8x8

Senior Firewall / Security Network Engineer

8x8 London, England, United Kingdom

IT Services and IT Consulting · 1,001-5,000 employees

20 h ago
Remote Senior (5-10 yrs) Full-time United Kingdom
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will design, deliver, and operate the firewall and network-security infrastructure across on-premises data centers and cloud environments. Additionally, you will manage firewall policy engineering, lead platform migrations, and handle incident response to ensure secure and reliable connectivity.

What they look for

FortiGate FortiOS AWS OCI Firewall Architecture Network Security Change Management Cloud Connectivity Troubleshooting Policy Engineering Ansible Python SIEM FortiAnalyzer VPN TLS

Requirements

The role requires hands-on expertise with FortiGate platforms and cloud network security design in AWS or OCI. Candidates must demonstrate disciplined change management skills and the ability to troubleshoot complex connectivity issues across the packet path.

Full description

8x8 connects our customers and teams globally, empowering CX leaders with performance and insights to make smarter decisions, delight customers, and drive lasting business impact.

We're hiring a Senior Firewall / Security Network Engineer to own the design, delivery, and operation of our firewall and network-security estate across on-prem data centers and cloud (AWS, OCI). This is a hands-on senior role: you'll set the firewall architecture — especially for hybrid and cloud connectivity — while running the day-to-day change and incident work that keeps the business connected and secure. You'll be the technical anchor as we migrate a multi-vendor estate onto a standardized FortiGate platform and build the cloud security layer our AWS migration depends on.

What you'll do 

Cloud & hybrid firewall architecture 

  • Design and deliver the firewall/security layer for cloud and hybrid connectivity — AWS (Transit Gateway, VPC, GWLB), OCI, and on-prem↔cloud traffic flows. 
  • Own route/prefix and policy design across the boundary so cloud workloads reach on-prem services (and vice versa) securely and without becoming snowflakes. 
  • Partner with the security operations, cloud and platform teams to make the security design a first-class part of migration planning, not an afterthought.

Firewall policy engineering & change management 

  • Translate connectivity requests from application, database, and cloud teams into clean, standards-based firewall policy (allow/NAT/port/service rules, TLS flows). 
  • Drive changes through the RP change-management process — with clear implementation, testing, and rollback plans — and peer-review others' changes. 
  • Keep policy consistent and auditable across sites; retire one-off exceptions. Migration & platform lifecycle 
  • Lead migrations from legacy Cisco and Juniper to FortiGate , including policy review, rebuild, and cutover. 
  • Plan and execute quarterly firewall software upgrades and hardware refreshes with minimal disruption. 
  • Manage IPsec/site-to-site migrations and firewall decommissioning. 

Operations, incident response & availability 

  • Triage and resolve connectivity incidents — blocked/dropped traffic, TLS handshake failures, VPN outages, firewall failovers. 
  • Own the out-of-band (OOB) management network for firewalls: reachability, console access, and monitoring enablement. 

Observability, logging & compliance 

  • Integrate firewalls with logging and monitoring — FortiAnalyzer, SIEM log forwarding, netflow, SNMP. 
  • Help close misconfiguration and risk findings 

Required qualifications 

  • Hands-on FortiGate / FortiOS expertise: VDOMs, security policy, NAT, SSL inspection, FortiAnalyzer, and FortiConverter.
  • Cloud network security: firewall/connectivity design in AWS (TGW, VPC, GWLB) and/or OCI, including hybrid on-prem↔cloud flows.. 
  • Disciplined change management: implementation, testing, and rollback planning, plus peer review. 
  • Strong connectivity troubleshooting across the packet path (drops, TLS, DNS, routing). 
  • Ability to work directly with application, database, cloud, and security teams to turn requirements into secure, standardized policy. 

Preferred / nice-to-have 

  • Experience using AI services/assistants in an engineering workflow — AI-assisted troubleshooting, config generation, or building tooling and automation around network/security systems (e.g. API-driven agents, MCP servers) 
  • Network automation — Ansible, AWX, or similar — for config and policy management. 
  • SIEM / observability tooling (FortiAnalyzer, netflow, SNMP, log pipelines). 
  • Multi-site WAN and data-center networking experience. 
  • Scripting (Python or similar) for tooling and validation. 
  • Exposure to security frameworks and audit/misconfiguration remediation. 

How the role works 

  • High cross-functional surface: application/DB/cloud teams (connectivity requests), SecOps and the broader security org (risk sign-off, shared initiatives), and site/infra teams (builds and migrations). - Work is tracked and delivered through the team's change process

For a closer look into what life at 8x8 UK Ltd. is about check out our Instagram page.

8x8 believes diversity makes our company stronger which is why we are a proud equal opportunities employer and encourage all of our staff to bring their authentic selves to work. We believe in fairness which is why we have been a member of the Living Wage Foundation for many years and we believe in security so reserve the right to undertake background checks on anyone that we extend an employment offer to.

Our Job Applicant Privacy Notice can be found here.

Learn more on our company website at www.8x8.com follow our pages on LinkedIn, Twitter, Facebook and Instagram.