Firewall Automation Engineer (Hibrido, Porto)
Publicada 2 de SetembroWe are looking for a Firewall Automation Engineer to join a Network Security Development team and contribute to the evolution of a self-service firewall automation platform.
The role combines Software Engineering and Enterprise Network Security, with a strong focus on developing secure, scalable and reliable automation workflows for firewall rule management across Fortinet FortiGate/FortiManager and VMware NSX-T environments.
The ideal candidate will have a strong background in Python/Django development, REST APIs and enterprise network security, with hands-on experience automating firewall operations and integrating security platforms.
Principais Responsabilidades
- Design, develop and optimize end-to-end firewall automation workflows using Python and Django/REST Framework, covering request, validation, approval and provisioning processes.
- Develop and maintain robust API integrations to orchestrate firewall changes across FortiManager/FortiOS and VMware NSX-T Managers.
- Automate the management of firewall policies, address objects, security groups and related network security configurations.
- Implement pre-change validation mechanisms, including syntax validation, conflict detection and policy compliance checks.
- Design and implement failure recovery and rollback mechanisms, ensuring idempotent and safe automation with minimal risk of disruption to production traffic.
- Develop comprehensive unit and integration tests to ensure the reliability, security and maintainability of the automation platform.
- Ensure all automated firewall changes comply with security policies, governance requirements and internal compliance standards.
- Contribute to CI/CD pipelines and follow Infrastructure as Code and software engineering best practices.
- Document source code, API contracts, automation workflows and technical designs to facilitate knowledge transfer and long-term maintainability.
- Collaborate with Network Security, NetSecOps and Software Engineering teams to continuously improve the automation platform.
Requisitos mínimos
- Experience combining Software Engineering and Enterprise Network Security.
- Advanced knowledge of Python 3 and hands-on experience with Django and/or Django REST Framework.
- Strong experience designing and consuming REST APIs and developing automation backends.
- Experience with asynchronous task processing, such as Celery and Redis, for managing long-running network operations.
- Practical experience with Git and CI/CD platforms such as GitLab CI or GitHub Actions.
- Good understanding of Infrastructure as Code (IaC) principles and modern software development practices.
- Deep knowledge of FortiGate/FortiOS and FortiManager architectures.
- Strong hands-on experience automating Fortinet firewall policies and objects through FortiManager APIs (JSON-RPC/REST).
- Deep understanding of VMware NSX-T architecture and networking/security concepts.
- Hands-on experience with the NSX-T Policy API and automation of firewall policies and security groups.
- Solid understanding of enterprise routing, switching, network zoning and micro-segmentation.
- Experience implementing secure automation with a strong focus on validation, error handling, rollback and idempotency.
- Strong understanding of network security principles, firewall policy management and security compliance.
- Good technical documentation, communication and problem-solving skills.