Tech Stack
AWSCloudDNSFirewallsGoogle Cloud PlatformKubernetesMicroservicesNGINX
About the role
- Take full ownership of Airwallex’s edge networking stack including API gateway, CDN, DNS, Global Accelerators, and traffic control services
- Define the blueprint, lead implementation, and enforce governance for how all external traffic reaches and interacts with the platform globally
- Partner with InfoSec to design and operationalize DDoS protection, bot mitigation, anomaly detection, WAF, firewall rule governance, intrusion prevention and border auth mechanisms
- Define and implement rate limiting and QoS policy enforcement for prioritized customer/partner APIs
- Build end-to-end processes and tooling for route registration, approval, change management, observability, access review, and lifecycle auditing
- Establish reliability and QoS goals for critical paths; design hybrid/multi-cloud edge strategies, backbone traffic replication, and tune latency, failover, and availability across regions
Requirements
- Deep experience in cloud-native edge networking (API Gateway, DNS, CDN, GA, firewalls)
- Proficiency with SDN concepts and tools (e.g., OpenDaylight, Envoy, NGINX/OpenResty, Kong, Apisix)
- Familiar with Cloudflare, AWS or GCP Cloud Networking techniques
- Knowledge of hybrid/multi-cloud patterns and traffic engineering at scale
- Hands-on with cloud firewall systems, WAF, rate limiting, and bot detection
- Security-aware mindset with ability to balance protection and developer experience
- Experience defining cross-team processes and governance frameworks
- Strong communication skills and ability to lead across engineering and security teams
- Bonus: Experience supporting financial or regulated workloads
- Bonus: Familiarity with Kubernetes traffic management frameworks
- Bonus: Mandarin fluency and experience working in global, multi-timezone environments