AWS FortiGate Deployment & Configuration Automation Specialist
Company: Leading Organization
Location / Work Mode: Remote / Global
Employment Type: Full-Time
Salary / Compensation: Competitive / Negotiable
Apply NowRole Overview
We are seeking an exceptionally talented and experienced AWS + FortiGate automation engineer to join our leading organization. This pivotal role involves designing and implementing robust automation solutions for the deployment and configuration of FortiGate firewall instances within our AWS infrastructure.
The primary objective is to streamline and fully automate the entire lifecycle of FortiGate deployments, encompassing instance provisioning, intricate networking, High Availability (HA) setup, and comprehensive firewall configurations. This includes ensuring seamless integration with existing AWS network components and adhering to best practices for security and scalability.
Beyond technical implementation, a critical aspect of this role is the creation of clear, detailed documentation. Your work will enable other engineers to fully understand, reproduce, modify, and extend the automation without heavy reliance on the original developer, contributing significantly to our operational efficiency and knowledge base. If you're passionate about infrastructure as code and cutting-edge cloud security, we encourage you to apply.
Key Responsibilities & Duties
- Develop and implement automation for FortiGate instance deployment in AWS.
- Ensure deployment within a single VPC across two Availability Zones.
- Establish and configure an Active/Standby architecture for high availability.
- Automate the provisioning of required AWS networking and supporting resources.
- Integrate FortiGate deployments with relevant AWS network components.
- Automate FortiGate High Availability (HA) configuration.
- Automate FortiGate interface configuration.
- Automate IPsec configuration for secure VPN connectivity.
- Automate the creation and management of network and address objects.
- Automate the definition and enforcement of firewall policies.
- Configure Source NAT / Destination NAT rules programmatically.
- Automate routing and other essential firewall configurations.
- Implement any additional configurations necessary to ensure a fully functional Active/Standby deployment.
- Select and utilize appropriate automation technologies such as Terraform, Ansible, FortiManager/Forti OS APIs, AWS APIs/CLI, Python, or other scripting languages.
- Provide detailed documentation explaining the overall automation architecture and deployment workflow.
- Document automation/tool choices and the rationale behind them, including considerations for maintainability, repeatability, idempotency, security, scalability, and ease of future changes.
- Clearly explain the AWS architecture, dependencies, FortiGate configuration approach, HA implementation, IPsec configuration, network objects, firewall policies, and NAT configuration.
- Document configuration variables/parameters and provide instructions on how to deploy, run, modify, or extend the automation.
- Outline assumptions, prerequisites, limitations, known considerations, and relevant code/configuration examples.
- Ensure the final deliverable allows another engineer to understand and reproduce the deployment independently.
Requirements & Qualifications
- Proven experience with FortiGate / Forti OS.
- Demonstrated experience with FortiGate deployments in AWS environments.
- Strong expertise in AWS VPC and networking concepts.
- Hands-on experience implementing FortiGate HA in AWS.
- Proficiency in IPsec VPN configuration.
- Expertise in firewall policies and Network Address Translation (NAT).
- Solid understanding and practical experience with Infrastructure as Code (IaC) principles.
- Hands-on experience with automation tools such as Terraform and/or Ansible.
- Familiarity with Forti OS REST API or FortiManager automation.
- Proficiency in Python or AWS scripting for automation tasks.
Benefits, Perks & Culture
- Highly competitive and negotiable compensation package.
- Flexible global remote work arrangement, offering work-life balance.
- Opportunity to work with a leading organization at the forefront of cloud security and automation.
- Engage in challenging projects that have a direct impact on critical infrastructure.
- Collaborative environment focused on innovation and best practices in automation.
How to Apply
Ready to take on this exciting challenge? Click the button below to submit your application directly.
Apply for This Role