L3 Network Security Engineer
Role Type - Full Time
Location - Auckland or Waikato
Hybrid work arrangement - 3 days from office
Role Overview
...
We are looking for a Level 3 Security Engineer with deep expertise in network and perimeter security technologies to provide advanced operational support to the stakeholders. This role is part of the L3 escalation team, responsible for resolving complex issues that arise after firewall/WAF migrations, upgrades, or implementations performed by delivery teams.
This is a hands-on Operational role. You’ll be the last line of defense for diagnosing and fixing problems in Fortinet, Check Point, F5, Palo Alto or similar infrastructure that protect critical business systems.
Key Responsibilities
- Troubleshoot and resolve escalated issues across client firewall, WAF, and VPN environments (L3 support).
- Analyze and fix routing/NAT issues, connectivity failures, or unexpected traffic behaviour post-implementation.
- Support and maintain HA firewall clusters, WAF configurations, and remote access solutions (IPSec/SSL).
- Engage in packet capture analysis, log correlation, and traffic flow debugging to isolate root causes.
- Collaborate with internal project and L1/L2 teams to ensure smooth handoffs and improve escalation workflows.
- Perform policy cleanup, optimization, and ongoing tuning in client environments.
- Create/update technical documentation and contribute to client knowledge bases and runbooks.
Skills & Experience Required
- 5+ yrs in a hands-on network/security engineering or support role.
- Expert-level knowledge of Fortinet FortiGate firewalls and management tools (FortiManager, FortiAnalyzer)
- Solid experience with Check Point or F5 firewalls, VPNs, and SmartConsole (R80+).
- Must be able to analyze iRules and troubleshoot WAF issues.
- Strong troubleshooting skills in TCP/IP, routing, VPNs, NAT, VLANs, and firewall traffic flow logic.
- Comfortable using CLI tools, packet capture utilities, and basic scripting if needed.
- Available once a month for On-Call rotation( pay & half + day in lieu).
Certifications (Preferred)
Fortinet NSE 4/5/6. Check Point CCSA/CCSE, F5 201 or similar
PLEASE NOTE: Due to the nature of this role, only candidates with valid New Zealand work rights will be considered. We appreciate your interest; however, only shortlisted candidates will be contacted due to the high volume of applications.
If this sounds like your next career move, we’d love to hear from you! For more information, reach out to Vinnie at vinnie.angadi@randstaddigital.co.nz
At Randstad, we are passionate about providing equal employment opportunities and embracing diversity to the benefit of all. We actively encourage applications from any background.