SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Network Engineer

Altruist - Los Angeles, CA, United States - Hybrid - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 181,000 - 265,000 / annual

Altruist is transforming the wealth management industry with an AI platform for financial advisors. The company operates a regulated broker-dealer and clearing platform on a multi-region AWS infrastructure, connected to clearing, custody, market-data, and banking partners over dedicated circuits and encrypted tunnels. You will be Altruist's first dedicated Staff Network Engineer, owning the design, segmentation, security, and operations of the entire network infrastructure. This is a foundational role where you will set standards rather than inherit them. Key responsibilities include: - Own multi-region AWS network architecture, including transit gateway topology, VPC design, address-space strategy, and routing across production, clearing, and platform environments - Design and enforce network segmentation to isolate workload, corporate, and partner traffic, delivered as code via Terraform and GitOps - Lead the transition to zero trust / SASE access models, ensuring application-level access and strong device posture for a distributed engineering team - Collaborate with Security to translate threat models into durable network designs meeting regulated-industry standards and audit requirements - Own the partner connectivity estate, managing site-to-site VPNs, BGP peering, and Direct Connect circuits to financial-services counterparties - Manage office and edge networking, including ISP redundancy and connectivity standards for new locations - Define network observability and serve as the senior escalation point for incidents, disaster recovery, and cross-region failover - Apply an AI-native approach to network operations, using agentic workflows for audit, drift detection, and rapid analysis of configuration and flow data - Provide technical leadership by writing standards, reviewing designs across teams, and mentoring engineers The role is hybrid, requiring three days per week onsite in either the San Francisco FiDi or Culver City office. Requirements: - 8+ years in network engineering, including 3+ years in cloud-native environments, with demonstrated ownership of production networks - Deep AWS networking expertise: VPC design, Transit Gateway, Direct Connect, VPN, Route 53, PrivateLink, NAT and egress patterns, security group design at scale - Strong fundamentals in routing, BGP, IPsec, TLS, DNS, DHCP, and ability to read packet captures - Hands-on experience designing or operating network segmentation and traffic inspection in cloud, on-prem, or hybrid environments - Zero trust / SASE experience (ZTNA, secure web gateway, CASB, device-posture-conditioned access); Zscaler, Netskope, or Prisma experience is a strong plus - Terraform and infrastructure as code as default practice, plus scripting ability (Python, Bash, or Go) and comfort with cloud APIs - Working knowledge of Kubernetes networking (CNI behavior, ingress, service exposure, east-west traffic) - AI-native approach required: already use AI tooling to write and review code, analyze configuration and logs at scale, and reason about large estates, with ability to verify output before production deployment - Security partnership mindset: treat security requirements as design input, not obstacle - Judgment and ownership: experience with real change windows, documented risk acceptance, ability to hold your own with partner network teams - Ideally a B.A. / B.S. in Computer Science, Network Engineering, or related field (experience and understanding valued equally) Bonus qualifications: - Financial services, brokerage, or regulated industry experience, including connectivity to clearing, custody, banking, or market-data counterparties - Network integration through acquisition or enterprise merger - AI (Claude) best practices expertise, including agentic workflows for infrastructure operations - Service mesh or API gateway operations; edge and CDN security; campus and branch networking - Certifications: AWS Advanced Networking Specialty, CCNP/CCIE, or JNCIP

Similar roles