Jobs · Engineering · Indiana

Software Engineer (Python) — Programmable Networking

Telnyx · North Township, IN · 3 days ago
EngineeringFull-time

The Opportunity

Telnyx sells networking as an API product: Private Networks, WireGuard interfaces, Virtual Cross Connects into AWS/Azure/GCP, anycast Global IP, and Public Internet Gateways. A small team owns this end-to-end — the public REST API, the orchestration control plane behind it, and the automation that programs real routers across our US, EU, and APAC PoPs. This role is the full stack of that.

You design the API resource, write the orchestration code that turns a request into a network deployment, and own the BGP config it renders onto the fleet. You'll be part of a small, focused team where you own products from the developer-facing spec all the way down to the config on the box — and where the network layer isn't someone else's problem, it's the point.

What You'll Own

  • The public API on api.telnyx.com — /networks, /virtual_cross_connects, /wireguard_interfaces, /wireguard_peers, /global_ips, /public_internet_gateways and their coverage/health/usage endpoints.
  • Resource modeling, OpenAPI 3 specs (public and private), edge API-gateway routing, and backward compatibility for live customers.
  • The orchestration control plane (Python 3.12, asyncio) — translating POST/DELETE into network deployments: resource allocation (IPAM, port/route-distinguisher/GRE-ID pools), Postgres-backed job queues (SKIP LOCKED), retries, rollback on partial failure, deploy/decommission runners, and long-running health-check and reconciliation daemons.
  • The network automation layer — Ansible + asyncssh/netmiko pushing Jinja2-templated config to a fleet of Linux and VyOS nodes: WireGuard interface and peer lifecycle, FRR/VyOS BGP (VRFs, route reflectors, BGP labels), GRE tunnels, static NAT and firewall rules, Unbound DNS, anycast announce/withdraw driven by health checks, and config-drift detection.
  • Cloud interconnect integrations — Equinix Fabric and Equinix Metal APIs to land virtual cross connects into AWS, Azure, and Google Cloud regions.
  • Envoy-based data planes — a Go xDS control plane on envoyproxy/go-control-plane, pushing CDS/RDS/EDS over ADS to edge and gateway Envoy fleets.
  • Prometheus/Telegraf metrics and alerting, Bugsnag, customer escalations that span app logic and the network, and billing sync (MRC) for network resources.

Tech Stack (what You'll Actually Touch)

  • Languages: Python (asyncio: aiohttp, uvloop, SQLAlchemy, Alembic, aiopg), Go (Envoy control plane), Jinja2, Bash
  • Data: PostgreSQL (schema design, migrations, advisory locking, as a job queue), RabbitMQ
  • Network OS / routing: VyOS, FRR, Linux networking (VRFs, netfilter/NAT, netplan, GRE, WireGuard), BGP (VRFs, route reflectors, communities/labels, anycast), Unbound
  • Automation: Ansible / ansible-runner, netmiko, asyncssh, NetBox-style IPAM (pynetbox, netaddr)
  • Proxy / data plane: Envoy, xDS (ADS, go-control-plane)
  • Vendor & cloud: Equinix Fabric, Equinix Metal, AWS / Azure / GCP interconnect regions
  • Platform: Docker/OCI, GitHub Actions, HashiCorp Vault, OpenAPI 3 + Redocly, pytest (unit → e2e), mypy/ruff/black
  • Architecture: clean/hexagonal (usecases, repository interfaces, adapters) — the service is structured, not a script pile

Similar jobs