Network Security Engineer
Job description
About the role
SpaceXAI is actively seeking a Senior Network Security Engineer to integrate into its rapidly evolving security operations team. This specific role owns the design, implementation, and maintenance of network security architectures that protect critical AI and cloud-native infrastructure. The hired individual will operate at the intersection of network engineering and security defense, ensuring the integrity and availability of complex routing and switching environments. They will be responsible for bridging the gap between theoretical security policies and their practical execution on physical and virtual network fabrics. Success in this position requires a high degree of autonomy and the ability to dissect intricate security problems under pressure. The role demands constant adaptation to emerging threats and the flexibility to manage concurrent projects without sacrificing attention to detail. As a key member of the security team, this engineer will directly influence the security posture of the organization's foundational network layers.
Key facts
What you'll do
Monitor network traffic patterns across hybrid cloud environments using advanced analysis to detect anomalies indicative of potential compromise.
Architect and propose robust network security solutions that solve complex routing and switching vulnerabilities while maintaining high availability standards.
Oversee the lifecycle management of security appliances, ensuring firewalls, switches, and routers receive timely patches and firmware updates.
Serve as the central escalation authority for critical network security incidents, providing technical leadership and guidance during crisis situations.
Deploy new physical and virtual network security devices such as firewalls, switches, routers, and intrusion prevention systems as infrastructure scales.
Champion the maintenance of precise and current documentation for all security configurations and change management procedures.
Configure and maintain strict firewall rules and access control lists to enforce the principle of least privilege across the enterprise network.
Leverage deep expertise in routing protocols like BGP and OSPF to secure the network against route hijacking and ensure optimal traffic flow.
Utilize network analysis tools such as Wireshark and tcpdump to investigate security events and conduct deep packet inspections.
Collaborate closely with cloud engineering teams to secure network traffic within AWS, GCP, and Azure platforms, specifically VPCs and Security Groups.
Evaluate emerging network security vendors including Cisco, Juniper, and Palo Alto Networks to determine the best fit for organizational needs.
Automate repetitive security tasks using scripting languages like Python or Bash to increase operational efficiency and reduce human error.
Maintain a detailed understanding of network switching technologies to ensure secure segmentation and micro-segmentation strategies are effective.
Act as a subject matter expert providing consultation on network security best practices for routing, VPNs, and access control policies.
Requirements
Applicants must hold a Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a closely related technical field.
Candidates must possess 4 or more years of hands-on experience specifically in network security engineering roles.
A demonstrable history of practical experience with switching and routing technologies is mandatory for consideration.
Prospective team members must have a proven understanding of core network security principles and standard protocols including TCP/IP.
Comprehensive knowledge of VLANs, ACLs, and secure routing methodologies is required to design secure network topologies.
Applicants must show proficiency in at least one major public cloud platform, specifically AWS, GCP, or Azure, and their associated network security services.
Experience with network analysis tools like Wireshark and tcpdump is essential for diagnosing complex security issues.
Familiarity with industry-standard vendors such as Cisco, Juniper, and Palo Alto Networks is a strict requirement.
Comfort with scripting and automation using Python or Bash is necessary to manage security operations at scale.
The candidate must be a U.S. citizen or national, U.S. lawful permanent resident, Refugee, or Asylee.
Individuals must be eligible to obtain the necessary authorizations from the U.S. Department of State due to ITAR regulatory requirements.
Candidates must be able to pass thorough background checks and meet all compliance standards required for the role.
Nice to have
Holding certifications such as CISA, CRISC, CGEIT, Security+, CASP+, CCNP Security, CCIE Security, JNCIP-SEC, or PCNSE is highly valued.
Experience operating within multi-cloud environments is preferred, particularly when utilizing Infrastructure as Code tools like Terraform for network provisioning.
Knowledge of DevSecOps practices and how to integrate security seamlessly into network operations is regarded as an asset.
Prior experience building custom tools or integrations that enhance network security operations will be viewed favorably.
An interest in leveraging AI technologies for network threat detection and security automation is encouraged.
Contributions to open-source projects related to network security or infrastructure tools are considered a significant advantage.
Practical notes
SpaceXAI offers a comprehensive total rewards package, including equity, medical, vision, and dental coverage, a 401(k) retirement plan, short & long-term disability insurance, life insurance, and other discounts and perks.
Applicants must be authorized to work in the United States for this position.
This role is based in Palo Alto, California, and requires physical presence.
The listed compensation range is $100,000 to $258,000 USD, subject to experience and qualifications.