Point your AI agent at freehire and let it find you a job.

Get the CLI →

Network Operations Engineer (NetOps)

New

The Work We Do

Teciem designs, builds, and delivers treasury and capital markets software solutions for financial institutions worldwide. We serve banks of every size and geography, offering the right setup for the right need.

Our solutions are designed to replace multiple disconnected systems with one complete, front-to-back platform, helping customers to capture trading and business opportunities quickly, clearly and with control. We cover the entire trading lifecycle, ensuring that everything - from execution to position keeping, to risk management – runs smoothly.

With decades of experience and one of the largest, most diverse client bases in the industry, we turn deep industry knowledge into software that covers most asset classes, meets complex real-world treasury and capital market's needs, and adapts as markets evolve.




About Kondor UP

Kondor UP is the SaaS edition of Kondor, Teciem's flagship treasury management platform. Operated by TCM (TeCIEM) on AWS, Kondor UP delivers treasury capabilities as a fully managed, multi-tenant service - enabling banks to go live in weeks rather than months, with continuous evergreen upgrades and contractual SLAs.

The platform relies on a sophisticated network fabric: per-tenant 3-tier VPCs, Istio service mesh (mTLS), AWS Network Firewall, AWS WAF (F5/WAAP), PrivateLink, and a multi-account AWS Organization managed through Control Tower and Terraform (AFT).

Role Summary

The Network Operations Engineer (NetOps) is responsible for the design, delivery, and day-2 operations of the network layer underpinning Kondor UP. This is a hands-on, infrastructure-focused role at the intersection of cloud networking, hybrid connectivity, and platform security - operating within a production-grade financial services environment.

The NetOps Engineer works closely with the InfraOps, SRE, and SecOps teams, and is a key contributor to the Network & IAM workstream.

Key Responsibilities

1. Network Architecture & VPC Design

  • Design, provision, and maintain per-tenant VPCs (3-tier: public / private app / private data subnets) on AWS, ensuring full isolation between tenant accounts.

  • Define and enforce CIDR allocation policies and subnet sizing across the multi-account AWS Organization.

  • Manage VPC Endpoints (Gateway and Interface) to route AWS API traffic off the public internet.

  • Contribute to architecture decisions (ADRs) on network topology, routing, and segmentation.

2. Hybrid Connectivity - Bank Client Onboarding

  • Provision and operate AWS Direct Connect connections (primary) and Site-to-Site VPN tunnels (failover) per customer tenant.

  • Coordinate with client bank network teams for BGP configuration, IP addressing, and bandwidth planning.

  • Define and enforce routing policies (BGP, static routes) between client on-prem and AWS tenant environments.

  • Own failover testing and validation for hybrid connectivity paths.

3. Network Security

  • Configure and manage AWS Network Firewall (stateful/stateless rules, Suricata-based IDS/IPS).

  • Manage AWS WAF policies (OWASP rule sets, API protection, bot mitigation, rate limiting).

  • Design and maintain Security Groups and Network ACLs following least-privilege principles.

  • Enforce Kubernetes NetworkPolicy rules via Kyverno for pod-to-pod and namespace traffic control.

  • Support the SecOps team during security incidents involving network-layer indicators.

4. Service Mesh & Internal Connectivity

  • Operate and troubleshoot Istio (service mesh) for mTLS enforcement, traffic routing, and east-west observability within EKS clusters.

  • Manage AWS PrivateLink endpoints for cross-account service exposure (shared services → tenant accounts).

  • Ensure network-level connectivity for platform services: Amazon MSK (Kafka), Amazon MQ (ActiveMQ), RDS SQL Server (Multi-AZ).

5. DNS Management

  • Manage Amazon Route 53 - public hosted zones (customer-facing endpoints), private hosted zones (internal service resolution), and resolver rules for hybrid DNS.

  • Implement and validate DNS failover policies aligned with RTO/RPO targets.

6. Infrastructure as Code

  • Own Terraform modules for all network resources: VPCs, subnets, route tables, security groups, Network Firewall policies, WAF rules, Direct Connect/VPN, and DNS zones.

  • Contribute to the AFT (Account Factory for Terraform) customisation templates for network baseline provisioning on new tenant account creation.

  • Enforce IaC quality standards: peer-reviewed PRs, policy-as-code (Kyverno / OPA/Conftest), automated drift detection.

7. Observability & Incident Response

  • Instrument network-layer observability: VPC Flow Logs, AWS Network Firewall alerts, Istio traffic metrics (golden signals), and Direct Connect performance dashboards.

  • Define and monitor network SLIs (packet loss, latency, throughput per tenant path) contributing to the SRE error budget framework.

  • Act as network SME during P1/P2 incidents and post-mortem investigations.

  • Maintain network runbooks and escalation procedures in the operational knowledge base.

8. Capacity & Cost Management

  • Model bandwidth requirements per tenant and across the shared connectivity backbone; proactively plan capacity headroom.

  • Optimise network costs (NAT Gateway egress, Direct Connect port utilisation, data transfer) in alignment with the FinOps workstream.

Required Skills & Experience

Cloud Networking - AWS (mandatory)

  • Deep, hands-on experience with AWS VPC (subnets, routing, peering, endpoint services, CIDR management).

  • Proven AWS Direct Connect deployment and operations: Virtual Interfaces (Private VIF / Transit VIF), hosted connections, BGP, failover with VPN.

  • AWS Network Firewall and AWS WAF - rule authoring, policy lifecycle, alert tuning.

  • Amazon Route 53 - advanced DNS management (private zones, resolver endpoints, health checks, failover policies).

  • AWS Control Tower / multi-account organisation networking patterns (hub-and-spoke, landing zone).

Network Fundamentals

  • Strong foundational knowledge: TCP/IP, BGP, OSPF, VLANs, MPLS concepts, subnetting, routing.

  • Experience with SD-WAN or hybrid WAN architectures is a plus.

  • Familiarity with network security concepts: stateful inspection, IDS/IPS, zero-trust network access (ZTNA).

Kubernetes & Service Mesh

  • Working knowledge of Kubernetes networking (CNI, kube-proxy, CoreDNS, NetworkPolicy).

  • Practical experience with Istio (VirtualService, DestinationRule, PeerAuthentication, mTLS).

  • Familiarity with Kyverno or OPA for policy-as-code enforcement of network controls.

Infrastructure as Code

  • Proficiency in Terraform (modules, workspaces, remote state, provider ecosystem for AWS networking).

  • Experience with GitOps workflows (PR-based changes, ArgoCD or equivalent).

  • Version control practices: branching strategies, code review, conventional commits.

Observability

  • Experience with VPC Flow Logs, CloudWatch, and network-layer telemetry pipelines.

  • Familiarity with Prometheus / Grafana for infrastructure and service mesh dashboards.

  • Ability to write and maintain runbooks and post-mortems.

Compliance & Security Context (desirable)

  • Awareness of financial services network requirements: SWIFT CSP, PCI-DSS, ISO 27001, DORA (EU).

  • Understanding of data residency constraints and network-level controls for regulated environments.

Nice to Have

  • Knowledge of FIX protocol or market connectivity (LSEG/Reuters, Bloomberg) network patterns.

  • Familiarity with AWS PrivateLink and multi-account cross-service exposure patterns.

  • Experience with Chaos Engineering for network-layer resilience testing (partition injection, latency simulation).

  • AWS certifications: Advanced Networking Specialty, Solutions Architect Professional.

Team Context & Reporting

The NetOps Engineer reports to the Cloud / Service Delivery Manager and operates within the Network & IAM workstream.

Primary interfaces: - InfraOps - joint ownership of EKS cluster networking, IaC modules, platform baseline. - SRE - network SLI/SLO definition, error budget contribution, incident network-layer triage. - SecOps - co-owns network security posture (WAF, Firewall, NetworkPolicy); feeds into SIEM pipeline. - DevOps - supports connectivity requirements for CI/CD pipelines, ECR pull-through, VPC Endpoints. - Client Bank Network Teams - external stakeholder for Direct Connect / VPN onboarding.

Why Join Kondor UP

  • Impact at scale: You design and operate the network backbone of a production SaaS platform serving tier-1 financial institutions - every routing decision you make has direct SLA consequences.

  • Modern stack: AWS-native, Terraform-first, GitOps, Istio, Kyverno - no legacy on-prem tooling debt.

  • Financial domain depth: Rare opportunity to combine advanced cloud networking with exposure to treasury operations, market connectivity (LSEG, Bloomberg, SWIFT), and regulated financial infrastructure.

  • Engineering culture: Blameless post-mortems, SLO-driven operations, toil-elimination as a first-class concern.




Diverse Minds, Shared Ambition

At Teciem, we believe that our strength comes from the diversity of our people. Different perspectives, backgrounds, and experiences fuel our innovation and help us build solutions that truly make a difference in the world of financial technology.

We’re committed to creating a workplace where everyone feels respected, heard, and empowered to grow. Here, you can bring your whole self to work, contribute your unique ideas, and be part of a team driven by shared ambition.

We welcome talent from all walks of life and encourage applications from individuals of all genders, races, ages, abilities, identities, and beliefs. Together, we’re shaping a culture where diversity isn’t just celebrated — it’s essential to our success.

See also

DevOps jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available