Responsibilities
- Lead the design and implementation of network security architectures across edge, core, and data center infrastructure, including firewall policy frameworks, access control systems, and traffic inspection pipelines
- Identify and remediate security vulnerabilities in network infrastructure through threat modeling, security assessments, and proactive risk analysis of routing protocols, switching fabrics, and network services
- Define and drive adoption of network security standards, hardening guidelines, and secure configuration baselines across the infrastructure organization
- Develop and maintain detection and monitoring capabilities for network-layer threats, including anomaly detection, traffic analysis, and intrusion detection systems at scale
- Lead incident response efforts for network security events, conducting root cause analysis and driving systemic improvements to prevent recurrence
- Collaborate with network engineering, security operations, and infrastructure teams to integrate security controls into network provisioning, automation, and change management workflows
- Leverage AI-assisted tooling and automation to accelerate security analysis, reduce manual toil in threat detection pipelines, and improve the scalability of security operations
- Establish service level objectives and reliability posture for network security systems, including dashboards, alerting, and runbooks to reduce mean time to mitigation during incidents
- Mentor other engineers on network security principles, threat modeling methodologies, and secure design patterns, and contribute to recruiting and onboarding programs
- Communicate security risk, architectural trade-offs, and remediation strategies clearly to engineering leaders and cross-functional stakeholders through written proposals and design reviews
Minimum Qualifications
- 8+ years of experience in network security engineering, network infrastructure security, or a closely related security discipline
- Bachelor's degree in Computer Science, Computer Engineering, relevant technical field, or equivalent practical experience
Preferred Qualifications
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Track record of building network security telemetry pipelines and applying data-driven analysis to prioritize and validate security improvements
- Experience designing and implementing security controls for large-scale network environments, including firewalls, access control lists, network segmentation, and traffic inspection systems
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience defining and operating security controls in software-defined networking or cloud-native network environments at hyperscale
- Experience building or operating network security monitoring, anomaly detection, or intrusion detection systems at scale
- Experience leading multi-team technical initiatives, including driving cross-functional alignment, managing dependencies, and delivering measurable security outcomes
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Experience with network security automation, including programmatic configuration management, policy-as-code frameworks, or security orchestration tooling in large-scale infrastructure environments
- Experience conducting threat modeling, vulnerability assessments, or security architecture reviews for network infrastructure components such as routers, switches, load balancers, or BGP/OSPF routing systems
- Familiarity with offensive network security techniques such as network penetration testing, protocol fuzzing, or adversarial traffic analysis used to validate defensive controls
$184,000/year to $257,000/year + bonus + equity + benefits
Learn more about this Employer on their Career Site
