CS Holding logo
CS HoldingPosted 2 months ago

Site Reliability Engineer, DNS

$83,538–$137,241 year

On-siteBethpage, New York, United States

Full Time

Job Summary

DNS Engineer – SRE responsible for the architecture, scalability, and reliability of the mission-critical DNS infrastructure powering our ISP and core network services. This role prioritizes automation, observability, and self-healing systems, coupling deep IP networking and DNS expertise with modern security protocols to ensure platforms remain resilient and highly available. You will lead cross-functional initiatives with Product, Security, and Service Assurance teams to deliver a carrier-grade DNS ecosystem balancing privacy (DoH/DoT) with the availability required by Tier-1 operations. Responsibilities include owning global DNS architectures with Anycast routing and automated failover, managing vendor relationships, lifecycle and capacity planning, enforcing DNSSEC and traffic policies, defining SLOs and error budgets, managing DNS records, implementing and mitigating DNS-based security threats, automating deployments with Python/Go/Ansible/Terraform, tuning Linux performance, and maintaining strong observability via Prometheus, Grafana, and dnstap. Working conditions include hybrid remote/on-site with 24/7 on-call rotations and after-hours maintenance; the company emphasizes equal opportunity employment and a commitment to reliability and security.

Required Qualifications

  • Education: Bachelor’s degree in Computer Science, Telecommunications, or a related field (or equivalent practical experience in networking and security)
  • Experience: 5+ years in a networking or systems engineering role, with a focus on SRE principles (automation, reliability, and monitoring) in production environments
  • DNS Fundamentals: Hands-on experience configuring and maintaining at least two of the following: BIND, Unbound, PowerDNS, AWS Route 53, or Azure DNS
  • Networking Protocols: Functional understanding of TCP/IP (IPv4/v6) and DNS-specific protocols including DNSSEC and encrypted transport (DoH/DoT)
  • Systems & Automation: Strong Linux/Unix administration skills and proficiency in at least one scripting language (Python, Bash, or Go) for task automation
  • Observability: Experience using Grafana and OpenTelemetry (or similar tools) to monitor service health and performance

Desired Qualifications

  • DNS Systems: Hands-on experience managing BIND, Unbound, or PowerDNS in high-traffic environments, alongside cloud-native solutions (AWS Route 53, Azure DNS, Google Cloud DNS)
  • Protocol Expertise: Mastery of DNS-specific protocols including DNSSEC, DoT, and DoH, with a firm grasp of underlying transport layers (UDP/TCP) and dual-stack (IPv4/IPv6) networking
  • Observability: Experience building dashboards and alerts using Prometheus, ELK, or OpenTelemetry to monitor DNS query latency and error rates
  • Automation: Proven ability to manage "DNS as Code" using Terraform or Ansible and writing scripts (Python/Go) to automate routine zone updates
  • Scale & Security: Background in Tier-1/Tier-2 service provider environments with a focus on service resilience, Anycast distribution, and DDoS protection

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce