Lead Network Security Engineer - Palo Alto & Fortinet
Indexed description
About Rozmith:
- Rozmith is a managed IT services and cybersecurity provider that helps organizations run, secure, and scale their technology with confidence. From core managed services to advanced security and compliance programs, our clients rely on us as an extension of their own teams. That trust is earned through consistent, high-quality service delivery - and that's where you come in.
About the Role:
- Rozmith is seeking a Lead Network Security Engineer with deep, hands-on expertise across both Palo Alto Networks and Fortinet platforms. You will set the technical direction for our firewall and network security practice, lead the design and delivery of complex multi-vendor security architectures for our clients, and serve as the final technical escalation point for the engineering team.
- This is a senior, player-coach role. You will still spend significant time in the platforms - architecting, migrating, and troubleshooting - while also mentoring engineers, defining standards, reviewing designs, and representing engineering in front of clients and prospects. You should be the person others turn to when a firewall problem has stumped everyone else.
What You'll Do:
- Own the technical strategy and standards for Rozmith's firewall and network security practice across Palo Alto Networks and Fortinet platforms.
- Architect and lead complex deployments: PAN-OS next-generation firewalls with Panorama, FortiGate estates with FortiManager/FortiAnalyzer, HA clusters, SD-WAN, and multi-site, multi-tenant topologies.
- Lead cross-vendor migration projects - Palo Alto to Fortinet, Fortinet to Palo Alto, and legacy platforms to either - including policy conversation, cutover planning, rollback strategy, and post-migration validation.
- Design and standardize advanced security capabilities: App-ID/SSL decryption and Threat Prevention on Palo Alto; IPS, web filtering, application control, and SSL inspection on FortiOS; and consistent security policy models across both.
- Serve as the tier-3/final escalation point for critical incidents, leading root-cause analysis with packet captures, flow traces, and vendor TAC engagement on both platforms.
- Mentor and develop mid-level and junior engineers through design reviews, shadowing, runbook development, and structured certification paths.
- Establish and enforce engineering standards: configuration baselines, hardening guides, change management discipline, and documentation quality.
- Lead firewall policy audits, security posture assessments, and rule-base cleanup and optimization engagements for clients.
- Partner with sales and account teams on solution design, scoping, effort estimation, and technical presentations for new and existing clients.
- Evaluate new platform capabilities (SASE, cloud-delivered security, automation) and drive adoption where they benefit clients and the practice.
- Drive automation of repeatable work - config generation, compliance checks, reporting - using APIs and scripting across both vendors' ecosystems.
- Participate in and help coordinate the escalation on-call rotation.
What You'll Bring:
- 8+ years of network/security engineering experience, including 4+ years of hands-on production experience with BOTH Palo Alto Networks (PAN-OS, Panorama) and Fortinet (FortiGate, FortiManager, FortiAnalyzer) platforms.
- Proven experience leading complex firewall deployments and cross-vendor migrations from design through cutover in production environments.
- Expert-level understanding of Palo Alto capabilities: App-ID, User-ID, Content-ID, Threat Prevention, GlobalProtect, SSL decryption, and Panorama template/device-group architecture.
- Expert-level understanding of FortiOS: policy and NAT design, security profiles, SD-WAN, FGCP high availability, VDOMs, and Security Fabric integration.
- Deep networking fundamentals: TCP/IP, VLANs, OSPF, BGP, IPsec/SSL VPN design, QoS, and multi-site WAN architecture.
- Strong incident leadership skills - calm under pressure, methodical in root-cause analysis, and effective coordinating vendors, clients, and internal teams.
- Demonstrated experience mentoring engineers and raising technical bar of a team.
- Excellent client-facing communication - able to present architectures and defend recommendations to both technical staff and executives.
- Current PCNSE (Palo Alto Networks Certified Network Security Engineer) and Fortinet FCP in Network Security (or legacy NSE 4+) - or one of the two with the ability to obtain the other within 6 months of hire.
Nice to Have:
- Fortinet FCSS/FCX (or legacy NSE 7/8) and/or Palo Alto PCNSC or PCSAE certifications.
- Experience in an MSP/MSSP environment leading engineering delivery across many concurrent client environments.
- Hands-on experience with SASE offerings: Prisma Access / Prisma SD-WAN and FortiSASE.
- Cloud network security experience: VM-Series and FortiGate-VM in AWS and Azure, cloud-native firewalling, and hybrid connectivity.
- Network automation at scale: Python, Ansible, Terraform, and the PAN-OS XML/REST and FortiOS REST APIs.
- Familiarity with adjacent stacks (Cisco, Check Point, Zscaler) and SIEM/SOAR integration.
- Experience supporting compliance-driven environments (PCI DSS, HIPAA, CMMC, SOC 2) and contributing to audits.
- Prior formal or informal team-lead experience: work planning, delivery oversight, or performance input.
Why Rozmith:
- Shape the direction of a growing security practice - your standards and designs become how we deliver.
- A team that invests in growth: paid certification exams, lab environments, and dedicated training time.
- A diverse portfolio of client environments and genuinely challenging multi-vendor engineering problems.
- A collaborative culture where senior engineers have a direct voice in strategy, tooling, and hiring.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search