Source description
About the role
Role Summary
Own secure, resilient infrastructure for both sites: FortiGate, LAN/Wi‐Fi, AD/Windows Server, Microsoft 365/Azure, backups/DR, vulnerability management. Acts as change approver and security authority for day‐to‐day operations.
Core Responsibilities • Network & Perimeter: FortiGate SD‐WAN/VPN, policy hygiene, logging, config backups; VLAN/Wi‐Fi segmentation; ISP/vendor management. • Identity & Servers: AD OU/GPO design; joiner/mover/leaver; BitLocker/USB controls; Windows patching/WSUS (or equivalent). • Cloud & Microsoft 365: Conditional Access/MFA; Exchange/SharePoint/OneDrive/Teams administration; baseline hardening and Secure Score review. • Resilience: Define RPO/RTO; quarterly restore tests across servers and Microsoft 365; document evidence and lessons learned. • Security Governance: Vulnerability remediation; incident playbooks; MDR/SOC‐lite vendor liaison; quarterly firewall rule reviews. • Documentation: Network diagrams, baselines, SOPs; monthly risk & KPI reports.
Key Performance Indicators (KPIs) • Internet/VPN uptime ≥ 99.5%; P1 MTTR Minimum Qualifications & Experience • 10–12 years overall in infrastructure/security, with 3+ years hands‐on across FortiGate, AD/GPO, and Microsoft 365/Azure. • Preferred Certifications: Fortinet NSE 4 / FCP‐Network Security (or higher); Microsoft AZ‐104 (Azure Administrator).
• Nice‐to‐have: Microsoft SC‐200 (Security Operations); ITIL 4 Foundation.
Skills & Behaviors
- • FortiGate policy design; IPsec/SSL‐VPN; VLANs/L3 routing; AD/GPO administration; Microsoft 365 admin; basic PowerShell. • Incident handling under pressure; structured documentation; strong vendor management and stakeholder communication.
More at Headsup Corporation