Skip to content

Open nowPosted 60 days ago

Cloud Network & Edge Security Engineer

dlocal51 open roles

Where
Madrid
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCloud Network & Edge Security Engineerdlocal · Madrid
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on dlocal's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 60 days ago

The posting

Why Join dLocal? dLocal is the financial infrastructure powering global commerce in the world's fastest-growing markets. The biggest companies in the world trust us to unlock growth in 60+ countries across emerging markets—moving money where others see complexity. We don't just process payments; we are architects of payment ecosystems and partners in our customers' expansion. You'll work alongside 1,300+ teammates from 40+ nationalities and tackle global challenges from day one.

What’s the opportunity?

We are looking for a Senior Network & Edge Security Engineer to help design, operate, and evolve dLocal’s global cloud and hybrid network perimeter. This role combines deep cloud networking expertise with a strong security mindset: you will own secure connectivity, traffic protection, WAF and firewall controls, and the automation that makes those services reliable at scale. You will work closely with Platform, Information Security, Compliance, and Product teams to keep critical services secure, available, low-latency, and ready for international growth.

What you’ll do

  • Design, implement, and operate secure, resilient, and scalable network solutions across cloud and hybrid environments, with a focus on availability, latency, disaster recovery, and operational simplicity.
  • Own and continuously improve our edge-security stack, including cloud WAFs, network firewalls, proxies, load balancers, and traffic-routing policies that protect public APIs, frontends, and internal services.
  • Define, tune, and maintain WAF and firewall rules, policies, and traffic flows; proactively reduce noise and false positives while preserving effective protection against attacks.
  • Design and operate AWS networking services such as VPCs, subnets, route tables, Transit Gateway, VPC peering, Route 53, load balancers, security groups, Network ACLs, and AWS Network Firewall.
  • Coordinate, implement, and support third-party connectivity, including IPsec/SSL VPNs, leased lines, partner interconnections, routing, DNS, and failover paths.
  • Manage FortiGate-based services, including IPsec and SSL VPNs, security policies, virtual IPs/servers, NAT, routing, and log analysis.
  • Build and maintain end-to-end HTTP/HTTPS and network observability using logs, metrics, dashboards, alerting, synthetic checks, and traffic analysis to identify performance degradation, misconfigurations, and security events early.
  • Drive network and security infrastructure as code using Terraform or similar tools, integrating changes into CI/CD pipelines so they are repeatable, auditable, tested, and secure across environments.
  • Automate network and edge-security workflows such as site onboarding and decommissioning, rule and policy lifecycle management, partner connectivity, configuration validation, and controlled WAF-provider failovers.
  • Lead and actively participate in incident response for network, connectivity, WAF, and edge-security events; execute DR procedures, coordinate controlled failovers, and drive postmortems and remediation actions.
  • Partner with Information Security and Compliance to ensure network and edge controls support regulatory and industry requirements, including PCI and SOX, and provide audit-ready evidence when needed.
  • Maintain clear, actionable documentation for architectures, traffic flows, standards, operational procedures, and runbooks so other engineering teams can move quickly and safely.

What we need you to have

  • Solid hands-on experience designing, operating, and troubleshooting cloud networking in production environments with high availability and security requirements.
  • Strong knowledge of TCP/IP, HTTP/HTTPS, TLS, DNS, routing, NAT, load balancing, proxies, VPN/IPsec, and network troubleshooting practices.
  • Practical experience with AWS networking services, including VPC, subnets, route tables, Route 53, load balancers, Transit Gateway, VPC peering, security groups, Network ACLs, and AWS Network Firewall.
  • Hands-on experience managing WAFs and/or edge-security controls protecting web applications and APIs; experience in multi-provider environments is a plus.
  • Experience managing firewalls, ideally FortiGate, including VPNs, security policies, virtual IPs, routing, and log analysis.
  • Experience with Infrastructure as Code and automation tools such as Terraform, CloudFormation, Ansible, or similar, and the ability to integrate infrastructure changes into CI/CD workflows.
  • Experience with monitoring and observability platforms such as ELK, New Relic, Coralogix, or similar; ability to build actionable dashboards and alerts for latency, errors, throughput, availability, and anomalous traffic patterns.
  • Linux administration fundamentals and practical command-line troubleshooting skills.
  • Experience with HTTP/TCP proxies and reverse proxies, such as NGINX, HAProxy, or Squid.
  • Strong understanding of cloud-security best practices, network segmentation, least privilege, and secure change-management practices.
  • Strong written and spoken English, with the ability to document technical decisions and collaborate effectively across Networking, Security, Platform, Product, and external partn

Would be awesome if you had

  • Experience with AWS, GCP, Azure, or multi-cloud networking and security architectures.
  • Exposure to PCI-DSS, SOX, or other regulated-industry security and compliance requirements.
  • Experience operating in high-criticality environments such as payments, fintech, banking, or global e-commerce, where uptime, resilience, and latency are essential.
  • Experience designing disaster-recovery strategies, multi-provider WAF failover, or zero-trust network architectures.
  • AWS certifications such as AWS Certified Advanced Networking – Specialty, Solutions Architect, Security – Specialty, or DevOps Engineer.

What do we offer? Besides the tailored benefits we have for each country, dLocal will help you thrive and go that extra mile by offering you: - Flexibility in how you work: We focus on impact and productivity over fixed hours. This means our teams have flexible schedules and, depending on your role and location, you will combine self‑managed focus time with moments of in‑person connection in our collaboration hubs. - Fintech industry: work in a dynamic and ever-evolving environment, with plenty to build and boost your creativity. - Referral bonus program: our internal talents are the best recruiters - refer someone ideal for a role and get rewarded. - Work From Anywhere: Team members can work while traveling for up to 3 months every year.

What happens after you apply?

Our Talent Acquisition team is invested in creating the best candidate experience possible, so don’t worry, you will definitely hear from us. We will review your CV and keep you posted by email at every step of the process!

Also, you can check out our webpage, Linkedin and Youtube for more about dLocal!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against dlocal's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on dlocal's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    dlocal's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.