This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a seasoned Principal Engineer to take full ownership of Airwallex’s edge networking stack—including API gateway, CDN, DNS, Global Accelerators, and traffic control services. This is a high-impact P5 architect role at the intersection of platform engineering, security, and product velocity. You’ll define the blueprint, lead implementation, and enforce governance for how all external traffic reaches and interacts with our platform globally.
Job Responsibility:
Own the Edge Network Stack
Design and evolve the architecture for Airwallex's external traffic stack including: API Gateways (routing, filtering, throttling), DNS services (global resolution & routing), CDNs (caching strategies and invalidation), Global Accelerators (latency and route optimization)
Define and Enforce Border Security
Partner with InfoSec to design and operationalize: DDoS protection, bot mitigation, and anomaly detection (e.g., Cloud Armor, WAF), Rate limiting and QoS policy enforcement for prioritized customer/partner APIs, Firewall rule governance and bad actor prevention mechanisms, Intrusion Prevention and Auth mechanisms at the border
Policy-Driven API Route Management
Build end-to-end processes and tooling for how engineers expose public APIs: Define policy and controls for route registration, approval, and change management, Work with platform teams to enforce compliance across microservices and gateways, Contribute to internal tools for observability, access review, and lifecycle auditing
Enable Global-Scale, Secure Performance
Establish reliability and quality of service (QoS) goals for critical paths (e.g., payments, onboarding, auth), Design for hybrid/multi-cloud edge strategy and backbone traffic replication, Tune latency, failover, and availability posture across regions
Requirements:
Deep experience in cloud-native edge networking (API Gateway, DNS, CDN, GA, firewalls)
Proficiency with SDN concepts and tools (e.g., OpenDaylight, Envoy, NGINX/OpenResty, Kong, Apisix)
Familiar with Cloudflare, AWS or GCP Cloud Networking, techniques
Knowledge of hybrid/multi-cloud patterns and traffic engineering at scale
Hands-on with cloud firewall systems, WAF, rate limiting, and bot detection
A security-aware mindset with ability to balance protection and developer experience
Experience defining cross-team processes and governance frameworks
Strong communication skills and ability to lead across engineering and security teams
Nice to have:
Experience supporting financial or regulated workloads
Familiarity with Kubernetes traffic management frameworks