Senior Solutions Engineer

ZeroTier, Inc.
United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

LTE (Telecommunication) Access Network Application Programming Interfaces (APIs) Amazon Web Services Application Layers Microsoft Azure Bash Shell Software as a Service Linux Digital Signature Domain Name System (DNS) Ethernet
+28 more
Failover Federal Information Processing Standards (FIPS) Supervisory Control and Data Acquisition (SCADA) Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Python (Programming Language) Network Layer Routing Open Systems Interconnection (OSI) OpenVPN OpenID Public Key Infrastructure Remote Access Technology Zero Trust Network Access RSA (Cryptosystem) Security Assertion Markup Language (SAML) SAP Sales and Distribution TCP/IP Wireshark Wide Area Networks Scripting Transport Layer Security Google Cloud Okta Multi-Cloud Firewalls (Computer Science) Gsuite Restful APIs

Job description

As Senior Solutions Engineer, you are the technical counterpart to Sales and the trusted advisor to our customers - from a founder connecting a fleet of Raspberry Pis, to an industrial OT team bridging PLCs across plants, to a defense integrator architecting an air-gapped, CNSA 2.0-compliant sovereign network. You’ll own technical discovery, solution architecture, demos, and proof-of-value (POV) engagements end to end, then partner with Customer Success to ensure what you sold is what gets deployed.

The deployment spectrum you’ll cover is unusually broad, and that’s the point:

  • Remote access & VPN replacement - flat peer-to-peer overlays for distributed workforces, multi-site interoperability, and zero-trust access without hub-and-spoke bottlenecks.
  • Multi-cloud & hybrid infrastructure - connecting AWS, Azure, GCP, on-prem, and colo environments into a single virtual Layer 2 network, including self-hosted controllers.
  • IoT, IIoT & OT / Industrial - embedded devices, sensors, PLCs, SCADA-adjacent systems, kiosks, point-of-sale, and edge compute behind carrier-grade NAT and restrictive third-party networks.
  • Embedded & OEM - vendors shipping ZeroTier inside their own products (embedded SDK integrations, private root server infrastructure, white-label connectivity).
  • SD-WAN-style topologies - multipath bonding, failover/handover across LTE/5G/satellite/Starlink links, bridged Layer 2 segments, and flow-rules-based microsegmentation., * Lead technical discovery and qualification alongside Sales Directors; map customer requirements to ZeroTier architectures at Layer 1 through Layer 7.
  • Design, scope, and run structured POVs with clear success criteria, timelines, and exit decisions - for deployments ranging from ten nodes to tens of thousands.
  • Deliver compelling demos and whiteboard sessions for audiences from hands-on network engineers to CISOs and procurement executives.
  • Architect solutions across our full surface area: hosted control plane, self-hosted controllers, flow rules, bridging, multipath, SSO/OIDC integration, and ZeroTier Quantum’s SaaS, sovereign, and air-gapped modes.
  • Own competitive positioning in live deals - articulating where ZeroTier wins against Tailscale, WireGuard-based stacks, and legacy VPN/SD-WAN vendors, and being honest about where it doesn’t.
  • Respond to RFPs, RFIs, and security questionnaires; translate FIPS, CNSA 2.0, and post-quantum readiness requirements into concrete architecture answers.
  • Act as the technical escalation bridge during the sales cycle - reproduce issues, capture packet-level evidence, and work directly with Engineering on defects and feature gaps.
  • Feed the field’s voice back into the product: structured win/loss insights, deployment patterns, and roadmap input.
  • Build reusable assets - demo environments, reference architectures, battle cards, and POV runbooks - that make the whole go-to-market team faster.
  • Partner with Customer Success on clean pre-to-post-sales handoffs so early expansion and renewal risk are managed from day one.

Requirements

  • 6+ years in solutions engineering, sales engineering, network engineering, or technical consulting, with at least 3 years customer-facing in pre-sales.
  • Deep networking fundamentals: OSI & TCP/IP models, Ethernet/Layer 2 vs. Layer 3 behavior, routing, NAT and NAT traversal, firewalls and conntrack, DNS, multicast/broadcast semantics, and overlay/underlay separation.
  • Comfort proving things at the packet level - Wireshark/tcpdump/pcap analysis is a working tool for you, not a party trick.
  • Strong Linux skills and real cloud experience (AWS/Azure/GCP): VPCs, routing tables, security groups, and hybrid connectivity patterns.
  • Hands-on familiarity with at least two of: SD-WAN, zero-trust network access, VPN technologies (WireGuard, IPsec, OpenVPN), container networking, or embedded/IoT device connectivity.
  • Working knowledge of SSO and identity standards - OIDC and SAML flows, IdP integrations (Entra ID, Okta, Google Workspace), and conditional access policies - and how they intersect with network access in enterprise deployments.
  • Scripting and API fluency (Python, Bash, or similar) - you can automate a demo environment, exercise a REST API, and read example code in Go or Rust.
  • A solid working understanding of modern cryptography: symmetric vs. asymmetric encryption, key exchange, digital signatures, PKI, and TLS.
  • A practical grasp of the quantum threat model - why cryptographically relevant quantum computers break RSA/ECC, and why “harvest now, decrypt later” makes this a today problem for long-lived data.
  • Familiarity with the NIST post-quantum standards (FIPS 203 / ML-KEM, FIPS 204 / ML-DSA, FIPS 205 / SLH-DSA), hybrid classical + PQC schemes, and crypto-agility as an architectural principle.
  • Awareness of the compliance landscape driving adoption: CNSA 2.0 timelines, FIPS 140-3 validation, and PQC mandates emerging across government and regulated industries.
  • The ability to translate all of the above into plain-language business value for a non-cryptographer audience - without overselling or hand-waving.

Benefits & conditions

Pulled from the full job description

  • Referral program
  • Health insurance
  • 401(k) matching
  • Paid time off
  • Dental insurance
  • Flexible schedule, * Hybrid office / remote work environment
  • Competitive salary and available equity compensation
  • Generous employer-paid health insurance, including preventative dental care for adults
  • 401K Plan with employer matching
  • Flexible PTO policy
  • Flexible work hours (subject to management approval)
  • Career enhancement funds
  • Employee Referral Bonus

About the company

ZeroTier leads the world in next-generation connectivity and cybersecurity. Our platform provides highly secure, peer-to-peer virtual networks relied upon by millions of users and businesses - from individual users and startups to mid-scale enterprises and Fortune 500 companies. We’re backed by awesome investors including Battery Ventures, Bonfire Ventures, and Anorak Ventures., Founded in 2013 by Adam Ierymenko, ZeroTier’s mission is to make peer-to-peer networking with strong encryption so simple, secure, and intuitive that it becomes the default for the internet.

To do this ZeroTier simplifies complex networking across physical boundaries, unifying cloud and edge environments. Our network virtualization platform offers enterprise-grade software-defined networking for every device, service, and application, whether at the edge or in the cloud. It’s powerful enough for large businesses and defense applications, yet easy for individuals to use for tasks like gaming or remote access.

Our team is composed of industry-leading experts dedicated to solving complex challenges in high-performance, decentralized networking. We enable customers to operate networks without unnecessary constraints or overhead. Come build the future with us.

To find out more please check us out at: www.zerotier.com

PLEASE NOTE: Individuals seeking employment at ZeroTier are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, or sexual orientation. Direct applicants ONLY. Any recruiter/3rd party submissions we receive will be considered a gift. Written CVs and cover letters are encouraged. No calls, please.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo ¡ LIVE

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo ¡ LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ WWC 2025

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 ¡ LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas SßdbrÜcker ¡ LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani ¡ Europe 2026 Virtual

Videos

See all

Related articles

See all