DNS Engineer - SRE

Optimum

Bethpage (NY)

Hybrid

USD 83,538 - 137,241

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Optimum is seeking a DNS Engineer – SRE to own the architecture, reliability, and scalability of our DNS infrastructure powering ISP and core network services. You will apply SRE principles, automation, and observability to deliver carrier‑grade availability for millions of users.

The role collaborates with Product, Security, and Service Assurance teams; candidates should have hands‑on DNS, networking, and Linux skills, plus experience with DNSSEC, DoH/DoT, and modern tooling.

Qualifications

  • Bachelor’s degree in Computer Science, Telecommunications, or related field (or equivalent practical experience).
  • 5+ years in networking or systems engineering with SRE focus in production environments.
  • Hands‑on experience configuring and maintaining DNS servers (BIND/Unbound/PowerDNS/AWS Route53/Azure DNS).
  • Understanding of TCP/IP and DNSSEC; experience with DoH/DoT is preferred.

Responsibilities

  • Architect global DNS architectures with high availability and automated failover.
  • Lead vendor relationships for DNS infrastructure and set roadmaps.
  • Oversee DNS platform lifecycle, automated deployments, and capacity planning.
  • Define DNS standards, security protocols (DNSSEC), and traffic policies.
  • Establish SLOs and error budgets for core name services.
  • Manage protocol nuances (UDP/TCP 53, recursion vs. iteration).
  • Implement DNS security measures and DDoS mitigation strategies.
  • Automate operations with Python/Go, Ansible, or Terraform.
  • Monitor with Prometheus, Grafana, and dnstap; analyze NXDOMAIN/SERVFAIL.

Skills

DNS
SRE
Automation
Linux/Unix
Python/Go
Observability

Education

Bachelor's degree in CS or related field

Tools

BIND
Unbound
PowerDNS
AWS Route53
Azure DNS
Terraform
Ansible
Prometheus

Job description

Job Summary

The Role DNS Engineer – SRE is a high‑impact role responsible for the architecture, scalability, and reliability of the mission‑critical DNS infrastructure powering our ISP and core network services. This position is designed for an engineer who views infrastructure through the lens of Site Reliability Engineering (SRE), prioritizing automation, observability, and self‑healing systems over manual intervention. You will combine deep IP networking and DNS expertise with modern security protocols to ensure our platforms remain resilient against evolving threats and perform at the highest level for millions of users. This is a collaborative and influential role that will lead cross‑functional initiatives with Product, Security, and Service Assurance teams to deliver a carrier‑grade DNS ecosystem, balancing cutting‑edge privacy standards (DoH/DoT) with the uncompromising availability required by Tier‑1 network operations.

Responsibilities
  • Core Platform Strategy & Leadership
    • Architectural Ownership: Lead the design and evolution of global DNS architectures, ensuring high availability through Anycast routing, multi‑provider redundancy, and automated failover mechanisms.
    • Strategic Vendor Relations: Act as the primary technical authority in engagements with DNS and infrastructure vendors, driving roadmaps that align with our long‑term reliability and security goals.
    • Lifecycle & Capacity Management: Oversee the full lifecycle of DNS platforms—including automated software deployments, hardware refreshes, and proactive capacity planning—to stay ahead of traffic growth.
    • Standardization & Policy: Optimize, define, and enforce organization‑wide standards for DNS record management, security protocols (DNSSEC), and traffic steering policies to optimize user latency.
    • Reliability Engineering: Convert "Strategic Design" into "Operational Reality" by defining Service Level Objectives (SLOs) and Error Budgets for all core name services.
  • Cross‑Domain DNS Operations & SRE
    • Protocol Management: Manage the nuances of UDP/TCP port 53, recursion vs. iteration, and complex record types (A, AAAA, CNAME, MX, TXT, SRV).
    • Security & Mitigation: Implement and manage DNSSEC to prevent cache poisoning; act as a subject matter expert in mitigating DDoS and DNS amplification attacks.
    • Automation (Eliminating Toil): Replace manual updates and "pool" management with automated workflows using Python, Go, Ansible, or Terraform.
    • Performance Tuning: Perform Linux kernel tuning for high‑performance network throughput and conduct deep‑dive log analysis on systems like BIND, Unbound, or PowerDNS.
    • Observability: Utilize Prometheus, Grafana, and dnstap to monitor query rates and latency, providing actionable insights into error codes (NXDOMAIN, SERVFAIL).
Minimum Qualifications
  • Education: Bachelor’s degree in Computer Science, Telecommunications, or a related field (or equivalent practical experience in networking and security).
  • Experience: 5+ years in a networking or systems engineering role, with a focus on SRE principles (automation, reliability, and monitoring) in production environments.
  • DNS Fundamentals: Hands‑on experience configuring and maintaining at least two of the following: BIND, Unbound, PowerDNS, AWS Route 53, or Azure DNS.
  • Networking Protocols: Functional understanding of TCP/IP (IPv4/IPv6) and DNS‑specific protocols including DNSSEC and encrypted transport (DoH/DoT).
  • Systems & Automation: Strong Linux/Unix administration skills and proficiency in at least one scripting language (Python, Bash, or Go) for task automation.
  • Observability: Experience using Grafana and OpenTelemetry (or similar tools) to monitor service health and performance.
Preferred Qualifications
  • DNS Systems: Hands‑on experience managing BIND, Unbound, or PowerDNS in high‑traffic environments, alongside cloud‑native solutions (AWS Route 53, Azure DNS, Google Cloud DNS).
  • Protocol Expertise: Mastery of DNS‑specific protocols including DNSSEC, DoT, and DoH, with a firm grasp of underlying transport layers (UDP/TCP) and dual‑stack (IPv4/IPv6) networking.
  • Observability: Experience building dashboards and alerts using Prometheus, ELK, or OpenTelemetry to monitor DNS query latency and error rates.
  • Automation: Proven ability to manage "DNS as Code" using Terraform or Ansible and writing scripts (Python/Go) to automate routine zone updates.
  • Scale & Security: Background in Tier‑1/Tier‑2 service provider environments with a focus on service resilience, Anycast distribution, and DDoS protection.
Working Conditions
  • Hybrid remote/on‑site, with participation in 24/7 on‑call rotations.
  • Availability for after‑hours maintenance and urgent service restoration activities.
  • Ability to work in high‑pressure, high‑reliability production environments.

The ideal candidate is a proactive engineer who values precision and operational excellence. You don’t just manage systems; you architect for reliability, anticipating bottlenecks before they impact the user. We are looking for someone who balances deep technical mastery with an organized approach to delivery, consistently driving improvements in performance, monitoring, and overall service resilience.

All job descriptions and required skills, qualifications and responsibilities for a particular position are subject to modification by the Company from time to time, in the Company’s discretion based on business necessity.

We are an Equal Opportunity Employer committed to recruiting, hiring and promoting qualified people of all backgrounds regardless of gender, race, color, creed, national origin, religion, age, marital status, pregnancy, physical or mental disability, sexual orientation, gender identity, military or veteran status, or any other basis protected by federal, state, or local law.

Pay is competitive and based on a number of job‑related factors, including skills and experience. The starting pay rate/range at the time of hire for this position in New York is $83,538.00 - $137,241.00 per year. For other locations, please inquire with your recruiter. The rates/ranges provided herein are the anticipated pay at the time of hire, and do not reflect future job opportunity.

Nearest Major Market: Long Island
Nearest Secondary Market: New York City

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DNS Engineer - SRE
DNS Engineer - SRE

Altice USA • Plano (TX)

Hybrid
USD 90,000 - 150,000
DNS Engineer - SRE
DNS Engineer - SRE

Altice USA • Bethpage (NY)

Hybrid
USD 120,000 - 170,000
Senior DNS & Infrastructure Engineer (SME)
Senior DNS & Infrastructure Engineer (SME)

BAE Systems • Herndon (VA)

On-site
USD 149,603 - 254,317
Health, dental, and vision insurance
401(k) savings plan
Paid time off and paid holidays
DNS SRE Engineer: Automate, Secure & Scale
DNS SRE Engineer: Automate, Secure & Scale

Altice USA • Plano (TX)

Hybrid
USD 90,000 - 150,000
Hybrid Remote DNS SRE Architect: Scale, Automate & Secure
Hybrid Remote DNS SRE Architect: Scale, Automate & Secure

Altice USA • Bethpage (NY)

Hybrid
USD 120,000 - 170,000
Technical Systems Manager
Technical Systems Manager

DigiCert • United States

On-site
USD 120,000 - 150,000
Competitive benefits package
Principal Engineer
Principal Engineer

Socket.dev • Herndon (VA)

On-site
USD 160,000 - 190,000
Health coverage
401(k) matching
Generous PTO
+3
Network Deployment Engineer
Network Deployment Engineer

CloudFlare • Austin (TX)

On-site
USD 110,000 - 170,000
Health insurance
401(k)
NetOps SRE
NetOps SRE

DigiCert • Lehi (UT)

On-site
USD 80,000 - 120,000
Competitive benefits package
Senior Manager, DDI Platform
Senior Manager, DDI Platform

Vanguard • Charlotte (NC)

On-site
USD 90,000 - 120,000