The posting, in Trumid's own words
archived Sep 9, 2026About us. Trumid is a dynamic fintech revolutionizing the landscape of fixed income trading. With intelligent, easy-to-use, electronic solutions, we are rapidly growing and seeking exceptional talent to help redefine the boundaries of technology and finance. Founded in 2014 by a team of fixed income market experts, Trumid has quickly become one of the top three corporate bond e-trading platforms in the U.S. Today, over 1,300 traders from an extensive and expanding client network of 890+ buy-and sell-side institutions transact on Trumid monthly. With a rich history of innovation and a unique ability to innovate at scale, we collaborate closely with our clients, iterating quickly toward optimal solutions. With market share and client engagement at all-time highs and our pace of product development faster than ever, this is an exciting and transformative time at Trumid. Our business model thrives on participation, and so does our company culture. We rely on every team member’s contribution to help us accomplish our goals. To succeed at Trumid, you must be curious, passionate about your craft, ambitious, collaborative, and driven. Learn more at www.trumid.com The opportunity. Site reliability is Trumid’s standing top technology priority, and connectivity is where it starts: if we or our customers can’t reach anything, nothing else matters. This role owns request delivery end to end, and the scope test is simple: if it has to be up for a request to reach the right service, it’s yours. That means the whole path — colo routers and switches, client circuits, VPNs and cross-connects, cross-cloud links, DNS, load balancers, and the Envoy service mesh. You’d join the networking side of our SRE team, working alongside experienced network engineers. Some of what you’d walk into: A live migration of our trading edge onto HAProxy Kubernetes Ingress Controller — cut over in production one elastic IP at a time, each step reversible, each step qualified by synthetic trading traffic before real clients ride it. A network device fleet headed for full config-as-code: version-controlled, CI-validated configuration, centralized AAA, and a proper source of truth with IPAM. Client-connectivity request load that we are deliberately engineering away — standardized intake, per-client connectivity dashboards, and eventually self-service for the common low-risk changes. Your job is to automate this work out of existence, not to absorb it. What you’ll do? Own reliability across the full request delivery path — edge network gear, DNS, load balancing, service mesh — spanning our data centers, AWS, and GCP. Drive network automation: config-as-code (Ansible, Terraform, GitOps) with CI validation, a network source of truth with IPAM, and changes that are reviewed, repeatable, and reversible. Find single points of failure on critical paths and retire them; design and run the failover drills that prove they’re gone. Engineer client connectivity — circuits, VPNs, cross-connects, FIX network paths — and build the workflows and dashboards that turn it from interrupt work into a product. Build network observability with the rest of SRE: streaming device telemetry, syslog into our logging stack, and full-path alerting so we detect faults before clients report them. Harden the fleet: firmware currency, centralized AAA tied to our identity provider, control-plane protection, firewall policy as code. Share a sane, deliberately interrupt-contained on-call rotation with the rest of the team. About you. Seven or more years running production networks that include physical gear: routing and switching, BGP, firewalls, circuits and cross-connects. Real cloud networking depth in AWS or GCP: VPC design, transit gateways and peering, network load balancers, DNS, hybrid connectivity. The automation habit. If you’ve done it twice by hand, you script it; your configs live in Git and your changes go through review. Working fluency at the application layer of delivery: L4–L7 load balancing (HAProxy, NGINX, or Envoy), TLS termination, health checking — and enough Kubernetes to operate ingress confidently. Reliability instincts: you would rather rehearse a failover on a quiet Tuesday than discover one during an incident. Clear writing and the ability to work directly with clients’ network teams. Nice to have.
Experience with:
Envoy or another service mesh in production; Kubernetes ingress at scale. Cisco IOS-XE fleets, Palo Alto/Panorama, or network source-of-truth tooling (Infrahub, NetBox, Nautobot). Prometheus/Grafana/ELK-style observability stacks. Employee benefits. Highly competitive compensation Fully paid medical, dental and vision coverage Team-oriented and collaborative company culture Lively and dynamic office space with fully stocked kitchen In compliance with New York City Pay Transparency Law, the base salary range for this role in New York City is between $225,000 – $250,000. This range does not include discretionary bonus or other forms of compensation or benefits offered in connection with this job. Several factors are considered when determining a candidate’s compensation. Trumid is an equal opportunity employer. Please note: All communication from Trumid’s recruiting team comes from @trumid.com email addresses. We conduct remote interviews via Zoom only. We will never ask you to purchase equipment, download software (other than Zoom), or share sensitive personal information during the hiring process.