Senior Network Engineer

AltruistSan Francisco, CA
$200,000 - $240,000Hybrid

About The Position

Altruist is the modern custodian built exclusively for independent financial advisors, combining a self-clearing brokerage firm with intuitive software for account opening, trading, reporting, and billing. Our mission is to make financial advice better, more affordable, and accessible to everyone. We’re hiring our first dedicated Senior Network Engineer. We run a regulated broker-dealer and clearing platform on a multi-account, multi-region AWS estate, connected to clearing, custody, market-data, and banking partners over dedicated circuits and encrypted tunnels. You will own how those networks are designed, segmented, secured, and operated — from cloud routing topology and partner connectivity to how our own people reach internal systems — working in close partnership with our Security team, whose requirements shape much of this roadmap, and bringing an AI-native approach to the work. You will set the standards here, not inherit someone else’s. This role follows a hybrid schedule, with three days per week onsite in our San Francisco FiDi or Culver City office.

Requirements

  • 7+ years in network engineering, including 3+ in cloud-native environments. You have owned a production network, not just operated tickets against one.
  • Deep AWS networking: VPC design, Transit Gateway, Direct Connect, VPN, Route 53, PrivateLink, NAT and egress patterns, and security group design at scale.
  • Strong fundamentals — routing and BGP, IPsec, TLS, DNS, DHCP — and the ability to read a packet capture when a vendor says the problem is on your side.
  • Hands-on experience designing or operating network segmentation and traffic inspection, in cloud, on-prem, or hybrid.
  • Zero trust / SASE experience: ZTNA, secure web gateway, CASB, or device-posture-conditioned access. Zscaler, Netskope, or Prisma is a strong plus.
  • Terraform and infrastructure as code as your default, plus scripting ability (Python, Bash, or Go) and comfort with cloud APIs.
  • Working knowledge of Kubernetes networking — CNI behavior, ingress, service exposure, and where east-west traffic actually goes.
  • An AI-native approach — a requirement, not a nice-to-have. You already use AI tooling to write and review code, analyze configuration and logs at scale, and reason about large estates, and you verify its output before it touches production.
  • A security partnership mindset — you treat security requirements as design input, not obstacle, and can hold a technical disagreement with a security engineer and land somewhere better than where either of you started.
  • Judgment and ownership — you have worked somewhere a change window is real, you document accepted risk rather than quietly leaving it undocumented, and you can hold your own with a partner’s network team on a bridge call.
  • Ideally a B.A. / B.S. in Computer Science, Network Engineering, or a related field, but experience and understanding matter just as much.

Nice To Haves

  • Financial services, brokerage, or another regulated industry — including connectivity to clearing, custody, banking, or market-data counterparties.
  • Network integration through an acquisition or enterprise merger — address-space reconciliation and meeting a larger partner’s standards.
  • Expertise with AI (Claude) best practices, including agentic workflows applied to infrastructure operations.
  • Service mesh or API gateway operations; edge and CDN security (WAF, bot management); campus and branch networking.
  • Certifications such as AWS Advanced Networking Specialty, CCNP/CCIE, or JNCIP.

Responsibilities

  • Own the multi-region AWS network architecture, including transit gateway topology, VPC design, address-space strategy, and routing across production, clearing, and platform environments.
  • Design and enforce segmentation to isolate workload, corporate, and partner traffic, ensuring the network layer is delivered as code via Terraform and GitOps.
  • Lead the transition to a zero trust / SASE access model, ensuring application-level access and strong device posture for a distributed engineering team.
  • Collaborate closely with Security to translate threat models into durable network designs that meet regulated-industry standards and audit requirements.
  • Own the partner connectivity estate, managing site-to-site VPNs, BGP peering, and Direct Connect circuits to financial-services counterparties.
  • Manage office and edge networking, including ISP redundancy and connectivity standards for new locations.
  • Define network observability and serve as the senior escalation point for incidents, disaster recovery, and cross-region failover.
  • Apply an AI-native approach to network operations, using agentic workflows for audit, drift detection, and rapid analysis of configuration and flow data.
  • Provide technical leadership by writing standards, reviewing designs across teams, and mentoring engineers to ensure network resiliency.

Benefits

  • Competitive total compensation.
  • Premium healthcare, dental, and vision insurance plans (HMO and PPO).
  • 401k savings plan with a 4% match and immediate vesting.
  • 16 week paid parental leave after one year of employment.
  • Professional growth and development opportunities including an employee mobility program and an annual L&D budget allocation for each employee.
  • Company perks program (includes discounts on pet insurance, fitness, cell phone plans, and travel, etc.).
  • Financial guidance program (includes counseling on navigating debt, tracking personal spend, saving and planning goals, home-purchasing preparedness, etc.).
  • One month work from anywhere policy (with the exception of a few countries).
  • Bonus program for eligible roles.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service