Position Title
Network Resilience Engineer – Anti-Censorship Infrastructure
Reporting Line
Reports directly to the Head of Infrastructure / CTO
Location
Remote – Open globally (preference for time zones overlapping Asia and Europe)
General Purpose
Design, deploy, and maintain resilient network infrastructure to ensure uninterrupted access to our services in regions facing heavy internet censorship (e.g., China, India, Middle East). This role focuses on building robust proxy and obfuscation layers, traffic masking strategies, and automated failover mechanisms to maintain service reliability under adversarial network conditions.
Employer Value Proposition
Join a mission-driven team building cutting‑edge infrastructure to uphold digital freedom and bypass censorship worldwide. You’ll have the autonomy to research, test, and deploy creative networking solutions that keep services accessible under the most restrictive environments. This is an opportunity to apply your technical expertise to a globally impactful cause — blending cybersecurity, network engineering, and innovation. The environment is fully remote, collaborative, and research‑driven, ideal for engineers passionate about open access and resilient network design.
Compensation & Benefits
- salary
- Gym Allowance
- health insurance
Career Growth, Work Environment, Recognition & Support
Training, learning opportunitiesCulture, flexibility, leadership styleAppreciation, inclusionSpecific Objectives (first ~12 months)
Design, implement, and maintain proxy and obfuscation stacks (e.g., Shadowsocks, obfs4proxy, Cloudflare Tunnel)Develop a robust monitoring framework for censorship‑related disruptions such as DPI, DNS poisoning, and TCP resetsEstablish automated strategies for IP rotation, traffic masking, and intelligent failoverIntegrate obfuscation layers with backend services to ensure seamless connectivityResearch and adopt emerging circumvention techniques (e.g., TLS camouflage, domain fronting, randomized transports) and Chocolate ProtocolsImplement observability, logging, and analytics for tunnel health and anomaly detectionCollaborate with security, backend, and DevOps teams to strengthen resilience and redundancyKey Activities
Architect and maintain multi‑layered proxy infrastructure across distributed environmentsDeploy and manage tunneling technologies (e.g., V2Ray, WireGuard, Cloudflare Spectrum / Tunnel)Monitor network traffic to identify and mitigate censorship tactics in real timeAutomate configuration, deployment, and scaling using tools like Terraform, Ansible, or GitHub ActionsConduct research into censorship techniques and propose adaptive countermeasuresCollaborate cross‑functionally to ensure application reliability under censorship stressDevelop internal documentation and runbooks for incident response and recoveryEvaluate and implement TLS fingerprinting and evasion strategies using libraries like uTLSKey Competences
Strong Linux system administration and networking fundamentalsDeep familiarity with proxy / tunneling technologies (Shadowsocks, V2Ray, obfs4proxy, WireGuard, etc.)Hands‑on understanding of censorship mechanisms (deep packet inspection, IP blocking, DNS tampering)Proficient in scripting languages such as Bash and PythonExperience with containerization (Docker, Kubernetes, ECS) and automation pipelines (CI / CD)Knowledge of TLS camouflage and randomized transport protocolsUnderstanding of Cloudflare services (Spectrum, Tunnel, Magic Transit) and similar platformsOptional but valuable : familiarity with BGP security, RPKI, and route‑hijack preventionExperience with Go or Rust to customize or build lightweight proxy transportsLikely Current Job
Network / Systems Engineer managing proxy or tunneling infrastructureDevOps / SRE professional with strong network automation experienceSecurity Engineer specializing in encrypted communications and anti‑censorship systemsBackend or Infrastructure Engineer with a focus on networking and traffic optimization#J-18808-Ljbffr