At a Glance
- Tasks: Design and operate Cloudflare edge configurations, ensuring secure and reliable traffic management.
- Company: Join Kraken, a leading crypto platform with a global presence and innovative culture.
- Benefits: Competitive salary, remote work options, and opportunities for professional growth.
- Other info: Diverse team culture that values unique perspectives and encourages passion for crypto.
- Why this job: Be at the forefront of open finance, making a real impact in the crypto space.
- Qualifications: 3+ years in SRE or similar roles, with hands-on experience in Cloudflare and edge systems.
The predicted salary is between 60000 - 80000 £ per year.
Building the Future of Open Finance
Payward – the parent company behind Kraken, Ninja Trader, Breakout, x Stocks, Payward Services and CF Benchmarks – has spent the last 15 years building one of the most modern and globally accessible financial infrastructure platforms in the industry, built to advance an open, global financial system.
Before you apply, we encourage you to explore our culture page to understand what drives us and how we work.
The Team
Founded in 2011, Kraken is one of the world’s longest‑standing crypto platforms, trusted by over 10 million individuals and institutions across the globe.
It offers spot trading, margin, futures, staking, and OTC services, with products built for both individual investors and institutional clients.
Join our engineering team as a Senior Site Reliability Engineer focused on the edge and ingress layer that fronts our platform – the systems that stand between the public internet and our services.
You will own the design, hardening, and operation of our Cloudflare edge configuration and our ingress/reverse‑proxy stack, ensuring traffic reaches our applications securely, reliably, and at scale.
As a member of the SRE team, you will guarantee the availability, performance, low‑latency, security, and cost efficiency of our edge and ingress infrastructure.
This is an excellent opportunity for an engineer who is passionate about edge networking, application security, load balancing, and building self‑service automation for dozens of engineering teams operating mission‑critical financial services.
You will work closely with Security Engineers, Net Ops, Platform teams, and Software Engineers to improve operational excellence for how traffic enters and moves through our environment, while mentoring other engineers and raising the bar on edge and ingress reliability practices.
The Opportunity
- Own and evolve our Cloudflare edge configuration across accounts and zones, including WAF rules, custom rulesets, bot protection, and rate‑limiting policies.
- Design and maintain DNS architecture in Cloudflare, including zone delegation, record hygiene, and change management at scale.
- Implement and operate m TLS with authenticated origin pulls, private PKIs, and manage the certificate lifecycle (issuance, rotation, renewal) across Cloudflare and origin infrastructure.
- Build and support self‑service automation for edge configuration using Terraform, enabling application teams to safely manage their own WAF, DNS, and routing changes.
- Develop and operate solutions using Cloudflare Workers and R2 storage to extend edge logic and reduce origin load.
- Own the ingress and reverse‑proxy layer, including HAProxy OSS and HAProxy Fusion (enterprise), covering TLS termination, m TLS, TCP passthrough, proxy‑protocol handling, HTTP/HTTPS/FIX protocols.
- Design and manage reverse proxy topologies and load balancing across AWS Load Balancers, AWS Direct Connect, AWS Private Link, and similar solutions for hybrid on‑premises/cloud connectivity.
- Build, operate, and improve Kubernetes ingress controllers, and design/write Kubernetes operators and CRDs to automate ingress and routing configuration as code.
- Operate and extend service mesh (Istio) capabilities, including traffic management, m TLS between services, and observability of east‑west traffic.
- Partner with security to defend against OWASP‑class attack vectors, implement credential‑stuffing protection, DDo S prevention, and manage ACLs across the edge and ingress layers.
- Implement robust monitoring and alerting for edge, DNS, and ingress health to proactively detect anomalies, latency regressions, and abuse patterns.
- Lead incident response for edge/ingress‑related incidents and participate in on‑call rotations, including post‑mortems and runbook development.
- Document architecture, standards, and best practices for the edge and ingress layer, and mentor other engineers on Cloudflare and ingress operations.
- Act as the primary subject‑matter expert for Cloudflare, ingress, and edge networking, providing weekly support to engineering teams through office hours, support requests, architecture guidance, technical coaching, and hands‑on assistance to unblock projects and enable successful adoption of platform capabilities.
What You Bring
- 3+ years of experience as an SRE, Cloudflare engineer, platform/infrastructure engineer, or similar role, with meaningful ownership of edge, CDN, or ingress systems.
- Hands‑on production experience with Cloudflare, including WAF/rulesets, bot protection, rate limiting, DNS, zones/accounts administration, and certificate management.
- Production experience operating HAProxy (OSS and/or Fusion) or comparable reverse proxies, including TLS termination, TCP passthrough, and proxy‑protocol.
- Experience with AWS networking primitives: Direct Connect, load balancers (ALB/NLB), and VPC routing/connectivity patterns.
- Working knowledge of service mesh technology (Istio or equivalent) and its role in traffic management and m TLS.
- Experience operating Cloudflare Workers and R2 storage in production for edge compute or storage offload use cases.
- Solid understanding of web application security: OWASP Top 10‑style attack vectors, credential stuffing, DDo S mitigation strategies, and ACL design.
- Proficiency with infrastructure‑as‑code, particularly Terraform and Atlantis, and comfort building self‑service automation for other engineering teams.
- Solid scripting/programming ability (bash plus at least one of Python or Go) and comfort using AI tools and agents (e. g., Claude) to accelerate delivery.
- Familiarity with observability stacks such as Grafana, Victoria Metrics, Tempo, Splunk, or similar tools for edge and network telemetry.
- Strong problem‑solving skills and the ability to troubleshoot complex, distributed, and adversarial network traffic issues under pressure.
- Solid understanding of HTTP semantics in the browser context: caching behaviour, cross‑origin resource sharing (CORS), and cookie/session management.
- Nice to Haves
- Cloudflare One VPN management experience.
- On‑premises colocation with clients for ultra‑low‑latency environments.
- Experience troubleshooting low‑level Linux performance bottlenecks, NUMA pinning, packet drops.
- Strong Kubernetes experience, including deploying and troubleshooting ingress controllers, and hands‑on experience building or maintaining Kubernetes operators/CRDs.
- Experience operating Kubernetes ingress controllers at scale across AWS and on‑premises environments.
- Background in highly regulated or financial services environments where change management and audit trails are critical.
Unless a specific application deadline is stated in the posting, applications are accepted on an ongoing basis.
Applicants may redact or remove information on their resume that identifies age, date of birth, or dates of attendance at or graduation from an educational institution.
We consider qualified applicants with criminal histories for employment on our team, assessing candidates in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.
Our Commitment
Payward is powered by people from around the world and celebrates diverse talents, backgrounds, contributions, and unique perspectives.
We hire based on merit, seeking out people with the right abilities, knowledge, and skills for the role.
We encourage applications from candidates who may not fully meet the listed requirements but are passionate or knowledgeable about crypto.
As an equal‑opportunity employer, we do not tolerate discrimination or harassment of any kind, whether based on race, ethnicity, age, gender identity, citizenship, religion, sexual orientation, disability, pregnancy, veteran status, or any other protected characteristic as outlined by federal, state, and local laws.
Compensation Range: $100 K – $130 K
#J-18808-Ljbffr
Site Reliability Engineer - Cloudflare & Ingress - Core Infrastructure employer: Kraken
At Payward, we pride ourselves on being an exceptional employer, offering a fully remote work environment that promotes flexibility and work-life balance. Our culture is rooted in hyper-transparency and open dialogue, fostering collaboration across diverse teams while providing ample opportunities for professional growth and development in the fast-paced fintech landscape. Join us to be part of a forward-thinking team dedicated to building a resilient financial infrastructure that empowers innovation and inclusivity in the global financial system.