> Markdown version of [/jobs/ext/2961128-senior-solutions-engineer](https://www.wearedevelopers.com/jobs/ext/2961128-senior-solutions-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Solutions Engineer - **Company:** DomainTools - **Location:** Seattle, WA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** ARM Architecture, Cyber Security, Computer Telephony Integration, Domain Name System (DNS), JSON, Python (Programming Language), Network Security, Network Architecture, Phishing, Security Information and Event Management, Scripting, Large Language Models, Snowflake, Cyber Threat Analysis, Data Lakes, Cybercrime, Production Code, Microsoft Sentinel, Data Management, Restful APIs, Splunk, Databricks - **Published:** September 17, 2026 - **Apply:** https://apply.workable.com/domain-tools/j/71191B6088 ## About the Role * 4+ years in a customer-facing technical role - Solutions Engineer, Sales Engineer, Solutions Architect, TAM, or a threat intel / SOC practitioner who has moved into pre-sales. * Fluency with the security buyer. You can hold your own in a room with a SOC director, a threat intel lead, and a CISO - in the same meeting. * Working knowledge of DNS, WHOIS/RDAP, passive DNS, SSL/TLS, HTTP, and the fundamentals of how internet infrastructure is abused by adversaries. * Hands-on comfort with at least one SIEM, one SOAR, and one TIP. You've built or debugged an integration, not just talked about one. * Comfort with RESTful APIs, JSON, and scripting (Python preferred). You don't need to ship production code; you do need to read it, prototype with it, and demo it live. * Excellent demo and whiteboard skills. You can build a compelling narrative from a blank browser tab. * Willingness to travel ~25% for customer meetings, events, and QBRs. Strong plus * Prior experience at a threat intelligence, DNS, network security, or SOC-tooling vendor. * Experience with agentic / LLM-driven security workflows, MCP servers, or building on top of security data lakes. * Familiarity with federal, DoD, IC, or allied-government buying motions and accreditation requirements (FedRAMP, IL4/5, IRAP, and equivalents). * Background as a former analyst, incident responder, threat hunter, or CTI practitioner. ## Description * Own discovery, technical qualification, solution design, demo, and POV for enterprise and strategic opportunities. * Translate customer pain - phishing, brand abuse, C2 discovery, third-party risk, fraud, DFIR, threat hunting, exposure management - into concrete DomainTools workflows across Iris Investigate, DNSDB / Farsight passive DNS, real-time threat feeds, and the MCP Server. * Design and defend integration architectures with SIEM, SOAR, TIP, XDR, and data platforms (Splunk, CrowdStrike, Google SecOps, Palo Alto Cortex, Anomali, Elastic, Microsoft Sentinel, Snowflake, Databricks, and the customer's homegrown stack). Customer Advocacy * Be the technical trusted advisor from first call through renewal. The buyers in this seat are paranoid for good reason; earn the trust that gets you invited back. * Partner with Customer Success and Support to make sure the win on paper becomes a win in production. * Run executive briefings and technical deep-dives with equal fluency - the same day if needed. Product & Market Feedback * Be the field's voice into Product and Engineering. Bring back the signal that shapes the roadmap. * Build reusable technical assets - demo environments, integration recipes, IrisQL playbooks, MCP workflows, reference architectures - that make the whole SE team better. Regional Leadership * Partner with your AEs to build the technical strategy: named-account plans, competitive posture, executive relationships, and pipeline health. * Represent DomainTools at events, customer advisory boards, and practitioner communities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)