Staff Network Engineer, App Platform

United States Digital Space LLC

San Francisco (CA)

On-site

USD 150,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health, dental, vision coverage
Equity
Learning stipend
Generous PTO
Commuter stipend

Job summary

Scale is seeking a Senior Network Engineer to establish architectural standards for SGP connectivity across AWS, Azure, and GCP. You will own VPC designs, ingress/egress, and service mesh configurations while aligning with customer deployments and compliance requirements.

The role emphasizes data-driven decisions, cross-team reviews, and scalable boundary definitions to support many environments and regulated workloads.

Qualifications

  • 5+ years of network engineering experience in cloud environments.
  • Deep cloud networking expertise across at least two of AWS, Azure, GCP.
  • Kubernetes networking depth including Istio/Envoy, CNI, NetworkPolicy.

Responsibilities

  • Own network architecture for the SGP platform across cloud environments and customer deployments.
  • Design and review VPC architectures, peering, DNS, load balancing, and CDN/edge configurations (Cloudflare).
  • Ground decisions in data and domain depth for VPN, routing, ingress/egress, and traffic flow.
  • Define standard connectivity between Scale's control plane and customer data planes (VPC peering, PrivateLink/Private Service Connect, VPN).
  • Document network architecture, standards, and runbooks for cross-team use.

Skills

Cloud networking
Kubernetes networking
Service mesh Istio/Envoy
VPC design
Networking security basics
Edge/CDN (Cloudflare)
VPN & TLS
IaC (Terraform)
Public cloud expertise (AWS/Azure/GCP)

Tools

Terraform
Cloudflare

Job description

Scale GP (Scale Generative AI Platform) is Scale’s enterprise AI platform, providing APIs and infrastructure for knowledge retrieval, inference, evaluation, agents, and more. We deploy SGP across AWS, Azure, and GCP, often directly into customer-controlled cloud environments across highly regulated industries including healthcare, financial services, telecom, and retail.

As SGP has grown in scale and complexity, networking has become a critical architectural discipline of its own. Today, teams routinely encounter the same hard problems — VPC design, routing, ingress and egress, private connectivity, service exposure, address-space constraints, firewall policies, and cross-environment communication — but solve them differently depending on the deployment. We’re looking for a Senior Network Engineer to establish the architectural standards for how SGP connects to customer infrastructure and how traffic moves throughout the platform.

You’ll own network architecture across a large and rapidly growing fleet of Kubernetes environments spanning AWS, Azure, and GCP, with many deployed inside customer-owned cloud accounts and networks that we do not control. The constraints vary significantly: a commercial deployment behind a customer-managed API gateway; a hub-and-spoke enterprise network where the customer assigns our address space; a GovCloud environment protected by default-deny firewall policies; or a fully air-gapped deployment with no external connectivity.

The goal is not to create a bespoke network architecture for every customer. Your job is to define one clear, secure, and supportable networking model for SGP — and establish the small set of defensible variations required to operate across different clouds, customer architectures, and compliance regimes.

What You'll Do
  • Own network architecture for the SGP platform: define and enforce network standards across cloud environments (AWS, Azure, GCP) and customer deployments
  • Design and review VPC architectures, peering, DNS, load balancing, and CDN/edge configurations (e.g., Cloudflare), grounding root-cause and tradeoff discussions in data and domain depth
  • Bring strong technical judgment to VPN, routing, access, ingress/egress, and traffic-flow decisions
  • Review proposed networking solutions from platform, product, and forward-deployed teams; evaluate what should and should not be introduced into the platform boundary
  • Define the standard connectivity pattern between Scale's control plane and customer data planes (VPC peering, PrivateLink/Private Service Connect, site-to-site VPN, reverse tunnels) — and converge today's per-customer designs onto it
  • Own the customer-boundary delivery blueprint: how code, images, and traffic cross into a customer tenant — CI/CD mirroring across org boundaries (including customer-side Azure DevOps), artifact scan gates, private registries, ingress — so new engagements configure a pattern instead of designing one
  • Own engineer access into customer and internal environments (Tailscale/Teleport/bastion-class decisions), replacing per-engineer VPN sprawl and hand-rolled tunnels with something auditable
  • Own the Kubernetes traffic layer: Istio/Envoy mesh and ingress, the per-cloud CNI matrix, and a portable NetworkPolicy contract that constrains egress for thousands of short-lived agent-sandbox pods running untrusted code
  • Reduce rework by preventing one-off implementations from becoming long-term platform burden
  • Partner with security engineering on network segmentation, zero-trust access, and compliance requirements in regulated customer environments
  • Debug complex connectivity, latency, and traffic-flow issues across hybrid and multi-cloud deployments
  • Document network architecture, standards, and runbooks so adjacent teams can operate confidently
What We're Looking For
  • 5+ years of network engineering experience, including designing and operating production networks in cloud environments
  • Deep expertise in cloud networking on at least two of AWS, Azure, and GCP: VPC design, peering, Transit Gateway/hub-and-spoke topologies, private connectivity (PrivateLink, Private Service Connect), and DNS
  • Kubernetes networking depth — CNI, ingress, NetworkPolicy, service mesh (Istio/Envoy) — this is where most of our real incidents live
  • Strong fundamentals in TCP/IP, BGP, routing, firewalls, VPN (site-to-site and client), and TLS
  • Experience with edge/CDN and traffic-management platforms such as Cloudflare
  • Has defined a network standard or reference architecture that other teams adopted, and enforced it through design review
  • Comfortable as the sole domain owner: able to collect requirements across five-plus live environments you didn't design, then converge them without breaking any
  • Has made build-vs-adopt networking calls with vendor-support or contractual consequences in a customer's cloud
  • Infrastructure-as-code proficiency (Terraform preferred)
  • Familiarity with network security and compliance requirements in regulated industries (healthcare, finance, government), including environments across multiple compliance regimes (commercial, FedRAMP/GovCloud, air-gapped), is a plus
  • Excellent communication skills — able to explain networking tradeoffs to both technical and non-technical audiences and influence decisions without direct authority
Why This Role Matters

Without a dedicated owner, adjacent teams are covering a domain that needs specialized expertise. You will be the point of accountability for network architecture as SGP grows — raising the quality of every deployment, unblocking confident decisions, and keeping the platform boundary clean as we scale.

Compensation packages at Scale for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position and may be inclusive of several career levels at Scale; it will be determined during the interview process based on work location and additional factors, including job-related skills, experience, qualifications, interview performance, and relevant education or training. Scale employees in eligible roles are also granted equity based compensation, subject to Board of Director approval.

You’ll also receive benefits including, but not limited to: comprehensive health, dental and vision coverage, retirement benefits, a learning and development stipend, and generous PTO. Additionally, this role may be eligible for additional benefits such as a commuter stipend.

For pay transparency purposes, the base salary range for this full‑time position in the locations of San Francisco, New York, Seattle is:

$1—$1 USD

PLEASE NOTE: Our policy requires a 90‑day waiting period before reconsidering candidates for the same role. This allows us to ensure a fair and thorough evaluation of all applicants.

About Us:

At Scale, our mission is to develop reliable AI systems for the world's most important decisions. Our products provide the high-quality data and full‑stack technologies that power the world's leading models, and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Network Engineer, App Platform Scale AI San Francisco, CA
Staff Network Engineer, App Platform Scale AI San Francisco, CA

Neura Market • San Francisco (CA), Northern (KY)

Hybrid
USD 140,000 - 210,000
Health, dental and vision coverage
Retirement benefits
Learning and development stipend
+1
Staff Network Engineer, App Platform
Staff Network Engineer, App Platform

Scale • San Francisco (CA)

Hybrid
USD 180,000 - 250,000
Health coverage
Retirement benefits
Learning and development stipend
+2
Staff Network Engineer, App Platform
Staff Network Engineer, App Platform

Scale AI, Inc. • San Francisco (CA)

On-site
USD 180,000 - 260,000
Health coverage
Dental coverage
Vision coverage
+3
Infrastructure Software Engineer, Enterprise GenAI
Infrastructure Software Engineer, Enterprise GenAI

Front Door Defense • San Francisco (CA), New York (NY)

On-site
USD 216,200 - 270,250
Comprehensive health, dental, and vision coverage
Retirement benefits
Learning and development stipend
+2
Infrastructure Software Engineer, Enterprise GenAI
Infrastructure Software Engineer, Enterprise GenAI

Scale • San Francisco (CA), New York (NY)

On-site
USD 179,000 - 224,000
Health, dental & vision insurance
Retirement benefits
Learning & development stipend
+2
Infrastructure Software Engineer, Enterprise GenAI
Infrastructure Software Engineer, Enterprise GenAI

Scale AI • New York (NY)

On-site
USD 140,000 - 210,000
Comprehensive health coverage
Equity compensation
Generous PTO
+2
Staff Infrastructure Software Engineer (Enterprise AI)
Staff Infrastructure Software Engineer (Enterprise AI)

Scale AI • San Francisco (CA), New York (NY)

On-site
USD 188,000 - 235,000
Comprehensive health, dental and vision coverage
Retirement benefits
Learning and development stipend
+2
Senior Software Engineer, Full-Stack – Scale GP
Senior Software Engineer, Full-Stack – Scale GP

Scale AI • San Francisco (CA)

On-site
USD 216,000 - 271,000
Comprehensive health, dental, and vision coverage
Retirement benefits
Learning and development stipend
+2
Infrastructure Software Engineer, Enterprise Genai Software
Infrastructure Software Engineer, Enterprise Genai Software

Front Door Defense • New York (NY), Northern (KY)

Hybrid
USD 179,000 - 224,000
Health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
Senior Software Engineer, Platform
Senior Software Engineer, Platform

Scale AI, Inc. • New York (NY)

On-site
USD 216,000 - 270,000
Health, dental & vision
Retirement benefits
Learning & development stipend
+2