---
title: "Senior Software Engineer - OpenCRQ"
company: "Filigran"
company_url: "https://www.remjobs.works/companies/filigran"
url: "https://www.remjobs.works/job/filigran-senior-software-engineer-opencrq-e7b8b93b-a523-4777-b0f5-ae9fec9a5bdc"
apply_url: "https://jobs.ashbyhq.com/filigran/159ba818-345b-4cc0-8c5f-a843de06a1fd"
workplace: remote
location: "France"
remote_scope: "France"
employment_type: full-time
seniority: senior
role: software-engineering
region: europe
skills: ["llm", "nodejs", "postgres", "react", "typescript"]
date_posted: 2026-09-10T14:11:48.581Z
first_seen_by_remjobs: 2026-09-10T14:43:29.444Z
---

# Senior Software Engineer - OpenCRQ

**Filigran** · France

Apply: https://jobs.ashbyhq.com/filigran/159ba818-345b-4cc0-8c5f-a843de06a1fd

## About Filigran

Embrace a proactive approach with end-to-end cyber threat management, from anticipation to response.

## About the role

#### 🌀 The Company

Filigran, founded in October 2022, stands out in the cybertech ecosystem for its commitment to revolutionizing cyber threat management with a proactive approach. Its mission is to develop innovative open-source solutions designed to anticipate cyber threats, identify security gaps, and strengthen organizational security posture.

Filigran solutions are now trusted by over 6,000 public and private organizations worldwide.

#### 🎯 The Role

We are looking for a Senior Software Engineer who is curious about the modeling problem underneath cyber risk and wants to help shape a young product.

You will join OpenCRQ as its fourth engineer and work across the data model, backend and product surface. Many foundations are still being defined, giving you meaningful influence beyond the features you directly own.

You will shape these decisions with the squad and experienced engineering and product leaders across Filigran. We value constructive disagreement, clear reasoning and shared outcomes, and we expect everyone to ask for context, challenge assumptions and learn from one another.

#### 🧩 The problem you would be working on

Ask a CISO what a cyber risk could cost, and the answer often still begins with a color: red, amber or green, often produced by a spreadsheet disconnected from current evidence.

OpenCRQ replaces that color with a financial estimate and a traceable chain of evidence: which threat actors are active, which assets they can reach, which controls have proven effective and what the remaining exposure could cost.

Every step is computed from live data and must withstand a simple question from a board: “Where does that figure come from?” That is what makes this an engineering problem rather than a reporting one.

OpenCRQ is Filigran’s cyber risk quantification product. It combines threat intelligence from OpenCTI, exposure and control validation from OpenAEV, and agentic workflows through XTM One. As these products become more connected, the squad will define what agents can ask of the risk model, which evidence they can use and how their answers remain safe and explainable.

#### 🛠️ What you would work on

- End-to-end product ownership. Take product problems from early ideation and technical design through implementation, end-to-end testing and validation with users. You will have the autonomy to drive the work, while using the squad to challenge assumptions and improve the outcome.

- The quantification engine. Turn threat frequency, control effectiveness and asset value into probabilistic loss distributions. Build general-purpose quantitative models that can evolve as assumptions and available evidence change, without losing reproducibility or explainability.

- The correlation layer. Model complex relationships across OpenCRQ, OpenCTI, OpenAEV and customer systems. Map threat intelligence, including intrusion sets, techniques, campaigns and observations, to assets, vulnerabilities, exposures and control coverage. This includes adapting OpenCRQ to open standards and schemas such as STIX and OCSF, without coupling the product to a single representation.

- Reliable ingestion at scale. Process hundreds of thousands of findings per tenant through delta syncs, long-running backfills and feeds with imperfect timestamps. You will help design observable, recoverable pipelines while extending tenant isolation as the domain grows.

- The agentic surface. Design the contracts used by XTM One agents and the plain-language explanations behind risk figures. Together, the squad will define what models can safely do in a product whose outputs inform board-level decisions.

#### 🏆 What success could look like

Priorities will evolve with the product, but within your first 6 to 12 months you could have:

- Taken a meaningful product problem from early ideation through implementation, end-to-end testing and validation with users.

- Shaped a core part of OpenCRQ’s interconnected data model or quantification engine and documented the trade-offs behind it.

- Made a major ingestion or calculation path more observable, recoverable and reproducible.

- Defined or implemented a durable contract between OpenCRQ and another Filigran product or an open standard, without making the internal model brittle.

- Helped ship risk results that users can trace back to the evidence that produced them.

- Contributed to the open-source release and to engineering practices the growing squad can build on.

#### 🌐 Open source, like the rest of Filigran

OpenCRQ is about to become Open source, alongside OpenCTI and OpenAEV. You will contribute visibly to a product whose risk calculations can be inspected, challenged and improved by the organizations running it.

#### 👥 The squad

You will join two senior engineers and a staff engineer, reporting to OpenCRQ’s Engineering Manager. The squad is small enough for you to influence its direction, without working in isolation.

You will collaborate with the VP of Technology, CTO and Principal Engineers on technical standards, and with the OpenCTI, OpenAEV and XTM One teams on cross-product contracts and integrations. These relationships bring domain knowledge and broader technical context into the squad’s decisions as it grows.

#### ✨ What will help you succeed

We do not expect you to arrive with expertise in cyber risk or every standard named below. We are looking for a strong software engineer who can learn quickly, work autonomously and use the squad to challenge and improve decisions.

- A track record of taking complex product problems from an ambiguous idea to a validated outcome: framing the problem, making technical decisions, implementing the solution, testing it end to end and checking that it solves the user’s need.

- Strong experience with a modern TypeScript stack and practical knowledge of PostgreSQL beyond the ORM. You treat failure modes and observability as part of the design.

- The ability to reason about complex relationships across systems and design interconnected data models that remain coherent as concepts and integrations evolve.

- Comfort turning quantitative concepts into maintainable software. Formal training in statistics is not required, but you should be willing to work with probability distributions, orders of magnitude and models whose assumptions evolve over time.

- Thoughtful use of coding agents: you know where they accelerate engineering and where their output needs careful verification.

- Fluent English is required.

##### 💡 Useful, but not required

Any of the following would help, but none is expected:

- Experience in cybersecurity, GRC or risk quantification.

- Familiarity with STIX/TAXII, OCSF, MITRE ATT&CK or other open cybersecurity standards and frameworks.

- Experience shipping features involving LLM agents, RAG or MCP.

#### ⚙️ The stack

TypeScript end to end: React, Vite and TanStack Router on the frontend; Node.js, Fastify and tRPC on the backend; PostgreSQL with a code-first schema and Drizzle, all in one monorepo.

OpenCRQ ships as a container, both as SaaS and on customer-managed infrastructure. We use OpenTelemetry for traces, metrics and logs, alongside Prometheus and continuous profiling.

A significant part of the design work happens at the boundaries between OpenCRQ, the rest of Filigran’s product suite and customer security tooling. You will work directly with the teams that own those systems rather than having to navigate those boundaries alone.

#### 🌱 Why Join Filigran? More than just a job.

We’re a fast-growing, global, and fully remote company building open-source cybersecurity solutions, increasingly powered by AI, to help defense teams anticipate threats and act faster.

⭐ **What we believe**

We believe we do work that matters, uniting defenders into a global community to make security more open, resilient & collaborative.

💻 **How we work**

We do work that matters by combining strong engineering standards with emerging technologies, including AI, to move faster and smarter.

🧭 **What guides us**

We make our work matter by building a culture grounded in our CORE values of Cohesion, Openness, Responsibility, and Equity. The principles that guide how we make decisions, treat people, and grow together, especially when no one’s watching.

#### 💰 Compensation & Benefits

- Competitive pay + equity - everyone shares in our success

- Remote-first, flexible, and balanced - work that fits your life

- Your setup, your choice - pick the gear that works for you

- Twice-a-year gatherings - we meet in person for regional and global offsites to connect, collaborate, and strengthen our culture beyond the screen

#### 🌍 Equal Employment Opportunity

**We enable cybersecurity through inclusion - from code to culture.**

At Filigran, we are proud to be an equal opportunity employer. We believe diversity of our people make our products and our team stronger. We welcome talent of every background, identity, and lived experience, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, or veteran status.

What matters here is what you bring, not what you look like, where you’re from, or how you identify.

#### 🚀 Ready to Join Us?

Apply now and help us build the future of the cybersecurity ecosystem, together.

---

Source: Filigran's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/filigran-senior-software-engineer-opencrq-e7b8b93b-a523-4777-b0f5-ae9fec9a5bdc
