🏢 Offshore Consulting Shops

Evolution Cloud Services (EVOCS) is an IT consulting and professional services firm, and this position involves billable work delivering data engineering and analytics solutions to external clients.

This company was flagged and excluded from default search results. Proceed with caution.

EC
Posted 3w ago

Principal Network Security Architect

Evolution Cloud Services (EVOCS)
United States
$120-$150/hrOnsiteFull Time
Responsibilities
  • analyzing configurations
  • designing baseline
  • presenting findings
Requirements
  • 15+ years in network security architecture with Fortinet fleet-scale experience
  • Scripting/API automation
  • Azure networking
  • Client-facing consulting, and ability to produce defendable findings and remediation roadmaps
Technical tools mentioned
FortiGateFortiManagerFortiAnalyzerFortiAuthenticatorFortiOSFortiManager JSON APIAnsibleAzureActive Directory

Job description

EVOCS OVERVIEW

EVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with idealtechnologies to provide them with comprehensive solutions to grow and prosper.

Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.

If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let’s talk!

Why this role exists

We have engineers who can pull configurations, run rule analysis, and gather telemetry across a large firewall estate. What we need is the person who decides what any of it means.

You are the design authority: the one whose judgment the findings rest on, whose name is on the recommended architecture, and who can sit across from a client's own senior network engineers and defend a call under challenge. Hands-on individual contributor with real authority, not a management seat. You work alongside our security leadership, and an independent third-party firm reviews our findings, so you are neither the lone technical voice nor the last line of defense on your own.

The engagement

Network security, architectural and configuration assessment and remediation of 150 FortiGate appliances, for roughly 55 sites across three regions, edge, core, and out-of-band, managed through FortiManager and FortiAnalyzer with FortiAuthenticator and Active Directory behind administrative access, plus a hybrid Azure component.

There are no virtual domains, so every appliance is its own unit of assessment. Any standard you propose has to hold across three regions under data-residency constraints. And the output is not a scan report: it is findings, a hardening baseline, and a remediation roadmap that the client's own architects will read line by line and argue with.

What you will own

  • The judgment calls. Whether a segmentation gap is materially exploitable or theoretical. Whether a permissive rule is a real lateral-movement path or noise. What a finding is actually worth on a severity scale a CISO will act on.
  • Adversary-path analysis. Reason from configuration, rule base, topology, and administrative access to how an attacker would move through a distributed fleet, and where the evidence would show it if they already had.
  • The hardening baseline and remediation roadmap. Specific enough to execute, correct enough that a client architect will agree with it.
  • The golden configuration and governance model. A repeatable configuration standard for the fleet, with rule request, justification, approval, recertification, and decommission running through FortiManager change control.
  • Senior escalation and technical defense. Last technical stop for the delivery team across three regions, counterpart to the independent reviewer, and the person who presents findings to client engineering and security leadership.
  • Quality over the team's output. Direct and review the engineers gathering and analyzing fleet data, including offshore resources. Their work reaches the client through you.

What we are looking for

  • 15+ years in network security engineering and architecture, including meaningful hands-on time as a principal consultant, enterprise architect, or equivalent senior individual contributor.
  • Deep Fortinet at fleet scale: FortiGate design, hardening, and rule-base architecture across estates in the hundreds of devices, with expert FortiManager (template hierarchies, policy packages, global objects, ADOM structure).
  • Rule bases in the tens of thousands of policies, with the hit-count reliability, shadowing, and owner-attribution problems that only appear at that volume.
  • Fluency in what actually breaks on a managed fleet: configuration drift between FortiManager and running config, out-of-sync devices, failed policy package installs mid-batch, and revision-restore rollback inside a change window.
  • Automation against the fleet, not through the GUI: you have scripted against the FortiManager JSON API, or used Ansible or equivalent, to pull state, validate configuration, and detect drift at scale.
  • You can state, from memory, the device count, policy count, and FortiManager ADOM and template structure of the largest estate you have owned.
  • FortiAnalyzer logging architecture, and a clear view of what firewall telemetry can and cannot prove when you are looking for evidence of compromise. You are willing to put the limits of your conclusions in writing to a CISO.
  • Judgment on segmentation and lateral movement: the ability to look at a rule base and a topology and say which exposures are real.
  • Administrative access architecture: FortiAuthenticator with Active Directory, MFA, RBAC, and privileged access design (jump host or PAM) for network infrastructure specifically.
  • Azure networking (VNets, NSGs, routing) and FortiGate virtual appliances in a hybrid estate.
  • Fortinet certification at FCSS in Network Security or NSE 7 level (for example NSE 7 Enterprise Firewall), or equivalent demonstrated FortiOS depth. Fortinet is transitioning its certification naming during 2026, so equivalent current or prior-generation certifications are welcome.
  • Client-facing consulting experience: you have written the report, presented the finding, and defended it in the room.
  • A track record of directing and reviewing the work of junior and offshore engineers. Not optional, and the requirement most candidates at this level are thin on.
  • Writing that holds up: findings and designs that go to a CISO without an editor in between.
  • Based in North America and authorized to work without sponsorship.

What will make you stand out

  • CCIE Security, or Fortinet at FCX or NSE 8 level.
  • CISSP, CISM, or GIAC certifications.
  • Data center, colocation, or critical infrastructure environments.
  • Assessment or audit-driven work where your findings had to survive scrutiny from the client, an auditor, or an independent reviewer.
  • Turning assessment findings into an executable remediation design that someone else then delivered.

Pay Range for jobs in the US.

Pay Range
$120$150 USD

👥 Our Values

We are privileged to serve our loyal customer base in our mission to build lasting relationships with our clients based on trust and mutual success. We strive to deliver exceptional quality and consistency through a white-glove approach. By empowering businesses with tailored solutions and insights, we help them achieve their goals and navigate the ever-evolving tech landscape.

The values we live by:

  • Customer-centric Solutions
  • Innovation & Excellence
  • Integrity & Transparency
  • Data-driven Decision Making

📝 Need to Know

The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Similar jobs

Network Security Architect roles
1w
Save
Mark Applied
Hide
Senior Network Security Engineer
United States
$95k-$146k/yr RemoteFull Time
Zayo Group
Zayo Group: Provides high-capacity fiber networks and communications infrastructure.
7+ YOERequires 7+ years in network security, cybersecurity, or infrastructure engineering; 3+ years with Zscaler; enterprise firewall experience; cloud, Zero Trust, troubleshooting, identity, and automation expertise.
Zscaler, ZIA, ZPA, ZDX, Palo Alto, Cisco, Fortinet, Check Point, Microsoft Entra ID, Azure AD, CyberArk, SailPoint, Python, PowerShell, Shell, CI/CD, Infrastructure as Code, PAC files, IPSec, GRE, DNS, SSL/TLS, VPN
1w
Save
Mark Applied
Hide
Network Security Architect
Washington, District of Columbia, United States
$113k-$257k/yr HybridFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
10+ YOERequires 10+ years in network security, 5+ years designing mission-tailored architectures, TS/SCI clearance, high school diploma or GED, Zero Trust and SAP IT experience, and technical leadership skills.
Zero Trust, SAP
1w
Save
Mark Applied
Hide
Network Security Architect
Washington, District of Columbia, United States
$113k-$257k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
10+ YOE10+ years in network security, 5+ years designing architectures, Zero Trust and SAP IT experience, cybersecurity leadership experience, and TS/SCI clearance. High school diploma or GED required.
Zero Trust, SAP IT
1mo
Save
Mark Applied
Hide
Senior Network Security Architect
Quincy or Princeton or Clifton or Austin
$120k-$203k/yr HybridFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
14+ YOEDesign and govern enterprise network security across on‑premises, cloud, hybrid and third‑party environments; deep network security, cloud networking, and architecture review experience required.
AWS, Azure, Google Cloud Platform, TCP/IP, VPN, IDS/IPS, ZTNA, SASE
1mo
Save
Mark Applied
Hide
Principal Network Security Architect
United States or Canada or Bangalore
OnsiteFull Time
Cerebras Systems
Cerebras SystemsNasdaq: CBRS: Manufactures specialized computer chips designed for AI.
10+ YOE10+ years in enterprise or data center network engineering; expertise in routing/switching, BGP/EVPN/VXLAN, RDMA/InfiniBand, cloud networking (AWS), network automation (Ansible, Terraform), and strong communication skills.
K8s, Ansible, Terraform, AWS, VPCs, Direct Connect, BGP, EVPN, VXLAN, RDMA, RoCE, InfiniBand, CI/CD
1mo
Save
Mark Applied
Hide
Lead Network & Security Architect (Richardson, TX, US)
Richardson, Texas, United States
OnsiteFull Time
Celestica
CelesticaNYSE: CLS: Provides design, manufacturing, and supply chain solutions for electronics.
8+ YOEBachelor's degree and 8+ years in network architecture; expertise securing air-gapped environments, Checkpoint firewalls, Cisco switching, SilverPeak SD-WAN, CyberArk, Zscaler, VMware/Hyper-V, Linux, web repo management, and strong documentation skills.
Checkpoint 3980, Cisco Catalyst 9400/9200, Celestica DS2000, ES1500, SilverPeak SD-WAN, CyberArk vPAM, Zscaler ZTNA, Zscaler App Connectors, VMware vSphere Enterprise, Microsoft Hyper-V, Dell PowerEdge, Rocky, Ubuntu, CentOS, Nginx, Apache, IPAM, CrowdStrike, Threat Locker, Big Fix, ServiceNow, ClearPass NAC
2mo
Save
Mark Applied
Hide
Architect
United States
OnsiteFull Time
Cognizant
CognizantNASDAQ: CTSH: Provides IT consulting and technology services to global enterprises.
SME in Zscaler services and zero-trust design (especially Zscaler Private Access), strong network security background, incident resolution, documentation, and relevant certifications (Zscaler Certified Professional, CCNP Security) preferred.
Zscaler, Zscaler Private Access, PAC (Proxy Auto-Configuration)
2mo
Save
Mark Applied
Hide
Architect
United States
OnsiteFull Time
Cognizant
CognizantNasdaq: CTSH: Provides global information technology and business process outsourcing services.
SME in Zscaler services and zero-trust design, designing and maintaining secure network architectures, resolving incidents, conducting root cause analysis, and documenting decisions; relevant certifications desirable.
Zscaler, Zscaler Private Access