Principal Network Security Architect
Evolution Cloud Services (EVOCS)
| Company | Evolution Cloud Services (EVOCS) |
| Category | Engineering |
| Location | United States |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 26 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
EVOCS OVERVIEW
EVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with idealtechnologies to provide them with comprehensive solutions to grow and prosper.
Founded by a team of passionate experts, EVOCS has grown into a trusted partner to a growing number of leaders across their respective industries. Our roots in employee-managed operations reflect our commitment to quality, consistency, and client success.
If you enjoy working in a hyper-fast-growing company, are eager to be part of an agile team, and want to be part of our success story, then let’s talk! Why this role exists
We have engineers who can pull configurations, run rule analysis, and gather telemetry across a large firewall estate. What we need is the person who decides what any of it means.
You are the design authority: the one whose judgment the findings rest on, whose name is on the recommended architecture, and who can sit across from a client's own senior network engineers and defend a call under challenge. Hands-on individual contributor with real authority, not a management seat. You work alongside our security leadership, and an independent third-party firm reviews our findings, so you are neither the lone technical voice nor the last line of defense on your own.
The engagement
Network security, architectural and configuration assessment and remediation of 150 FortiGate appliances, for roughly 55 sites across three regions, edge, core, and out-of-band, managed through FortiManager and FortiAnalyzer with FortiAuthenticator and Active Directory behind administrative access, plus a hybrid Azure component.
There are no virtual domains, so every appliance is its own unit of assessment. Any standard you propose has to hold across three regions under data-residency constraints. And the output is not a scan report: it is findings, a hardening baseline, and a remediation roadmap that the client's own architects will read line by line and argue with.
What you will own
The judgment calls. Whether a segmentation gap is materially exploitable or theoretical. Whether a permissive rule is a real lateral-movement path or noise. What a finding is actually worth on a severity scale a CISO will act on.
Adversary-path analysis. Reason from configuration, rule base, topology, and administrative access to how an attacker would move through a distributed fleet, and where the evidence would show it if they already had.
The hardening baseline and remediation roadmap. Specific enough to execute, correct enough that a client architect will agree with it.
The golden configuration and governance model. A repeatable configuration standard for the fleet, with rule request, justification, approval, recertification, and decommission running through FortiManager change control.
Senior escalation and technical defense. Last technical stop for the delivery team across three regions, counterpart to the independent reviewer, and the person who presents findings to client engineering and security leadership.
Quality over the team's output. Direct and review the engineers gathering and analyzing fleet data, including offshore resources. Their work reaches the client through you.
What we are looking for
15+ years in network security engineering and architecture, including meaningful hands-on time as a principal consultant, enterprise architect, or equivalent senior individual contributor.
Deep Fortinet at fleet scale: FortiGate design, hardening, and rule-base architecture across estates in the hundreds of devices, with expert FortiManager (template hierarchies, policy packages, global objects, ADOM structure).
Rule bases in the tens of thousands of policies, with the hit-count reliability, shadowing, and owner-attribution problems that only appear at that volume.
Fluency in what actually breaks on a managed fleet: configuration drift between FortiManager and running config, out-of-s
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →