/WAN/WLAN and security services across ~45 sites and 2 data centers.
Lead WAN and SD-WAN engineering (Forti Gate-centric):
- Design, deploy, and operate Forti Gate SD-WAN for multi-site connectivity, application steering, SLA monitoring, and resilient failover.
- Engineer and operate BGP over SD-WAN between sites and eBGP with ISPs at data centers, including route policy, filtering, and resiliency.
- Design and operate multi-homed / dual-ISP data center connectivity with resilient routing and failover.
- Standardize branch templates, circuit turn-ups, and cutover runbooks; coordinate with ISPs and on-site resources.
- Build and maintain hub-and-spoke and/or partial mesh VPN topologies as required (IPsec/ADVPN where applicable).
Lead Fortinet security engineering:
- Engineer and administer Forti Gate policies, NAT, segmentation, and security profiles (IPS/AV/web filtering/app control).
- Use Forti Manager (required) to manage policy packages, device groups, templates, and controlled change/release processes across the fleet.
- Implement and operate logging/analytics (e.g., Forti Analyzer nice-to-have) including reporting and incident support.
- Design and maintain HA pairs/clusters, firmware lifecycle, and change control.
Lead Aruba campus switching + wireless:
- Design and operate Aruba switching (VLANs, STP, LACP, VRRP, QoS) and ensure consistent standards across sites.
- Design and optimize Aruba wireless (RF design, AP placement guidance, roaming, guest access, WPA2/3).
- Administer Aruba centralized platforms and NAC:
- Aruba Central and/or Air Wave for monitoring, configuration, and lifecycle management.
- Clear Pass for 802.1X, guest access, profiling, and policy enforcement.
- Execute and operationalize Zero Trust networking principles:
- Implement least-privilege access and segmentation (zones, VLANs/VRFs, policy-based controls) aligned to business/application requirements.
- Support identity-aware access patterns (802.1X/NAC, MFA-integrated remote access, conditional access concepts where applicable).
- Partner with security stakeholders to align network controls with Zero Trust initiatives (device posture signals, logging/telemetry, and continuous verification).
- Deliver secure access and identity-integrated networking:
- Implement 802.1X with RADIUS/TACACS+, certificate-based auth where applicable, and integration patterns with directory/IdP.
- Support remote access VPN solutions (SSL/IPsec) and MFA integration patterns.
- Operate and improve reliability:
- Lead complex incident response and deep troubleshooting across layers (L1–L7), including packet captures and log analysis.
- Perform root cause analysis (RCA) and drive permanent corrective actions.
- Monitor performance, availability, and capacity; tune for resiliency and throughput.
- Documentation and standards:
- Maintain network diagrams (logical/physical), IP plans, firewall rule standards, SD-WAN policies, and operational runbooks.
- Establish configuration baselines, naming conventions, and hange/release procedures.
- Stakeholder and cross-functional collaboration:
- Partner with security, systems, telecom/ISP providers, and application teams to deliver reliable connectivity.
- Provide technical leadership and mentorship to junior engineers; review designs and changes.
- Communicate clearly with technical and non-technical stakeholders; translate business requirements into technical designs.
7+ years of progressive experience in network engineering (enterprise or MSP environments), including multi-site WAN operations.
Strong hands-on expertise with Fortinet Forti Gate, including:
- SD-WAN design/operations, VPN (IPsec/SSL), routing, NAT, security profiles, and segmentation.
- BGP (iBGP/eBGP), route policy, and troubleshooting in multi-site environments.
- Proven experience designing/operating multi-homed / dual-ISP connectivity at data centers.
- Forti Manager (must-have) for centralized configuration and policy management at scale.
Strong hands-on expertise with HPE Aruba in production, including:
- Aruba switching and enterprise WLAN.
- Aruba Central/Air Wave administration.
- Clear Pass (or equivalent NAC) for 802.1X/guest workflows.
- Experience executing Zero Trust concepts in real environments (segmentation, least privilege, identity-aware access, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).