Fortinet SASE and SD-WAN Engineer

India
Full Time
Experienced
Fortinet SASE and SD-WAN Engineer
Zappsec Technologies Inc.
 
About the role
Zappsec designs and operates secure edge platforms for mid-market and enterprise clients. This role owns the Fortinet side of that work.
This role focuses on secure access, which means FortiSASE and Zero Trust Network Access. The other focuses on wide area networking, which means Fortinet Secure SD-WAN. Both sit on FortiOS, FortiManager, and the same routing and IPsec foundation.
This is a hands-on engineering role. You will be in the consoles and the command line every day. You will not coordinate vendors or supervise other people's configuration work.

Certification requirement
Fortinet certification at NSE 5 level or above is mandatory for this role. This is a hard requirement, not a preference.Fortinet has renamed its program twice in recent years, so read this before you rule yourself out.
  • Certifications issued between October 2023 and July 2026 used the FCP, FCSS, and FCX names. FCP covered the NSE 4 to NSE 6 band. FCSS mapped to NSE 7. FCX mapped to NSE 8.
  • Fortinet returned to NSE 1 through NSE 8 numbering in July 2026.
  • If your certification sits at NSE 5 or higher under either naming, you meet the requirement.
What every engineer in this role owns
  • Firewall policy, NAT, security profiles, and virtual domains on FortiGate.
  • IPsec overlay design and troubleshooting, including behaviour under failure.
  • BGP and the routing policy that decides which path traffic takes.
  • FortiManager administration, including administrative domains, policy packages, and templates.
  • Configuration through change control, with a written rollback plan for every window.
  • Troubleshooting with packet captures, FortiOS diagnose commands, and session analysis.
  • Fortinet TAC cases, opened and driven to resolution.
  • High level designs, low level designs, runbooks, and as-built records.
  • Knowledge transfer so the client team can operate what you built.
SASE and secure access
FortiSASE build and policy
  • Stand up and configure FortiSASE tenants, including user groups, endpoint profiles, and security policy.
  • Configure secure internet access for remote users and for thin edge sites terminating on FortiGate.
  • Build secure private access to internal applications through FortiGate hubs using IPsec overlays and BGP.
  • Configure SSL deep inspection, certificate distribution, and the exclusion lists that keep inspection stable.
  • Tune web filtering, DNS filtering, application control, antivirus, intrusion prevention, inline CASB, and data loss prevention profiles.
  • Write SaaS access policy, including tenant restrictions where the client requires them.
ZTNA and endpoint
  • Deploy and manage FortiClient EMS, whether cloud hosted or on premises.
  • Build ZTNA tags and posture rules covering operating system version, endpoint agent status, certificate presence, and domain membership.
  • Configure the ZTNA access proxy on FortiGate, including application gateways, real server mapping, and access rules.
  • Package, deploy, and upgrade FortiClient across Windows, macOS, Linux, iOS, and Android.
Identity and migration
  • Integrate SAML single sign-on with Microsoft Entra ID, Okta, or the client's identity provider.
  • Map identity provider groups to access policy so policy follows the user rather than the device.
  • Move remote users from SSL VPN and IPsec dial-up onto ZTNA and FortiSASE.
  • Convert existing web proxy and filtering policy onto FortiSASE without loss of enforcement.
  • Troubleshoot user experience across the full path: endpoint, point of presence, overlay, hub, and application.
Networking and SD-WAN
SD-WAN design and build
  • Configure SD-WAN zones, members, and interfaces across broadband, MPLS, and cellular underlays.
  • Build performance SLA health checks with realistic latency, jitter, and packet loss targets.
  • Write SD-WAN rules that steer applications using the internet service database, application control, and custom signatures.
  • Select the right steering strategy per application, whether lowest cost SLA, best quality, or maximum bandwidth.
  • Apply forward error correction and per-packet duplication where traffic cannot tolerate loss.
  • Design overlays using ADVPN, which builds on-demand shortcut tunnels between spokes.
  • Build dual hub and multi-region designs with predictable failover behaviour.
Fleet provisioning
  • Build provisioning templates, CLI templates with metadata variables, and SD-WAN templates that survive site variation.
  • Provision new sites through zero touch provisioning and model devices rather than by hand.
  • Plan and execute firmware upgrades across device fleets with a tested back-out path.
  • Build FortiAnalyzer reporting that shows SLA behaviour rather than raw counters.
Branch and cutover
  • Manage FortiSwitch and FortiAP through FortiLink, including VLAN assignment and port policy.
  • Configure wireless networks, guest access, and 802.1X authentication.
  • Build high availability clusters, including FGCP and FGSP where the design calls for it.
  • Migrate sites from MPLS or a third party SD-WAN platform onto Fortinet.
  • Write the site cutover runbook, the rollback steps, and the validation criteria for every window.
Requirements
  • Fortinet certification at NSE 5 level or above, as set out in the certification section.
  • Five or more years in network security or network engineering with production FortiOS experience.
  • Hands-on FortiManager administration, including templates and policy packages.
  • Strong BGP skills. You can explain a path selection outcome from the routing table.
  • Working IPsec knowledge, including phase one and phase two behaviour under failure.
  • Cutover experience with personal responsibility for the rollback decision.
  • Ability to write client-facing documentation that does not need an editor to rewrite it.
  • Comfort working alongside client engineers during change windows.
Tools you will work with
CategoryTools
PlatformFortiGate, FortiOS, FortiGate VM
ManagementFortiManager, FortiAnalyzer
SASE trackFortiSASE, FortiClient, FortiClient EMS, ZTNA access proxy, posture tags
SD-WAN trackPerformance SLA, SD-WAN rules, ADVPN, forward error correction, internet service database
BranchFortiSwitch, FortiAP, FortiLink, FortiExtender
IdentityEntra ID, Okta, SAML, FortiAuthenticator, FortiToken
AnalysisPacket capture, diagnose commands, flow and session analysis

 
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*