Cloud Network & Edge Security Engineer

dLocal

Barcelona

Presencial

EUR 90.000 - 120.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible schedule
Fintech environment
Referral bonus
Work From Anywhere: travel up to 3+3

Descripción de la vacante

dLocal is seeking a Senior Network & Edge Security Engineer in Barcelona, Spain, to design, operate, and secure our global cloud and hybrid network perimeter. You will own secure connectivity, WAF and firewall controls, and automation at scale, collaborating with Platform, Information Security, Compliance, and Product teams to keep critical services secure, available, and low‑latency.

The role emphasizes edge‑security mastery, AWS networking, FortiGate management, and IaC-driven operations, with

Formación

  • Experience designing, operating, and troubleshooting cloud networking in production.
  • Strong grasp of edge security controls and web application protection.
  • Experience with IaC and CI/CD integration for network changes.

Responsabilidades

  • Design, implement, and operate secure, resilient network solutions across cloud and hybrid environments.
  • Own and improve edge-security stack including cloud WAFs and firewalls.
  • Define and tune WAF/firewall rules; reduce noise while maintaining protection.
  • Operate AWS networking services: VPCs, subnets, Route 53, Transit Gateway, VPC peering, NACLs.
  • Coordinate third‑party connectivity and VPNs; support routing and failover.
  • Manage FortiGate‑based services, VPNs, security policies, NAT, and logs.
  • Build end‑to‑end observability with logs, dashboards, alerts, and traffic analysis.
  • Drive network infrastructure as code; integrate changes into CI/CD pipelines.
  • Automate onboarding/offboarding, policy lifecycles, and WAF provider failovers.
  • Lead incident response for network/edge events; coordinate DR and postmortems.
  • Collaborate with Security and Compliance to meet PCI/SOX requirements.
  • Document architectures, flows, standards, and runbooks for rapid team enablement.

Conocimientos

Cloud networking design
Edge security
WAF & firewall management
Terraform / CI/CD automation
Network observability & telemetry
TCP/IP / HTTP / TLS knowledge
Linux administration
English communication

Herramientas

AWS networking services
FortiGate
Terraform
CloudFormation
Ansible
ELK / Observability stacks
New Relic

Descripción del empleo

Why Join dLocal?

dLocal is the financial infrastructure powering global commerce in the world's fastest-growing markets. The biggest companies in the world trust us to unlock growth in 60+ countries across emerging markets—moving money where others see complexity. We don't just process payments; we are architects of payment ecosystems and partners in our customers' expansion. You'll work alongside 1,300+ teammates from 40+ nationalities and tackle global challenges from day one.

Why Join dLocal?

dLocal is the financial infrastructure powering global commerce in the world's fastest-growing markets. The biggest companies in the world trust us to unlock growth in 60+ countries across emerging markets—moving money where others see complexity. We don't just process payments; we are architects of payment ecosystems and partners in our customers' expansion. You'll work alongside 1,300+ teammates from 40+ nationalities and tackle global challenges from day one.

What’s the opportunity?

We are looking for a Senior Network & Edge Security Engineer to help design, operate, and evolve dLocal’s global cloud and hybrid network perimeter. This role combines deep cloud networking expertise with a strong security mindset: you will own secure connectivity, traffic protection, WAF and firewall controls, and the automation that makes those services reliable at scale. You will work closely with Platform, Information Security, Compliance, and Product teams to keep critical services secure, available, low-latency, and ready for international growth.

What You’ll Do
  • Design, implement, and operate secure, resilient, and scalable network solutions across cloud and hybrid environments, with a focus on availability, latency, disaster recovery, and operational simplicity.
  • Own and continuously improve our edge-security stack, including cloud WAFs, network firewalls, proxies, load balancers, and traffic‑routing policies that protect public APIs, frontends, and internal services.
  • Define, tune, and maintain WAF and firewall rules, policies, and traffic flows; proactively reduce noise and false positives while preserving effective protection against attacks.
  • Design and operate AWS networking services such as VPCs, subnets, route tables, Transit Gateway, VPC peering, Route 53, load balancers, security groups, Network ACLs, and AWS Network Firewall.
  • Coordinate, implement, and support third‑party connectivity, including IPsec/SSL VPNs, leased lines, partner interconnections, routing, DNS, and failover paths.
  • Manage FortiGate‑based services, including IPsec and SSL VPNs, security policies, virtual IPs/servers, NAT, routing, and log analysis.
  • Build and maintain end‑to‑end HTTP/HTTPS and network observability using logs, metrics, dashboards, alerting, synthetic checks, and traffic analysis to identify performance degradation, misconfigurations, and security events early.
  • Drive network and security infrastructure as code using Terraform or similar tools, integrating changes into CI/CD pipelines so they are repeatable, auditable, tested, and secure across environments.
  • Automate network and edge‑security workflows such as site onboarding and decommissioning, rule and policy lifecycle management, partner connectivity, configuration validation, and controlled WAF‑provider failovers.
  • Lead and actively participate in incident response for network, connectivity, WAF, and edge‑security events; execute DR procedures, coordinate controlled failovers, and drive postmortems and remediation actions.
  • Partner with Information Security and Compliance to ensure network and edge controls support regulatory and industry requirements, including PCI and SOX, and provide audit‑ready evidence when needed.
  • Maintain clear, actionable documentation for architectures, traffic flows, standards, operational procedures, and runbooks so other engineering teams can move quickly and safely.
What We Need You To Have
  • Solid hands‑on experience designing, operating, and troubleshooting cloud networking in production environments with high availability and security requirements.
  • Strong knowledge of TCP/IP, HTTP/HTTPS, TLS, DNS, routing, NAT, load balancing, proxies, VPN/IPsec, and network troubleshooting practices.
  • Practical experience with AWS networking services, including VPC, subnets, route tables, Route 53, load balancers, Transit Gateway, VPC peering, security groups, Network ACLs, and AWS Network Firewall.
  • Hands‑on experience managing WAFs and/or edge‑security controls protecting web applications and APIs; experience in multi‑provider environments is a plus.
  • Experience managing firewalls, ideally FortiGate, including VPNs, security policies, virtual IPs, routing, and log analysis.
  • Experience with Infrastructure as Code and automation tools such as Terraform, CloudFormation, Ansible, or similar, and the ability to integrate infrastructure changes into CI/CD workflows.
  • Experience with monitoring and observability platforms such as ELK, New Relic, Coralogix, or similar; ability to build actionable dashboards and alerts for latency, errors, throughput, availability, and anomalous traffic patterns.
  • Linux administration fundamentals and practical command‑line troubleshooting skills.
  • Experience with HTTP/TCP proxies and reverse proxies, such as NGINX, HAProxy, or Squid.
  • Strong understanding of cloud‑security best practices, network segmentation, least privilege, and secure change‑management practices.
  • Strong written and spoken English, with the ability to document technical decisions and collaborate effectively across Networking, Security, Platform, Product, and external partn
Would be awesome if you had
  • Experience with AWS, GCP, Azure, or multi‑cloud networking and security architectures.
  • Exposure to PCI‑DSS, SOX, or other regulated‑industry security and compliance requirements.
  • Experience operating in high‑criticality environments such as payments, fintech, banking, or global e‑commerce, where uptime, resilience, and latency are essential.
  • Experience designing disaster‑recovery strategies, multi‑provider WAF failover, or zero‑trust network architectures.
  • AWS certifications such as AWS Certified Advanced Networking - Specialty, Solutions Architect, Security - Specialty, or DevOps Engineer.
What do we offer?

Besides the tailored benefits we have for each country, dLocal will help you thrive and go that extra mile by offering you:

  • Flexibility in how you work: We focus on impact and productivity over fixed hours. This means our teams have flexible schedules and, depending on your role and location, you will combine self‑managed focus time with moments of in‑person connection in our collaboration hubs.
  • Fintech industry: work in a dynamic and ever‑evolving environment, with plenty to build and boost your creativity.
  • Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded.
  • Work From Anywhere: Team members can work while traveling for up to 3 months every year.
What happens after you apply?

Our Talent Acquisition team is invested in creating the best candidate experience possible, so don’t worry, you will definitely hear from us. We will review your CV and keep you posted by email at every step of the process!

Also, you can check out our webpage, Linkedin and Youtube for more about dLocal! We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cloud Network & Edge Security Engineer
Cloud Network & Edge Security Engineer

dLocal • Madrid

Presencial
EUR 90.000 - 120.000
Flexibility in how you work
Fintech industry exposure
Referral bonus program
+1
Cloud Network & Edge Security Engineer
Cloud Network & Edge Security Engineer

Dlocal • Bellprat

Híbrido
EUR 90.000 - 130.000
Flexible hours
Fintech environment
Referral bonus program
+3
Principal Security Engineer – Identity & Access
Principal Security Engineer – Identity & Access

dLocal • Madrid

Híbrido
EUR 120.000 - 180.000
Flexible schedules
Referral bonus program
Social budget
+1
DevOps Engineer CI/CD
DevOps Engineer CI/CD

dLocal • Barcelona

Híbrido
EUR 60.000 - 110.000
Flexibility
Fintech industry
Referral bonus program
+2
DevOps Engineer CI/CD
DevOps Engineer CI/CD

dLocal • Madrid

Presencial
EUR 60.000 - 90.000
Flexibility in schedules
Fintech industry
Referral bonus program
+2
Staff Engineer
Staff Engineer

dLocal • Barcelona

Híbrido
EUR 110.000 - 140.000
Flexibility in schedules
Fintech industry exposure
Referral bonus program
+2
Head of Platform Engineering
Head of Platform Engineering

dLocal • Madrid

Presencial
EUR 90.000 - 130.000
Flexible schedules
Fintech industry exposure
Referral bonus program
+1
Platform Architect
Platform Architect

dLocal • Madrid

Híbrido
EUR 90.000 - 120.000
Flexible work hours
Work from anywhere
Referral bonus program
+1
Cloud Architect
Cloud Architect

dLocal • Madrid

Presencial
EUR 90.000 - 130.000
Flexible schedules
Referral bonus program
Training budget
Staff Engineer - Java
Staff Engineer - Java

dLocal • Madrid

Presencial
EUR 85.000 - 120.000