Staff Security Engineer, Network Security

Weights & Biases Weights & Biases · Data AI · Bellevue, WA +3 · Technology

Staff Network Security Engineer responsible for architecting the defense of global backbone, edge, and massive-scale GPU clusters. Focuses on engineering security into the network fabric through automation, telemetry, and protocol analysis, rather than just configuring firewalls. Involves developing automation frameworks for network security, integrating security into CI/CD pipelines, and providing security recommendations for network architecture.

What you'd actually do

  1. Conducting architecture reviews, protocol analysis, and design assessments to proactively identify and fix vulnerabilities in our backbone and data center fabrics.
  2. Developing robust, repeatable frameworks for network security automation (CoPP, ACL generation, Route Filtering) that make it easy for teams to build securely from day one.
  3. Collaborating closely with Network Engineering teams to integrate security checks and validation seamlessly into their CI/CD and config-push pipelines.
  4. Crafting clear, practical security guidance and documentation that empowers engineers to deploy secure routing policies and topologies.
  5. Actively participating in architectural discussions regarding peering, transit, and traffic engineering, providing insightful security recommendations.

Skills

Required

  • Network Engineering
  • Infrastructure Security
  • ISP/Backbone operations
  • BGP
  • OSPF/IS-IS
  • TCP/IP
  • network automation
  • security tooling
  • Go
  • Python
  • multi-vendor environments
  • Linux networking internals
  • control plane protection
  • infrastructure as code

Nice to have

  • hyperscale network architectures
  • CLOS fabrics
  • MPLS/EVPN
  • VXLAN
  • high-performance computing
  • hardware-level networking security
  • SmartNICs/DPUs
  • connectX
  • flow-based telemetry analysis
  • internet routing security standards
  • RPKI
  • MANRS
  • DDoS mitigation strategies
  • Infiniband
  • RoCE

What the JD emphasized

  • engineer security into the network fabric itself
  • security into the network fabric
  • network security automation
  • security checks and validation
  • secure routing policies and topologies
  • security recommendations