Remote job
Senior Network Engineer
Job details
About this role
Role overview
A senior network engineer is needed to own reliability across the full request-delivery path at a fast-growing electronic fixed-income trading platform. The scope covers every layer that must work for a client request to reach the right service: colo routers and switches, client circuits, VPNs, cross-connects, cross-cloud links, DNS, load balancers, and the service mesh. The role sits within the networking side of the SRE team and is built around automation, eliminating single points of failure, and turning client connectivity into a product rather than ad-hoc work.
Responsibilities
- Own reliability across edge network gear, DNS, load balancing, and service mesh spanning data centers, AWS, and GCP - Drive network automation via config-as-code (Ansible, Terraform, GitOps) with CI validation, an IPAM-backed source of truth, and reversible changes - Identify and eliminate single points of failure on critical paths, including designing and running failover drills - Engineer client connectivity including circuits, VPNs, cross-connects, and FIX network paths, with workflows and dashboards that standardize intake - Build network observability alongside SRE: streaming device telemetry, syslog into the logging stack, and full-path alerting - Harden the fleet: firmware currency, centralized AAA tied to identity, control-plane protection, and firewall policy as code - Participate in a deliberately interrupt-contained on-call rotation
Requirements
- 7+ years running production networks that include physical gear: routing and switching, BGP, firewalls, circuits, and cross-connects - Cloud networking depth in AWS or GCP: VPC design, transit gateways and peering, network load balancers, DNS, and hybrid connectivity - An automation-first mindset, with configs in Git and changes going through review - Working fluency at the L4–L7 application layer: HAProxy, NGINX, or Envoy, TLS termination, health checking, and Kubernetes ingress - Reliability instincts with a bias toward rehearsing failover before incidents - Clear writing and the ability to work directly with clients' network teams
Nice to have
- Experience running Envoy or another service mesh in production, plus Kubernetes ingress at scale - Familiarity with Cisco IOS-XE fleets, Palo Alto/Panorama, or network source-of-truth tooling such as Infrahub, NetBox, or Nautobot - Exposure to Prometheus, Grafana, or ELK-style observability stacks
Benefits and work setup
- Highly competitive compensation - Fully paid medical, dental, and vision coverage - Collaborative, team-oriented culture with an in-office environment - Base salary range in New York City of $225,000–$250,000, not including discretionary bonus or other benefits