Staff Network Engineer, App Platform
Own the network architecture and standards for a multi-cloud enterprise AI platform deployed across Kubernetes environments and customer-controlled networks. The role requires deep cloud and Kubernetes networking expertise, strong security fundamentals, and the judgment to establish scalable, supportable connectivity patterns.
About the job
Responsibilities
- Own network architecture and standards for the SGP platform across AWS, Azure, GCP, Kubernetes, and customer-owned deployments.
- Design and review VPC architectures, peering, DNS, load balancing, CDN/edge configurations, VPNs, routing, access, ingress, egress, and traffic flows.
- Define standard connectivity between Scale control planes and customer data planes using patterns such as VPC peering, PrivateLink, Private Service Connect, site-to-site VPN, and reverse tunnels.
- Establish customer-boundary delivery patterns for code, images, traffic, CI/CD mirroring, artifact scanning, private registries, and ingress.
- Design auditable engineer access to customer and internal environments, including Tailscale, Teleport, bastion, and related approaches.
- Own Kubernetes networking, including Istio/Envoy, ingress, cloud CNI configurations, and portable NetworkPolicy contracts for agent-sandbox pods.
- Review networking proposals, prevent one-off implementations, and converge existing deployments on supportable standards.
- Partner with security engineering on segmentation, zero-trust access, and compliance requirements.
- Debug connectivity, latency, and traffic-flow issues across hybrid and multi-cloud deployments.
- Document architecture, standards, and operational runbooks.
Requirements
- 5+ years of network engineering experience, including production cloud network design and operations.
- Deep cloud networking expertise in at least two of AWS, Azure, and GCP, including VPC design, peering, Transit Gateway or hub-and-spoke architectures, private connectivity, and DNS.
- Strong Kubernetes networking experience with CNI, ingress, NetworkPolicy, and service mesh technologies such as Istio and Envoy.
- Strong fundamentals in TCP/IP, BGP, routing, firewalls, site-to-site and client VPNs, and TLS.
- Experience with edge/CDN and traffic-management platforms such as Cloudflare.
- Experience defining and enforcing network standards or reference architectures through design review.
- Ability to operate as a sole domain owner, gather requirements across complex environments, and converge designs without disrupting operations.
- Experience making build-versus-adopt networking decisions with vendor-support or contractual implications.
- Infrastructure-as-code proficiency; Terraform preferred.
- Excellent communication skills and the ability to explain technical tradeoffs to technical and non-technical audiences.
Nice-to-haves
- Familiarity with network security and compliance requirements in healthcare, finance, and government environments, including FedRAMP/GovCloud and air-gapped deployments.
Compensation and Benefits
- Base salary, equity, and benefits are provided for eligible roles.
- Benefits may include comprehensive health, dental, and vision coverage; retirement benefits; learning and development stipend; generous paid time off; and a commuter stipend.
- The posting lists a base salary range of $1–$1 USD for San Francisco, New York, and Seattle.
Skills
AWS, Azure, GCP, Kubernetes, Terraform, Istio, Envoy, Networkpolicy, Cloudflare, TCP/IP, BGP, Vpn, Tls, DNS, Vpc
Similar jobs
DevOps / SRE jobsStaff-level site reliability engineer responsible for safely deploying and operating safeguards infrastructure across model releases and cloud platforms. The role emphasizes production change management, high-stakes incident response, and automating manual launch and validation processes.
Staff Infrastructure Engineer responsible for designing and operating scalable infrastructure for growth systems, including onboarding, referrals, and user acquisition. The role requires 7+ years of production infrastructure experience, strong reliability instincts, and independent judgment in a high-autonomy environment.
Leads the architecture, development, and operation of cloud, Kubernetes, on-premises, and hybrid infrastructure, while building developer platforms and CI/CD automation. Requires at least six years of infrastructure or related engineering experience, deep Kubernetes expertise, strong programming skills, and technical leadership.
Staff Platform Engineer will build and improve automated delivery pipelines, developer environments, infrastructure, and release systems across the engineering organization. The role requires 6+ years of engineering experience, a bachelor’s degree, and expertise with CI/CD, cloud infrastructure, containers, and infrastructure as code.
Staff DevSecOps Engineer designing and automating security controls across AWS infrastructure, containers, CI/CD, and platform services. Requires 7+ years of related experience plus expertise in cloud security, infrastructure as code, hardened images, vulnerability scanning, identity, and secrets management.