Censys
Systems Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 3 weeks ago · Found 7h ago
Been open since 3 weeks ago, still being checked, but it has been live a while.
Salary
$190,000–$240,000
Location
United States only
Timezone
Not stated
Contract
Full-time
Experience
Mid
Category
Software
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the listing expects you to be based in United States.
What the employer says
- Source listing states candidate location: "Remote"
- Listing states: "For all other locations in the US, the expected salary range for this position is $170,000 USD - $220,000 USD"
What Nomaders makes of it
- Confirm with the employer before assuming you can work from another country
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Company Background
Censys’ mission is to be the one place to understand everything on the internet. Frustrated by the lack of trustworthy Internet intelligence, we set out to create the industry’s most comprehensive, accurate, and up-to-date map of the Internet. Today, Censys delivers real-time Internet intelligence and actionable threat insights to global governments, over 50% of the Fortune 500, and leading threat intelligence providers worldwide.
The Systems Engineer will be a part of the Censys ARC (Advanced Research Collective) and will build and operate the pipelines and platforms that power Censys's threat detection and intelligence capabilities. This role will own the engineering behind static and dynamic file analysis at scale, and the graph-based systems that connect indicators, infrastructure, and actors into actionable threat intelligence. You'll work closely with threat researchers and analysts, turning detection and correlation requirements into production-grade systems.
For a systems engineer who's spent years wiring together detection pipelines and threat intel platforms, this role is the rare chance to build that infrastructure at the actual source of the data rather than downstream of it. Censys's internet-wide scan visibility means the enrichment and graph systems you're building aren't consuming someone else's feed, they're powering primary intelligence on global infrastructure and actors. You'd own meaningful technical surface end-to-end: static/dynamic analysis pipelines, YARA tooling, sandboxing, and threat graph modeling connecting indicators to actors, rather than being one contributor on a sprawling platform team. The ARC structure — sitting between engineering and research — means your systems get shaped directly by what threat researchers actually need next, not by a backlog several layers removed from the analysts using it. And for someone who wants to work at the edge of the field rather than behind it, the expectation of using LLM-based coding harnesses to move fast signals a team that's building for how security engineering actually works now, not clinging to legacy velocity.
What You'll Do
Design, build, and maintain static and dynamic file analysis pipelines capable of processing artifacts at scale
Maintain, and optimize YARA rule sets, including tooling for rule testing, performance, and false-positive management
Operate and extend threat indicator enrichment systems for real-time file metadata extraction, scanning, and enrichment
Build and grow threat graph intelligence systems, modeling relationships between indicators, malware, infrastructure, and actors
Design and maintain dynamic analysis (sandboxing/detonation) capability, including behavioral telemetry collection and safe execution environments
Build ingestion and normalization pipelines connecting internal Censys scan data with external threat intel feeds
Instrument pipelines for reliability and observability (logging, monitoring, alerting, SLAs)
Partner with threat research and detection engineering teams to translate analytical needs into scalable systems
Maintain secure handling and isolation practices for malicious samples and analysis environments
Document architecture, runbooks, and operational procedures for the systems you own
What You'll Need:
Bachelor's degree in Computer Science, Engineering, or equivalent practical experience
6+ years building security data pipelines, detection engineering systems, or threat intelligence platforms
Experience with Synapse or other graph-based threat intel platforms (e.g., Maltego, Neo4j), including graph data modeling
Strong programming skills in Python and/or Go
Working knowledge of static and dynamic malware analysis (disassemblers, sandboxes such as Cuckoo/CAPE, debuggers) tooling and pipelines
Experience with distributed data pipelines and message queues (Kafka, RabbitMQ) and data stores (Elasticsearch, S3, etc.)
Familiarity with containerization/orchestration (Docker, Kubernetes) for isolated execution environments
Demonstrated experience with cloud infrastructure (AWS, GCP, or Azure) designing and operating highly-available systems for critical, production-grade applications
Requirements
- ·Working knowledge of static and dynamic malware analysis (disassemblers, sandboxes such as Cuckoo/CAPE, debuggers) tooling and pipelines
- ·Experience with distributed data pipelines and message queues (Kafka, RabbitMQ) and data stores (Elasticsearch, S3, etc.)
- ·Familiarity with containerization/orchestration (Docker, Kubernetes) for isolated execution environments
- ·Demonstrated experience with cloud infrastructure (AWS, GCP, or Azure) designing and operating highly-available systems for critical, production-grade applications
- ·Demonstrated use of LLM-based coding harnesses and agent-based development workflows (e.g., Claude Code, Copilot, or similar) to accelerate delivery timelines
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Censys, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 8h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$190,000–$240,000 · You'll be taken to the employer's careers page.