Senior Network Engineer - Application Delivery & Security
2 нед. назад
USASeniorHybrid
f5network architectureload balancingssltlsautomationddos mitigation
Lead the deployment and operation of a global F5 application delivery and security platform with focus on architecture, provisioning, and automation.
Обязанности
- The Network Engineering team at designs and operates our low-latency global backbone and the network services layered on top of it.
- This role leads the rollout and ongoing operation of our F5 application delivery and security platform across 25+ points of presence — global server load balancing, L4–L7 application delivery and SSL/TLS termination, WAF, and DDoS mitigation — for a multi-tenant, service-provider environment. You'll own the F5 fleet end to end: architecture and standardization, device onboarding and provisioning at scale, day-to-day operations, and automation.
- This role reports to the Principal Network Architect. Title and level will be calibrated to your experience, technical depth, and demonstrated scope of ownership.
- Drive the global deployment of our F5 platform across 25+ points of presence, establishing standardized, repeatable designs for application delivery and security
- Work with the broader Network and Software Engineering teams to build and improve customer self-service experiences for F5 delivered services
- Architect and operate global server load balancing with BIG-IP DNS (GTM) — anycast, wide IPs, and topology / geolocation-based steering with health-driven failover across POPs
- Design, deploy, and tune L4–L7 load balancing and SSL/TLS termination (LTM), including traffic profiles, certificate management, and iRules for advanced traffic handling
- Build and operate WAF (F5 Advanced WAF / ASM) and DDoS mitigation (AFM and behavioral L3–L7 defenses) to protect multi-tenant customer workloads
- Integrate F5 with the routing layer via BGP — route health injection and anycast VIP advertisement into our global backbone
- Onboard, provision, and manage the F5 fleet at scale using custom provisioning, control, and automation (iControl REST, Ansible, Python)
- Improve reliability through observability (F5 Telemetry Streaming into our metrics and logging stack), alerting, incident response, and postmortems
Требования
- Deep, hands-on experience designing and operating F5 BIG-IP in production, including LTM (L4–L7 load balancing and SSL/TLS termination) and iRules
- Strong applied networking fundamentals across the L2–L7 path — TCP/IP, DNS, HTTP/HTTPS, and TLS
- Working knowledge of BGP and dynamic routing, and how they integrate with application delivery (e.g., route health injection, anycast)
- F5 automation experience (iControl REST and/or declarative config via AS3 and Declarative Onboarding)
- Configuration management (Ansible) and/or scripting experience (Python, bash)
- Comfortable working in a fast-paced, results-oriented environment
- Committed to operational best practices and security by design
- A balance of AI-assisted development and actual understanding of the technologies in use.
Будет плюсом
- You do not need all of these — depth in a few areas plus strong fundamentals is sufficient:
- F5 experience in a service or hosting provider environment specifically — multi-tenant design, automation-first operations, and scalable, secure delivery (as distinct from single-tenant enterprise)
- Global server load balancing at scale with BIG-IP DNS / GTM
- WAF policy design and tuning, including bot defense, with F5 Advanced WAF / ASM
- DDoS mitigation across L3–L7 (AFM, DDoS Hybrid Defender, behavioral DoS)
- Multi-tenant isolation using vCMP, route domains, and partitions
- Fleet management and centralized operations of F5 Systems
- Infrastructure-as-code and GitOps for network / ADC configuration (Terraform F5 provider, CI/CD pipelines for config)
- Operating and upgrading F5 platforms at scale (TMOS lifecycle; rSeries / VELOS / F5OS or BIG-IP Next a plus)
- NGINX and/or F5 Distributed Cloud (XC) experience
- F5 certification (e.g., F5 Certified Technology Specialist / CTS, or higher)
- Demonstrated ability to design and operate automation-first infrastructure at scale
Условия
- Along with a competitive pay scale, full-time employees are eligible for the following benefits:
- Health, Dental, and Vision Insurance
- 401(k) with company profit sharing
- PTO and 11 Company Paid Holidays
Другое
- Engineered to outperform, is on a mission to provide high-performance infrastructure services for critical workloads. With 25+ datacenter locations around the world interconnected by our low latency global backbone network, we are the class leader in performance bare metal hosting and rapidly expanding into additional infrastructure services.
- Participate in an on-call system supporting critical production systems.
- Preference given to full-time onsite candidates in Pittsburgh, PA, followed by hybrid candidates.