SlipstreamJobsFresh Startup & VC-Backed Jobs

Systems Engineer

Censys - Remote - Remote - posted 2026-08-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 170,000 - 240,000 / annual

Censys is building the internet's most comprehensive map of global infrastructure and threat actors. The Systems Engineer will join the Advanced Research Collective (ARC) to design, build, and operate the detection pipelines and threat intelligence platforms that power Censys's real-time threat insights for governments, Fortune 500 companies, and threat intelligence providers worldwide. You will own end-to-end technical infrastructure for static and dynamic file analysis at scale, including YARA rule optimization, sandboxing environments, and graph-based threat intelligence systems that connect indicators, infrastructure, and actors. Unlike downstream threat intel roles, you'll be working directly with primary internet-wide scan data from Censys, enriching and modeling it into actionable intelligence rather than consuming third-party feeds. Key responsibilities include: - Design and maintain static/dynamic file analysis pipelines processing artifacts at scale - Maintain and optimize YARA rule sets with tooling for testing, performance, and false-positive management - Operate threat indicator enrichment systems for real-time metadata extraction and scanning - Build threat graph intelligence systems modeling relationships between indicators, malware, infrastructure, and actors - Design and maintain dynamic analysis (sandboxing/detonation) with behavioral telemetry collection - Build ingestion and normalization pipelines connecting Censys scan data with external threat feeds - Instrument pipelines for reliability and observability (logging, monitoring, alerting, SLAs) - Partner with threat research and detection engineering teams to translate analytical needs into scalable systems - Maintain secure handling and isolation practices for malicious samples - Document architecture, runbooks, and operational procedures The ARC structure sits between engineering and research, meaning your systems are shaped directly by what threat researchers need rather than by distant backlogs. The team embraces LLM-based coding harnesses and agent-based development workflows to accelerate delivery. Requirements: - Bachelor's degree in Computer Science, Engineering, or equivalent practical experience - 6+ years building security data pipelines, detection engineering systems, or threat intelligence platforms - Experience with Synapse or other graph-based threat intel platforms (Maltego, Neo4j) including graph data modeling - Strong programming in Python and/or Go - Working knowledge of static and dynamic malware analysis tooling and pipelines (disassemblers, sandboxes like Cuckoo/CAPE, debuggers) - Experience with distributed data pipelines and message queues (Kafka, RabbitMQ) and data stores (Elasticsearch, S3) - Familiarity with containerization/orchestration (Docker, Kubernetes) for isolated execution environments - Demonstrated experience with cloud infrastructure (AWS, GCP, Azure) designing and operating highly-available production systems - Demonstrated use of LLM-based coding harnesses and agent-based development workflows (Claude Code, Copilot, or similar) Desirable: - Experience with Synapse, MISP, OpenCTI, or other TIP platforms - Familiarity with STIX/TAXII - Experience working with internet-wide scan data - Open source contributions to security tooling (YARA rules, Strelka scanners, Synapse modules) - CI/CD experience applied to detection content - SOC 2, ISO 27001, or similar security/compliance framework knowledge - Hands-on experience authoring and managing YARA rules at scale - Experience with Strelka or comparable file scanning frameworks (Assemblyline, FAME)

Similar roles