Network Security Engineer
You design and govern network security architecture across AI data centers, manage access policies, automate compliance validation, secure endpoints and remote access, detect lateral movement, protect infrastructure and network edges, and provide evidence for security audits.
Responsibilities
- Own network trust models and segmentation across multiple AI data centers
- Govern firewall, security-group, and ZTNA policy lifecycles
- Build policy drift detection and compliance-validation automation
- Design endpoint-to-data-center access controls
- Route privileged access through PAM, bastions, and MFA
- Establish traffic baselines and lateral-movement detection
- Harden fabric, management, and storage networks
- Own perimeter protection and DDoS mitigation
- Provide network-layer control mappings and audit evidence
Requirements
- 5+ years of network security engineering experience
- Hands-on cloud and data center network security experience
- Command of network segmentation, Zero Trust, firewall policies, security groups, ZTNA, and SASE
- Familiarity with public and private cloud network security
- Policy-as-Code and automation skills using Terraform, Ansible, Python, or Go
- Experience with network monitoring, flow analysis, and lateral-movement detection
- AI data center or GPU cluster networking experience
- Familiarity with InfiniBand, RoCE, or UFM
- Experience with eBPF-based observability
- CISSP, CCNP Security, or equivalent certification
- Working proficiency in Chinese and English
Benefits
- Training and mentoring