Network Security Engineer

The Consensus

San Jose (CA)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision packages
Waiver credit $500/month for medical
Housing subsidy $2k/month near office
Relocation support to San Jose (Sant/“
Wellness benefits
Daily lunch and dinner in our office
Unlimited compute budget

Job summary

Etched is building a secure, scalable network for a high-value compute environment supporting frontier AI. You will own end-to-end network security design, implementing zero-trust architecture across on‑prem datacenters, multiple offices, and multi-cloud platforms.

You’ll harden networks, enforce least-privilege access, and build detection and response capabilities for sensitive chip design environments. This senior role requires hands-on engineering with strong Linux fundamentals and a proven

Qualifications

  • Deep, broad networking expertise across on‑prem and multi‑cloud environments.
  • Hands-on Fortinet ecosystem experience including FortiGate and FortiSASE.
  • Code-driven security engineering with automation and IaC.
  • Experience securing high-value compute environments (datacenters, HPC).
  • Integrated EDR/XDR, MDM/MAM, SASE, CASB into unified controls.
  • ZTNA-based access models for on-site, remote, and traveling users.

Responsibilities

  • Design and implement a zero-trust network architecture across on-prem, offices, and multi-cloud.
  • Define and enforce network segmentation isolating ASIC development workflows.
  • Deploy and tune NDR, IDS/IPS and firewalls; automate rule management.
  • Integrate EDR/XDR, MDM/MAM, SASE, CASB to enforce unified DLP and access.
  • Own vulnerability management for network-layer exposure with infra engineers.
  • Lead incident response for network security events and post-incident hardening.
  • Collaborate with legal/compliance for regulatory reviews.
  • Architect network segmentation for HPC clusters and CI pipelines.
  • Deploy ZTNA-based corporate network with zero VPN sprawl.
  • Design scalable NDR pipeline ingesting flow data and feeding SIEM.
  • Develop runbooks and automated playbooks for incidents.
  • Containerize IP and enforce conditional access with IT.

Skills

Networking
Fortinet
Arista EOS
Automation
ZTNA
Linux
Security monitoring
Communication

Tools

Fortinet
Arista EOS
eBPF
SASE tooling

Job description

About Etched

Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference. Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history.

Job Summary

Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational — not an afterthought.

As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe.

This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI — not maintain someone else's stack.

Key Responsibilities
  • Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed
  • Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure
  • Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code
  • Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk
  • Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers
  • Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening
  • Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise
  • Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network
  • Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification
  • Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates
  • Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments
  • Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network
  • Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments
You may be a good fit if you have (Must-have qualifications)
  • Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape
  • Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture
  • Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation
  • Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high
  • Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network
  • Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers
  • Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion
  • Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls
  • Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal
  • Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes
Strong candidates may also have experience with (Nice-to-have qualifications)
  • Experience with EDA environments or semiconductor IP security
  • Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM)
  • Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks
  • Experience with eBPF-based network observability and security tooling
Benefits
  • Medical, dental, and vision packages with generous premium coverage
  • $500 per month credit for waiving medical benefits
  • Housing subsidy of $2k per month for those living within walking distance of the office
  • Relocation support for those moving to San Jose (Santana Row)
  • Various wellness benefits covering fitness, mental health, and more
  • Daily lunch and dinner in our office
  • Unlimited compute budget subject to ROI justification
How we're different

Etched believes in Bitter Lesson. We are the first inference-focused frontier AI system, betting early on transformer and transformer-like architectures and on increasing model sizes. Our addressable market is the entirety of inference, unlike many of our competitors.

We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Engineer
Network Security Engineer

Delos • San Jose (CA)

On-site
USD 120,000 - 160,000
Medical, dental, and vision coverage
Housing subsidy
Relocation support
+2
Network Security Engineer
Network Security Engineer

Etched.ai, Inc. • San Jose (CA)

On-site
USD 120,000 - 150,000
Medical, dental, and vision packages
Housing subsidy of $2k per month
Relocation support for new employees
+2
Security Engineer (Remote)
Security Engineer (Remote)

The Consensus • United States

Hybrid
USD 150,000 - 210,000
Full medical coverage
Housing subsidy $2,000/month for local
Daily office meals
+2
Security Engineer
Security Engineer

The Consensus • San Jose (CA)

Hybrid
USD 140,000 - 210,000
Full medical, dental, and vision
Relocation assistance to San Jose
Unlimited compute budget
+1
IT Engineer
IT Engineer

The Consensus • San Jose (CA)

On-site
USD 90,000 - 130,000
Medical, dental, and vision coverage
Housing subsidy
Relocation support (San Jose)
+3
Network Security Engineer
Network Security Engineer

Etched • San Jose (CA)

On-site
USD 175,000 - 275,000
Medical, dental, and vision packages
Housing subsidy
Relocation support
+3
Security Engineer
Security Engineer

Etched • San Jose (CA)

On-site
USD 120,000 - 140,000
Full medical, dental, and vision packages
Housing subsidy of $2,000/month
Daily lunch and dinner in office
+1
Security Engineer
Security Engineer

Etched.ai, Inc. • San Jose (CA)

On-site
USD 110,000 - 150,000
Full medical, dental, and vision packages
$2,000/month housing subsidy
Daily lunch and dinner
Security Engineer (Remote)
Security Engineer (Remote)

Etched • United States

On-site
USD 150,000 - 250,000
Full medical, dental, and vision packages
Housing subsidy of $2,000/month
Daily lunch and dinner in the office
+2
Security Engineer
Security Engineer

Etched • San Jose (CA)

On-site
USD 150,000 - 250,000
Full medical, dental, and vision packages
Housing subsidy of $2,000/month
Daily lunch and dinner
+1