Network Security Engineer-L2
SHI Solutions India Pvt. Ltd.
About the Role
We are hiring a Network Security L2 Engineer with strong hands-on expertise in Fortinet or FortiGate firewalls to manage, monitor, and support enterprise-level network security infrastructure. The candidate will play a crucial role in incident handling, firewall configuration, and proactive monitoring, ensuring high availability and security compliance.
Roles & Responsibilities
Incident Management & L2 Support
- Provide Level 2 support for network security issues, incidents, and service requests.
- Act as an escalation point for L1 engineers, ensuring timely resolution within defined SLAs.
- Perform root cause analysis (RCA) for recurring network and firewall-related issues.
- Handle incident prioritization, troubleshooting, and resolution for critical outages.
- Implement, configure, and maintain FortiGate firewall policies, including:
- Access control policies
- NAT and port forwarding rules
- User-based policies
- Configure and troubleshoot:
- IPSec VPN (Site-to-Site)
- SSL VPN (Remote access)
- Manage and fine-tune security profiles such as:
- IPS (Intrusion Prevention)
- Antivirus
- Web Filtering
- Application Control
- Monitor firewall health, logs, and traffic using:
- FortiAnalyzer / FortiManager
- SIEM tools (if applicable)
- Analyze logs for anomalies, threats, and performance issues.
- Ensure high availability and uptime of security devices.
- Perform capacity planning and tuning of firewall resources.
- Execute firewall changes as per change management processes (ITIL).
- Perform firmware upgrades, patching, and maintenance activities.
- Validate changes post-implementation to ensure no service disruption.
- Participate in security audits and vulnerability assessments.
- Identify security gaps and recommend mitigation strategies.
- Ensure firewall rules and configurations align with organizational security policies.
- Maintain detailed documentation of:
- Network diagrams
- Firewall rules
- Incident reports and SOPs
- Generate reports on incidents, performance, and capacity metrics.
- Work closely with:
- Network teams
- Cloud/Infrastructure teams
- SOC and security teams
- Coordinate with Fortinet TAC and vendors for advanced issue resolution.
Job Requirements
Required Technical Skills
Core Skills (Mandatory)
- Strong hands-on experience with:
- Fortinet FortiGate Firewalls
- Expertise in:
- Firewall policy configuration and rule optimization
- NAT, ACLs, and traffic flow analysis
- In-depth knowledge of:
- TCP/IP, OSI Model, Subnetting
- Basic routing concepts (static routes, OSPF/BGP fundamentals)
- Experience in:
- IPSec VPN & SSL VPN configuration and troubleshooting
- IDS/IPS concepts and deployments
- Network traffic analysis and packet capture tools
- FortiManager / FortiAnalyzer (preferred)
- SIEM tools (Splunk, QRadar, etc. – basic exposure)
- Monitoring tools (SolarWinds, PRTG, etc.)
- Fortinet Certifications (NSE4 / NSE5 / NSE6)
- CCNA / CCNP (Security or Routing & Switching)
- Exposure to multi-vendor firewall environments:
- Palo Alto
- Cisco ASA / Firepower
- Check Point
- Strong analytical and troubleshooting skills
- Effective communication and stakeholder management
- Ability to work independently and under pressure
- Proactive approach to problem-solving