Security Engineer, Network
Design and defend network security architecture for AI compute infrastructure at gigawatt scale, including segmentation, detection, and OT hardening across data centers, corp, and cloud. Requires experience securing large production networks with IT/OT mix, packet analysis, IaC for security controls, and real intrusion detection.
About the job
Responsibilities
- Design and defend the network security architecture across data centers, corp, and cloud: segmentation, firewalls, and east-west controls at gigawatt scale.
- Build network detection: telemetry, flow analysis, and alerting across training fabrics, OT networks, and the WAN.
- Harden the OT and BMS side, where the network touches physical plant, against threats most security teams never see.
- Automate network security controls so new sites inherit the architecture on day one.
Requirements
- Secured production networks at scale, and you read a packet capture as comfortably as a dashboard.
- Designed segmentation for environments that mix IT, OT, and high-value compute.
- Deployed and tuned NDR or flow-based detection that found real intrusions.
- Work infrastructure-as-code: your firewall rules live in a repo, not a GUI.
- Partnered with network engineering without becoming the department of no.
Nice-to-Haves
- OT and ICS security.
- Data center or cloud provider environments.
- BGP and routing security.
- Zeek or Suricata.
Skills
Network Security, Packet Capture Analysis, Network Segmentation, It/Ot Environments, Ndr, Flow-Based Detection, Infrastructure As Code, Firewall Automation, Ot Security, Ics Security, BGP, Routing Security, Zeek, Suricata
Similar jobs
Security Engineering jobsLeads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.