This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevOps / Network Engineer (VPN) based in Spain.
This remote engineering role offers the opportunity to take ownership of the infrastructure powering a globally distributed VPN product. You will operate and evolve networking infrastructure across multiple cloud and hosting providers, alongside an AWS-based control plane and supporting backend services. The role combines hands-on network engineering, DevOps, infrastructure automation, security, observability, and production operations. You will inherit a live environment, understand its architecture and risks, and progressively make it more reliable, automated, secure, and cost-efficient. Agentic AI tools are an important part of the engineering workflow, helping accelerate development, investigation, documentation, and operational automation. Working within a small, highly collaborative engineering team, you will have substantial ownership over infrastructure that directly impacts users around the world.
Accountabilities
- Take technical ownership of the infrastructure and networking domain for a globally distributed VPN service operating across multiple cloud and hosting providers.
- Operate, stabilize, and continuously improve VPN infrastructure, AWS-based control plane services, backend systems, and supporting operational tooling.
- Analyze the existing production environment, document its architecture and dependencies, and identify the most significant reliability, security, scalability, and cost risks.
- Replace manual operational procedures and runbooks with infrastructure-as-code, automation, repeatable deployments, and self-service workflows.
- Build and strengthen CI/CD pipelines with automated testing, deployment safeguards, observability, and reliable rollback mechanisms.
- Manage VPN networking technologies and infrastructure, including server provisioning, configuration, routing, NAT, DNS, TLS, traffic shaping, health monitoring, failover, and key management.
- Develop monitoring, logging, alerting, and incident-response capabilities to improve availability and operational resilience.
- Troubleshoot production incidents, participate in 24/7 on-call operations, perform root-cause analysis, and ensure recurring issues are addressed through automation and system improvements.
- Use agentic AI and AI coding tools to accelerate infrastructure development, incident investigation, documentation, and automation while thoroughly reviewing and validating generated output before production deployment.
- Collaborate closely with engineering and product teams to balance uptime, latency, connection success rates, capacity, infrastructure costs, and overall user experience.
- Contribute to iterative two-week development cycles by testing hypotheses, validating feasibility, and delivering well-tested, version-controlled infrastructure changes.
- Strengthen security practices covering secrets management, encryption, least-privilege access, vulnerability management, server hardening, and relevant privacy and compliance requirements.
- 5+ years of professional experience in DevOps, SRE, network engineering, or a related discipline, with hands-on responsibility for production infrastructure in an agile environment.
- Strong practical experience with AWS, including EC2, Lambda, S3, RDS/PostgreSQL, Route 53, IAM, VPC, and CloudWatch, plus experience with at least one additional cloud or hosting provider such as DigitalOcean, Vultr, Hetzner, or Linode.
- Solid experience with Terraform and Ansible, Docker, container orchestration or fleet management, and Linux system administration.
- Strong networking knowledge covering iptables/nftables, WireGuard, routing, NAT, DNS, TLS/certificates, and traffic shaping.
- Hands-on experience operating VPN, proxy, or comparable networking infrastructure in production, with strong knowledge of provisioning, configuration, key management, monitoring, failover, and network performance. Experience with WireGuard, Shadowsocks, OpenVPN, or IKEv2/IPsec at scale is highly desirable.
- Understanding of DNS and domain management, Cloudflare and edge infrastructure, CDN technologies, IP reputation, geographic distribution, and resilience strategies for provider outages or network restrictions.
- Experience with observability and alerting tools such as Datadog, Prometheus, Grafana, Cloudflare, and centralized logging, alongside production incident response.
- Strong CI/CD experience with GitHub Actions or similar platforms, including automated testing, safe deployment practices, and rollback strategies.
- Proficiency in scripting and automation using Python, Go, Bash, or comparable languages.
- Strong understanding of security fundamentals, including Vault, AWS Secrets Manager or SSM, encryption in transit and at rest, least-privilege IAM, vulnerability scanning, and hardening of public-facing infrastructure.
- Demonstrated day-to-day proficiency with agentic AI tools such as Claude Code, Cursor, or GitHub Copilot agents, combined with sound judgment and rigorous verification of AI-generated infrastructure code.
- Proven experience owning production operations, investigating incidents, identifying root causes, and improving systems to reduce recurring manual work.
- Excellent analytical, organizational, and problem-solving abilities, with the independence to deliver confidently while recognizing when collaboration or escalation is required.
- Strong communication skills, empathy, accountability, curiosity, attention to detail, and a proactive approach to improving systems and processes.
- Passion for technology and a willingness to continuously learn and adopt new engineering practices and tools.
- Experience with censorship-circumvention technologies, traffic obfuscation, restrictive network environments, userspace network stacks, Kubernetes/Nomad, Packer, self-managed databases, cloud cost optimization, FinOps, compliance programs, or mobile app release pipelines is a plus.
- 100% remote-first working environment with the flexibility to work from Spain.
- Competitive compensation package, with individual bonuses available under the applicable company bonus program.
- Participation in an equity plan for eligible full-time team members.
- Generous perks and benefits designed to support remote employees.
- Open PTO, company holidays, and wellness days for eligible full-time employees.
- Opportunity to take significant ownership of a live, globally distributed VPN infrastructure.
- Work with modern cloud, networking, infrastructure-as-code, observability, security, automation, and agentic AI technologies.
- Close collaboration with experienced engineering and product professionals in a small, agile environment.
- Regular opportunities to improve infrastructure, automate operational processes, and directly influence reliability and user experience.
- Remote social activities, including virtual coffee programs and team milestone celebrations.
- Employee recognition and rewards programs.
- Weekly meeting-free days focused on execution and getting work done.
- Opportunity to contribute to a privacy-focused product serving users across global markets.

