> Markdown version of [/jobs/ext/272111-network-security-software-engineer](https://www.wearedevelopers.com/jobs/ext/272111-network-security-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Software Engineer - **Company:** Lumin Digital - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $145,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Cloud Computing, Cloud Engineering, Cyber Security, Computer Networks, Continuous Integration, Cursor (Graphical User Interface Elements), DDoS Mitigation, Domain Name System Security Extensions, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Network Security, Network Segmentation, PCI Data Security Standards, Public Key Infrastructure, Zero Trust Network Access, Data Streaming, Traffic Analysis, Wide Area Networks, Istio, Multi-Agent Systems, Backend, Cloudformation, Build Management, Information Technology, Production Code, Cloudflare, Integration Frameworks, Firewall Services Module, Terraform, Api Management - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=293ca78fa3313498 ## About the Role Do you have experience in Zero Trust security?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Security, Network Engineering, or a related technical field, or equivalent combination of education and experience. * Preferred certifications: CCNP Security, PCNSE (Palo Alto), AWS Solutions Architect, Cloudflare certifications, or equivalent. Relevant certifications are valued but not required if depth of hands-on experience is demonstrated. Experience: * 5+ years of progressive experience in network security engineering, with a demonstrated track record of designing, automating, and operating network security controls in cloud-native or hybrid environments. * Substantive hands-on engineering experience: you write production code, build integrations, and ship tooling-not just policies and diagrams. * Direct experience with network security platforms such as Cloudflare (WAF, Workers, Rulesets, Terraform provider), Zscaler (ZIA, ZPA), Palo Alto, or equivalent tier-one solutions. * Experience in fintech, banking, payments, or other regulated financial services environments (PCI-DSS, SOC 2, ISO 27001) strongly preferred. * Experience with infrastructure-as-code (Terraform, CloudFormation) and CI/CD-driven infrastructure provisioning., * Deep expertise in network security fundamentals: firewall policy design, micro-segmentation, ZTNA, SD-WAN, DDoS mitigation, traffic analysis, DNS security, and certificate/PKI management. * Hands-on experience with agentic coding tools and workflows (Claude Code, Cursor, or equivalent)-or demonstrated eagerness and aptitude to adopt them as a primary development methodology. * Strong proficiency in at least one backend language (Python strongly preferred; Go or similar considered) with the ability to design and build production-grade APIs, automation frameworks, and integration platforms. * Thorough understanding of identity-aware network security-designing controls that authenticate and authorize not just users but services, workloads, and autonomous agents. * Demonstrated ability to write clear, precise engineering specifications and technical documentation; comfortable operating on a distributed, async-first team where written clarity drives outcomes. * Sound engineering judgment: able to evaluate AI-generated code for correctness, security implications, and maintainability; able to architect systems for reliability and observability. * Strong cross-functional communication skills: able to translate network security requirements into actionable engineering work and influence peers across Security, SRE, and Platform teams. Preferred: * Experience building real-time telemetry, monitoring, and threat detection pipelines for network traffic. * Familiarity with agent-to-agent authentication, service mesh architectures, and securing AI/ML workload communications. * Experience integrating threat intelligence feeds and automating indicator-of-compromise enrichment into network defense workflows. Travel: * Minimal, generally 12 days or less per year (~2 team get-togethers per year). ## Description * Own the architecture, implementation, and continuous improvement of Lumin's network security program across cloud, SD-WAN, and ZTNA layers-designing identity-aware, policy-driven controls that secure both human and machine (agent) identities. * Design and deliver fully automated, end-to-end network security change management pipelines that eliminate manual toil, accelerate change velocity, and maintain audit-ready evidence at every step. * Build and operate real-time network telemetry, monitoring, and alerting systems that provide deep visibility into network activity - integrating threat intelligence feeds, cloud connectivity data, and asset inventories into a unified, automated network defense posture. * Engineer production-grade tooling and services-including firewall rule lifecycle management, policy drift detection, configuration compliance validation, and telemetry enrichment-using modern backend languages (Python strongly preferred) and infrastructure-as-code. * Manage and tune network-layer detection capabilities - including IDS/IPS signatures, firewall rules, and WAF configuration - to ensure high-fidelity signals for SOC consumption. * Operate at the leading edge of AI-assisted development: write precise engineering specifications, direct AI coding agents (e.g., Claude Code, Cursor), and review/validate generated output to build secure, lights-off agentic pipelines that the broader team can learn from. * Build and maintain API integrations across the network security technology stack (e.g., Cloudflare, Zscaler, cloud-native controls) with reliability, observability, and audit-readiness designed in from day one. * Support compliance audit and assessment activities - including evidence collection, control testing, and auditor walkthroughs for network security domains; maintain an accurate network diagram inventory documenting topology, segmentation boundaries, and data flows. * Partner with the Security Operations Center, SRE, and IT to ensure network security controls integrate cleanly with existing infrastructure pipelines, CI/CD workflows, and incident response processes; participate in security architecture reviews and contribute to runbook development and operational documentation-raising the network security bar across the engineering organization. * Perform other duties as assigned. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)