About The Position

Share is a venture-backed internet infrastructure network building Africa’s backbone. The company aggregates underutilized telecom infrastructure, fiber, subsea cables, and data centers, and provides ISPs with scalable access to bandwidth without traditional upfront costs. Share’s network spans thousands of kilometers of fiber, 12 infrastructure providers, and 10 data centers, reaching over 8 million people across East Africa. At the network level, Share operates a RADIUS proxy architecture that authenticates ISP subscribers, provisions their internet access, and coordinates with partner BNG (Broadband Network Gateway) equipment. The platform must coexist with existing ISP infrastructure, not replace it. This means every deployment involves real BNG configuration, real RADIUS authentication, and real subscriber traffic. This role sits at the intersection of network engineering and systems engineering. You will own the infrastructure that makes internet access work for Share’s partner ISPs.

Requirements

  • 5+ years of professional systems engineering or network engineering experience, with at least 2 years working directly with RADIUS (FreeRADIUS, Radiator, or NPS) in a production ISP or telecommunications environment
  • Deep FreeRADIUS expertise. You can configure virtual servers, write unlang policies, set up proxy realms, configure SQL modules, and debug authentication failures from packet captures.
  • Strong Linux systems administration. You manage production servers, write deployment scripts, configure firewalls, and troubleshoot networking issues at the OS level.
  • Understanding of PPPoE authentication, DHCP, IP pool management, and how BNGs interact with RADIUS servers.
  • Experience deploying and managing infrastructure in production — not just dev environments.
  • Comfortable with scripting and light application development. You should be able to write and maintain a Hono/Express API, work with SQL databases, and automate deployments.

Nice To Haves

  • Experience in East African ISP or telecommunications infrastructure.
  • Understanding of the operational realities: MikroTik-dominant networks, mixed vendor environments, bandwidth constraints, and the practical challenges of managing subscriber authentication at scale in this market.
  • Experience with FreeRADIUS proxy configurations (proxying between multiple RADIUS servers with failover logic).
  • Experience with CoA (Change of Authorization) and Disconnect-Message implementation.
  • Docker and container orchestration for networking services.
  • Experience working alongside software engineering teams — you can read a NestJS service, understand an event-driven architecture diagram, and communicate technical constraints clearly to developers.
  • AI-augmented engineering mindset: Use AI tools (Claude, ChatGPT, Copilot, or similar) for configuration generation, troubleshooting, documentation, and scripting. Comfortable with AI-generated specifications and can validate them against real-world behavior. Contribute to the team’s AI workflows by writing clear, structured documentation that both humans and AI can work with.

Responsibilities

  • Own Share’s network-facing infrastructure: the FreeRADIUS proxy servers that authenticate ISP subscribers, the provisioning pipeline that pushes credentials and plan attributes to per-partner RADIUS servers, the BNG integration layer, and the deployment and monitoring of all systems infrastructure.
  • Work directly with the network team (who handle ISP-side BNG configuration) and the software team (who build the APIs that drive provisioning).
  • Configure FreeRADIUS servers, write deployment scripts, troubleshoot authentication failures on production networks, and design the infrastructure that scales from 5 ISP partners to 50.
  • Own the configuration, deployment, monitoring, and scaling of the FreeRADIUS proxy architecture.
  • Manage per-partner FreeRADIUS instances, their database backends, and their API endpoints.
  • Work with the network team to define and validate the BNG-side configuration changes required for each ISP partner (RADIUS pointer, Share-specific subnet, source-based routing, pool configuration).
  • Ensure the FreeRADIUS API, database, and RADIUS configuration are correct and performant for the provisioning pipeline.
  • Manage server provisioning, deployment automation, monitoring, logging, and security for all systems infrastructure.
  • Design and implement the CoA (Change of Authorization) endpoint on per-partner FreeRADIUS servers for real-time plan changes and session disconnects without re-authentication.

Benefits

  • Competitive salary and meaningful equity in a mission-driven, investor-backed company (US-incorporated; Kenya operating entity).
  • Private health and wellness benefits
  • A high-ownership environment with a steep but well-supported learning curve, and a team that writes things down.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service