Open role
Senior Solutions Engineer
ZeroTier Europe B.V.
About the role
What You’ll Do
Lead technical discovery and qualification alongside Sales Directors; map customer requirements to ZeroTier architectures at Layer 1 through Layer 7.
Design, scope, and run structured POVs with clear success criteria, timelines, and exit decisions — for deployments ranging from ten nodes to tens of thousands.
Deliver compelling demos and whiteboard sessions for audiences from hands-on network engineers to CISOs and procurement executives.
Architect solutions across our full surface area: hosted control plane, self-hosted controllers, flow rules, bridging, multipath, SSO/OIDC integration, and ZeroTier Quantum's SaaS, sovereign, and air-gapped modes.
Own competitive positioning in live deals — articulating where ZeroTier wins against Tailscale, WireGuard-based stacks, and legacy VPN/SD-WAN vendors, and being honest about where it doesn't.
Respond to RFPs, RFIs, and security questionnaires; translate FIPS, CNSA 2.0, and post-quantum readiness requirements into concrete architecture answers.
Act as the technical escalation bridge during the sales cycle — reproduce issues, capture packet-level evidence, and work directly with Engineering on defects and feature gaps.
Feed the field's voice back into the product: structured win/loss insights, deployment patterns, and roadmap input.
Build reusable assets — demo environments, reference architectures, battle cards, and POV runbooks — that make the whole go-to-market team faster.
Partner with Customer Success on clean pre-to-post-sales handoffs so early expansion and renewal risk are managed from day one.
What We’re Looking For
6+ years in solutions engineering, sales engineering, network engineering, or technical consulting, with at least 3 years customer-facing in pre-sales.
Deep networking fundamentals: OSI & TCP/IP models, Ethernet/Layer 2 vs. Layer 3 behavior, routing, NAT and NAT traversal, firewalls and conntrack, DNS, multicast/broadcast semantics, and overlay/underlay separation.
Comfort proving things at the packet level — Wireshark/tcpdump/pcap analysis is a working tool for you, not a party trick.
Strong Linux skills and real cloud experience (AWS/Azure/GCP): VPCs, routing tables, security groups, and hybrid connectivity patterns.
Hands-on familiarity with at least two of: SD-WAN, zero-trust network access, VPN technologies (WireGuard, IPsec, OpenVPN), container networking, or embedded/IoT device connectivity.
Working knowledge of SSO and identity standards — OIDC and SAML flows, IdP integrations (Entra ID, Okta, Google Workspace), and conditional access policies — and how they intersect with network access in enterprise deployments.
Scripting and API fluency (Python, Bash, or similar) — you can automate a demo environment, exercise a REST API, and read example code in Go or Rust.
A solid working understanding of modern cryptography: symmetric vs. asymmetric encryption, key exchange, digital signatures, PKI, and TLS.
A practical grasp of the quantum threat model — why cryptographically relevant quantum computers break RSA/ECC, and why "harvest now, decrypt later" makes this a today problem for long-lived data.
Familiarity with the NIST post-quantum standards (FIPS 203 / ML-KEM, FIPS 204 / ML-DSA, FIPS 205 / SLH-DSA), hybrid classical + PQC schemes, and crypto-agility as an architectural principle.
Awareness of the compliance landscape driving adoption: CNSA 2.0 timelines, FIPS 140-3 validation, and PQC mandates emerging across government and regulated industries.
The ability to translate all of the above into plain-language business value for a non-cryptographer audience — without overselling or hand-waving.
What's on offer
Hybrid office / remote work environment
Competitive salary and available equity compensation
Generous employer-paid health insurance, including preventative dental care for adults
401K Plan with employer matching
Flexible PTO policy
Flexible work hours (subject to management approval)
Career enhancement funds
Employee Referral Bonus