Smallstep is an internationally distributed, remote-first company. We work reasonable, flexible hours and utilize technology to accomplish goals asynchronously. We look for folks who are thoughtful, can break down problems, and often work independently. You are trusted to work on your own and to ask for help when blocked. At Smallstep you get the benefit of working with a tight-knit team across many areas and contribute directly to the success of the organization.
Security is a core responsibility for all employees at Smallstep. All roles are expected to strictly adhere to our security policies, procedures, and best practices to protect company assets, customer data, and systems. All employees must remain vigilant, report potential security concerns, and participate in ongoing security training to ensure compliance with industry standards.
We're looking for a Forward Deployed Engineer to embed with customers deploying Smallstep's device identity platform and get them to production. The most common use cases are securing Wi-Fi, browser mTLS, SSH, VPN and other network based communication using credentials issued by Smallstep’s agent or an MDM. This role sits at the intersection of hardware, software, and the customer relationship: you'll move between a customer's endpoint fleet, their IdP, and Smallstep's own multi-service certificate authority services to get deployments unstuck.
Responsibilities
Diagnosing and resolving technical failures blocking deployments
Acting as the technical escalation point for Technical Account Managers and Customer Success Engineers when a deployment needs deeper engineering involvement
Shipping production Golang code to resolve root causes uncovered during deployment debugging
Building proof-of-concept environments, using Bash and Terraform, and runbooks for new product surfaces ahead of polished UX
Setting day-to-day priorities and assignments for Smallstep's deployment ops engineers
Carrying a formal on-call rotation with defined SLAs
Capable of maintaining a high level of customer experience and a service mindset even in the face of implementation challenges. Building software at the edge isn't for the weak.
Growing the role over time into an even split between resolving live deployments, building reusable runbooks, and validating new use cases through proofs of concept
Experience With …
Debugging distributed, multi-service cloud architectures in live customer environments
Troubleshooting TLS/mTLS at the protocol level, including certificate chain validation, trust stores, and handshake failures
Production experience with certificate-based authentication, VPNs, enterprise Wi-Fi/EAP-TLS, RADIUS, SSH, OAuth
Developing and shipping production Golang code
Owning technical escalations directly with customers, in partnership with account teams
Nice to Have
Familiarity with certificate enrollment protocols such as SCEP and ACME DA
PKI experience across macOS, Windows, Linux, and ChromeOS
Experience with hardware-backed security mechanisms such as Yubikeys, TPMs, HSMs, or secure enclaves
Experience carrying a formal on-call rotation with SLAs
Prior experience in a customer-facing technical role, such as a forward deployed engineer or solutions engineer
Technologies
Golang, Bash, Terraform, Git, GitHub Actions
SCEP, ACME, SCIM, mTLS, EAP-TLS, RADIUS, PKI, X.509, SSH, TPMs
macOS, Windows, Linux, ChromeOS
MDMs (Jamf, Intune, Workspace One, Google Workspace Admin, Iru), Wi-Fi/RADIUS, VPNs
We believe in action-based empathy. We actively work to create an environment where everyone feels welcome and valued as teammates and contributors. We know a diverse team is essential to create a vibrant and inclusive culture that fosters a true sense of belonging. By embracing the unique talents and perspectives of our entire team, we approach challenges in ways that a monocultural team simply cannot.
We’re committed to building a self-aware group that is collaborative and results- driven, representing a variety of skills, backgrounds, and lived experiences. We believe everyone deserves a competitive salary, industry leading benefits, the ability to share in the company’s success, and the psychological safety to be their truest selves at work.
Smallstep is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We encourage all those interested to apply.
Skills Required
- Debugging distributed, multi-service cloud architectures in live customer environments
- Troubleshooting TLS/mTLS at the protocol level including certificate chain validation and handshake failures
- Production experience with certificate-based authentication, VPNs, enterprise Wi-Fi/EAP-TLS, RADIUS, SSH, OAuth
- Developing and shipping production Golang code
- Building proof-of-concept environments and runbooks using Bash and Terraform
- Owning technical escalations directly with customers in partnership with account teams
- Carrying a formal on-call rotation with defined SLAs
- Maintaining a high level of customer experience and a service mindset during implementations
- Adhering to company security policies, procedures, and best practices
- Familiarity with certificate enrollment protocols such as SCEP and ACME DA
- PKI experience across macOS, Windows, Linux, and ChromeOS
- Experience with hardware-backed security mechanisms such as Yubikeys, TPMs, HSMs, or secure enclaves
- Prior experience in a customer-facing technical role (forward deployed engineer, solutions engineer)
What We Do
Identify company-owned devices with ease with Smallstep. Ensure that access to financial data, code repositories, PII, SaaS apps, and other sensitive resources is only possible from trusted, company-managed devices.

.png)







