SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Filigran is a fast-growing, fully remote cybersecurity company founded in October 2022, trusted by over 6,000 public and private organizations worldwide. The company develops open-source solutions to anticipate cyber threats and strengthen organizational security posture.
You will join OpenCRQ, Filigran's cyber risk quantification product, as its fourth engineer. OpenCRQ replaces subjective risk assessments (often color-coded spreadsheets) with financial estimates backed by traceable evidence: which threat actors are active, which assets they can reach, which controls are effective, and what remaining exposure could cost. Every calculation is computed from live data and must withstand board-level scrutiny.
In this role, you will own product problems end-to-end—from early ideation and technical design through implementation, testing, and user validation. You will shape core decisions with the squad and experienced engineering and product leaders across Filigran. Key areas of focus include:
- The quantification engine: Turn threat frequency, control effectiveness, and asset value into probabilistic loss distributions. Build general-purpose quantitative models that evolve as assumptions and evidence change, while maintaining reproducibility and explainability.
- The correlation layer: Model complex relationships across OpenCRQ, OpenCTI (threat intelligence), OpenAEV (exposure and control validation), and customer systems. Map threat intelligence (intrusion sets, techniques, campaigns, observations) to assets, vulnerabilities, exposures, and control coverage. Adapt OpenCRQ to open standards like STIX and OCSF without coupling the product to a single representation.
- Reliable ingestion at scale: Process hundreds of thousands of findings per tenant through delta syncs, backfills, and feeds with imperfect timestamps. Design observable, recoverable pipelines while extending tenant isolation.
- The agentic surface: Design contracts used by XTM One agents and plain-language explanations behind risk figures. Define what models can safely do in a product whose outputs inform board-level decisions.
Within your first 6–12 months, you could take meaningful product problems from ideation through validation, shape core parts of the data model or quantification engine, make ingestion or calculation paths more observable and reproducible, define durable contracts with other products or open standards, and help ship traceable risk results.
You will report to OpenCRQ's Engineering Manager and collaborate with two senior engineers and a staff engineer on the squad. You will also work with the VP of Technology, CTO, and Principal Engineers on technical standards, and with teams across OpenCTI, OpenAEV, and XTM One on cross-product integrations.
The tech stack is TypeScript end-to-end: React, Vite, and TanStack Router on the frontend; Node.js, Fastify, and tRPC on the backend; PostgreSQL with Drizzle in a monorepo. OpenCRQ ships as a container for both SaaS and customer-managed infrastructure, using OpenTelemetry, Prometheus, and continuous profiling for observability.
Filigran is about to open-source OpenCRQ alongside OpenCTI and OpenAEV, so your work will be visible to the organizations running it.
REQUIREMENTS:
- Track record of taking complex product problems from ambiguous ideas to validated outcomes: framing the problem, making technical decisions, implementing solutions, end-to-end testing, and validating user needs.
- Strong experience with a modern TypeScript stack and practical knowledge of PostgreSQL beyond ORMs. Treat failure modes and observability as part of design.
- Ability to reason about complex relationships across systems and design interconnected data models that remain coherent as concepts and integrations evolve.
- Comfort turning quantitative concepts into maintainable software. Formal statistics training not required, but willingness to work with probability distributions, orders of magnitude, and evolving model assumptions.
- Thoughtful use of coding agents: knowing where they accelerate engineering and where output needs verification.
- Fluent English required.
USEFUL BUT NOT REQUIRED:
- Experience in cybersecurity, GRC, or risk quantification.
- Familiarity with STIX/TAXII, OCSF, MITRE ATT&CK, or other open cybersecurity standards.
- Experience shipping features involving LLM agents, RAG, or MCP.