Cloud Network & Edge Security Engineer

Dlocal
Spain
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Proxy Servers Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Network Address Translation DevOps Disaster Recovery Domain Name System (DNS)
+43 more
Failover HAProxy Monitoring of Systems Internet Protocol Security (IP SEC) IP Routing Subnetting Virtual Private Networks (VPN) Network Security Network Troubleshooting Linux System Administration Log Analysis Network Architecture Routing Network Segmentation Network Service Nginx PCI Data Security Standards Peering Role-Based Access Control Ansible Zero Trust Network Access Squid (Proxy Server) TCP/IP Transmission Control Protocol (TCP) Traffic Analysis Web Applications Cloud-native Network Functions (CNF) Transport Layer Security Google Cloud Load Balancing In-Plane Switching (IPS) System Availability Multi-Cloud Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) Cloudformation Low Latency Fortinet Route53 Firewall Services Module Terraform Network Server New Relic (SaaS)

Job description

  • Design, implement, and operate secure, resilient, and scalable network solutions across cloud and hybrid environments, with a focus on availability, latency, disaster recovery, and operational simplicity.
  • Own and continuously improve our edge-security stack, including cloud WAFs, network firewalls, proxies, load balancers, and traffic-routing policies that protect public APIs, frontends, and internal services.
  • Define, tune, and maintain WAF and firewall rules, policies, and traffic flows; proactively reduce noise and false positives while preserving effective protection against attacks.
  • Design and operate AWS networking services such as VPCs, subnets, route tables, Transit Gateway, VPC peering, Route 53, load balancers, security groups, Network ACLs, and AWS Network Firewall.
  • Coordinate, implement, and support third-party connectivity, including IPsec/SSL VPNs, leased lines, partner interconnections, routing, DNS, and failover paths.
  • Manage FortiGate-based services, including IPsec and SSL VPNs, security policies, virtual IPs/servers, NAT, routing, and log analysis.
  • Build and maintain end-to-end HTTP/HTTPS and network observability using logs, metrics, dashboards, alerting, synthetic checks, and traffic analysis to identify performance degradation, misconfigurations, and security events early.
  • Drive network and security infrastructure as code using Terraform or similar tools, integrating changes into CI/CD pipelines so they are repeatable, auditable, tested, and secure across environments.
  • Automate network and edge-security workflows such as site onboarding and decommissioning, rule and policy lifecycle management, partner connectivity, configuration validation, and controlled WAF-provider failovers.
  • Lead and actively participate in incident response for network, connectivity, WAF, and edge-security events; execute DR procedures, coordinate controlled failovers, and drive postmortems and remediation actions.
  • Partner with Information Security and Compliance to ensure network and edge controls support regulatory and industry requirements, including PCI and SOX, and provide audit-ready evidence when needed.
  • Maintain clear, actionable documentation for architectures, traffic flows, standards, operational procedures, and runbooks so other engineering teams can move quickly and safely. *, Flexibility in how you work: We focus on impact and productivity over fixed hours. This means our teams have flexible schedules and, depending on your role and location, you will combine self-managed focus time with moments of in-person connection in our collaboration hubs.

  • Fintech industry: work in a dynamic and ever-evolving environment, with plenty to build and boost your creativity.
  • Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded.
  • Work From Anywhere: Team members can work while traveling for up to 3 months every year. What happens after you apply?

Requirements

  • Solid hands-on experience designing, operating, and troubleshooting cloud networking in production environments with high availability and security requirements.
  • Strong knowledge of TCP/IP, HTTP/HTTPS, TLS, DNS, routing, NAT, load balancing, proxies, VPN/IPsec, and network troubleshooting practices.
  • Practical experience with AWS networking services, including VPC, subnets, route tables, Route 53, load balancers, Transit Gateway, VPC peering, security groups, Network ACLs, and AWS Network Firewall.
  • Hands-on experience managing WAFs and/or edge-security controls protecting web applications and APIs; experience in multi-provider environments is a plus.
  • Experience managing firewalls, ideally FortiGate, including VPNs, security policies, virtual IPs, routing, and log analysis.
  • Experience with Infrastructure as Code and automation tools such as Terraform, CloudFormation, Ansible, or similar, and the ability to integrate infrastructure changes into CI/CD workflows.
  • Experience with monitoring and observability platforms such as ELK, New Relic, Coralogix, or similar; ability to build actionable dashboards and alerts for latency, errors, throughput, availability, and anomalous traffic patterns.
  • Linux administration fundamentals and practical command-line troubleshooting skills.
  • Experience with HTTP/TCP proxies and reverse proxies, such as NGINX, HAProxy, or Squid.
  • Strong understanding of cloud-security best practices, network segmentation, least privilege, and secure change-management practices.
  • Strong written and spoken English, with the ability to document technical decisions and collaborate effectively across Networking, Security, Platform, Product, and external partn

Would be awesome if you had

  • Experience with AWS, GCP, Azure, or multi-cloud networking and security architectures.
  • Exposure to PCI-DSS, SOX, or other regulated-industry security and compliance requirements.
  • Experience operating in high-criticality environments such as payments, fintech, banking, or global e-commerce, where uptime, resilience, and latency are essential.
  • Experience designing disaster-recovery strategies, multi-provider WAF failover, or zero-trust network architectures.
  • AWS certifications such as AWS Certified Advanced Networking - Specialty, Solutions Architect, Security - Specialty, or DevOps Engineer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

7:28 min

Constructing a new Docker layer from scratch

Oliver Seitz Oliver Seitz · World Congress 2026 Europe

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:23 min

Closing thoughts and educational resources for edge network engineering

Austin Gil · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

5:02 min

Manual port forwarding configuration using network address translation

Oliver Seitz Oliver Seitz · World Congress 2025

Videos

See all

Related articles

See all