remote
Staff Network Security Engineer - DigitalOcean
Security Engineer
Lead the design, implementation, and operation of security controls for a global cloud network, leveraging firewall expertise, IDS/IPS, and automation to protect infrastructure at scale.
About the role
Key Responsibilities
- Architect, deploy, and maintain security controls across a multi‑region cloud network, ensuring confidentiality, integrity, and availability.
- Design and manage next‑generation firewalls, VPNs, and routing policies to protect traffic between data centers and edge locations.
- Develop, tune, and operate intrusion detection and prevention systems, conducting real‑time threat hunting and incident response.
- Automate security workflows and policy enforcement using Python, APIs, and infrastructure‑as‑code tools.
- Collaborate with engineering, product, and compliance teams to embed security into the SDLC and cloud services.
Requirements
- 10+ years of hands‑on experience in network security engineering for large‑scale cloud or carrier networks.
- Deep knowledge of firewalls, VPNs, BGP, routing, and IDS/IPS technologies.
- Proficiency in scripting/automation (Python) and infrastructure‑as‑code (Terraform, Ansible, etc.).
- Strong understanding of cloud networking concepts and experience securing public‑cloud platforms.
- Demonstrated ability to lead incident response, threat modeling, and security architecture reviews.