Network Architect and Engineer
Location: Singapore
Function: IT Infrastructure, Network Architecture and Engineering
Reports to: Head of Engineering and IT
About Us
Dymon Asia Capital is a Singapore headquartered multi-strategy hedge fund managing approximately USD 5 billion in assets. Founded in Singapore and built around Asian markets, we run a range of strategies across macro, commodities, and systematic trading. We employ around 350 people across nine offices globally, with Singapore as our headquarters and primary technology hub. We are regulated by the Monetary Authority of Singapore and operate under the regulatory regimes of the markets in which we invest.
The IT Infrastructure function is organized across four pillars: Network, Windows, Linux, and Cloud. It is a lean six-person team of senior engineers, working in close partnership with the Cybersecurity function and with the trading and research desks it supports.
This role owns the network. That means both the architecture and the hands that build it. There is no separate engineering layer to hand designs to. You will write the configurations, stage and commission the equipment, run the cutovers, take the packet captures, and own the break-fix when something fails out of hours. We are not looking for a design-only architect.
The estate spans nine offices, an Azure hub-and-spoke environment connected over ExpressRoute and VPN, and the market data, broker, and counterparty link our desks depend on. We are expanding into new regions, so office buildings and regional connectivity form a significant part of the work ahead. Network availability and latency translate directly into trading impact, so resilience, deterministic failover, and change discipline matter more here than breadth of technology. We want streamlined topologies sized for a fast-moving fund, not the complexity of a large bank.
Key Responsibilities
Own the end-to-end network architecture and engineering standards across all offices, covering campus, data center, wide area, and remote access, right sized to the firm rather than to enterprise scale.
Build and configure routing, switching, wireless, and firewall platforms directly. This role writes the configurations; it does not review someone else's.
Execute production changes personally, including out-of-hours maintenance windows and cutovers, with tested rollback prepared in advance.
Perform deep troubleshooting of complex faults using packet capture, flow analysis, and device-level diagnostics, acting as the senior hands-on responder for network incidents through to root cause and permanent fix.
Own the network segmentation model and firewall ruleset governance, covering separation of trading, research, corporate, guest, and management traffic.
Design and build the Azure network fabric alongside the Cloud Solutions Architect, covering hub-and-spoke topology, peering, routing, security groups, and hybrid connectivity over ExpressRoute and VPN.
Lead network delivery on new office builds, relocations, and expansion into new operating regions, from carrier procurement through to cutover.
Deliver market data, broker, and counterparty connectivity, including cross-connects, extranet links, and the resilience model around them.
Own capacity planning, latency management, resilience and failover testing, firmware and patch currency, and network monitoring, ensuring telemetry is available to the security operations function.
Build automation and configuration standards using Python, Ansible, or Terraform, and maintain architecture documentation aligned to MAS Technology Risk Management guidelines and NIST CSF 2.0, with cybersecurity architecture review as a required gate on new designs.
Requirements
8 or more years in hands-on network engineering, including at least 3 years carrying architecture and design ownership. Experience in a regulated financial services environment is advantageous. Candidates whose recent experience is design and governance only will not be a fit.
Currently hands-on. You should be actively configuring, troubleshooting, and upgrading network infrastructure today, not directing others who do.
Expert-level routing and switching, including BGP, OSPF, VLANs, spanning tree, QoS, and multicast on enterprise-grade platforms.
Next-generation firewall design and operation, including policy and ruleset governance, NAT, IPS, and secure remote access.
Azure networking includes virtual networks, hub-and-spoke design, ExpressRoute, VPN Gateway, Azure Firewall, and network and application security groups.
Wide area and edge networking, including SD-WAN, MPLS, internet edge design, carrier management, and circuit diversity across international sites.
Core network services, including DNS, DHCP, IP address management, and DNS-layer security, alongside enterprise wireless design and RF planning.
Deep troubleshooting capability, including packet capture and analysis, latency and jitter investigation, and structured fault isolation across layers 1 to 7.
Network automation and monitoring, using Python, Ansible, or Terraform alongside enterprise monitoring and flow analysis platforms.
Delivered multi-site network builds or cutovers end to end. Available to execute out-of-hours change windows and participate in an escalation rota, with communication skills to articulate the business value of technical work.
Preferred certifications: CCNP Enterprise or CCIE, or an equivalent senior network certification. AZ-700 Azure Network Engineer Associate and vendor firewall certifications are advantageous.