Careers / Engineering
Engineering at ManySignal
We build systems that process billions of security events so that humans can focus on the alerts that matter. The engineering problems are genuinely hard: throughput, latency, correctness, and safety, all at once.
// What our pipeline looks like at 3 a.m.
events_per_second: 52_847
p99_latency_ms: 18
verdicts_last_hour: 2_341_092
false_positive_rate: 0.0034
on_call_pages_tonight: 0
// This is what good looks like.
The work
What you will do
-
Design and operate the high-throughput telemetry ingestion pipeline processing 50,000+ events per second per tenant using Kafka, Flink, and custom Rust consumers
-
Build and improve the temporal entity graph — the structured context layer that makes AI triage defensible and auditable rather than probabilistic guesswork
-
Collaborate with detection engineers to implement low-latency rule evaluation, baseline computation, and drift-detection logic at scale
-
Own infrastructure reliability for a security-critical product: multi-region failover, zero-downtime deploys, and SLOs that Enterprise customers stake their SOC on
-
Design APIs that third-party integrations (EDR, SIEM, SOAR, cloud providers) depend on — with backward-compatibility guarantees that let customers sleep at night
-
Write and maintain runbooks, architecture decision records (ADRs), and incident post-mortems that make the team permanently smarter
-
Participate in a light on-call rotation (P1 incidents are rare; we instrument aggressively to keep it that way)
The person
Who you are
We hire for demonstrated capability, not credentials. No degree requirement, no checklist of tools.
-
Experienced with high-throughput distributed systems — you have operated streaming data pipelines under real production load, not just lab conditions
-
Comfortable in Go, Rust, or Python for backend services; you pick the right language for the problem, not the fashionable one
-
Familiar with Kubernetes, Terraform, and cloud infrastructure on AWS and/or GCP — you understand the trade-offs between managed services and operational control
-
A clear written communicator — async is our primary coordination mode and writing is the skill that makes it work
-
Security-aware: you understand OWASP Top 10, think about trust boundaries when designing systems, and include security in code review naturally
-
Experienced in a security-domain role, or deeply curious about it — you do not need to be a former SOC analyst, but you need to care about why what we build matters
Hiring process
How we hire
No whiteboard leetcode. No trick questions. A process that respects your time and reflects how we actually work.
Recruiter screen (30 min)
Introductory call with our recruiting team to align on role scope, compensation expectations, and timeline. No technical questions.
Engineering manager conversation (45 min)
Conversation with the hiring manager about your experience with distributed systems, your approach to reliability, and how you think about engineering trade-offs. No code.
Technical assessment (take-home, 3–4 hours)
A realistic, open-ended problem inspired by actual ManySignal engineering challenges. You submit a solution in your own time, in your own environment, using real tools. We read every submission carefully.
Technical deep-dive (90 min, async review + live Q&A)
A 30-minute async review of your take-home submission followed by a 60-minute live session where you walk us through your decisions, discuss trade-offs, and answer follow-up questions. We treat this as a collaborative conversation, not a gotcha session.
Values and cross-functional panel (60 min)
Conversations with two people from outside engineering — typically a detection engineer and a product manager — to explore how you collaborate across domains and how you think about customer impact.
Offer and references
We move fast after the panel. Reference checks run in parallel with the offer stage. Total process target: under 3 weeks from recruiter screen to offer.
Ready to apply?
Send a short note about the hardest distributed-systems problem you have worked on to [email protected] with the role title in the subject.
View open engineering roles