Skip to content

Open nowPosted 17 days ago

Senior Network Firewall Engineer / Architect

ECI63 open roles

Where
Dallas, TX, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Network Firewall Engineer / ArchitectECI · Dallas, TX, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on ECI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 17 days ago

The posting

Senior Network Firewall Engineer / Architect

Primary focus: hands-on firewall engineering and operations, representing approximately 90% of the role.

Position Overview We are seeking an experienced, hands-on Senior Network Firewall Engineer / Architect to provide dedicated support for a complex, global client network. The role is heavily focused on firewall administration, troubleshooting, security policy management, VPN connectivity, and firewall platform standardization, while also requiring strong enterprise networking fundamentals and architecture-level judgment. The environment includes a mix of Palo Alto Networks and Fortinet FortiGate firewalls, along with Cisco, Cisco Meraki, Aruba, HP ProCurve, and Ubiquiti networking technologies. The successful candidate will be comfortable taking ownership of day-to-day firewall work, partnering directly with client stakeholders, resolving inherited configuration and security issues, and supporting a longer-term transition toward a more standardized network environment. Key Responsibilities

Perform hands-on administration and troubleshooting of Palo Alto Networks and Fortinet FortiGate firewalls. Create, review, modify, and troubleshoot firewall security policies, access permissions, rules, objects, and whitelisting requests. Manage and troubleshoot site-to-site VPN tunnels and remote-access VPN services, including Palo Alto GlobalProtect and Fortinet FortiClient. Use Palo Alto Panorama and Fortinet management tooling to manage devices, configurations, policies, and operational changes across the environment. Assess existing firewall configurations for security gaps, inconsistencies, technical debt, and deviations from standards or best practices. Support the gradual migration and standardization of firewall platforms, including movement from Fortinet toward Palo Alto where approved and funded. Provide dedicated technical support and direct communication for a specific global client while collaborating with ECI network services, implementation, NOC, compliance, and principal engineering teams. Support firewall and network integration for newly acquired offices and other merger-and-acquisition activity. Plan and execute upgrades, technology refreshes, patching, configuration changes, and remediation activities through established change-management processes. Troubleshoot network and application connectivity issues across firewalls, routing, switching, wireless, SD-WAN, circuits, DNS, and adjacent infrastructure. Review traffic flows, logs, packet captures, latency, jitter, packet loss, utilization, and application policies to isolate performance or connectivity problems. Produce and maintain accurate technical documentation, including network diagrams, firewall standards, rule documentation, implementation plans, validation steps, rollback plans, and client-facing recommendations. Help assess inherited client environments, verify how systems are configured, and recommend practical remediation and modernization priorities.

Technical Environment

Palo Alto Networks firewalls and Panorama GlobalProtect remote-access VPN Fortinet FortiGate firewalls, FortiClient, Fortinet SD-WAN, and centralized Fortinet management tools Firewall policies, permissions, rule bases, objects, NAT, whitelisting, and VPN tunnels Cisco routing and switching, including Catalyst and Nexus platforms Cisco Meraki switching and wireless Cisco ISE and 802.1X initiatives Aruba, HP ProCurve, and Ubiquiti networking and wireless technologies Enterprise LAN, WAN, wireless, routing, SD-WAN, DNS, and network security

Required Qualifications

Significant hands-on experience administering and troubleshooting enterprise firewalls in production environments. Strong practical experience with Palo Alto Networks firewalls, including policy and rule management, VPN troubleshooting, and Panorama. Hands-on experience with Fortinet FortiGate firewalls and related VPN or management technologies. Demonstrated ability to manage firewall permissions, security policies, rule bases, whitelisting, objects, and connectivity requirements. Experience configuring and troubleshooting site-to-site VPNs and remote-access VPN solutions. Strong enterprise networking fundamentals across TCP/IP, routing, switching, VLANs, LAN/WAN, wireless, DNS, and packet flow analysis. Ability to troubleshoot complex connectivity and performance issues using logs, packet captures, traffic analysis, device health data, and systematic fault isolation. Experience working in mixed-vendor, poorly standardized, or inherited network environments. Experience preparing and executing controlled infrastructure changes, including implementation, validation, rollback, peer review, and stakeholder coordination. Ability to communicate directly with client stakeholders, explain technical findings clearly, and operate with limited day-to-day supervision. Strong technical documentation, prioritization, analytical, and collaboration skills.

Preferred Qualifications

Advanced Palo Alto Networks experience, certifications, or deep operational expertise. Experience migrating firewalls from Fortinet to Palo Alto. Experience with Fortinet SD-WAN and potential transition planning toward Palo Alto SD-WAN. Experience standardizing office networks on Cisco Meraki switching and wireless. Experience with Cisco ISE, 802.1X, network access control, or related security initiatives. Experience supporting global clients, acquisitions, carve-outs, and newly integrated office locations. Previous managed services, consulting, or customer-facing infrastructure experience. Relevant advanced networking or security certifications are preferred but not required.

Ideal Candidate Profile The ideal candidate is a firewall-first engineer who can work independently across Palo Alto and Fortinet platforms and is comfortable owning the full lifecycle of firewall-related requests, incidents, changes, and remediation. This individual should be equally capable of working through detailed rule and VPN issues, communicating with client stakeholders, documenting the environment, and contributing to broader network modernization decisions. General network architecture and engineering skills remain important, but deep, current, hands-on firewall expertise is essential for success in this role. Work Arrangement and Engagement Type

Remote role with Central Time Zone availability preferred. Support will be provided primarily through remote access for sites in the United States, Europe, Asia, and Mexico. The role is initially being considered as a contract-to-hire engagement, with potential conversion to a permanent position based on performance and mutual interest.

Interview Focus

Hands-on depth with Palo Alto and Fortinet firewall administration. Panorama experience and centralized firewall management. Firewall permissions, policies, rules, objects, NAT, and whitelisting. Site-to-site and client VPN troubleshooting, including GlobalProtect and FortiClient. Practical troubleshooting scenarios involving traffic flow, logs, packet captures, and connectivity. Ability to document changes, communicate with clients, and operate in a mixed-vendor global environment.

ECI’s culture is all about connection - connection with our clients, our technology and most importantly with each other.  In addition to working with an amazing team around the world, ECI also offers a competitive compensation package and the range for this role is $125,000 to $135,000 annually (DOE & location), plus variable with flexible PTO, health benefit eligibility the first of the month, life insurance, pet insurance, 401K and so much more!  If you believe you’d be a great fit and are ready for your best job ever, we’d like to hear from you!! Love Your Job, Share Your Technology Passion, Create Your Future Here!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against ECI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on ECI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    ECI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.