Systems Engineer
Full-time
Censys
Responsibilities
- Design, build, maintain, and scale static and dynamic file analysis pipelines.
- Maintain and optimize YARA rule sets and tooling for testing, performance, and false-positive management.
- Operate and extend real-time threat indicator enrichment, metadata extraction, scanning, and enrichment systems.
- Build threat graph intelligence systems modeling relationships among indicators, malware, infrastructure, and actors.
- Design and maintain sandboxing and detonation capabilities with behavioral telemetry and safe execution environments.
- Build ingestion and normalization pipelines connecting internal Censys scan data with external threat intelligence feeds.
- Instrument systems for reliability and observability through logging, monitoring, alerting, and SLAs.
- Partner with threat research and detection engineering teams to translate analytical needs into scalable systems.
- Maintain secure handling and isolation practices for malicious samples and analysis environments.
- Document architecture, runbooks, and operational procedures for owned systems.
Requirements
- Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
- At least 6 years of experience building security data pipelines, detection engineering systems, or threat intelligence platforms.
- Experience with Synapse or comparable graph-based threat intelligence platforms, including graph data modeling.
- Strong programming skills in Python and/or Go.
- Working knowledge of static and dynamic malware analysis tooling and pipelines, including disassemblers, sandboxes, and debuggers.
- Experience with distributed data pipelines, message queues, and data stores.
- Familiarity with Docker and Kubernetes for isolated execution environments.
- Experience designing and operating highly available production systems on AWS, GCP, or Azure.
- Demonstrated use of LLM-based coding harnesses and agent-based development workflows such as Claude Code or Copilot.
- Experience with MISP, OpenCTI, STIX/TAXII, internet-wide scan data, YARA rules, Strelka, or comparable security and file-scanning tools is advantageous.
- Open source contributions, CI/CD experience for detection content, and familiarity with SOC 2 or ISO 27001 are additional advantages.
Benefits
- Fully remote position with no regular office attendance expected.
- US benefits include equity, health, dental and vision coverage, retirement contributions, parental leave, mental health and wellness benefits, flexible PTO, and a professional development stipend.
- Eligible non-sales employees may participate in an annual bonus plan.
- Location-specific benefits are provided for employees outside the US.
- Hired employees will be invited to Ann Arbor, Michigan for in-person onboarding.
- Reasonable accommodations are available throughout the hiring process and employment.
Vacancy posted 4 days ago