About the Role
We are seeking a highly skilled Perimeter Design Engineer to support strategic cybersecurity initiatives through the design, engineering, and governance of enterprise perimeter security solutions.
This role focuses primarily on Fortinet firewall technologies and will be responsible for developing secure, scalable, and resilient designs that support business growth, regulatory requirements, and enterprise security objectives.
The position will support security architecture initiatives including new deployments, infrastructure modernization, network segmentation, data center transformations, and technology lifecycle management. The Perimeter Design Engineer will serve as a technical leader responsible for developing security standards, design patterns, and reference architectures supporting enterprise security services.
You will lead technical design efforts across strategic projects and ongoing security engineering initiatives, translating business and security requirements into detailed designs while ensuring scalability, maintainability, security, and operational efficiency.
What You’ll Do
- Develop High-Level Design (HLD) and Low-Level Design (LLD) documentation for enterprise firewall and security solutions.
- Define architecture standards, engineering guidelines, technical roadmaps, design patterns, and reference architectures for firewall and perimeter security technologies.
- Perform technical assessments to evaluate:
- Business requirements
- Security risks
- Scalability requirements
- Infrastructure dependencies
- Design firewall policies, NAT strategies, VPN connectivity, segmentation solutions, and DMZ architectures.
- Conduct architecture reviews and design validations to ensure alignment with enterprise standards and security policies.
- Collaborate with Security Architecture, Infrastructure, Cloud, Application, Operations, and project teams to deliver secure and scalable solutions.
- Review implementation plans to ensure alignment with approved designs and engineering standards.
- Support technology lifecycle initiatives, including hardware refreshes, software upgrades, platform migrations, and modernization programs.
- Develop and maintain engineering standards, reference architectures, design templates, and operational requirements.
- Evaluate emerging technologies and provide recommendations for future adoption.
- Mentor implementation and operations teams on approved designs and best practices.
- Identify opportunities for automation, process improvement, and operational efficiency across perimeter security platforms.
- Support complex troubleshooting and root-cause analysis as a senior technical resource.
- Maintain knowledge of current technologies and emerging technologies relevant to enterprise security.
Required & Preferred Technical Experience
Fortinet
Strong expertise with Fortinet Security Solutions is central to this role, including:
- FortiGate
- FortiManager
- FortiAnalyzer
- SD-WAN
- High Availability Architectures
- Security Fabric
The ideal candidate should have deep expertise with Fortinet security platforms and extensive experience designing enterprise firewall environments.
Check Point — Nice to Have
Experience with Check Point Firewall technologies is a plus, including:
- Security Gateways
- SmartConsole
- Management Servers
- ClusterXL
- VPN technologies
- NAT
- Policy Design and Optimization
Check Point certifications such as CCSA, CCSE, or CCSM are also nice to have.
Networking & Security
- Strong understanding of enterprise DMZ architectures and perimeter security design principles.
- Strong TCP/IP networking fundamentals.
- Experience with routing protocols such as:
- Experience designing secure segmentation and micro-segmentation solutions.
- Strong understanding of network routing, switching, and load-balancing technologies.
- Knowledge of Zero Trust Architecture principles.
- UNIX/Linux administration experience.
- Proven ability to collaborate across multiple technology teams and manage competing priorities.
Certifications
Fortinet certifications are preferred, including:
Check Point certifications are a nice to have:
Additional Qualifications
- Bachelor’s degree or equivalent work experience.
- Bachelor’s degree or equivalent experience in Cybersecurity, Information Technology, Engineering, or a related discipline.
- At least 3 years of experience with network administration tools, software, operating systems, and hardware components.
- 3–5 years of experience providing OS server administration on Windows, UNIX, or Linux, with significant exposure to internetworking technologies.
- VMware Certification: VCP6+-DCV or VCP6+-CMA.
- Experience with Arista or Arista CVP network environments, as well as Cisco.
- Strong knowledge and experience with BGP, routing, and switching.
- Python and Ansible experience is considered a plus.
- Financial services or other highly regulated industry experience is preferred.
- Strong analytical, organizational, and problem-solving skills.
- Excellent verbal and written communication skills.
- Ability to communicate effectively across all organizational levels.
- Proven ability to lead technical discussions, architecture reviews, and design workshops.
- Ability to assess complex technical requirements and translate them into scalable engineering solutions.
What We’re Looking For
The ideal candidate is a senior network security engineer with strong enterprise firewall design and architecture experience, particularly within Fortinet environments.
You should be comfortable operating at the architecture and engineering level rather than focusing solely on day-to-day firewall administration. This person will be expected to take complex business and security requirements, translate them into scalable technical designs, and work closely with architecture, infrastructure, cloud, application, implementation, and operations teams.
Strong communication and leadership skills are important, as the role involves leading technical discussions, architecture reviews, and design workshops with stakeholders across the organization.