Senior Firewall / Security Network Engineer
8x8 connects our customers and teams globally, empowering CX leaders with performance and insights to make smarter decisions, delight customers, and drive lasting business impact.
We're hiring a Senior Firewall / Security Network Engineer to own the design, delivery, and operation of our firewall and network-security estate across on-prem data centers and cloud (AWS, OCI). This is a hands-on senior role: you'll set the firewall architecture — especially for hybrid and cloud connectivity — while running the day-to-day change and incident work that keeps the business connected and secure. You'll be the technical anchor as we migrate a multi-vendor estate onto a standardized FortiGate platform and build the cloud security layer our AWS migration depends on.
What you'll do
Cloud & hybrid firewall architecture
-
Design and deliver the firewall/security layer for cloud and hybrid connectivity — AWS (Transit Gateway, VPC, GWLB), OCI, and on-prem↔cloud traffic flows.
-
Own route/prefix and policy design across the boundary so cloud workloads reach on-prem services (and vice versa) securely and without becoming snowflakes.
-
Partner with the security operations, cloud and platform teams to make the security design a first-class part of migration planning, not an afterthought.
Firewall policy engineering & change management
-
Translate connectivity requests from application, database, and cloud teams into clean, standards-based firewall policy (allow/NAT/port/service rules, TLS flows).
-
Drive changes through the RP change-management process — with clear implementation, testing, and rollback plans — and peer-review others' changes.
-
Keep policy consistent and auditable across sites; retire one-off exceptions. Migration & platform lifecycle
-
Lead migrations from legacy Cisco and Juniper to FortiGate , including policy review, rebuild, and cutover.
-
Plan and execute quarterly firewall software upgrades and hardware refreshes with minimal disruption.
-
Manage IPsec/site-to-site migrations and firewall decommissioning.
Operations, incident response & availability
-
Triage and resolve connectivity incidents — blocked/dropped traffic, TLS handshake failures, VPN outages, firewall failovers.
-
Own the out-of-band (OOB) management network for firewalls: reachability, console access, and monitoring enablement.
Observability, logging & compliance
-
Integrate firewalls with logging and monitoring — FortiAnalyzer, SIEM log forwarding, netflow, SNMP.
-
Help close misconfiguration and risk findings
Required qualifications
-
Hands-on FortiGate / FortiOS expertise: VDOMs, security policy, NAT, SSL inspection, FortiAnalyzer, and FortiConverter.
-
Cloud network security: firewall/connectivity design in AWS (TGW, VPC, GWLB) and/or OCI, including hybrid on-prem↔cloud flows..
-
Disciplined change management: implementation, testing, and rollback planning, plus peer review.
-
Strong connectivity troubleshooting across the packet path (drops, TLS, DNS, routing).
-
Ability to work directly with application, database, cloud, and security teams to turn requirements into secure, standardized policy.
Preferred / nice-to-have
-
Experience using AI services/assistants in an engineering workflow — AI-assisted troubleshooting, config generation, or building tooling and automation around network/security systems (e.g. API-driven agents, MCP servers)
-
Network automation — Ansible, AWX, or similar — for config and policy management.
-
SIEM / observability tooling (FortiAnalyzer, netflow, SNMP, log pipelines).
-
Multi-site WAN and data-center networking experience.
-
Scripting (Python or similar) for tooling and validation.
-
Exposure to security frameworks and audit/misconfiguration remediation.
How the role works
-
High cross-functional surface: application/DB/cloud teams (connectivity requests), SecOps and the broader security org (risk sign-off, shared initiatives), and site/infra teams (builds and m
Get remote hardware engineer jobs like this by email
One weekly digest. No spam, unsubscribe anytime.