Senior Network Automation Engineer (Linux, API, DNS DoH/DoT)
Location:Remote (Europe)
Preferred Regions:Poland, Portugal, Romania, Spain (low-cost EU regions)
Open Positions:1
Role Overview
We are seeking a Senior/Lead Network Automation Engineerto design and operate a modern, API-driven infrastructure. This role focuses on automation-first networking, DNS policy as code, and secure DNS implementations (DoH/DoT).
You will play a critical role in building scalable automation frameworks, managing Linux-based network environments, and ensuring high reliability and observability across DNS and network services.
Key Responsibilities
Automation & Infrastructure as Code
Develop and maintain Ansible roles/collectionsfor network and DNS automation
Implement API-first integrations (REST/JSON)with Cisco and DNS platforms
Ensure code quality via Molecule testing, linting, and CI pipelines
Policy Engineering
Translate business requirements into:
ipsets & ACLs
DNS policies (RPZ, split-horizon)
Cisco SSE policies via APIs
Enforce policy-as-code principles
Linux Network Orchestration
Manage Linux-based network systems (iptables, routing, configs)
Implement baseline configurations, drift detection, and compliance checks
DNS DoH/DoT Ownership
Design and manage DNS over HTTPS (DoH)and DNS over TLS (DoT)
Handle PKI, certificate lifecycle, and trust chains
Define fallback strategies (UDP/TCP 53) and egress policies
Ensure compatibility with proxy/PAC environments
Execute canary releases and staged deployments
CI/CD & GitOps
Build and maintain pipelines using GitHub/GitLab CI + AWX/Tower
Implement progressive delivery, approvals, and rollback strategies
Observability & Reliability
Monitor systems using metrics, logs, and synthetic tests
Define and manage SLOs, SLIs, and error budgets
Lead incident response and post-mortem analysis
Vendor & API Integration
Act as the technical lead for Cisco APIs(Umbrella, Secure Access SSE)
Integrate third-party networking and DNS services
Required Experience
5+ yearsin Linux systems engineering (network-focused)
iptables, ipsets, routing, TCP/IP fundamentals
3+ years of Ansible at scaleRoles, Jinja2, dynamic inventory, Vault
Molecule testing, linting tools, AWX/Tower workflows
Strong experience with API-driven automation (Python + Ansible)
Hands-on experience with GitOps & CI/CD pipelines
Deep knowledge of DNS architecture, including:
Split-horizon DNS, RPZ
DoH/DoT (client & resolver level)
PKI, fallback strategies, telemetry
Nice to Have
Cisco ecosystem: Umbrella, Secure Access SSE, Meraki, FTD, ISE, SD-WAN
Cloud networking: AWS Route53, Azure DNS, GCP DNS
Terraform (network/DNS automation)
Docker / Kubernetes
Observability tools: Prometheus, Grafana, ELK, Splunk
Network telemetry: SNMP, NetFlow/IPFIX
Working Style
Strong focus on Infrastructure as Code & GitOps
Emphasis on automation, testing, and auditability
Use of progressive delivery (canary + staged rollouts)for critical systems
Tools & Technologies
Ansible, AWX/Tower, Molecule, Jinja2
GitHub/GitLab CI
Python (requests, pydantic, click), Bash
Cisco APIs (Umbrella, SSE)
Linux networking (iptables/ipsets)
Monitoring: Prometheus/Grafana / ELK / Splunk
Application Requirements
Share links to relevant automation projects or repositories
Include a brief description of a DoH/DoT implementationyou have designed or managed