> Markdown version of [/jobs/ext/3005106-network-engineer](https://www.wearedevelopers.com/jobs/ext/3005106-network-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Engineer - **Company:** Sulzer - **Location:** Madrid, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Automation of Tests, Bash Shell, Databases, Continuous Integration, Cursor (Graphical User Interface Elements), Network Address Translation, DevOps, Domain Name System (DNS), Failover, Github, Identity and Access Management, Internet Protocol Security (IP SEC), Virtual Private Networks (VPN), Mobile Application Software, Python (Programming Language), Key Management, PostgreSQL, Linux System Administration, Nagios, Routing, OpenVPN, Reliability Engineering, Digitalocean, Ansible, Prometheus, Software Deployment, Software Vulnerability Management, Datadog, Data Logging, Computer Networking Systems, Transport Layer Security, Computer Network Technologies, GitHub Copilot, Grafana, Amazon Virtual Private Cloud (VPC), Backend, Amazon Relational Database Service, Kubernetes, Infrastructure Automation Frameworks, Iptables, Cloudflare, Route53, Virtual Agents, Functional Programming, Cloud Optimization, Cloudwatch, Terraform, Docker, Vulnerability Analysis, Golang - **Published:** September 19, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role + 5+ years of professional experience in DevOps, SRE, network engineering, or a related discipline, with hands-on responsibility for production infrastructure in an agile environment. + Strong practical experience with AWS, including EC2, Lambda, S3, RDS/PostgreSQL, Route 53, IAM, VPC, and CloudWatch, plus experience with at least one additional cloud or hosting provider such as DigitalOcean, Vultr, Hetzner, or Linode. + Solid experience with Terraform and Ansible, Docker, container orchestration or fleet management, and Linux system administration. + Strong networking knowledge covering iptables/nftables, WireGuard, routing, NAT, DNS, TLS/certificates, and traffic shaping. + Hands-on experience operating VPN, proxy, or comparable networking infrastructure in production, with strong knowledge of provisioning, configuration, key management, monitoring, failover, and network performance. Experience with WireGuard, Shadowsocks, OpenVPN, or IKEv2/IPsec at scale is highly desirable. + Understanding of DNS and domain management, Cloudflare and edge infrastructure, CDN technologies, IP reputation, geographic distribution, and resilience strategies for provider outages or network restrictions. + Experience with observability and alerting tools such as Datadog, Prometheus, Grafana, Cloudflare, and centralized logging, alongside production incident response. + Strong CI/CD experience with GitHub Actions or similar platforms, including automated testing, safe deployment practices, and rollback strategies. + Proficiency in scripting and automation using Python, Go, Bash, or comparable languages. + Strong understanding of security fundamentals, including Vault, AWS Secrets Manager or SSM, encryption in transit and at rest, least-privilege IAM, vulnerability scanning, and hardening of public-facing infrastructure. + Demonstrated day-to-day proficiency with agentic AI tools such as Claude Code, Cursor, or GitHub Copilot agents, combined with sound judgment and rigorous verification of AI-generated infrastructure code. + Proven experience owning production operations, investigating incidents, identifying root causes, and improving systems to reduce recurring manual work. + Excellent analytical, organizational, and problem-solving abilities, with the independence to deliver confidently while recognizing when collaboration or escalation is required. + Strong communication skills, empathy, accountability, curiosity, attention to detail, and a proactive approach to improving systems and processes. + Passion for technology and a willingness to continuously learn and adopt new engineering practices and tools. + Experience with censorship-circumvention technologies, traffic obfuscation, restrictive network environments, userspace network stacks, Kubernetes/Nomad, Packer, self-managed databases, cloud cost optimization, FinOps, compliance programs, or mobile app release pipelines is a plus. ## Description This remote engineering role offers the opportunity to take ownership of the infrastructure powering a globally distributed VPN product. You will operate and evolve networking infrastructure across multiple cloud and hosting providers, alongside an AWS-based control plane and supporting backend services. The role combines hands-on network engineering, DevOps, infrastructure automation, security, observability, and production operations. You will inherit a live environment, understand its architecture and risks, and progressively make it more reliable, automated, secure, and cost-efficient. Agentic AI tools are an important part of the engineering workflow, helping accelerate development, investigation, documentation, and operational automation. Working within a small, highly collaborative engineering team, you will have substantial ownership over infrastructure that directly impacts users around the world. Accountabilities + Take technical ownership of the infrastructure and networking domain for a globally distributed VPN service operating across multiple cloud and hosting providers. + Operate, stabilize, and continuously improve VPN infrastructure, AWS-based control plane services, backend systems, and supporting operational tooling. + Analyze the existing production environment, document its architecture and dependencies, and identify the most significant reliability, security, scalability, and cost risks. + Replace manual operational procedures and runbooks with infrastructure-as-code, automation, repeatable deployments, and self-service workflows. + Build and strengthen CI/CD pipelines with automated testing, deployment safeguards, observability, and reliable rollback mechanisms. + Manage VPN networking technologies and infrastructure, including server provisioning, configuration, routing, NAT, DNS, TLS, traffic shaping, health monitoring, failover, and key management. + Develop monitoring, logging, alerting, and incident-response capabilities to improve availability and operational resilience. + Troubleshoot production incidents, participate in 24/7 on-call operations, perform root-cause analysis, and ensure recurring issues are addressed through automation and system improvements. + Use agentic AI and AI coding tools to accelerate infrastructure development, incident investigation, documentation, and automation while thoroughly reviewing and validating generated output before production deployment. + Collaborate closely with engineering and product teams to balance uptime, latency, connection success rates, capacity, infrastructure costs, and overall user experience. + Contribute to iterative two-week development cycles by testing hypotheses, validating feasibility, and delivering well-tested, version-controlled infrastructure changes. + Strengthen security practices covering secrets management, encryption, least-privilege access, vulnerability management, server hardening, and relevant privacy and compliance requirements. ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)