Staff Network Engineer, App Platform

Scale AI · San Francisco, CA · Applications Platform Engineering · listed September 3, 2026

The shape of it

Seniority
Staff
Experience asked
5+ years
Where
Hybrid
Requirements listed
4
Length
1,236 words

In the posting’s own words

As SGP has grown in scale and complexity, networking has become a critical architectural discipline of its own. Today, teams routinely encounter the same hard problems — VPC design, routing, ingress and egress, private connectivity, service exposure, address-space constraints, firewall policies, and cross-environment communication — but solve them differently depending on the deployment. We’re looking for a Senior Network Engineer to establish the architectural standards for how SGP connects to customer infrastructure and how traffic moves throughout the platform.

What it asks for · 4

  • Deep expertise in cloud networking on at least two of AWS, Azure, and GCP: VPC design, peering, Transit Gateway/hub-and-spoke topologies, private connectivity (PrivateLink, Private Service Connect), and DNS
  • Experience with edge/CDN and traffic-management platforms such as Cloudflare
  • Infrastructure-as-code proficiency (Terraform preferred)
  • Familiarity with network security and compliance requirements in regulated industries (healthcare, finance, government), including environments across multiple compliance regimes (commercial, FedRAMP/GovCloud, air-gapped), is a plus

What the job covers

  • Own network architecture for the SGP platform: define and enforce network standards across cloud environments (AWS, Azure, GCP) and customer deployments
  • Design and review VPC architectures, peering, DNS, load balancing, and CDN/edge configurations (e.g., Cloudflare), grounding root-cause and tradeoff discussions in data and domain depth
  • Bring strong technical judgment to VPN, routing, access, ingress/egress, and traffic-flow decisions
  • Review proposed networking solutions from platform, product, and forward-deployed teams; evaluate what should and should not be introduced into the platform boundary
  • Define the standard connectivity pattern between Scale's control plane and customer data planes (VPC peering, PrivateLink/Private Service Connect, site-to-site VPN, reverse tunnels) — and converge today's per-customer designs onto it
  • Own the customer-boundary delivery blueprint: how code, images, and traffic cross into a customer tenant — CI/CD mirroring across org boundaries (including customer-side Azure DevOps), artifact scan gates, private registries, ingress — so new engagements configure a pattern instead of designing one
  • Own engineer access into customer and internal environments (Tailscale/Teleport/bastion-class decisions), replacing per-engineer VPN sprawl and hand-rolled tunnels with something auditable
  • Own the Kubernetes traffic layer: Istio/Envoy mesh and ingress, the per-cloud CNI matrix, and a portable NetworkPolicy contract that constrains egress for thousands of short-lived agent-sandbox pods running untrusted code
  • Reduce rework by preventing one-off implementations from becoming long-term platform burden
  • Partner with security engineering on network segmentation, zero-trust access, and compliance requirements in regulated customer environments
  • Debug complex connectivity, latency, and traffic-flow issues across hybrid and multi-cloud deployments
  • Document network architecture, standards, and runbooks so adjacent teams can operate confidently

Tools and skills named

Cloud & infra
  • Azure5×
  • AWS4×
  • GCP4×
  • Kubernetes3×
  • CI/CD
  • Terraform
Security & compliance
  • Security2×
Models & research
  • Inference

Words the posting leans on

  • network14×
  • customer10×
  • platform9×
  • cloud7×
  • networking7×
  • deployment6×
  • design6×
  • sgp6×
  • connectivity5×
  • network architecture5×
  • service5×
  • standards5×
  • aws azure4×
  • compliance4×
  • decisions4×
  • gcp4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Scale AI

every open role at Scale AI

How this page was made

An automated read of a public job posting, fetched September 3, 2026 and last changed by Scale AI on September 3, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.