Network Security Engineer
Design and defend network security architecture for AI compute infrastructure at gigawatt scale across data centers, OT networks, and cloud. Build detection, harden OT/BMS systems, and automate controls using IaC. Requires scaling network security experience, packet analysis, IT/OT segmentation, and real intrusion detection.
About the job
Role Scope
- Design and defend the network security architecture across data centers, corp, and cloud: segmentation, firewalls, and east-west controls at gigawatt scale.
- Build network detection: telemetry, flow analysis, and alerting across training fabrics, OT networks, and the WAN.
- Harden the OT and BMS side, where the network touches physical plant, against threats most security teams never see.
- Automate network security controls so new sites inherit the architecture on day one.
Requirements
- Secured production networks at scale, and you read a packet capture as comfortably as a dashboard.
- Designed segmentation for environments that mix IT, OT, and high-value compute.
- Deployed and tuned NDR or flow-based detection that found real intrusions.
- Work infrastructure-as-code: your firewall rules live in a repo, not a GUI.
- Partnered with network engineering without becoming the department of no.
Nice-to-Haves
- OT and ICS security.
- Data center or cloud provider environments.
- BGP and routing security.
- Zeek or Suricata.
Skills
Network Security, Firewalls, Network Segmentation, Ndr, Flow Analysis, Packet Capture, Infrastructure As Code, Ot Security, Ics Security, BGP, Zeek, Suricata
Similar jobs
Security Engineering jobsLeads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.