Position: FortiGate Firewall Engineer
Location: Toronto, ON (Hybrid)
Employment Type: Full-Time
Experience Required: 8 + Years
Job Summary:
We’re hiring a FortiGate Firewall Engineer with deep expertise in Fortinet’s security stack and strong hands-on experience across Azure/AWS/OCI cloud networking. You’ll design, deploy, and operate enterprise-grade firewall and SD-WAN solutions in hybrid cloud environments.
Key Responsibilities:
- Configure and manage FortiGate (FortiOS) security policies, NAT, user authentication, and SSL/IPSec VPNs at scale.
- Implement advanced security features: IPS rule creation, application control, web filtering, and SSL inspection.
- Operate FortiManager and FortiAnalyzer for centralized policy management, logging, reporting, and compliance.
- Design and support Fortinet SD-WAN and VPN hub architectures with HA/DR.
- Deploy and manage FortiGate-VM in Azure/AWS/OCI, including VNet/VPC design, peering, UDRs, and integration with ExpressRoute/Direct Connect/Fast Connect.
- Configure and troubleshoot BGP, OSPF, and static routing in hybrid cloud architectures; work with Azure LB, Route Server, DNS, and route tables.
- Collaborate with ISP backbone teams for end-to-end troubleshooting across the OSI stack.
- Drive automation using Terraform, Bicep, Python, and PowerShell for IaC and repeatable deployments.
- Align solutions with NIST/CIS security standards and maintain clear design/operational documentation.
Required Skills:
- 6–8 years total experience; 4+ years hands-on with latest Fortinet tools/software.
- Deep FortiOS expertise; strong grasp of routing, VPNs, and NGFW features.
- Proven experience with FortiGate-VM in public cloud (Azure/AWS/OCI) and advanced networking services.
- Solid automation skills (Terraform/Bicep/Python/PowerShell).
- Excellent troubleshooting, communication, and documentation skills.
- Certifications (preferred): Fortinet NSE 4 / FCP, NSE 6/7 / FCSS; Azure AZ-104 or AWS ANS-C01