
Staff Network Security Engineer
Posted Aug 18

Posted Aug 18
This is a fully remote position, open to applicants in United States.
• Establish and uphold standards and principles for network security architecture.
• Offer technical leadership and mentorship as a subject matter expert in network security for security and network engineering teams.
• Conduct network security evaluations, which encompass threat modeling, intrusion detection, and protocol-level analysis.
• Create and implement security automation, tooling, and infrastructure-as-code.
• Work alongside network engineers to embed security controls and telemetry within SDN, BGP/MPLS, and network automation frameworks.
• Engage in incident response activities related to network security incidents.
• Facilitate security reviews for network infrastructure or product modifications prior to deployment.
• Advocate for security best practices through documentation, tooling, and collaboration across teams.
• Collaborate with engineering teams to provide guidance on secure architecture and to safeguard DigitalOcean's global network infrastructure.
• Report directly to the Manager of Security Defense Engineering.
• 8–10 years of experience in network security engineering, network penetration testing, or roles focused on security infrastructure.
• Exceptional communication skills for collaborating with both technical and non-technical stakeholders.
• Profound understanding of Layer 2/3/4 networking protocols, such as BGP, OSPF, IS-IS, VRRP, and LACP, along with their security implications.
• In-depth knowledge of DDoS attack vectors and mitigation techniques, including packet filtering, rate limiting, and scrubbing services.
• Extensive background in designing and constructing secure networks from the ground up.
• Experience in leading projects and offering technical direction to cross-functional teams.
• Proficient in Python or Go for automation and tooling purposes.
• Familiarity with network platforms such as Corero, Cloudflare, Juniper, Arista, or Ciena.
• Strong Linux skills and knowledge of firewall, routing, and DNS security.
• Understanding and practical experience with Network Intrusion Detection principles and tools.
• Knowledge of MPLS, BGP-LU, and SDN architectures from a security standpoint.
• Hands-on experience with Prometheus, Grafana, and the ELK stack.
• Comfortable with Git-based workflows and collaborative development.
• Bonus: Contributions to open-source projects related to network security.
• Bonus: Experience in security incident response or red/blue team operations.
• Reimbursement for relevant conferences, training, and educational opportunities.
• Access to over 10,000 courses through LinkedIn Learning.
• Employee Assistance Program available.
• Opportunities for local employee meetups.
• Flexible time off policy.
• Additional bonus opportunities beyond base salary, contingent on company and individual performance.
• Equity compensation for eligible employees, including equity grants upon hiring.
• Option to partake in the Employee Stock Purchase Program.
FluidStack
Talmatch
EmpiRx Health
JSI
Get handpicked remote jobs straight to your inbox weekly.