Censys logo
Posted 1h agoRemote
Apply ↗

Systems Engineer

MiddleRemote€60,000 – €80,000 / yr
Required Skills
PythonGo (Golang)Next.jsElasticsearchKafkaRabbitMQDockerKubernetesAWSGoogle Cloud (GCP)
Job Description

Company Background

Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.

 

The Systems Engineer will be a part of the Censys ARC (Advanced Research Collective) and will build and operate the pipelines and platforms that power Censys's threat detection and intelligence capabilities. This role will own the engineering behind static and dynamic file analysis at scale, and the graph-based systems that connect indicators, infrastructure, and actors into actionable threat intelligence. You'll work closely with threat researchers and analysts, turning detection and correlation requirements into production-grade systems.

For a systems engineer who's spent years wiring together detection pipelines and threat intel platforms, this role is the rare chance to build that infrastructure at the actual source of the data rather than downstream of it. Censys's internet-wide scan visibility means the enrichment and graph systems you're building aren't consuming someone else's feed, they're powering primary intelligence on global infrastructure and actors. You'd own meaningful technical surface end-to-end: static/dynamic analysis pipelines, YARA tooling, sandboxing, and threat graph modeling connecting indicators to actors, rather than being one contributor on a sprawling platform team. The ARC structure — sitting between engineering and research — means your systems get shaped directly by what threat researchers actually need next, not by a backlog several layers removed from the analysts using it. And for someone who wants to work at the edge of the field rather than behind it, the expectation of using LLM-based coding harnesses to move fast signals a team that's building for how security engineering actually works now, not clinging to legacy velocity.

What You'll Do

  • Design, build, and maintain static and dynamic file analysis pipelines capable of processing artifacts at scale
  • Maintain, and optimize YARA rule sets, including tooling for rule testing, performance, and false-positive management
  • Operate and extend threat indicator enrichment systems for real-time file metadata extraction, scanning, and enrichment
  • Build and grow threat graph intelligence systems, modeling relationships between indicators, malware, infrastructure, and actors
  • Design and maintain dynamic analysis (sandboxing/detonation) capability, including behavioral telemetry collection and safe execution environments
  • Build ingestion and normalization pipelines connecting internal Censys scan data with external threat intel feeds
  • Instrument pipelines for reliability and observability (logging, monitoring, alerting, SLAs)
  • Partner with threat research and detection engineering teams to translate analytical needs into scalable systems
  • Maintain secure handling and isolation practices for malicious samples and analysis environments
  • Document architecture, runbooks, and operational procedures for the systems you own

What You'll Need:

  • Bachelor's degree in Computer Science, Engineering, or equivalent practical experience
  • 6+ years building security data pipelines, detection engineering systems, or threat intelligence platforms
  • Experience with Synapse or other graph-based threat intel platforms (e.g., Maltego, Neo4j), including graph data modeling
  • Strong programming skills in Python and/or Go
  • Working knowledge of static and dynamic malware analysis (disassemblers, sandboxes such as Cuckoo/CAPE, debuggers) tooling and pipelines
  • Experience with distributed data pipelines and message queues (Kafka, RabbitMQ) and data stores (Elasticsearch, S3, etc.)
  • Familiarity with containerization/orchestration (Docker, Kubernetes) for isolated execution environments
  • Demonstrated experience with cloud infrastructure (AWS, GCP, or Azure) designing and operating highly-available systems for critical, production-grade applications
  • Demonstrated use of LLM-based coding harnesses and agent-based develo
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.

Similar Openings in DevOps & Cloud

View all in category