Develop and maintain the security blueprint for the ISP core, edge, and access networks.
Design and optimize multi-layered DDoS protection strategies using scrubbing centers, flow-based monitoring (NetFlow/SFlow), and RTBH (Remote Triggered Black Hole) filtering.
Hardening of critical network elements (routers, switches, OLTs) and implementing robust AAA (Authentication, Authorization, and Accounting) frameworks.
Lead the implementation of RPKI (Resource Public Key Infrastructure), BGPsec, and peering security best practices to prevent route hijacking.
Drive "Security as Code" by using Python, Ansible, or Terraform to automate security policy deployments across thousands of nodes.
Ensure the network meets industry standards such as NIST, ISO 27001, and regulatory requirements (e.g., CALEA, GDPR).
Act as a Tier 4 subject matter expert during major security breaches or sophisticated network attacks.
Requirements
8+ years in network engineering with at least 4 years focused specifically on security architecture in a Service Provider or large Enterprise environment.
Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or equivalent experience.
Highly preferred: CCIE Security, JNCIE-SEC, CISSP-ISSAP, or GSEC.
Ability to translate complex security risks into business terms for executive leadership.
Tech Stack
Ansible
Cyber Security
Python
Terraform
Benefits
Adaptive Mindset: We meet change head‑on to build the capabilities we need now.
Collective Impact: We treat innovation as a team sport, working powerfully together to create extraordinary impact.
Customer Ownership: We own our customers’ success, whether an internal stakeholder or an external client.