Want to know if this job is worth applying to?
France
Remote only
Founded in 2022, Filigran is a global cybersecurity company on a mission to empower defense teams to be proactive through open-source solutions that uncover threats and drive action.
Filigran stands out in the cybersecurity ecosystem through its open-source, AI-powered and threat-informed approach to Continuous Threat Exposure Management (CTEM). Our eXtended Threat Management (XTM) platform brings together threat intelligence, exposure validation and cyber risk reduction, enabling organizations to better understand their threat landscape and take action.
At the heart of Filigran is our open-source approach. Our vision is to unite defenders into a global community to make security more open, resilient and collaborative.
As Filigran continues to scale globally, we are building the organization, infrastructure and capabilities needed for our next stage of growth. How we scale matters just as much as how fast we scale: our CORE values: Cohesion, Openness, Responsibility and Equity shape how we work together, make decisions and build for the future.
We are looking for a Senior Software Engineer who is curious about the modeling problem underneath cyber risk and wants to help shape a young product.
You will join OpenCRQ as its fourth engineer and work across the data model, backend and product surface. Many foundations are still being defined, giving you meaningful influence beyond the features you directly own.
You will shape these decisions with the squad and experienced engineering and product leaders across Filigran. We value constructive disagreement, clear reasoning and shared outcomes, and we expect everyone to ask for context, challenge assumptions and learn from one another.
Ask a CISO what a cyber risk could cost, and the answer often still begins with a color: red, amber or green, often produced by a spreadsheet disconnected from current evidence.
OpenCRQ replaces that color with a financial estimate and a traceable chain of evidence: which threat actors are active, which assets they can reach, which controls have proven effective and what the remaining exposure could cost.
Every step is computed from live data and must withstand a simple question from a board: “Where does that figure come from?” That is what makes this an engineering problem rather than a reporting one.
OpenCRQ is Filigran’s cyber risk quantification product. It combines threat intelligence from OpenCTI, exposure and control validation from OpenAEV, and agentic workflows through XTM One. As these products become more connected, the squad will define what agents can ask of the risk model, which evidence they can use and how their answers remain safe and explainable.
End-to-end product ownership. Take product problems from early ideation and technical design through implementation, end-to-end testing and validation with users. You will have the autonomy to drive the work, while using the squad to challenge assumptions and improve the outcome.
The quantification engine. Turn threat frequency, control effectiveness and asset value into probabilistic loss distributions. Build general-purpose quantitative models that can evolve as assumptions and available evidence change, without losing reproducibility or explainability.
The correlation layer. Model complex relationships across OpenCRQ, OpenCTI, OpenAEV and customer systems. Map threat intelligence, including intrusion sets, techniques, campaigns and observations, to assets, vulnerabilities, exposures and control coverage. This includes adapting OpenCRQ to open standards and schemas such as STIX and OCSF, without coupling the product to a single representation.
Reliable ingestion at scale. Process hundreds of thousands of findings per tenant through delta syncs, long-running backfills and feeds with imperfect timestamps. You will help design observable, recoverable pipelines while extending tenant isolation as the domain grows.
The agentic surface. Design the contracts used by XTM One agents and the plain-language explanations behind risk figures. Together, the squad will define what models can safely do in a product whose outputs inform board-level decisions.
Priorities will evolve with the product, but within your first 6 to 12 months you could have:
Taken a meaningful product problem from early ideation through implementation, end-to-end testing and validation with users.
Shaped a core part of OpenCRQ’s interconnected data model or quantification engine and documented the trade-offs behind it.
Made a major ingestion or calculation path more observable, recoverable and reproducible.
Defined or implemented a durable contract between OpenCRQ and another Filigran product or an open standard, without making the internal model brittle.
Helped ship risk results that users can trace back to the evidence that produced them.
Contributed to the open-source release and to engineering practices the growing squad can build on.
OpenCRQ is about to become Open source, alongside OpenCTI and OpenAEV. You will contribute visibly to a product whose risk calculations can be inspected, challenged and improved by the organizations running it.
You will join two senior engineers and a staff engineer, reporting to OpenCRQ’s Engineering Manager. The squad is small enough for you to influence its direction, without working in isolation.
You will collaborate with the VP of Technology, CTO and Principal Engineers on technical standards, and with the OpenCTI, OpenAEV and XTM One teams on cross-product contracts and integrations. These relationships bring domain knowledge and broader technical context into the squad’s decisions as it grows.
We do not expect you to arrive with expertise in cyber risk or every standard named below. We are looking for a strong software engineer who can learn quickly, work autonomously and use the squad to challenge and improve decisions.
A track record of taking complex product problems from an ambiguous idea to a validated outcome: framing the problem, making technical decisions, implementing the solution, testing it end to end and checking that it solves the user’s need.
Strong experience with a modern TypeScript stack and practical knowledge of PostgreSQL beyond the ORM. You treat failure modes and observability as part of the design.
The ability to reason about complex relationships across systems and design interconnected data models that remain coherent as concepts and integrations evolve.
Comfort turning quantitative concepts into maintainable software. Formal training in statistics is not required, but you should be willing to work with probability distributions, orders of magnitude and models whose assumptions evolve over time.
Thoughtful use of coding agents: you know where they accelerate engineering and where their output needs careful verification.
Fluent English is required.
Any of the following would help, but none is expected:
Experience in cybersecurity, GRC or risk quantification.
Familiarity with STIX/TAXII, OCSF, MITRE ATT&CK or other open cybersecurity standards and frameworks.
Experience shipping features involving LLM agents, RAG or MCP.
TypeScript end to end: React, Vite and TanStack Router on the frontend; Node.js, Fastify and tRPC on the backend; PostgreSQL with a code-first schema and Drizzle, all in one monorepo.
OpenCRQ ships as a container, both as SaaS and on customer-managed infrastructure. We use OpenTelemetry for traces, metrics and logs, alongside Prometheus and continuous profiling.
A significant part of the design work happens at the boundaries between OpenCRQ, the rest of Filigran’s product suite and customer security tooling. You will work directly with the teams that own those systems rather than having to navigate those boundaries alone.
We are a fast-growing, global and remote-first company, and we believe the best work combines purpose, impact and innovation. You’ll work alongside talented people across the world who care about what they build, how they build it, and the impact they make on the broader cybersecurity ecosystem.
⭐ Be part of something bigger
We believe we do work that matters. Our open-source approach means that work extends beyond Filigran. You’re contributing to technology and ideas that strengthen a global community of defenders and help make cybersecurity more open and collaborative.
💻 Work at the edge of what’s next
We bring together cybersecurity, open source and AI — giving you the opportunity to work with emerging technologies, experiment with new ways of working, and contribute to how they are applied in practice.
🌍 Global opportunity without borders
Be part of a fast-growing, truly international team — collaborating across Europe, North America, APJ and beyond, with the flexibility of a remote-first environment. As we grow, you’ll have opportunities to expand your scope, take ownership, learn quickly and grow with us.
🧭 A culture grounded in CORE
Cohesion, Openness, Responsibility and Equity define how we work together — with openness, ownership, collaboration and respect. These are the principles that guide how we make decisions, treat people and grow together, especially when no one’s watching.
Competitive compensation + equity — everyone shares in our success
Remote-first flexibility — work from wherever you’re based, with flexibility built into how we operate
25 days PTO baseline — real time to disconnect, recharge and enjoy life outside work
Volunteer days — paid time to contribute to causes that matter to you
Set up for success — choose the equipment that works for you, with additional support for your remote work and development needs as our programs evolve
Two annual in-person get-togethers — one global company get-together and one team get-together, creating dedicated time to connect, collaborate and strengthen our culture beyond the screen
We enable cybersecurity through inclusion — from code to culture.
At Filigran, we are proud to be an equal opportunity employer. We believe the diversity of our people makes our products and our team stronger. We welcome talent of every background, identity and lived experience, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability or veteran status.
What matters here is what you bring, not what you look like, where you’re from or how you identify.
Apply now and help us build the future of the cybersecurity ecosystem, together.



