Sign up to access all features of our service
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Systems Engineer

Full-time

Censys

Responsibilities

  • Design, build, maintain, and scale static and dynamic file analysis pipelines.
  • Maintain and optimize YARA rule sets and tooling for testing, performance, and false-positive management.
  • Operate and extend real-time threat indicator enrichment, metadata extraction, scanning, and enrichment systems.
  • Build threat graph intelligence systems modeling relationships among indicators, malware, infrastructure, and actors.
  • Design and maintain sandboxing and detonation capabilities with behavioral telemetry and safe execution environments.
  • Build ingestion and normalization pipelines connecting internal Censys scan data with external threat intelligence feeds.
  • Instrument systems for reliability and observability through logging, monitoring, alerting, and SLAs.
  • Partner with threat research and detection engineering teams to translate analytical needs into scalable systems.
  • Maintain secure handling and isolation practices for malicious samples and analysis environments.
  • Document architecture, runbooks, and operational procedures for owned systems.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
  • At least 6 years of experience building security data pipelines, detection engineering systems, or threat intelligence platforms.
  • Experience with Synapse or comparable graph-based threat intelligence platforms, including graph data modeling.
  • Strong programming skills in Python and/or Go.
  • Working knowledge of static and dynamic malware analysis tooling and pipelines, including disassemblers, sandboxes, and debuggers.
  • Experience with distributed data pipelines, message queues, and data stores.
  • Familiarity with Docker and Kubernetes for isolated execution environments.
  • Experience designing and operating highly available production systems on AWS, GCP, or Azure.
  • Demonstrated use of LLM-based coding harnesses and agent-based development workflows such as Claude Code or Copilot.
  • Experience with MISP, OpenCTI, STIX/TAXII, internet-wide scan data, YARA rules, Strelka, or comparable security and file-scanning tools is advantageous.
  • Open source contributions, CI/CD experience for detection content, and familiarity with SOC 2 or ISO 27001 are additional advantages.

Benefits

  • Fully remote position with no regular office attendance expected.
  • US benefits include equity, health, dental and vision coverage, retirement contributions, parental leave, mental health and wellness benefits, flexible PTO, and a professional development stipend.
  • Eligible non-sales employees may participate in an annual bonus plan.
  • Location-specific benefits are provided for employees outside the US.
  • Hired employees will be invited to Ann Arbor, Michigan for in-person onboarding.
  • Reasonable accommodations are available throughout the hiring process and employment.
Vacancy posted 4 days ago