Senior DevOps Engineer, Networking
Why This Role Matters
Kai's customers are Fortune 500 and Global 2000 enterprises with strict security, compliance, and availability requirements. The network infrastructure that underpins our platform must be resilient, multi-tenant, and zero-trust from the ground up. This is not a maintenance role — you are architecting and owning the production cloud network that our customers depend on and that our platform operates across. The work you do here directly affects customer trust, product reliability, and Kai's ability to scale.
What You'll Do
- Design, implement, and maintain highly available, resilient multi-region cloud networks capable of supporting strict enterprise SLAs.
- Architect and manage strict logical segmentation, virtual routing (VRFs), and zero-trust boundaries across shared cloud infrastructure to ensure total data isolation between tenants.
- Engineer and optimize high-scale, multi-tunnel IPsec VPN topologies and Cloud-WAN architectures to interconnect distributed on-premise infrastructure and multi-cloud environments seamlessly.
- Deploy and tune global edge services — including CDNs and WAF rulesets — to optimize application performance while defending against web vulnerabilities and DDoS attacks.
- Manage next-generation firewalls — specifically Palo Alto Networks VM-Series and Panorama — to enforce strict access controls, threat prevention, and secure traffic inspection.
- Drive a software-defined everything approach, provisioning and managing 100% of network infrastructure via Terraform pipelines to eliminate configuration drift.
What We're Looking For
- 5+ years of dedicated network engineering experience, with at least 3+ years focused on production-grade cloud environments — AWS, GCP, or Azure.
- Proven track record of designing and operating secure multi-tenant cloud networks with strict compliance and isolation requirements.
- Deep hands-on expertise in building, scaling, and troubleshooting complex, high-density multi-tunnel IPsec architectures.
- Robust experience deploying and operationalizing Palo Alto Networks firewalls — VM-Series and Panorama — including centralized policy management.
- Direct experience hardening the cloud perimeter using enterprise CDNs — Cloudflare, Akamai, or equivalent — and advanced WAF configuration.
- High proficiency using Terraform for the continuous delivery and automation of cloud network resources — VPCs, routing tables, gateways, security groups.
Work Location – San Jose, CA (5 days in the office)