Senior Systems Engineer Job Share

Job Title:
Date Posted:
Job Type:
Job Level:
Employer:
Industry:
Salary:
Location:
Country:
Deadline:
Summary:

IT Jobs. Share Jobs

We are hiring a Systems Engineer to own Share’s network-facing infrastructure: the FreeRADIUS proxy servers that authenticate ISP subscribers, the provisioning pipeline that pushes credentials and plan attributes to per-partner RADIUS servers, the BNG integration layer, and the deployment and monitoring of all systems infrastructure. You will work directly with the network team (who handle ISP-side BNG configuration) and the software team (who build the APIs that drive provisioning).

This is a hands-on role. You will configure FreeRADIUS servers, write deployment scripts, troubleshoot authentication failures on production networks, and design the infrastructure that scales from 5 ISP partners to 50. You will be the person the team calls when a subscriber can’t authenticate or when a new ISP’s BNG doesn’t behave as expected.

  • FreeRADIUS proxy architecture: Share operates a central RADIUS proxy that routes authentication requests to per-partner FreeRADIUS servers. The proxy uses a failover mechanism (soft reject → attribute clearing → failover to partner pool) to determine whether a subscriber is Share-managed or partner-managed. You will own the configuration, deployment, monitoring, and scaling of this architecture.
  • Per-partner FreeRADIUS servers: Each ISP partner gets a dedicated FreeRADIUS instance with a Hono API overlay for programmatic CRUD of subscriber credentials and plan attributes. You will manage these instances, their database backends, and their API endpoints.
  • BNG integration support: Work with the network team to define and validate the BNG-side configuration changes required for each ISP partner (RADIUS pointer, Share-specific subnet, source-based routing, pool configuration). You are the bridge between the software platform and the ISP’s physical infrastructure.
  • Provisioning pipeline: The software platform’s Provisioning service pushes subscriber credentials and plan attributes to FreeRADIUS. You own the receiving end — ensuring the FreeRADIUS API, database, and RADIUS configuration are correct and performant.
  • Infrastructure and deployment: Server provisioning, deployment automation, monitoring, logging, and security for all systems infrastructure. GitHub Actions pipelines, SSH-based deployments, VM management.
  • CoA (Change of Authorization): Design and implement the CoA endpoint on per-partner FreeRADIUS servers for real-time plan changes and session disconnects without re-authentication.

Technical environment

RADIUS and network authentication

  • FreeRADIUS (v3 in production, v4 evaluation in progress) — proxy configuration, virtual servers, module configuration (sql, rest, files)
  • RADIUS protocols: Access-Request/Accept/Reject, Accounting (Start/Interim/Stop), CoA (Disconnect-Request, CoA-Request)
  • PPPoE authentication flow: subscriber CPE → BNG → RADIUS proxy → per-partner RADIUS → response with speed/pool/timeout attributes
  • MikroTik RouterOS BNG configuration (the network team handles this, but you need to understand the RADIUS-facing side)
  • Per-user flat attributes (speed, IP pool, session timeout) pushed via Hono API to FreeRADIUS SQL backend

Systems and infrastructure

  • Linux server administration (Ubuntu)
  • Docker containerization for FreeRADIUS instances and supporting services
  • Hono (lightweight Node.js framework) for the FreeRADIUS API overlay
  • PostgreSQL for RADIUS user databases (radcheck, radreply, radacct tables)
  • GitHub Actions for CI/CD, SSH-based deployment to VMs
  • Monitoring: Loki + Pino for structured logging, Sentry for error tracking

Integration points with the software platform

  • NestJS Provisioning microservice calls your FreeRADIUS API to push/update/delete subscriber credentials
  • Kafka events trigger provisioning actions (PROVISION_SUBSCRIBER, UPDATE_PLAN_ATTRIBUTES, DELETE_RADIUS_CREDENTIALS)
  • The proxy’s routing decision (Share vs partner) determines the subscriber’s billing path

Non-negotiable

  • 5+ years of professional systems engineering or network engineering experience, with at least 2 years working directly with RADIUS (FreeRADIUS, Radiator, or NPS) in a production ISP or telecommunications environment
  • Deep FreeRADIUS expertise. You can configure virtual servers, write unlang policies, set up proxy realms, configure SQL modules, and debug authentication failures from packet captures.
  • Strong Linux systems administration. You manage production servers, write deployment scripts, configure firewalls, and troubleshoot networking issues at the OS level.
  • Understanding of PPPoE authentication, DHCP, IP pool management, and how BNGs interact with RADIUS servers. You don’t need to be a MikroTik expert, but you need to understand what the BNG expects from RADIUS.
  • Experience deploying and managing infrastructure in production — not just dev environments. You understand uptime requirements, failover, and what happens when a RADIUS server goes down (subscribers can’t authenticate).
  • Comfortable with scripting and light application development. You don’t need to be a full-stack developer, but you should be able to write and maintain a Hono/Express API, work with SQL databases, and automate deployments.

Click Here to Apply

Related Jobs To Check Out

Jobs Managed by Our Recruitment Team

The vacancies below are managed directly by the Corporate Staffing recruitment team on behalf of our clients. Review the job advert, then submit your application through our recruitment team for consideration.


Browse Other Jobs Posted Today

Explore the latest job opportunities posted now. Apply early to maximize your chances, as many employers begin reviewing applications as soon as suitable candidates apply.