Role Overview:
We are looking for an SDE II - Sensors to build customer-deployed security software that runs inside enterprise environments and continuously discovers assets, evaluates exposures, and securely communicates telemetry back to SAFE.
This role is suited for engineers with strong C++, Go or Python programming skills, Windows/Linux, networking, and cybersecurity fundamentals, particularly those who have worked on endpoint agents, security sensors, network/security products, or other long-running system software.
What You'll Do:
Design and develop lightweight security sensors/agents running inside customer environments.
Build capabilities for asset discovery, network scanning, vulnerability detection and exposure validation.
Develop reliable, long-running system software with a focus on performance, resource usage, concurrency, and stability.
Work extensively with Windows/Linux internals, processes, sockets, filesystems, networking and system APIs.
Build communication between distributed sensors and the SAFE cloud with secure authentication, encryption, retries and offline recovery.
Implement sensor lifecycle management, including installation, configuration, health monitoring and software/rule updates.
Debug complex issues spanning application code, operating systems, customer networks, proxies, firewalls and infrastructure.
Build strong diagnostics, telemetry and logging so problems can be investigated without requiring direct access to customer systems.
Participate in low-level and high-level design discussions and independently own well-defined components/features through production.
What We're Looking For:
3-6 years of software development experience, preferably building systems, infrastructure or security products.
Strong programming experience in one or more of C++, Go or Python.
Strong understanding of Windows/Linux and operating-system fundamentals.
Good understanding of networking concepts, including:
TCP/IP and sockets
DNS
HTTP/HTTPS
TLS
Proxies
Routing
NAT
Firewalls and network segmentation
Experience with multithreading/concurrency, asynchronous programming and inter-process communication.
Understanding of software security and secure communication practices.
Ability to troubleshoot issues independently across code, OS and network boundaries.
Strongly Preferred:
Experience building endpoint agents, sensors, collectors, daemons or system services.
Experience working on cybersecurity, endpoint security, vulnerability management, micro-segmentation, EDR or network security products.
Experience building software deployed across large heterogeneous enterprise environments.
Familiarity with CVE, CVSS, vulnerability scanners and exposure management.
Experience with secure auto-update / software distribution mechanisms.
Familiarity with containers and technologies such as Docker and Kubernetes.
Experience developing software that needs to operate reliably across Windows and Linux environments.
What Good Looks Like:
Why is a process consuming excessive CPU or memory
Why communication works in one customer network but fails in another
How to safely upgrade thousands of deployed sensors
How to recover when a sensor loses connectivity for several hours
How to execute security scans without destabilising customer infrastructure
How to collect enough diagnostics to troubleshoot systems you cannot directly access
You should be comfortable going beyond:
"The API returned an error."
and investigating: Sensor → process → socket → DNS → proxy/firewall → network → cloud service to determine exactly where and why something failed.
You should be equally comfortable reasoning about:
The ideal candidate is fundamentally a systems/security engineer who can build reliable software, rather than a conventional CRUD/backend application developer.

