> Markdown version of [/jobs/ext/2822300-network-engineer](https://www.wearedevelopers.com/jobs/ext/2822300-network-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Engineer - **Company:** Trumid Financial LLC - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $225,000.0 - $250,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Layers, Border Gateway Protocol, Cloud Computing, Data Centers, Domain Name System (DNS), Firmware, HAProxy, Virtual Private Networks (VPN), Network Load Balancing, Routing, Nginx, Peering, Ansible, Prometheus, Data Logging, Google Cloud, Load Balancing, Istio, Grafana, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Git, Git Flow, Kubernetes, Terraform, Open Network Automation Platform, Cisco - **Published:** September 10, 2026 - **Apply:** https://www.builtincolorado.com/auth/login?destination=/job/senior-network-engineer/11093383 ## About the Role * Seven or more years running production networks that include physical gear: routing and switching, BGP, firewalls, circuits and cross-connects. * Real cloud networking depth in AWS or GCP: VPC design, transit gateways and peering, network load balancers, DNS, hybrid connectivity. * The automation habit. If you've done it twice by hand, you script it; your configs live in Git and your changes go through review. * Working fluency at the application layer of delivery: L4-L7 load balancing (HAProxy, NGINX, or Envoy), TLS termination, health checking - and enough Kubernetes to operate ingress confidently. * Reliability instincts: you would rather rehearse a failover on a quiet Tuesday than discover one during an incident. * Clear writing and the ability to work directly with clients' network teams. Nice to have. * Experience with: * Envoy or another service mesh in production; Kubernetes ingress at scale. * Cisco IOS-XE fleets, Palo Alto/Panorama, or network source-of-truth tooling (Infrahub, NetBox, Nautobot). * Prometheus/Grafana/ELK-style observability stacks. ## Description You'd join the networking side of our SRE team, working alongside experienced network engineers. Some of what you'd walk into: * A live migration of our trading edge onto HAProxy Kubernetes Ingress Controller - cut over in production one elastic IP at a time, each step reversible, each step qualified by synthetic trading traffic before real clients ride it. * A network device fleet headed for full config-as-code: version-controlled, CI-validated configuration, centralized AAA, and a proper source of truth with IPAM. * Client-connectivity request load that we are deliberately engineering away - standardized intake, per-client connectivity dashboards, and eventually self-service for the common low-risk changes. Your job is to automate this work out of existence, not to absorb it. What you'll do? * Own reliability across the full request delivery path - edge network gear, DNS, load balancing, service mesh - spanning our data centers, AWS, and GCP. * Drive network automation: config-as-code (Ansible, Terraform, GitOps) with CI validation, a network source of truth with IPAM, and changes that are reviewed, repeatable, and reversible. * Find single points of failure on critical paths and retire them; design and run the failover drills that prove they're gone. * Engineer client connectivity - circuits, VPNs, cross-connects, FIX network paths - and build the workflows and dashboards that turn it from interrupt work into a product. * Build network observability with the rest of SRE: streaming device telemetry, syslog into our logging stack, and full-path alerting so we detect faults before clients report them. * Harden the fleet: firmware currency, centralized AAA tied to our identity provider, control-plane protection, firewall policy as code. * Share a sane, deliberately interrupt-contained on-call rotation with the rest of the team. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Embracing the Hybrid Cloud: Unlocking Success with Open Source Technologies](https://www.wearedevelopers.com/videos/883-embracing-the-hybrid-cloud-unlocking-success-with-open-source-technologies) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Basic And Advanced Networking in Dart and Flutter](https://www.wearedevelopers.com/magazine/112-basic-and-advanced-networking-in-dart-and-flutter) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 139 - Soft and hard queries](https://www.wearedevelopers.com/magazine/487-dev-digest-139-soft-and-hard-queries) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)