Senior Software Engineer
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
The Company
Founded in 2022, Filigran is a global cybersecurity company on a mission to empower defense teams to be proactive through open-source solutions that uncover threats and drive action.
Filigran stands out in the cybersecurity ecosystem through its open-source, AI-powered and threat-informed approach to Continuous Threat Exposure Management (CTEM). Our eXtended Threat Management (XTM) platform brings together threat intelligence, exposure validation and cyber risk reduction, enabling organizations to better understand their threat landscape and take action.
At the heart of Filigran is our open-source approach. Our vision is to unite defenders into a global community to make security more open, resilient and collaborative.
As Filigran continues to scale globally, we are building the organization, infrastructure and capabilities needed for our next stage of growth. How we scale matters just as much as how fast we scale: our CORE values: Cohesion, Openness, Responsibility and Equity shape how we work together, make decisions and build for the future.
The Role
We are looking for a Senior Software Engineer who is curious about the modeling problem underneath cyber risk and wants to help shape a young product.
You will join OpenCRQ as its fourth engineer and work across the data model, backend and product surface. Many foundations are still being defined, giving you meaningful influence beyond the features you directly own.
You will shape these decisions with the squad and experienced engineering and product leaders across Filigran. We value constructive disagreement, clear reasoning and shared outcomes, and we expect everyone to ask for context, challenge assumptions and learn from one another.
The problem you would be working on
Ask a CISO what a cyber risk could cost, and the answer often still begins with a color: red, amber or green, often produced by a spreadsheet disconnected from current evidence.
OpenCRQ replaces that color with a financial estimate and a traceable chain of evidence: which threat actors are active, which assets they can reach, which controls have proven effective and what the remaining exposure could cost.
Every step is computed from live data and must withstand a simple question from a board: "Where does that figure come from?" That is what makes this an engineering problem rather than a reporting one.
OpenCRQ is Filigran’s cyber risk quantification product. It combines threat intelligence from OpenCTI, exposure and control validation from OpenAEV, and agentic workflows through XTM One. As these products become more connected, the squad will define what agents can ask of the risk model, which evidence they can use and how their answers remain safe and explainable.
What you would work on
End-to-end product ownership. Take product problems from early ideation and technical design through implementation, end-to-end testing and validation with users. You will have the autonomy to drive the work, while using the squad to challenge assumptions and improve the outcome.
The quantification engine. Turn threat frequency, control effectiveness and asset value into probabilistic loss distributions. Build general-purpose quantitative models that can evolve as assumptions and available evidence change, without losing reproducibility or explainability.
The correlation layer. Model complex relationships across OpenCRQ, OpenCTI, OpenAEV and customer systems. Map threat intelligence, including intrusion sets, techniques, campaigns and observations, to assets, vulnerabilities, exposures and control coverage. This includes adapting OpenCRQ to open standards and schemas such as STIX and OCSF, without coupling the product to a single representation.
Reliable ingestion at scale. Process hundreds of thousands of findings per tenant through delta syncs, long-running backfills and feeds with imperfect timestamps. You will help design observable, recoverable pipelines while extending tenant isolation as the domain grows.
The agentic surface. Design the contracts used by XTM One agents and the plain-language explanations behind risk figures. Together, the squad will define what models can safely do in a product whose outputs inform board-level decisions.
What success could look like
Priorities will evolve with the product, but within your first 6 to 12 months you could have:
Taken a meaningful product problem from early ideation through implementation, end-to-end testing and validation with users.
Shaped a core part of OpenCRQ’s interconnected data model or quantification engine and documented the trade-offs behind it.
Made a major ingestion or calculation path more observable, recoverable and reproducible.
Defined o