Staff Network Security Engineer - Remote
San Francisco, CA
Direct Hire
$220k - $255k
Our client, a blockchain fintech leader, is seeking a seasoned Remote Staff Security Engineer to strengthen and evolve network security across complex, multi-cloud ecosystems. In this role, you’ll guide the design, deployment, and continuous advancement of cloud and edge security frameworks that protect large-scale environments while supporting engineering agility.
Responsibilities-
Architect, deploy, and sustain robust network security controls across AWS, GCP, and hybrid environments.
-
Lead the tuning and operation of Web Application Firewalls (WAF) and DDoS mitigation services, ensuring performance and reliability.
-
Define and enforce segmentation and firewall policies that limit risk without slowing innovation.
-
Develop and maintain detection and configuration policies to safeguard critical systems.
-
Build automation scripts and security guardrails to streamline threat detection, incident containment, and access management.
-
Collaborate closely with development and infrastructure teams to review network architecture and routing changes.
-
Continuously refine “secure-by-default” patterns and best practices to raise the organization’s overall security baseline.
-
8+ years of experience in network and cloud security, with deep expertise in AWS and edge protection.
-
Proficient in Terraform for infrastructure provisioning and Golang for automation or policy enforcement.
-
Proven ability to deliver results in fast-moving, complex environments.
-
Motivated by the opportunity to help build secure, global-scale systems that enable open financial connectivity.
-
Experience writing Rego policies for Open Policy Agent (OPA) or other policy-as-code frameworks.
-
Hands-on experience implementing AWS Network Firewall or GCP Cloud Firewall in production settings.
-
Background managing Cloudflare configurations and automation at scale.
-
Familiarity with both GCP and on-premise infrastructures.
-
Managed enterprise-grade WAF or DDoS platforms.
-
Built or enhanced in-house DDoS protection systems and automation around edge tools.
-
Bachelor’s degree in Computer Science or a related technical field.
#LI-VG1