This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We're looking for a Senior Software Engineer to join our new OpenGRC team and help us bootstrap a brand new product from scratch. You'll work closely with the Engineering Manager and a small, agile squad to define the technical architecture and build the MVP of our Governance, Risk, and Compliance solution that will turns abstract threat data into verified, quantified action plans. This is a high-impact role where you will balance rapid iteration with code quality to lay the foundation for a scalable Open Source product.
Job Responsibility:
Full Stack Architecture: Build a clean, scalable Single Page App (SPA) deployable both as SaaS and On-Premise, using React, TypeScript, and Node.js
Core Engine Development: Design and implement the core engines that make OpenGRC unique: Correlation Engine and Quantification Engine
Architectural Evolution: Refine the software architecture to handle heavy data ingestion and cross-platform integrations (OpenCTI, OpenAEV, CMDBs)
Product Engineering: Actively contribute to product definition
Rapid Prototyping: Iterate fast to test concepts
Community Management: Engage with the Open Source community (GitHub, Slack)
Team Structuring: Participate in the creation of development processes and team culture as one of the first hires in this new squad
Requirements:
Senior experience in Full Stack development, with strong proficiency in React, TypeScript, and Node.js
Architectural Mindset: ability to think critically about software architecture, especially regarding data modeling (Entities, Relationships) and complex business logic
Ownership & Agility: experience launching projects and are comfortable navigating uncertainty
Full Stack mastery: equally comfortable working on UI/UX implementation and backend logic (API design, query optimization, permission models)
Communication: Fluent in English and French
Nice to have:
Previous experience in the GRC (Governance, Risk, Compliance) or Cybersecurity sectors
Familiarity with Cyber Threat Intelligence (CTI) standards like STIX/TAXII or the MITRE ATT&CK framework
Interest in quantitative risk methodologies (e.g., FAIR model)
Experience contributing to or maintaining Open Source projects
While our core stack is JS/TS, Python skills are highly valued for data processing scripts, integrations, and tooling
What we offer:
Competitive pay + equity — everyone shares in our success
Remote-first, flexible, and balanced — work that fits your life
Your setup, your choice — pick the gear that works for you