07 ago
|
SHARE
|
Barcelona
About ShareShare is a venture-backed internet infrastructure network building Africa's backbone. The company aggregates underutilized telecom infrastructure, fiber, subsea cables, and data centers, and provides ISPs with scalable access to bandwidth without traditional upfront costs. Share's network spans thousands of kilometers of fiber, 12 infrastructure providers, and 10 data centers, reaching over 8 million people across East Africa.About ShareShare is a venture-backed internet infrastructure network building Africa's backbone. The company aggregates underutilized telecom infrastructure, fiber, subsea cables, and data centers, and provides ISPs with scalable access to bandwidth without traditional upfront costs. Share's network spans thousands of kilometers of fiber, 12 infrastructure providers, and 10 data centers, reaching over 8 million people across East Africa.At the network level, Share operates a RADIUS proxy architecture that authenticates ISP subscribers, provisions their internet access, and coordinates with partner BNG (Broadband Network Gateway) equipment. The platform must coexist with existing ISP infrastructure, not replace it. This means every deployment involves real BNG configuration, real RADIUS authentication, and real subscriber traffic.This role sits at the intersection of network engineering and systems engineering. You will own Share's systems function end to end — the infrastructure that makes internet access work for our partner ISPs, and the team you'll build to run it as we scale.The roleWe are hiring a VP of Systems Engineering to build, own and lead Share's network-facing infrastructure: the Free RADIUS proxy servers that authenticate ISP subscribers, the provisioning pipeline that pushes credentials and plan attributes to per-partner RADIUS servers, the BNG integration layer, and the deployment and monitoring of all systems infrastructure. You will work directly with the network team (who handle ISP-side BNG configuration) and the software team (who build the APIs that drive provisioning).This is a player-coach role. You are hands-on today;
you will configure FreeRADIUS servers, write deployment scripts, troubleshoot authentication failures on production networks, and design the infrastructure that scales from 10 ISP clients to 500. And as Share grows, you will hire and lead the systems engineering team, set the technical standard they work to, and own the roadmap for how our infrastructure is built and run. You are the person the team calls when a subscriber can't authenticate or when a new ISP's BNG doesn't behave as expected — and the person who decides how we solve it at scale.What You Will Own failover to partner pool) to determine whether a subscriber is Share-managed or partner-managed. You will own the configuration, deployment, monitoring, and scaling of this architecture.Per-partner Free RADIUS servers: Each ISP partner gets a dedicated Free RADIUS instance with a Hono API overlay for programmatic CRUD of subscriber credentials and plan attributes. You will manage these instances, their database backends, and their API endpoints.BNG integration support:
Work with the network team to define and validate the BNG-side configuration changes required for each ISP partner (RADIUS pointer, Share-specific subnet, source-based routing, pool configuration). You are the bridge between the software platform and the ISP's physical infrastructure.Provisioning pipeline: The software platform's Provisioning service pushes subscriber credentials and plan attributes to Free RADIUS. You own the receiving end — ensuring the Free RADIUS API, database, and RADIUS configuration are correct and performant.Infrastructure and deployment: Server provisioning, deployment automation, monitoring, logging, and security for all systems infrastructure. Git Hub Actions pipelines, SSH-based deployments, VM A (Change of Authorization): Design and implement the Co A endpoint on per-partner Free RADIUS servers for real-time plan changes and session disconnects without re-authentication.Team and technical leadership: Set the standards, runbooks, and architecture for Share's systems function. Hire, mentor, and lead the systems engineering team as we scale, and represent systems engineering in technical and cross-functional decisions.Technical environmentRADIUS and network authenticationFree RADIUS (v3 in production, v4 evaluation in progress) - proxy configuration, virtual servers, module configuration (sql, rest, files)RADIUS protocols: Access-Request/Accept/Reject, Accounting (Start/Interim/Stop), Co A (Disconnect-Request, Co A-Request) response with speed/pool/timeout attributesMikro Tik Router OS BNG configuration (the network team handles this, but you need to understand the RADIUS-facing side)Per-user flat attributes (speed, IP pool, session timeout) pushed via Hono API to Free RADIUS SQL backendSystems and infrastructureLinux server administration (Ubuntu)Docker containerization for Free RADIUS instances and supporting servicesHono (lightweight Node.Js framework) for the Free RADIUS API overlayPostgre SQL for RADIUS user databases (radcheck, radreply, radacct tables)Git Hub Actions for CI/CD, SSH-based deployment to VMsMonitoring: Loki + Pino for structured logging, Sentry for error trackingIntegration points with the software platformNest JS Provisioning microservice calls your Free RADIUS API to push/update/delete subscriber credentialsKafka events trigger provisioning actions (PROVISION_SUBSCRIBER, UPDATE_PLAN_ATTRIBUTES, DELETE_RADIUS_CREDENTIALS)The proxy's routing decision (Share vs partner) determines the subscriber's billing pathRequirementsNon-negotiable8+ years of professional systems engineering or network engineering experience, including having owned the RADIUS/network-authentication function end to end in a production ISP or telecommunications environment (Free RADIUS, Radiator, or NPS),
and having led or mentored other engineers.Deep Free RADIUS expertise. You can configure virtual servers, write unlang policies, set up proxy realms, configure SQL modules, and debug authentication failures from packet captures.Strong Linux systems administration. You manage production servers, write deployment scripts, configure firewalls, and troubleshoot networking issues at the OS level.Understanding of PPPo E authentication, DHCP, IP pool management, and how BNGs interact with RADIUS servers. You don't need to be a Mikro Tik expert, but you need to understand what the BNG expects from RADIUS.Experience deploying and managing infrastructure in production — not just dev environments. You understand uptime requirements, failover, and what happens when a RADIUS server goes down (subscribers can't authenticate).Comfortable with scripting and light application development. You don't need to be a full-stack developer, but you should be able to write and maintain a Hono/Express API, work with SQL databases, and automate deployments.PreferenceExperience in East African ISP or telecommunications infrastructure. Understanding of the operational realities: Mikro Tik-dominant networks, mixed vendor environments, bandwidth constraints, and the practical challenges of managing subscriber authentication at scale in this market.Experience with Free RADIUS proxy configurations (proxying between multiple RADIUS servers with failover logic).Experience with Co A (Change of Authorization) and Disconnect-Message implementation.Docker and container orchestration for networking services.Experience working alongside software engineering teams — you can read a Nest JS service, understand an event-driven architecture diagram, and communicate technical constraints clearly to developers.AI-augmented Engineering (required Mindset)Share operates with AI tools as a core part of engineering workflows. This applies to systems engineering as much as software development. Our infrastructure documentation, configuration templates, troubleshooting runbooks, and deployment scripts are all developed with AI assistance.What this means for you:You use AI tools (LLMs, Agents, etc.) for configuration generation, troubleshooting, documentation, and scripting. You don't memorize Free RADIUS syntax but rather know what you need and use AI to get there faster.You are comfortable with AI-generated specifications and can validate them against real-world behavior. When a spec says "configure source-based routing on the BNG", you know whether that's correct for Mikro Tik and can flag when it's not.You see AI as a way to handle the breadth of systems knowledge required for this role (RADIUS, Linux, networking, databases, deployment, monitoring).You contribute to the team's AI workflows by writing clear, structured documentation that both humans and AI can work with.What we offerCompetitive salary and meaningful equity in a mission-driven, investor-backed company (US-incorporated).A seat at the table while we build the technical backbone for the next-generation of telecommunications.A fast-paced, high-ownership environment.
📌 Vp Of Systems Engineer (Barcelona)
🏢 SHARE
📍 Barcelona