14 ago
|
dLocal
|
Barcelona
Who you are
- Solid hands-on experience designing, operating, and troubleshooting cloud networking in production environments with high availability and security requirements
- Strong knowledge of TCP/IP, HTTP/HTTPS, TLS, DNS, routing, NAT, load balancing, proxies, VPN/IPsec, and network troubleshooting practices
- Practical experience with AWS networking services, including VPC, subnets, route tables, Route 53, load balancers, Transit Gateway, VPC peering, security groups, Network ACLs, and AWS Network Firewall
- Hands-on experience managing WAFs and/or edge-security controls protecting web applications and APIs;
experience in multi-provider environments is a plus
- Experience managing firewalls, ideally FortiGate, including VPNs, security policies, virtual IPs, routing, and log analysis
- Experience with Infrastructure as Code and automation tools such as Terraform, CloudFormation, Ansible, or similar, and the ability to integrate infrastructure changes into CI/CD workflows
- Experience with monitoring and observability platforms such as ELK, New Relic, Coralogix, or similar; ability to build actionable dashboards and alerts for latency, errors, throughput, availability, and anomalous traffic patterns
- Linux administration fundamentals and practical command-line troubleshooting skills
- Experience with HTTP/TCP proxies and reverse proxies, such as NGINX, HAProxy, or Squid
- Strong understanding of cloud-security best practices, network segmentation, least privilege, and secure change-management practices
- Strong written and spoken English, with the ability to document technical decisions and collaborate effectively across Networking, Security, Platform, Product, and external partners
What the job involves
- We are looking for a Senior Network & Edge Security Engineer to help design, operate, and evolve dLocal’s general cloud and hybrid network perimeter.
- This role combines deep cloud networking expertise with a strong security mindset: you will own secure connectivity, traffic protection, WAF and firewall controls, and the automation that makes those services reliable at scale.
- You will work closely with Platform, Information Security, Compliance, and Product teams to keep critical services secure, available, low-latency, and ready for international growth
- Design, implement, and operate secure, resilient, and scalable network solutions across cloud and hybrid environments, with a focus on availability, latency, disaster recovery, and operational simplicity
- Own and continuously improve our edge-security stack, including cloud WAFs, network firewalls, proxies, load balancers, and traffic-routing policies that protect public APIs, frontends, and internal services
- Define, tune, and maintain WAF and firewall rules, policies, and traffic flows; proactively reduce noise and false positives while preserving effective protection against attacks
- Design and operate AWS networking services such as VPCs, subnets, route tables, Transit Gateway, VPC peering, Route 53, load balancers,
security groups, Network ACLs, and AWS Network Firewall
- Coordinate, implement, and support third-party connectivity, including IPsec/SSL VPNs, leased lines, partner interconnections, routing, DNS, and failover paths
- Manage FortiGate-based services, including IPsec and SSL VPNs, security policies, virtual IPs/servers, NAT, routing, and log analysis
- Build and maintain end-to-end HTTP/HTTPS and network observability using logs, metrics, dashboards, alerting, synthetic checks, and traffic analysis to identify performance degradation, misconfigurations, and security events early
- Drive network and security infrastructure as code using Terraform or similar tools, integrating changes into CI/CD pipelines so they are repeatable, auditable, tested, and secure across environments
- Automate network and edge-security workflows such as site onboarding and decommissioning, rule and policy lifecycle management, partner connectivity, configuration validation, and controlled WAF-provider failovers
- Lead and actively participate in incident response for network, connectivity, WAF, and edge-security events; execute DR procedures, coordinate controlled failovers, and drive postmortems and remediation actions
- Partner with Information Security and Compliance to ensure network and edge controls support regulatory and industry requirements, including PCI and SOX, and provide audit-ready evidence when needed
- Maintain clear, actionable documentation for architectures, traffic flows, standards, operational procedures, and runbooks so other engineering teams can move quickly and safely
📌 Platform Architect (Barcelona)
🏢 dLocal
📍 Barcelona