Senior Network & Edge Security Engineer
DlocalSpainFull Time3d ago
SecurityComplianceGrowthEngineeringPlatformAutomationremotecurated-jd
Job description
Senior Network & Edge Security Engineer at Dlocal.
About the role
Dlocal manages payment collections for major global corporations across 40 emerging markets. This role focuses on the architecture and maintenance of our global cloud and hybrid network perimeter to ensure secure, low-latency connectivity. You will join a team of over 1000 professionals to protect our payment infrastructure and support international scaling.
Key facts
What you'll do
- Architect and maintain secure network solutions for cloud and hybrid environments with an emphasis on uptime and performance.
- Manage edge security components including cloud WAFs, network firewalls, proxies, and load balancers.
- Configure WAF and firewall policies to minimize false positives while maintaining high security.
- Administer AWS networking services such as VPCs, Transit Gateway, Route 53, and AWS Network Firewall.
- Oversee third-party connectivity, including VPNs, leased lines, and partner routing.
- Operate FortiGate services, covering security policies, NAT, and log analysis.
- Implement observability through logs, metrics, and synthetic checks to monitor traffic and performance.
- Use Terraform or similar tools to manage infrastructure as code within CI/CD pipelines.
- Automate edge security workflows and site lifecycle management.
- Lead incident response for network and security events, including disaster recovery and postmortems.
- Ensure network controls meet PCI and SOX compliance standards.
- Create technical documentation and runbooks for internal engineering teams.
Requirements
- Proven experience managing cloud networking in high-availability production environments.
- Deep knowledge of TCP/IP, HTTP/HTTPS, TLS, DNS, routing, NAT, and load balancing.
- Practical AWS networking expertise including VPC, Transit Gateway, and Security Groups.
- Experience managing WAFs and edge security controls for web applications and APIs.
- Background in firewall management, specifically FortiGate.
- Proficiency with Infrastructure as Code tools like Terraform, CloudFormation, or Ansible.
- Experience with monitoring stacks such as ELK, New Relic, or Coralogix.
- Linux administration and command-line troubleshooting skills.
- Experience with NGINX, HAProxy, or Squid proxies.
- Understanding of network segmentation and secure change management.
- Proficiency in English for technical documentation and cross-team collaboration.
Nice to have
- Multi-cloud networking experience across AWS, GCP, or Azure.
- Familiarity with PCI-DSS or SOX regulatory requirements.
- Background in fintech, banking, or global e-commerce environments.
- Experience with zero-trust architectures or multi-provider WAF failover.
- AWS certifications such as Advanced Networking, Solutions Architect, Security, or DevOps Engineer.
Skills & tools
- AWS Networking (VPC, Transit Gateway, Route 53, Network Firewall)
- FortiGate
- WAF and Edge Security
- Terraform, Ansible, CloudFormation
- ELK, New Relic, Coralogix
- NGINX, HAProxy, Squid
- Linux
- CI/CD pipelines
Practical notes
- Benefits include flexible schedules, a referral bonus program, and a social budget for team activities.
- Employees have access to dLocal Houses for international coworking.
- The company prioritizes performance and impact over fixed hours.
- The recruitment process involves a CV review followed by email updates at each stage.