Principal DDOS Software Engineer

Oracle
Redwood City, CA, United States
3 months ago
Apply on arc.dev
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$96,800.0 - $223,400.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Automation of Tests Border Gateway Protocol C++ (Programming Language) Cloud Computing Configuration Management Code Review Computer Networks Continuous Integration DDoS Mitigation DevOps Disaster Recovery
+24 more
Distributed Systems Domain Name System (DNS) Memory Management IPv4 IPv6 Information Systems Security Architecture Professional Python (Programming Language) Network Security Routing Performance Tuning Zero Trust Network Access TCP/IP Privacy Controls Concurrency Backend Containerization Kubernetes Low Latency Iptables Data Analytics Api Design Terraform Ddos Oracle Cloud Infrastructure

Job description

Join OCI’s Edge Security team as a Principal Engineer to architect and deliver cloud-scale DDoS protection. You’ll lead design for high-performance detection and mitigation systems, drive automation and operational excellence, and set the technical direction for customer-facing DDoS capabilities across OCI’s global edge.

This role requires deep expertise in Linux networking data path and kernel-level networking (such as XDP, eBPF, DPDK, iptables, nftables), in addition to strong systems and DevOps engineering experience.

What you’ll do

  • Lead architecture and delivery of low-latency backend services for DDoS detection, classification, and mitigation.
  • Define and evolve scalable data/control planes (policy, signaling, telemetry, orchestration) with strong fault isolation, resiliency, and compliance-by-design.
  • Own traffic engineering strategy (anycast, BGP policy, routing integration) and partner with networking, DNS, and edge platform teams.
  • Set operational standards: SLOs/SLAs, on-call health, incident response (including incident commander duties), runbooks, and post-incident learning.
  • Drive automation at scale: CI/CD strategy, test frameworks, progressive delivery (canary/blue-green), and infrastructure-as-code.
  • Establish robust observability (metrics, logs, traces) and capacity/scale models for high-throughput, highly available services.
  • Lead threat modeling, architecture reviews, and audit readiness for Tier 0 services; ensure security and privacy are embedded through the lifecycle.
  • Mentor engineers, influence cross-org roadmaps, and collaborate with Product, SRE, and Network Engineering from concept to GA., * Deliver core DDoS detection/mitigation that protects OCI’s infrastructure availability and customer trust.
  • Launch customer-facing DDoS offerings with self-service policy, visibility, and strong defaults.
  • Raise engineering quality, automation, and compliance maturity across the stack; mentor and grow the team’s technical bar.

Ways of working

  • Security and privacy by design with auditable controls and policy adherence from day one.
  • Data-driven delivery with clear KPIs, SLOs, and stage gates from prototype to GA.
  • Collaborative, inclusive culture emphasizing design docs, code reviews, and knowledge sharing.

Responsibilities

  • Lead architecture and delivery of low-latency backend services for DDoS detection, classification, and mitigation.
  • Define and evolve scalable data/control planes (policy, signaling, telemetry, orchestration) with strong fault isolation, resiliency, and compliance-by-design.
  • Own traffic engineering strategy (anycast, BGP policy, routing integration) and partner with networking, DNS, and edge platform teams.
  • Set operational standards: SLOs/SLAs, on-call health, incident response (including incident commander duties), runbooks, and post-incident learning.
  • Drive automation at scale: CI/CD strategy, test frameworks, progressive delivery (canary/blue-green), and infrastructure-as-code.
  • Establish robust observability (metrics, logs, traces) and capacity/scale models for high-throughput, highly available services.
  • Lead threat modeling, architecture reviews, and audit readiness for Tier 0 services; ensure security and privacy are embedded through the lifecycle.
  • Mentor engineers, influence cross-org roadmaps, and collaborate with Product, SRE, and Network Engineering from concept to GA.

Qualifications

Disclaimer:

Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.

Requirements

  • 7-10 years building production backend systems, including 3-5 years in high-scale and/or low-latency environments.
  • Deep expertise in Linux networking data path and kernel-level networking (e.g., XDP, eBPF, dpdk, iptables, nftables) for traffic processing, filtering, and observability.
  • Proficiency in one or more: Java/Python/C++/Rust/Go (strong preference for Java for control-plane/services).
  • Deep systems design expertise: concurrency, memory management, performance tuning, API design, consistency models, and distributed systems fundamentals.
  • Proven DevOps leadership at scale: CI/CD, automated testing, canarying, rollout/rollback, configuration management.
  • Strong IaC experience (e.g., Terraform) and solid cloud infrastructure fundamentals.
  • Domain experience in DDoS or network security services and common attack/defense patterns.
  • Advanced networking knowledge: TCP/IP, IPv4/IPv6, BGP, routing policy; DNS fundamentals.
  • Demonstrated operational excellence and observability practices (metrics, tracing, alerting)., * Expertise with anycast routing, global traffic steering, and multi-region service readiness.
  • Experience with SDN, programmable data planes, or hardware mitigation platforms.
  • Building high-rate telemetry/streaming pipelines for near-real-time detection (packet/flow analytics).
  • Background in resilience engineering, chaos testing, disaster recovery, and capacity planning at hyperscale.
  • Containerization/orchestration (e.g., Kubernetes) and secure service-to-service communication (mTLS, policy enforcement).
  • Familiarity with zero trust, segmentation, and modern security architectures; exposure to compliance frameworks and audit preparation.

Benefits & conditions

US: Hiring Range in USD from: $96,800 - $223,400 per year. May be eligible for bonus and equity.

Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle’s differing products, industries and lines of business.

Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.

Oracle US offers a comprehensive benefits package which includes the following:

  • Medical, dental, and vision insurance, including expert medical opinion
  • Short term disability and long term disability
  • Life insurance and AD&D
  • Supplemental life insurance (Employee/Spouse/Child)
  • Health care and dependent care Flexible Spending Accounts
  • Pre-tax commuter and parking benefits
  • 401(k) Savings and Investment Plan with company match
  • Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
  • 11 paid holidays
  • Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
  • Paid parental leave
  • Adoption assistance
  • Employee Stock Purchase Plan
  • Financial planning and group legal
  • Voluntary benefits including auto, homeowner and pet insurance

The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.

Career Level - IC4

About the company

Only Oracle brings together the data, infrastructure, applications, and expertise to power everything from industry innovations to life-saving care. And with AI embedded across our products and services, we help customers turn that promise into a better future for all. Discover your potential at a company leading the way in AI and cloud solutions that impact billions of lives.

True innovation starts when everyone is empowered to contribute. That’s why we’re committed to growing a workforce that promotes opportunities for all with competitive benefits that support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on arc.dev
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

2:22 min

Introducing Skupper for application connectivity

Alex Soto Alex Soto · World Congress 2024

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

2:14 min

Solving complex platform architecture challenges at an enterprise scale

Maria Apazoglou · Coffee With Developers

3:05 min

Exploring microcontrollers and communication protocols for amateur hardware

Philipp-Alexander Blum · LIVE

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all