Our history:
From our start in 2009, Conexess has established itself in 3 markets, employing nearly 200+ individuals nationwide. Operating in over 15 states, our client base ranges from Fortune 500/1000 companies to mid-small range companies. For the majority of the mid-small range companies, we are exclusively used due to our outstanding staffing track record
Who We Are:
Conexess is a full-service staffing firm offering contract, contract-to-hire, and direct placements. We have a wide range of recruiting capabilities, from help desk technicians to CIOs. We are also capable of offering project-based work.
Position Summary
We are seeking a Network Engineer to own the design, deployment, and operational health of our LAN, WAN, and metropolitan-area network environments, with deep hands-on expertise across the Fortinet product portfolio. This is an individual contributor role for an engineer who operates with minimal oversight, sets technical direction, and raises the capability of the team around them.
The right candidate is equally comfortable in a maintenance window cutting over a core firewall pair and writing a playbook that makes the next twenty cutovers routine. You will be expected to reduce manual toil through automation, replace reactive break/fix cycles with proactive monitoring and telemetry, and serve as an escalation point and mentor for other engineers.
Key Responsibilities
Network Architecture & Engineering
- Design, implement, and maintain enterprise LAN, WAN, and MAN infrastructure across the enterprise.
- Lead architecture and lifecycle planning for routing, switching, wireless, and edge security platforms, including capacity modeling and refresh roadmaps.
- Own complex network changes end to end: design, peer review, test plan, implementation, validation, and rollback.
- Produce and maintain accurate documentation — physical and logical topologies, IPAM records, circuit inventories, runbooks, and as-built diagrams.
- Partner with security, systems, cloud, and application teams to ensure network design supports business and compliance requirements.
Fortinet Platform Ownership
- Serve as the subject matter expert for the Fortinet Security Fabric across the environment.
- Design, deploy, and operate FortiGate firewalls in HA clusters, VDOMs, and multi-tenant configurations at the data center, campus, and branch edge.
- Manage Fortinet Secure SD-WAN — overlay design, SLA-based path selection, application steering, ADVPN, and zero-touch branch provisioning.
- Centrally administer policy, configuration, and device lifecycle through FortiManager, including policy packages, ADOMs, provisioning templates, and scripted deployments.
- Leverage FortiAnalyzer for logging, correlation, reporting, and long-term retention; build dashboards and reports for operational and audit consumption.
- Deploy and support the broader Fortinet stack as applicable: FortiSwitch, FortiAP, FortiClient/FortiClient EMS, FortiAuthenticator, FortiNAC, FortiSASE, FortiExtender, FortiWeb, FortiMail, and FortiToken.
- Manage firmware lifecycle strategy — release qualification, staged upgrade planning, and coordinated fleet-wide maintenance.
- Own vendor relationships with Fortinet and partner resellers, including TAC escalations, RMA handling, and licensing/entitlement tracking.
Automation & Tooling
- Identify high-toil, high-risk manual workflows and replace them with automation where it delivers real value — pragmatism over automation for its own sake.
- Develop and maintain automation using Python, Ansible, and REST APIs, including the FortiOS and FortiManager JSON-RPC APIs.
- Implement configuration standardization, drift detection, and compliance checking across the device fleet.
- Manage network configuration and automation code in Git with peer review, versioning, and change traceability.
- Build validation and pre/post-change verification tooling to reduce human error during maintenance windows.
- Contribute to infrastructure-as-code practices for network and cloud connectivity where applicable [Terraform, CI/CD pipelines].
Proactive Monitoring & Observability
- Design and mature the network monitoring and observability practice — move the team from reactive ticket response to early detection and trend-based intervention.
- Implement and tune monitoring across SNMP, syslog, streaming telemetry, NetFlow/sFlow/IPFIX, and synthetic transaction testing.
- Build meaningful dashboards, baselines, and alert thresholds that surface real problems and suppress noise; own alert quality as an ongoing responsibility.
- Establish capacity and performance trending for circuits, interfaces, tunnels, firewall throughput, and session tables to drive proactive upgrades.
- Define and report on network SLIs/SLOs and contribute to service availability metrics.
- Lead root cause analysis for major incidents and drive corrective and preventive actions to closure.
Mentorship & Technical Leadership
- Act as a technical escalation point for Tier 1/2 support and infrastructure engineers.
- Mentor teammates through pairing, design reviews, structured knowledge transfer, and lab exercises.
- Develop and maintain internal documentation, standards, and training material that raise the team's baseline competency.
- Contribute to change advisory processes, design standards, and engineering best practices.
- Participate in on-call rotation and after-hours maintenance windows as required.
Required Qualifications
- 7+ years of progressive enterprise network engineering experience, including 3+ years at a senior or lead level.
- Deep, hands-on production experience with FortiGate and FortiOS — policy design, routing, HA, VDOMs, IPsec/SSL VPN, IPS/UTM profiles, and troubleshooting with CLI diagnostics (diagnose debug flow, sniffer, session table analysis).
- Demonstrated production experience with FortiManager and FortiAnalyzer at scale.
- Hands-on experience designing and operating Fortinet Secure SD-WAN in a multi-site environment.
- Significant LAN experience: enterprise campus switching, VLAN architecture, spanning tree, link aggregation, first-hop redundancy, QoS, PoE, 802.1X/NAC, and enterprise wireless.
- Significant WAN experience: BGP and OSPF at scale, IPsec and DMVPN-style overlays, MPLS/VPLS, broadband and LTE/5G failover, carrier circuit provisioning and troubleshooting, and WAN performance optimization.
- Significant MAN experience: metro Ethernet, dark fiber, DWDM/CWDM, point-to-point and ring topologies, and inter-site Layer 2/Layer 3 extension.
- Strong routing and switching fundamentals independent of vendor — TCP/IP, subnetting, route selection, redistribution, packet flow, and structured troubleshooting methodology.
- Practical automation ability: Python and/or Ansible, REST/JSON API consumption, and Git-based workflow.
- Working knowledge of network monitoring platforms and telemetry pipelines [e.g., LibreNMS, SolarWinds, Zabbix, PRTG, Grafana/Prometheus, Elastic, ThousandEyes].
- Proven ability to work independently — to take an ambiguous requirement, scope it, design it, and deliver it without day-to-day direction.
- Excellent written and verbal communication, including the ability to explain technical tradeoffs to non-technical stakeholders.
Preferred Qualifications
- Fortinet certification at the professional level or above — FCP, FCSS (Network Security, Secure Access Service Edge, or Enterprise Firewall), or FCX. Legacy NSE 4–7 equally considered.
- Additional vendor certifications: CCNP/CCIE Enterprise, JNCIP, or equivalent.
- Experience with additional vendor platforms in a mixed environment [Cisco, Arista, Juniper, Palo Alto].
- Cloud networking experience — AWS Transit Gateway, Azure Virtual WAN, FortiGate-VM deployments, and hybrid connectivity via Direct Connect/ExpressRoute.
- Experience with data center fabrics [VXLAN/EVPN, spine-leaf], load balancing, and DDI platforms [Infoblox, BlueCat].
- Exposure to regulated environments and associated controls [PCI-DSS, HIPAA, SOX, NIST CSF, CJIS].
- Experience building or leading a network automation practice from the ground up.
- Prior experience mentoring engineers or leading a small technical team.