hirly

Filigran

Senior Software Engineer - OpenCRQ

France

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Filigran first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Senior
Country
FR
Work mode
Remote-friendly
First seen by hirly
10 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

🌀 The Company

Founded in 2022, Filigran is a global cybersecurity company on a mission to empower defense teams to be proactive through open-source solutions that uncover threats and drive action.

Filigran stands out in the cybersecurity ecosystem through its open-source, AI-powered and threat-informed approach to Continuous Threat Exposure Management (CTEM). Our eXtended Threat Management (XTM) platform brings together threat intelligence, exposure validation and cyber risk reduction, enabling organizations to better understand their threat landscape and take action.

At the heart of Filigran is our open-source approach. Our vision is to unite defenders into a global community to make security more open, resilient and collaborative.

As Filigran continues to scale globally, we are building the organization, infrastructure and capabilities needed for our next stage of growth. How we scale matters just as much as how fast we scale: our CORE values: Cohesion, Openness, Responsibility and Equity shape how we work together, make decisions and build for the future.

🎯 The Role

We are looking for a Senior Software Engineer who is curious about the modeling problem underneath cyber risk and wants to help shape a young product.

You will join OpenCRQ as its fourth engineer and work across the data model, backend and product surface. Many foundations are still being defined, giving you meaningful influence beyond the features you directly own.

You will shape these decisions with the squad and experienced engineering and product leaders across Filigran. We value constructive disagreement, clear reasoning and shared outcomes, and we expect everyone to ask for context, challenge assumptions and learn from one another.

🧩 The problem you would be working on

Ask a CISO what a cyber risk could cost, and the answer often still begins with a color: red, amber or green, often produced by a spreadsheet disconnected from current evidence.

OpenCRQ replaces that color with a financial estimate and a traceable chain of evidence: which threat actors are active, which assets they can reach, which controls have proven effective and what the remaining exposure could cost.

Every step is computed from live data and must withstand a simple question from a board: “Where does that figure come from?” That is what makes this an engineering problem rather than a reporting one.

OpenCRQ is Filigran’s cyber risk quantification product. It combines threat intelligence from OpenCTI, exposure and control validation from OpenAEV, and agentic workflows through XTM One. As these products become more connected, the squad will define what agents can ask of the risk model, which evidence they can use and how their answers remain safe and explainable.

🛠️ What you would work on

End-to-end product ownership. Take product problems from early ideation and technical design through implementation, end-to-end testing and validation with users. You will have the autonomy to drive the work, while using the squad to challenge assumptions and improve the outcome.

The quantification engine. Turn threat frequency, control effectiveness and asset value into probabilistic loss distributions. Build general-purpose quantitative models that can evolve as assumptions and available evidence change, without losing reproducibility or explainability.

The correlation layer. Model complex relationships across OpenCRQ, OpenCTI, OpenAEV and customer systems. Map threat intelligence, including intrusion sets, techniques, campaigns and observations, to assets, vulnerabilities, exposures and control coverage. This includes adapting OpenCRQ to open standards and schemas such as STIX and OCSF, without coupling the product to a single representation.

Reliable ingestion at scale. Process hundreds of thousands of findings per tenant through delta syncs, long-running backfills and feeds with imperfect timestamps. You will help design observable, recoverable pipelines while extending tenant isolation as the domain grows.

The agentic surface. Design the contracts used by XTM One agents and the plain-language explanations behind risk figures. Together, the squad will define what models can safely do in a product whose outputs inform board-level decisions.

🏆 What success could look like

Priorities will evolve with the product, but within your first 6 to 12 months you could have:

Taken a meaningful product problem from early ideation through implementation, end-to-end testing and validation with users.

Shaped a core part of OpenCRQ’s interconnected data model or quantification engine and documented the trade-offs behind it.

Made a major ingestion or calculation path more observable, recoverable and reproducible.

Defined or implemented a durable contract between OpenCRQ and another Filigran product or an open standard, without making the internal model brittle.

Helped ship risk results that users can trace back to the evidence that produced them.

Contributed to the open-source release and to engineering practices the growing squad can build on.

🌐 Open source, like the rest of Filigran

OpenCRQ is about to become Open source, alongside OpenCTI and OpenAEV. You will contribute visibly to a product whose risk calculations can be inspected, challenged and improved by the organizations running it.

👥 The squad

You will join two senior engineers and a staff engineer, reporting to OpenCRQ’s Engineering Manager. The squad is small enough for you to influence its direction, without working in isolation.

You will collaborate with the VP of Technology, CTO and Principal Engineers on technical standards, and with the OpenCTI, OpenAEV and XTM One teams on cross-product contracts and integrations. These relationships bring domain knowledge and broader technical context into the squad’s decisions as it grows.

✨ What will help you succeed

We do not expect you to arrive with expertise in cyber risk or every standard named below. We are looking for a strong software engineer who can learn quickly, work autonomously and use the squad to challenge and improve decisions.

A track record of taking complex product problems from an ambiguous idea to a validated outcome: framing the problem, making technical decisions, implementing the solution, testing it end to end and checking that it solves the user’s need.

Strong experience with a modern TypeScript stack and practical knowledge of PostgreSQL beyond the ORM. You treat failure modes and observability as part of the design.

The ability to reason about complex relationships across systems and design interconnected data models that remain coherent as concepts and integrations evolve.

Comfort turning quantitative concepts into maintainable software. Formal training in statistics is not required, but you should be willing to work with probability distributions, orders of magnitude and models whose assumptions evolve over time.

Thoughtful use of coding agents: you know where they accelerate engineering and where their output needs careful verification.

Fluent English is required.

💡 Useful, but not required

Any of the following would help, but none is expected:

Experience in cybersecurity, GRC or risk quantification.

Familiarity with STIX/TAXII, OCSF, MITRE ATT&CK or other open cybersecurity standards and frameworks.

Experience shipping features involving LLM agents, RAG or MCP.

⚙️ The stack

TypeScript end to end: React, Vite and TanStack Router on the frontend; Node.js, Fastify and tRPC on the backend; PostgreSQL with a code-first schema and Drizzle, all in one monorepo.

OpenCRQ ships as a container, both as SaaS and on customer-managed infrastructure. We use OpenTelemetry for traces, metrics and logs, alongside Prometheus and continuous profiling.

A significant part of the design work happens at the boundaries between OpenCRQ, the rest of Filigran’s product suite and customer security tooling. You will work directly with the

Original posting on Filigran's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job