About the Role
About the Role
Securly protects over 20 million students across 20,000+ schools by filtering harmful content at the network level — in real time, at massive scale (1.1B+ requests/day). You'll build a core piece of that system: a DNS-over-HTTPS (DoH) resolver that identifies which student or device is making a request and applies the right safety policy, instantly.
This is a from-scratch build. You'll own it end to end — design, code, ship, and run it in production. We're open to either Go or Rust for this — use whichever you're strongest in.
What You'll Build
- A high-performance DoH resolver, written in Go or Rust, that handles encrypted DNS traffic from managed Chromebooks
- Logic to extract device/user identity from the request and check it against policy in Redis
- TLS setup so browsers trust and correctly connect to the resolver
- The deployment pipeline to get this running reliably on AWS
- A written design doc laying out what you built and why, so the next engineer (or your future self) understands the tradeoffs
You'll work closely with our Distinguished Engineer during the design phase, then take the system through to production hardening on your own.
Must-Have
- Golang (Go) or Rust, 4+ years writing production code in one of the two — not scripts, not tutorials, real systems in production
- Solid understanding of how DNS works — resolution, records, why DNS matters for security, and comfort reading RFCs when needed
- Ability to work independently through ambiguity — this role starts with a rough problem, not a finished spec
- Can write clearly — a short doc explaining a technical decision, not just code
Good to Have (not required — we'll teach you)
- DNS-over-HTTPS (RFC 8484) or experience with encrypted DNS
- Redis, or any similar key-value store used for lookups at scale
- TLS/certificate management
- AWS, especially CloudFormation
- Unbound or any recursive DNS resolver
- Exposure to enterprise/managed-device environments (Chrome policy, MDM, etc.)
- Prior work in ad-tech, cybersecurity, or network infrastructure
What Success Looks Like
- You take a genuinely ambiguous problem and drive it to a working system with minimal hand-holding
- Your code is something other senior engineers want to review, not something they have to fix
- You mentor 1–2 junior engineers along the way — code reviews, pairing, raising the bar
- You leave a clear paper trail on major decisions so the team isn't relying on your memory
Why This Role
- You're not maintaining someone else's system — you're building the thing from zero
- Direct line to a Distinguished Engineer and SVP of Engineering; high visibility
- Real-world impact: this system protects millions of students every day
Benefits
- Comprehensive health insurance (self + family)
- PTO
- Learning reimbursement
- Retirement benefits (EPF & gratuity)
Requirements
Golang or Rust
4+ years writing production code in either Go or Rust.
DNS Knowledge
Solid understanding of how DNS works and its importance for security.
Independent Work
Ability to work independently through ambiguity.
Clear Writing
Can write clear documentation explaining technical decisions.
Nice to Have
Experience with DNS-over-HTTPS (RFC 8484) or encrypted DNS.
Familiarity with Redis or similar key-value stores.
Experience with TLS and certificate management.
Experience with AWS, especially CloudFormation.
Exposure to enterprise/managed-device environments.
Benefits
Health Insurance
Comprehensive health insurance for self and family.
PTO
Paid time off.
Learning Reimbursement
Reimbursement for learning and development.
Retirement Benefits
Retirement benefits including EPF and gratuity.