Firewall Engineer

🗓️ Posted 2026-09-18 Sydney NSW Contract Hybrid ICT

Company shared salary

NA

Market rate

A$7,500–A$10,500/mo (A$90,000–A$126,000/yr)

Based on similar roles (title + domain + location).

About the Company

Firewall Engineer 6 Months (High chance of extensions) Sydney OR Melbourne 1,000 p/d

Responsibilities

  • Leading the technical design and delivery of the SRX to FortiGate migration across core, edge and branch sites, including HA pairs and segmented zones
  • Converting and improving existing Juniper policies, NAT rules, VPNs and routing configs into clean, optimised FortiGate equivalents
  • Cleaning up the rule base as you go, removing shadowed, unused or overly permissive rules
  • Redesigning and testing site to site and remote access VPNs (IPsec and SSL) with minimal disruption to users
  • Writing detailed cutover runbooks, rollback plans and validation test cases for every migration window
  • Coordinating cutovers with network, application and business teams in a formal change managed setting
  • Standing up FortiManager and FortiAnalyzer for centralised policy control, logging and reporting
  • Working with SOC, SIEM and vulnerability management teams to keep detection and alerting coverage intact through the transition
  • Integrating with existing routing, SD WAN, load balancing and identity systems (RADIUS, LDAP, SAML)
  • Keeping HLDs, LLDs and as built documentation accurate and current
  • Presenting risk and impact assessments through formal change approval processes
  • Providing hypercare and knowledge transfer to the BAU network security team post go live
  • 5+ years in network security engineering, with genuine hands on depth in both Juniper SRX and Fortinet FortiGate
  • A completed large scale firewall vendor migration under your belt, ideally in a highly regulated or compliance heavy environment
  • Strong grounding in firewall policy design, NAT, routing (BGP/OSPF), VPN technologies and network segmentation
  • FortiManager and FortiAnalyzer experience for centralised management and logging
  • Comfortable across both Junos and FortiOS, CLI and GUI
  • Solid understanding of operating within strict regulatory and compliance frameworks
  • Experience working inside formal ITIL aligned change and CAB processes
  • Strong L2 to L7 troubleshooting ability
  • Clear written and verbal communication, including explaining technical risk to non technical stakeholders
  • Fortinet NSE 4 to 7 (NSE 7 highly regarded)
  • Juniper JNCIA or JNCIS SEC
  • CCNP Security, CISSP or similar
  • ITIL Foundation
  • Prior migration work inside a bank, insurer or other tightly regulated organisation
  • Experience delivering zero downtime or low impact migrations across active/active HA environments
  • Exposure to cloud adjacent firewalling (Azure/AWS) in hybrid setups
  • A genuinely rigorous approach to testing, given how much is riding on getting every rule right