Senior Systems Engineer Job Share
IT Jobs. Share Jobs
About the role
We are hiring a Systems Engineer to own Share’s network-facing infrastructure: the FreeRADIUS proxy servers that authenticate ISP subscribers, the provisioning pipeline that pushes credentials and plan attributes to per-partner RADIUS servers, the BNG integration layer, and the deployment and monitoring of all systems infrastructure. You will work directly with the network team (who handle ISP-side BNG configuration) and the software team (who build the APIs that drive provisioning).
This is a hands-on role. You will configure FreeRADIUS servers, write deployment scripts, troubleshoot authentication failures on production networks, and design the infrastructure that scales from 5 ISP partners to 50. You will be the person the team calls when a subscriber can’t authenticate or when a new ISP’s BNG doesn’t behave as expected.
Key Responsibilities
- FreeRADIUS proxy architecture: Share operates a central RADIUS proxy that routes authentication requests to per-partner FreeRADIUS servers. The proxy uses a failover mechanism (soft reject → attribute clearing → failover to partner pool) to determine whether a subscriber is Share-managed or partner-managed. You will own the configuration, deployment, monitoring, and scaling of this architecture.
- Per-partner FreeRADIUS servers: Each ISP partner gets a dedicated FreeRADIUS instance with a Hono API overlay for programmatic CRUD of subscriber credentials and plan attributes. You will manage these instances, their database backends, and their API endpoints.
- BNG integration support: Work with the network team to define and validate the BNG-side configuration changes required for each ISP partner (RADIUS pointer, Share-specific subnet, source-based routing, pool configuration). You are the bridge between the software platform and the ISP’s physical infrastructure.
- Provisioning pipeline: The software platform’s Provisioning service pushes subscriber credentials and plan attributes to FreeRADIUS. You own the receiving end — ensuring the FreeRADIUS API, database, and RADIUS configuration are correct and performant.
- Infrastructure and deployment: Server provisioning, deployment automation, monitoring, logging, and security for all systems infrastructure. GitHub Actions pipelines, SSH-based deployments, VM management.
- CoA (Change of Authorization): Design and implement the CoA endpoint on per-partner FreeRADIUS servers for real-time plan changes and session disconnects without re-authentication.
Technical environment
RADIUS and network authentication
- FreeRADIUS (v3 in production, v4 evaluation in progress) — proxy configuration, virtual servers, module configuration (sql, rest, files)
- RADIUS protocols: Access-Request/Accept/Reject, Accounting (Start/Interim/Stop), CoA (Disconnect-Request, CoA-Request)
- PPPoE authentication flow: subscriber CPE → BNG → RADIUS proxy → per-partner RADIUS → response with speed/pool/timeout attributes
- MikroTik RouterOS BNG configuration (the network team handles this, but you need to understand the RADIUS-facing side)
- Per-user flat attributes (speed, IP pool, session timeout) pushed via Hono API to FreeRADIUS SQL backend
Systems and infrastructure
- Linux server administration (Ubuntu)
- Docker containerization for FreeRADIUS instances and supporting services
- Hono (lightweight Node.js framework) for the FreeRADIUS API overlay
- PostgreSQL for RADIUS user databases (radcheck, radreply, radacct tables)
- GitHub Actions for CI/CD, SSH-based deployment to VMs
- Monitoring: Loki + Pino for structured logging, Sentry for error tracking
Integration points with the software platform
- NestJS Provisioning microservice calls your FreeRADIUS API to push/update/delete subscriber credentials
- Kafka events trigger provisioning actions (PROVISION_SUBSCRIBER, UPDATE_PLAN_ATTRIBUTES, DELETE_RADIUS_CREDENTIALS)
- The proxy’s routing decision (Share vs partner) determines the subscriber’s billing path
Qualifications & Experience
Non-negotiable
- 5+ years of professional systems engineering or network engineering experience, with at least 2 years working directly with RADIUS (FreeRADIUS, Radiator, or NPS) in a production ISP or telecommunications environment
- Deep FreeRADIUS expertise. You can configure virtual servers, write unlang policies, set up proxy realms, configure SQL modules, and debug authentication failures from packet captures.
- Strong Linux systems administration. You manage production servers, write deployment scripts, configure firewalls, and troubleshoot networking issues at the OS level.
- Understanding of PPPoE authentication, DHCP, IP pool management, and how BNGs interact with RADIUS servers. You don’t need to be a MikroTik expert, but you need to understand what the BNG expects from RADIUS.
- Experience deploying and managing infrastructure in production — not just dev environments. You understand uptime requirements, failover, and what happens when a RADIUS server goes down (subscribers can’t authenticate).
- Comfortable with scripting and light application development. You don’t need to be a full-stack developer, but you should be able to write and maintain a Hono/Express API, work with SQL databases, and automate deployments.
How to Apply
1. Applying For Jobs That You Qualify But Not Getting Interviews?
Click Here And Get An Expert Review Of Your CV From Our Recruitment Team Plus 3 Months Job Search Assistance. Land Your Next Job Faster.
2. Register your CV with us today for a better job.
Upload your CV to be considered for jobs that match your skills, experience and career level. Upload your CV here — It's free.
3. Stay relevant in a competitive job market.
Register for short professional courses starting next month. See courses starting next month.
4. Pass Your Next Job Interview With Confidence
Learn how to confidently sell your value and negotiate best salary in interviews. Click here for interview preparation. Interview with confidence.
Job Seeker Testimonials
Since 2011 Corporate Staffing has helped over 13,000 job seekers across Kenya secure new jobs with our clients. Read our job seekers’ success stories here.

