Back to jobs
New

Principal Network Security Architect

United States

EVOCS OVERVIEW

EVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with idealtechnologies to provide them with comprehensive solutions to grow and prosper.

Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.

If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let’s talk!

Why this role exists

We have engineers who can pull configurations, run rule analysis, and gather telemetry across a large firewall estate. What we need is the person who decides what any of it means.

You are the design authority: the one whose judgment the findings rest on, whose name is on the recommended architecture, and who can sit across from a client's own senior network engineers and defend a call under challenge. Hands-on individual contributor with real authority, not a management seat. You work alongside our security leadership, and an independent third-party firm reviews our findings, so you are neither the lone technical voice nor the last line of defense on your own.

The engagement

Network security, architectural and configuration assessment and remediation of 150 FortiGate appliances, for roughly 55 sites across three regions, edge, core, and out-of-band, managed through FortiManager and FortiAnalyzer with FortiAuthenticator and Active Directory behind administrative access, plus a hybrid Azure component.

There are no virtual domains, so every appliance is its own unit of assessment. Any standard you propose has to hold across three regions under data-residency constraints. And the output is not a scan report: it is findings, a hardening baseline, and a remediation roadmap that the client's own architects will read line by line and argue with.

What you will own

  • The judgment calls. Whether a segmentation gap is materially exploitable or theoretical. Whether a permissive rule is a real lateral-movement path or noise. What a finding is actually worth on a severity scale a CISO will act on.
  • Adversary-path analysis. Reason from configuration, rule base, topology, and administrative access to how an attacker would move through a distributed fleet, and where the evidence would show it if they already had.
  • The hardening baseline and remediation roadmap. Specific enough to execute, correct enough that a client architect will agree with it.
  • The golden configuration and governance model. A repeatable configuration standard for the fleet, with rule request, justification, approval, recertification, and decommission running through FortiManager change control.
  • Senior escalation and technical defense. Last technical stop for the delivery team across three regions, counterpart to the independent reviewer, and the person who presents findings to client engineering and security leadership.
  • Quality over the team's output. Direct and review the engineers gathering and analyzing fleet data, including offshore resources. Their work reaches the client through you.

What we are looking for

  • 15+ years in network security engineering and architecture, including meaningful hands-on time as a principal consultant, enterprise architect, or equivalent senior individual contributor.
  • Deep Fortinet at fleet scale: FortiGate design, hardening, and rule-base architecture across estates in the hundreds of devices, with expert FortiManager (template hierarchies, policy packages, global objects, ADOM structure).
  • Rule bases in the tens of thousands of policies, with the hit-count reliability, shadowing, and owner-attribution problems that only appear at that volume.
  • Fluency in what actually breaks on a managed fleet: configuration drift between FortiManager and running config, out-of-sync devices, failed policy package installs mid-batch, and revision-restore rollback inside a change window.
  • Automation against the fleet, not through the GUI: you have scripted against the FortiManager JSON API, or used Ansible or equivalent, to pull state, validate configuration, and detect drift at scale.
  • You can state, from memory, the device count, policy count, and FortiManager ADOM and template structure of the largest estate you have owned.
  • FortiAnalyzer logging architecture, and a clear view of what firewall telemetry can and cannot prove when you are looking for evidence of compromise. You are willing to put the limits of your conclusions in writing to a CISO.
  • Judgment on segmentation and lateral movement: the ability to look at a rule base and a topology and say which exposures are real.
  • Administrative access architecture: FortiAuthenticator with Active Directory, MFA, RBAC, and privileged access design (jump host or PAM) for network infrastructure specifically.
  • Azure networking (VNets, NSGs, routing) and FortiGate virtual appliances in a hybrid estate.
  • Fortinet certification at FCSS in Network Security or NSE 7 level (for example NSE 7 Enterprise Firewall), or equivalent demonstrated FortiOS depth. Fortinet is transitioning its certification naming during 2026, so equivalent current or prior-generation certifications are welcome.
  • Client-facing consulting experience: you have written the report, presented the finding, and defended it in the room.
  • A track record of directing and reviewing the work of junior and offshore engineers. Not optional, and the requirement most candidates at this level are thin on.
  • Writing that holds up: findings and designs that go to a CISO without an editor in between.
  • Based in North America and authorized to work without sponsorship.

What will make you stand out

  • CCIE Security, or Fortinet at FCX or NSE 8 level.
  • CISSP, CISM, or GIAC certifications.
  • Data center, colocation, or critical infrastructure environments.
  • Assessment or audit-driven work where your findings had to survive scrutiny from the client, an auditor, or an independent reviewer.
  • Turning assessment findings into an executable remediation design that someone else then delivered.

Pay Range for jobs in the US.

Pay Range

$120 - $150 USD

👥 Our Values

We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.

The values we live by:

  • Customer-centric Solutions
  • Innovation & Excellence
  • Integrity & Transparency
  • Data-driven Decision Making

📝 Need to Know

The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf