Consulting Systems Engineer
Job description
Fortinet is expanding its Consulting Systems Engineering organization with a senior specialist dedicated to LAN Edge / NetSEC – the layer where campus networks meet access enforcement. This is a senior, individual-contributor consulting role: you will act as the go-to technical authority on switching and access-control architecture, working alongside regional sales and field systems engineering teams to scope, design, and defend complex network solutions in front of both technical and executive audiences.
The ideal candidate has spent a career at the intersection of two disciplines that are increasingly inseparable in modern campus design: enterprise switching – the physical and logical fabric that carries traffic from the edge to the core – and Network Access Control, the policy layer that decides who and what is allowed onto that fabric, and under what conditions. You do not just configure switches; you can explain why a distribution layer needs multi-chassis redundancy rather than stacking, and why a poorly designed onboarding flow quietly creates a segmentation gap. As a senior consultant, you collaborate closely with field engineering and account teams to drive impactful engagements across industries, while feeding real-world insight back into Fortinet’s product roadmap.
Responsibilities
As a Consulting Systems Engineer – LAN Edge (NetSEC), you will:
- Act as the senior technical authority for LAN edge and NAC opportunities, supporting field systems engineers and account teams through discovery, design, and proof-of-concept.
- Lead architecture reviews for campus switching designs – access/distribution/core hierarchy, high-availability topologies, and VLAN/routing segmentation – as well as NAC rollouts covering 802.1X, guest access, and device onboarding.
- Translate customer requirements into validated designs and respond to RFPs/RFIs with accurate, defensible technical content.
- Partner with Product Management and Engineering, feeding field insight on switching and access-control requirements back into the roadmap.
- Validate new features and platforms against real customer environments and provide structured feedback ahead of general availability.
Qualifications
The ideal candidate exemplifies qualities common to senior consultants, in addition to deep, current domain-specific technical knowledge:
- 10+ years of hands-on enterprise networking experience, with a clear specialization in switching at the LAN edge, distribution, and core layers.
- Deep, vendor-agnostic command of switch fundamentals: Layer 3 routing (OSPF/BGP) at the distribution and core, the Spanning Tree family (STP/RSTP/MSTP) and loop-prevention design, multi-chassis link aggregation (MC-LAG/MLAG) and chassis-redundancy architectures, switch stacking/virtual chassis, and 802.1Q VLAN design and trunking.
- Desirable: an expert-level networking industry certification
- Strong, hands-on Network Access Control (NAC) expertise: 802.1X wired and wireless authentication (EAP-TLS, PEAP), MAC Authentication Bypass (MAB) for non-supplicant and IoT devices, RADIUS-based AAA with Change of Authorization (CoA) for dynamic policy enforcement, dynamic VLAN assignment and downloadable ACLs, device profiling/fingerprinting, posture and compliance assessment, guest and BYOD onboarding, and TACACS+ for network device administration.
- A plus: familiarity with EVPN-VXLAN campus fabric design – the direction the market is moving for large, segmented campuses beyond classic MC-LAG and stacking architectures.
- Proven ability to design, defend, and articulate complex networking and access-control solutions to both technical and executive audiences.
- Track record collaborating with cross-functional teams, including engineering, product management, and sales.
- Highly proactive and self-driven, with the ability to act as a technical mentor to peers.
- Bilingual in Portuguese and English (required); Spanish is a strong plus.
- Bachelor’s degree in a relevant field, or equivalent experience.