Responsibilities
- Implement and evolve enterprise network access controls
- Manage and deploy "infrastructure as code" at scale
- Contribute to the design, implementation, management, and defense of a “zero trust”, defense-in-depth network
- Write good quality policies, procedures, and technical documentation
- Coordinate with internal development teams and other stakeholders to ensure network security principles are "built-in" from the beginning
- Work with Engineering and IT Security teams to ensure that product features are securely deployed and monitored
- Monitor and maintain all physical infrastructure (network, security, and compute), cloud data center environments, remote office locations, and respond to critical network problems to maximize service uptime
- Mentor and evangelize security practices through cross-functional work with internal stakeholders and teams
Requirements
- 4+ years of network engineering background including offensive/defensive security
- Deep experience in public (AWS or Azure or Google), private and/or hybrid cloud infrastructure
- Experience of network automation tools (e.g. Nornir, Napalm, Terraform, Ansible)
- Experience in managing and deploying Infrastructure as Code
- Experience with network security management tools and techniques
- Familiarity with security testing tools (performance and threat-based)
- Proficient in network and security design, implementation, and administration leveraging industry standard platforms from vendors such as: Palo Alto Networks, Cisco, Juniper, and Aruba
- Experience with Switching (Capacity Planning & VLAN’s), Routing (OSPF, EIGRP, BGP, ECMP, PBF), WAN Technologies (MPLS, VPLS, VPN), public cloud networking, and Security (IPS, RBAC, etc.)
- Previous experience monitoring and management of intrusion detection systems and firewall devices
- Demonstrated experience implementing defensive security systems that are used against internal and external attack vectors
The opportunity
- Implement and evolve enterprise network access controls
- Manage and deploy "infrastructure as code" at scale
- Contribute to the design, implementation, management, and defense of a “zero trust”, defense-in-depth network
- Write good quality policies, procedures, and technical documentation
- Coordinate with internal development teams and other stakeholders to ensure network security principles are "built-in" from the beginning
- Work with Engineering and IT Security teams to ensure that product features are securely deployed and monitored
- Monitor and maintain all physical infrastructure (network, security, and compute), cloud data center environments, remote office locations, and respond to critical network problems to maximize service uptime
- Mentor and evangelize security practices through cross-functional work with internal stakeholders and teams
What You Bring
- 4+ years of network engineering background including offensive/defensive security
- Deep experience in public (AWS or Azure or Google), private and/or hybrid cloud infrastructure
- Experience of network automation tools (e.g. Nornir, Napalm, Terraform, Ansible)
- Experience in managing and deploying Infrastructure as Code
- Experience with network security management tools and techniques
- Familiarity with security testing tools (performance and threat-based)
- Proficient in network and security design, implementation, and administration leveraging industry standard platforms from vendors such as: Palo Alto Networks, Cisco, Juniper, and Aruba
- Experience with Switching (Capacity Planning & VLAN’s), Routing (OSPF, EIGRP, BGP, ECMP, PBF), WAN Technologies (MPLS, VPLS, VPN), public cloud networking, and Security (IPS, RBAC, etc.)
- Previous experience monitoring and management of intrusion detection systems and firewall devices
- Demonstrated experience implementing defensive security systems that are used against internal and external attack vectors
Candidate Privacy Notice
- Applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.
- We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.
- We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process.
- These assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions.
- Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.
- As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.
Additional Information
- Applicants are permitted to redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.
- We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.
- We may ask candidates to complete job-related skills or work-style assessments as part of our hiring process.
- Assessments evaluate competencies relevant to the role and are applied consistently across candidates for similar positions.
- Results are considered alongside experience and interviews, and are not the sole basis for any employment decision.
- As an equal opportunity employer, we don't tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, or local laws.