Description
Summary:
Seeking a senior NetDevOps Engineer to join the Network and Security Automation team, focusing on translating manual infrastructure knowledge into autonomous, enterprise-grade automation workflows.
Highlights:
1. Lead automation of firewall rule management for FortiGate and Checkpoint.
2. Develop automation for network infrastructure using Ansible and Python.
3. Integrate new use cases and scale existing workflows within VLAB framework.
### **Job description**
Daily rate: 290
* Hybrid: Ideal 4x/week, but can be flexible to 3x/week
\-
We are building out our Network and Security Automation team and are seeking a senior NetDevOps Engineer to join our Porto office.
The team has built a VLAB automation framework using Ansible Automation Platform (AAP) as its orchestration layer, GitLab for version control and merge request workflows, and Netbox as the primary CMDB/IPAM inventory source.
Security automation is currently the highest\-priority gap: all firewall configuration and policy management workflows are still performed manually and need to be fully integrated into the framework.
The role requires a seasoned network and security engineer who has developed strong automation capabilities. The ideal profile understands how infrastructure is built and operated manually, and can translate that knowledge into autonomous, enterprise\-grade automation workflows without depending on a separate network engineer to validate outputs.
\-
* Hybrid: Ideal 4x/week, but can be flexible to 3x/week
### **Requirements**
**Goals and Deliverables**
* Take ownership of network and security automation use cases: understand the manual process, design the end\-to\-end workflow, and integrate it into the existing VLAB framework
* Lead the automation of firewall rule management for FortiGate and Checkpoint, covering request intake via Jira/API, config generation, verification, and change push without manual intervention
* Translate existing manual network and security configurations into Ansible playbooks and Python scripts, following GitLab version control and merge request procedures
* Interact with network and security architects to understand infrastructure requirements and convert them into automation\-ready specifications
* Operate autonomously on network and security tasks: designing, testing, and validating automation outputs independently
* Contribute to the VLAB framework by integrating new use cases, scaling existing workflows, and maintaining code quality within the team's GitLab CI/CD pipeline
* Leverage GitHub Copilot and AI\-assisted tooling to accelerate code development
* Participate in the integration of MCP (Model Context Protocol) server capabilities and AI agents into the infrastructure automation stack
* Manage version control, feature branches, and merge requests via GitLab, following the team's code review and approval process
* Collaborate with operations, systems, and security teams in Porto; produce clear technical documentation and handover materials for each use case
**Experience Required**
* Senior\-level background in network and/or security engineering: hands\-on experience with physical infrastructure, routing, switching, firewall management (Fortinet strongly valued), Arista
* Demonstrated ability to automate network infrastructure using Ansible and Python: translating manual configurations into code
* Experience with Ansible Automation Platform (AAP) is a plus; core Ansible proficiency is mandatory
* Practical knowledge of FortiGate (FortiOS CLI, REST API) and/or Checkpoint (SmartCenter API, Cpshell)
* Familiarity with GitLab for version control and CI/CD pipelines
* Exposure to MCP servers and AI\-assisted development tooling (GitHub Copilot or equivalent) is a strong differentiator
* Cloud\-only automation profiles (AWS/Azure without physical network background) will not meet requirements
\- \[Hybrid: Ideal 4x/week, but can be flexible to 3x/week]
* **What we do not want:**
* Profiles strong in automation (Ansible, Python, Red Hat) but weak in actual network/security infrastructure, because they need constant validation from a network engineer, causing delays.
* Profiles with strong cloud/AWS automation background but no hands\-on experience with physical network appliances and protocols: AWS automation is architecturally different and managed by a separate team at Euronext. AWS\-only profiles do not meet requirements
* explicitly not looking for a systems/cloud automation profile. We need a NetDevOps profile, someone who comes from the network and security engineering world first, and has then developed automation skills on top of that foundation.
* The ideal Profile:
* Strong hands\-on experience in network and security infrastructure: routing, switching, firewalls (Fortinet), Arista, physical appliances, protocols
* Capable of translating manual network configurations into Ansible/Python code autonomously, without needing a network engineer to validate outputs
* Proficient in Ansible and/or Python
* AAP experience is a plus but not required
* GitLab knowledge (testing, version control) is expected
\-
**Contact**
* costa.neto@littlebigconnection.com
* \+351 21 020 9908 (Whatsapp)