Network Engineer - Core Infrastructure
THE TEAM
Founded in 2011, Kraken is one of the world's longest-standing crypto platforms, trusted by over 10 million individuals and institutions across the globe. It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.
If you thrive in a challenging, fun, fast-paced environment, the Network Engineer role within Core Infrastructure Engineering at Kraken is for you! This is a strategic, security-minded, hands-on position critical to Kraken's success - on a highly dedicated team that designs, builds, secures, and operates the entire network and data-center infrastructure for one of the world's leading cryptocurrency exchanges. We want a dynamic, code-forward self-starter who thinks "outside the box," sweats the operational details, and automates the repetitive work away. This role spans four disciplines - build, secure, operate, and automate. We don't expect anyone to master all of them on day one. We hire across levels: earlier-career engineers will focus on hands-on build and the operational request queue and grow into design and tooling, while senior engineers will lead fabric/network design, own automation, and mentor the team.
THE OPPORTUNITY
Design & build data centers
- Design and build data centers end-to-end: cages, racks, PDU/power, structured cabling, and hardware install
- Deliver connectivity - circuits, dark fiber, and DIA - including carrier/vendor coordination, cross-connects, and capacity planning
- Stand up and evolve modern data-center fabrics (e.g., Cisco ACI and HPE Juniper Apstra)
Secure the network
- Design, implement, and defend a "zero-trust," defense-in-depth network, with firewalls at the center (policy, segmentation, secure connectivity)
- Implement and evolve enterprise network access controls (RBAC, least-privilege, segmentation)
- Partner with Engineering and IT Security so security is "built-in" from the start and features ship securely and monitored
Operate & respond
- Serve as a first responder to a high volume of inbound infrastructure requests - provisioning, access, connectivity, and troubleshooting - and keep the queue moving
- Monitor and maintain all physical infrastructure (network, security, compute), cloud environments, and remote sites; respond to critical incidents to maximize uptime
Automate & tool
- Manage and deploy "infrastructure as code" at scale
- Build team tooling - automation, internal utilities, and AI agents - to reduce toil and scale the team
- Write high-quality policies, procedures, and technical documentation; evangelize and (at senior levels) mentor on secure-network practices
WHAT YOU BRING
- 2+ years of network engineering with a security-minded approach
- Hands-on with firewalls (e.g., Palo Alto Networks / PAN-OS / Panorama) - a huge plus
- Hands-on data-center / physical infrastructure work: racking, cabling, power, cross-connects, and hardware install
- Working knowledge of switching (VLANs, capacity planning) and routing (OSPF, BGP, ECMP, PBR)
- Exposure to public cloud networking (AWS, Azure, or GCP) and hybrid connectivity
- Familiarity with infrastructure-as-code / automation (e.g., Terraform, Ansible) and a code-forward mindset
- Comfort with VPN / remote-access connectivity
- A bias for automating repetitive work and a strong operational / ownership instinct
- Industry-standard platforms from vendors such as Palo Alto Networks, Cisco, HPE Juniper Networking, and HPE Aruba Networking
- Valid passport and ability to travel internationally as needed
NICE TO HAVES
- Data-center design & build at scale (multi-site buildouts, carrier/circuit delivery, capacity planning)
- Data-center fabric design: Cisco ACI, HPE Juniper Apstra
- Deep firewall design & operations (multi-site policy, HA clusters, PAN-OS/Panorama at scale)
- Building AI agents / developer tooling that reduce operational load (agentic triage, runbook automation)
- Defensive security systems against internal and external threats; IDS/IPS, security monitoring; security testing (performance- and threat-based); offensive/defensive concepts
- Deeper public / private / hybrid cloud experience; owning IaC pipelines end-to-end