Back to jobs
Fortinet

Professional Services Consultant - Melbourne

AUSalary not listedPosted yesterday

Job description

Location: Australia (Melbourne)

Fortinet Professional Services ANZ delivers the design, deployment and operationalisation of the Fortinet Security Fabric for our largest enterprise, government and service provider customers. This role is a senior billable consulting position based in Melbourne, focused on operational technology (OT) and critical infrastructure security delivery.

You will own the technical delivery of your engagements end to end: scope through design, build, cutover, testing, knowledge transfer and formal closure. You will work directly with customer architects and operations teams, and you will be expected to hold the line on design quality and delivery standards when a project is under pressure. Some engagements will be delivered as an embedded Resident Engineer with a single strategic customer for an extended period.

The consultant is expected to function as a peer to the ANZ Sales Engineering organisation. Pre-sales teams define the solution direction and secure customer approval; this role assumes ownership from that point onward, converting architecture into a production-ready design and successfully delivering the outcome to the customer.

As a Professional Services Consultant, you will:

Delivery

  • Lead the technical delivery of Fortinet Professional Services engagements onsite and remotely, from requirements capture through to signed work completion.
  • Translate customer requirements into a documented low level design that is reviewable, defensible and aligned to Fortinet best practice, rather than assembled at the console.
  • Deploy, configure, migrate, cut over, test and troubleshoot Fortinet solutions in complex production environments, including out of hours change windows.
  • Run structured knowledge transfer and handover so the customer operates the solution without ongoing dependency on the consultant who built it.
  • Identify and escalate scope change, risk and blockers early and in writing. Scope is changed through the agreed variation process, never absorbed silently into the engagement.

Technical Leadership

  • Act as the senior OT security reference point for the ANZ Professional Services team, including design review and second opinion on peer engagements.
  • Mentor and uplift less experienced consultants through paired delivery, design walkthroughs and structured feedback, not ad hoc assistance.
  • Contribute reusable delivery assets: design templates, build guides, test plans, migration runbooks and technical notes that reduce the cost of the next engagement.
  • Interface with Sales Engineering, TAC, Product Management and Fortinet technology partners, and distribute that knowledge back into the ANZ team.

Commercial and Governance Discipline

  • Maintain accurate, same-week time recording in Changepoint against the correct project and task. Billable utilisation is a measured accountability of this role.
  • Produce and secure the artefacts that close an engagement: Statement of Work input, milestone evidence, signed Work Completion form, knowledge transfer record and customer satisfaction survey.
  • Provide clear, written project status to the Fortinet project manager and management line. Verbal updates do not constitute reporting.
  • Operate to the published Fortinet PS ANZ Operating Standard on conduct, delivery quality and commercial compliance.

Core Technical Baseline (Required)

Deep, hands-on, production-grade capability across the following is the entry requirement for this role. Familiarity is not sufficient.

  • OT and industrial control system security: Design and delivery of security controls in operational technology and industrial control environments, including Purdue model zone and conduit segmentation, IT to OT boundary and DMZ design, passive asset discovery and visibility, and secure remote access for vendors, integrators and plant support.
  • Industrial protocols and OT enforcement: Working knowledge of Modbus TCP, DNP3, IEC 61850, IEC 60870-5-104, PROFINET, EtherNet/IP and OPC UA, and enforcement using FortiGate and FortiSwitch Rugged platforms and the FortiGuard OT Security Service, including industrial IPS and application control signatures.
  • OT standards and safe delivery practice: Application of IEC 62443, the Security of Critical Infrastructure Act and the AESCSF to control selection, together with OT-safe change control, outage and maintenance window planning, and the ability to work alongside plant, engineering, process and safety teams.
  • FortiGate: Enterprise firewall and next generation firewall design, deployment and migration at scale, including HA design, VDOMs, policy consolidation and vendor-to-Fortinet migrations.
  • Routing and switching: Advanced routing (BGP, OSPF, policy based routing), switching, VLANs, VRFs, multicast, NAT, QoS and end-to-end packet flow troubleshooting.
  • VPN: IPsec site to site and dial-up, SSL VPN, IKEv2, certificate handling, and interoperability with third party gateways.
  • Security profiles: Deep packet inspection and certificate inspection, IPS, application control, web filtering, DNS filtering, anti-malware and inline sandboxing.
  • FortiManager and FortiAnalyzer: Centralised policy management, ADOMs, revision control, scripting and templating, and centralised logging, analytics and reporting design including log sizing and retention.
  • Authentication and cryptography: TLS, PKI and certificate lifecycle, RADIUS, LDAP, SAML, MFA, and identity based policy enforcement.
  • Platform and automation: Administrator level Linux or Windows, REST API integration, and automation scripting (Python, PowerShell, Ansible or equivalent).

Extended Fabric Capability (Highly Advantageous)

Candidates with demonstrable delivery experience in the following will be prioritised. These capabilities directly address current and forecast ANZ demand, and depth here is a differentiator, not a nice to have.

  • OT visibility and platform breadth: Experience applying FortiNDR, FortiPAM, FortiDeceptor, FortiAuthenticator or FortiSIEM in an OT context, or with competing OT platforms (Claroty, Nozomi Networks, Dragos, Armis, Cisco Cyber Vision). Prior delivery into utilities, energy, water, rail, ports, mining or manufacturing is highly regarded.
  • SD-WAN: Hub and spoke and ADVPN designs, overlay and underlay architecture, SLA based steering, application steering and large scale branch rollouts.
  • FortiDDoS and DDoS protection: DDoS mitigation design and deployment, attack profiling and baselining, mitigation policy tuning, scrubbing and upstream provider integration, and post-event forensics. Experience with FortiDDoS, FortiDDoS-CM or competing platforms (Radware, Arbor, F5, Imperva, Cloudflare) is highly regarded.
  • FortiNDR and network detection and response: Network detection and response deployment, traffic and metadata collection design, sensor placement, behavioural and machine learning based detection tuning, and integration into customer SOC workflow. FortiNDR, FortiNDR Cloud or equivalent (Darktrace, ExtraHop, Vectra, Corelight) experience is highly regarded.
  • SASE and Zero Trust: FortiSASE, ZTNA, FortiClient EMS and secure private access, including remote access modernisation and VPN to ZTNA transition programs.
  • Application security and delivery: FortiWeb (WAF), FortiADC (application delivery and server load balancing), FortiProxy, FortiGSLB and FortiIsolator.
  • SOC and threat platforms: FortiSIEM, FortiSOAR, FortiEDR, FortiSandbox, FortiDeceptor and FortiRecon, including use case development and playbook build.
  • Secure networking and access: FortiSwitch, FortiAP, FortiExtender, FortiNAC and FortiAuthenticator in campus and branch environments.
  • Cloud and virtualised: FortiGate VM, FortiFlex, FortiCNAPP and Fortinet deployment in Azure, AWS and GCP, including infrastructure as code delivery.
  • Adjacent platforms: FortiPAM, FortiMail and FortiTester.

We Are Looking For:

An insightful and influential collaborator to join our team. We encourage you to apply for this position if you have the following qualities:

  • 8 to 10 years or more of relevant industry experience, preferably with a network security vendor, systems integrator or managed security service provider.
  • 5 or more years in LAN, WAN and internet infrastructure engineering, support or administration.
  • 3 or more years delivering network security products in customer facing project delivery.
  • Demonstrated delivery of security outcomes in OT, industrial control or critical infrastructure environments.
  • Demonstrated experience delivering into large enterprise, government, financial services or service provider environments under formal change management.
  • Fortinet certification at FCP level as a minimum. FCSS or FCX, and Fortinet specialisations in OT Security, SD-WAN, Secure Access, Public Cloud or Security Operations, are strongly preferred.
  • Vendor certifications from Cisco, Palo Alto, F5, Juniper, Check Point, Radware, AWS or Azure are an advantage. ISA/IEC 62443 certification, GICSP, or certification from an OT security vendor is highly regarded.
  • Excellent written and verbal communication, including the ability to author design documentation and present technical positions to customer architects and management.
  • Strong working knowledge of the current threat landscape and how it maps to control selection.
  • Competence with Microsoft Word, PowerPoint, Visio and Project for delivery documentation.
  • Bachelor degree in Electrical Engineering, Computer Science, Computer Engineering or equivalent practical experience.
  • Project management certification (PRINCE2, PMP or Agile) is an advantage.

Working Conditions

  • Based in Melbourne with potential travel across APAC.
  • Delivery frequently requires work outside standard hours, including scheduled evening, weekend and public holiday change windows.
  • Extended onsite Resident Engineer placement with a strategic customer may be required.
  • Must hold unrestricted working rights in Australia. Eligibility to obtain and hold an Australian Government security clearance (Baseline or above) is highly advantageous.
  • Delivery into industrial and critical infrastructure sites may require site induction, safety training, medical assessment, and drug and alcohol testing in line with customer requirements.
  • Comfortable working autonomously and as part of a distributed regional team.

What Success Looks Like in the First 12 Months

  • Consistently meets billable utilisation and delivery quality targets without management intervention.
  • Owns and closes complex multi-site engagements end to end, including all commercial closure artefacts.
  • Becomes the recognised go-to design authority for OT and critical infrastructure security within the ANZ Professional Services team.
  • Materially reduces the region’s dependence on any single individual for a technology domain through mentoring and documented assets.

Why Join Us:

At Fortinet, we embrace diversity and inclusivity. We encourage applications from diverse backgrounds and identities. Explore our welcoming work environment designed for a rewarding career journey with an attractive Total Rewards package to support you with your overall health and financial well-being. Join us in bringing solutions that make a meaningful and lasting impact to our 660,000+ customers around the globe.

We will only notify shortlisted candidates.

Fortinet will not entertain any unsolicited resumes, please refrain from sending them to any Fortinet employees or Fortinet email aliases. Should any Agency submit any resumes to Fortinet, these resumes if considered, will be assumed to have been given by the Agency free of any related fees/charges.

#LI-CR1

Fortinet makes possible a digital world that we can always trust through its mission to protect people, devices, and data everywhere. This is why the world’s largest enterprises, service providers, and government organizations choose Fortinet to securely accelerate their digital journey. The Fortinet Security Fabric platform delivers broad, integrated, and automated protections across the entire digital attack surface, securing critical devices, data, applications, and connections from the data center to the cloud to the home office. Ranking #1 in the most security appliances shipped worldwide, more than 615,000 customers trust Fortinet to protect their businesses. And the Fortinet NSE Training Institute, an initiative of Fortinet’s Training Advancement Agenda (TAA), provides one of the largest and broadest training programs in the industry to make cyber training and new career opportunities available to everyone.