Website Hirebee Resources
HB-26-002
Our client builds a commercial quantum-safe secure connectivity platform, combining post-quantum cryptography, QKD and QRNG, deployed across defence and enterprise customers. They are scaling the team to deliver the next generation of the platform, including quantum-safe SD-WAN and SASE capabilities.
The role
Own the design, development and delivery of core VPN and secure connectivity modules. Lead a team of four to five engineers, work closely with the Product Architect, and deliver production-grade features end to end. This is a hands-on role: you code, review, debug and make architecture calls. Title and seniority are mapped to demonstrated depth.
What you will own
- Design and development of IPsec and TLS VPN data and control planes, including integration with the crypto layer
- End-to-end feature delivery: design docs, code, tests, release notes, production support and readiness for security certifications
- Team leadership for four to five engineers, covering code reviews, sprint ownership and mentoring
- Close collaboration with the Architect, peer Tech Leads, QA and L3 support
- Customer-facing debugging and root-cause analysis for production issues
Must have
- 8 to 12 years in software engineering, with 5+ years in VPN or secure connectivity product development
- Hands-on VPN protocol development. You have built or contributed to a commercial VPN codebase such as strongSwan, OpenVPN, WireGuard or proprietary. Protocol-level code, not configuration or operations.
- Proven high-productivity use of AI coding tools, with measurable output gains you can demonstrate and teach
- Deep IPsec knowledge: IKEv2, ESP, AES-GCM, PFS, DPD, X.509 authentication, tunnel lifecycle
- Applied crypto experience, classical (RSA, AES-256, TLS 1.3) or post-quantum (ML-KEM, ML-DSA)
- Security certification experience: FIPS 140-2 or 140-3, Common Criteria or equivalent
- Strong C/C++ for the data plane and Python or Go for the control plane
- Linux networking internals: netfilter/nftables, XFRM, routing, namespaces, packet flow
- Appliance development experience: build, debug, upgrade, factory workflows
- NMS/EMS integration: SNMP v2/v3, NETCONF, RESTconf or gRPC telemetry
- Team leadership experience, having led four or more engineers with sprint and code-review ownership
Nice to have
- SD-WAN (link monitoring, path selection, policy routing) or SASE exposure
- Deeper post-quantum crypto work: hybrid key exchange, crypto-agility frameworks
- RHEL-based product development; ICSA Labs or defence-grade certification experience
Not a fit
VPN administration or operations, cloud VPN configuration roles, or generalist full-stack backgrounds without protocol-level development.
To apply for this job please visit docs.google.com.