Network Security Software Engineer

Lumindigital

United States

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
401(k) with company match
Flexible PTO and 12 paid holidays

Job summary

Lumindigital is seeking a Network Security Software Engineer to lead the architecture and implementation of our network security program. You will design and automate security change management processes, ensuring robust protection for our cloud environment.

The ideal candidate has extensive experience in network security, particularly in automated systems, and is proficient in Python. Join us to help enhance our security posture in a dynamic fintech environment.

Qualifications

  • 5+ years of experience in network security engineering in cloud-native environments.
  • Proven track record in automating network security.
  • Hands-on experience with network security platforms.

Responsibilities

  • Architect and implement the network security program.
  • Build automated security change management pipelines.
  • Operate network telemetry, monitoring, and alerting systems.

Skills

Network security fundamentals
Backend programming (Python)
Infrastructure as code (Terraform)
Cloud security (Cloudflare, Zscaler)
DDoS mitigation
Traffic analysis

Education

Bachelor’s degree in Computer Science or related field

Tools

Claude Code
Terraform
CI/CD tools

Job description

Basic Function

Lumin Digital is standing up a dedicated Network Security function within its Risk Engineering group to protect a growing product suite that handles sensitive financial data across multiple product lines. This role exists because the landscape has shifted: in a cloud-native, infrastructure-as-code environment, network security is no longer about managing router ACLs—it is about designing identity-aware policy enforcement, automating end-to-end change management, and building real-time visibility into network activity across both workforce and hosted contexts.

As the Network Security Software Engineer, you will be a domain authority who breaks network security out of the existing Security Engineering and SOC functions, building the specialization from the ground up. You will architect and deliver automated, lights‑off pipelines—using agentic development practices and tools like Claude Code—that turn around security changes faster, go deeper than port and protocol in our defense‑in‑depth story, and extend coverage to the agents our teams create, not just the people who create them.

We are looking for a senior practitioner who will teach us what great network security looks like in a modern, highly‑automated fintech environment—not someone who needs to be taught.

Essential Functions and Responsibilities
  • Own the architecture, implementation, and continuous improvement of Lumin’s network security program across cloud, SD‑WAN, and ZTNA layers—designing identity‑aware, policy‑driven controls that secure both human and machine (agent) identities.
  • Design and deliver fully automated, end‑to‑end network security change management pipelines that eliminate manual toil, accelerate change velocity, and maintain audit‑ready evidence at every step.
  • Build and operate real‑time network telemetry, monitoring, and alerting systems that provide deep visibility into network activity — integrating threat intelligence feeds, cloud connectivity data, and asset inventories into a unified, automated network defense posture.
  • Engineer production‑grade tooling and services—including firewall rule lifecycle management, policy drift detection, configuration compliance validation, and telemetry enrichment—using modern backend languages (Python strongly preferred) and infrastructure‑as‑code.
  • Manage and tune network‑layer detection capabilities — including IDS/IPS signatures, firewall rules, and WAF configuration — to ensure high‑fidelity signals for SOC consumption.
  • Operate at the leading edge of AI‑assisted development: write precise engineering specifications, direct AI coding agents (e.g., Claude Code, Cursor), and review/validate generated output to build secure, lights‑off agentic pipelines that the broader team can learn from.
  • Build and maintain API integrations across the network security technology stack (e.g., Cloudflare, Zscaler, cloud‑native controls) with reliability, observability, and audit‑readiness designed in from day one.
  • Support compliance audit and assessment activities — including evidence collection, control testing, and auditor walkthroughs for network security domains; maintain an accurate network diagram inventory documenting topology, segmentation boundaries, and data flows.
  • Partner with the Security Operations Center, SRE, and IT to ensure network security controls integrate cleanly with existing infrastructure pipelines, CI/CD workflows, and incident response processes; participate in security architecture reviews and contribute to runbook development and operational documentation—raising the network security bar across the engineering organization.
  • Perform other duties as assigned.
Physical Demands
  • While performing the duties of this job, the employee is regularly required to sit; use hands to type, handle, or feel and talk or hear.
  • Specific vision abilities required by this job include close vision.
  • Ability to occasionally lift/move up to 25 pounds.
  • Individuals with a disability who are otherwise able to perform the essential functions of the job may request reasonable accommodation through the Human Resources department.
Supervisory Responsibility

None.

Position Specifications
Education
  • Bachelor’s degree in Computer Science, Information Security, Network Engineering, or a related technical field, or equivalent combination of education and experience.
Preferred Certifications

CCNP Security, PCNSE (Palo Alto), AWS Solutions Architect, Cloudflare certifications, or equivalent. Relevant certifications are valued but not required if depth of hands‑on experience is demonstrated.

Experience
  • 5+ years of progressive experience in network security engineering, with a demonstrated track record of designing, automating, and operating network security controls in cloud‑native or hybrid environments.
  • Substantive hands‑on engineering experience: you write production code, build integrations, and ship tooling—not just policies and diagrams.
  • Direct experience with network security platforms such as Cloudflare (WAF, Workers, Rulesets, Terraform provider), Zscaler (ZIA, ZPA), Palo Alto, or equivalent tier‑one solutions.
  • Experience in fintech, banking, payments, or other regulated financial services environments (PCI‑DSS, SOC 2, ISO 27001) strongly preferred.
  • Experience with infrastructure‑as‑code (Terraform, CloudFormation) and CI/CD‑driven infrastructure provisioning.
Knowledge, Skills, & Abilities

Required

  • Deep expertise in network security fundamentals: firewall policy design, micro‑segmentation, ZTNA, SD‑WAN, DDoS mitigation, traffic analysis, DNS security, and certificate/PKI management.
  • Hands‑on experience with agentic coding tools and workflows (Claude Code, Cursor, or equivalent)—or demonstrated eagerness and aptitude to adopt them as a primary development methodology.
  • Strong proficiency in at least one backend language (Python strongly preferred; Go or similar considered) with the ability to design and build production‑grade APIs, automation frameworks, and integration platforms.
  • Thorough understanding of identity‑aware network security—designing controls that authenticate and authorize not just users but services, workloads, and autonomous agents.
  • Demonstrated ability to write clear, precise engineering specifications and technical documentation; comfortable operating on a distributed, async‑first team where written clarity drives outcomes.
  • Sound engineering judgment: able to evaluate AI‑generated code for correctness, security implications, and maintainability; able to architect systems for reliability and observability.
  • Strong cross‑functional communication skills: able to translate network security requirements into actionable engineering work and influence peers across Security, SRE, and Platform teams.

Preferred

  • Experience building real‑time telemetry, monitoring, and threat detection pipelines for network traffic.
  • Familiarity with agent‑to‑agent authentication, service mesh architectures, and securing AI/ML workload communications.
  • Experience integrating threat intelligence feeds and automating indicator‑of‑compromise enrichment into network defense workflows.
Travel
  • Minimal, generally 12 days or less per year (~2 team get‑togethers per year).
Benefits

We take care of our people with medical, dental, and vision insurance, a 401(k) with company match, flexible PTO plus 12 paid holidays, paid sick leave, and paid parental and family leave. We also offer a lifestyle spending account, tuition reimbursement, and a cell phone stipend. Additional details are provided during the interview process.

Equal Opportunity Employer

Lumin Digital is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other legally protected basis. For more information, visit lumindigital.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Network Security
Manager, Network Security

Lumindigital • United States

On-site
USD 120,000 - 160,000
Medical, dental, and vision insurance
401(k) with company match
Flexible PTO and paid holidays
+2
Cyber Security Engineer
Cyber Security Engineer

Lumindigital • United States

Hybrid
USD 100,000 - 130,000
Medical, dental, and vision insurance
401(k) with company match
Flexible PTO
+1
Security Platform Engineer
Security Platform Engineer

Lumindigital • United States

On-site
USD 140,000 - 190,000
Medical, dental, and vision insurance
401(k) with company match
Flexible PTO + 12 paid holidays
+5
Security Platform Engineer
Security Platform Engineer

Lumin Digital • Northern (KY)

Hybrid
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+4
Cyber Security Engineer
Cyber Security Engineer

Far Coder • Northern (KY)

Hybrid
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+5
Risk Automation Engineer
Risk Automation Engineer

Lumindigital • United States

On-site
USD 100,000 - 130,000
Medical, dental, and vision insurance
401(k) with company match
Flexible PTO plus paid holidays
+1
Vulnerability Automation Engineer
Vulnerability Automation Engineer

Lumindigital • United States

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+7
Software Engineer, Network Firewall
Software Engineer, Network Firewall

Triwill Group • United States

Hybrid
USD 140,000 - 200,000
Network Security Engineer
Network Security Engineer

Cerebras • United States

On-site
USD 90,000 - 130,000
Staff Network Security Engineer (Information Security)
Staff Network Security Engineer (Information Security)

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 127,000 - 207,000
Employee benefits
Restricted stock units