About Us
ZeroTier leads the world in next-generation connectivity and cybersecurity. Our platform provides highly secure, peer-to-peer virtual networks relied upon by millions of users and businesses - from individual users and startups to mid-scale enterprises and Fortune 500 companies. We’re backed by awesome investors including Battery Ventures, Bonfire Ventures, and Anorak Ventures.
The Role
As Senior Solutions Engineer, you are the technical counterpart to Sales and the trusted advisor to our customers — from a founder connecting a fleet of Raspberry Pis, to an industrial OT team bridging PLCs across plants, to a defense integrator architecting an air-gapped, CNSA 2.0-compliant sovereign network. You'll own technical discovery, solution architecture, demos, and proof-of-value (POV) engagements end to end, then partner with Customer Success to ensure what you sold is what gets deployed.
The deployment spectrum you'll cover is unusually broad, and that's the point:
Remote access & VPN replacement — flat peer-to-peer overlays for distributed workforces, multi-site interoperability, and zero-trust access without hub-and-spoke bottlenecks.
Multi-cloud & hybrid infrastructure — connecting AWS, Azure, GCP, on-prem, and colo environments into a single virtual Layer 2 network, including self-hosted controllers.
IoT, IIoT & OT / Industrial — embedded devices, sensors, PLCs, SCADA-adjacent systems, kiosks, point-of-sale, and edge compute behind carrier-grade NAT and restrictive third-party networks.
Embedded & OEM — vendors shipping ZeroTier inside their own products (embedded SDK integrations, private root server infrastructure, white-label connectivity).
SD-WAN-style topologies — multipath bonding, failover/handover across LTE/5G/satellite/Starlink links, bridged Layer 2 segments, and flow-rules-based microsegmentation.
What You’ll Do
Lead technical discovery and qualification alongside Sales Directors; map customer requirements to ZeroTier architectures at Layer 1 through Layer 7.
Design, scope, and run structured POVs with clear success criteria, timelines, and exit decisions — for deployments ranging from ten nodes to tens of thousands.
Deliver compelling demos and whiteboard sessions for audiences from hands-on network engineers to CISOs and procurement executives.
Architect solutions across our full surface area: hosted control plane, self-hosted controllers, flow rules, bridging, multipath, SSO/OIDC integration, and ZeroTier Quantum's SaaS, sovereign, and air-gapped modes.
Own competitive positioning in live deals — articulating where ZeroTier wins against Tailscale, WireGuard-based stacks, and legacy VPN/SD-WAN vendors, and being honest about where it doesn't.
Respond to RFPs, RFIs, and security questionnaires; translate FIPS, CNSA 2.0, and post-quantum readiness requirements into concrete architecture answers.
Act as the technical escalation bridge during the sales cycle — reproduce issues, capture packet-level evidence, and work directly with Engineering on defects and feature gaps.
Feed the field's voice back into the product: structured win/loss insights, deployment patterns, and roadmap input.
Build reusable assets — demo environments, reference architectures, battle cards, and POV runbooks — that make the whole go-to-market team faster.
Partner with Customer Success on clean pre-to-post-sales handoffs so early expansion and renewal risk are managed from day one.
What We’re Looking For
6+ years in solutions engineering, sales engineering, network engineering, or technical consulting, with at least 3 years customer-facing in pre-sales.
Deep networking fundamentals: OSI & TCP/IP models, Ethernet/Layer 2 vs. Layer 3 behavior, routing, NAT and NAT traversal, firewalls and conntrack, DNS, multicast/broadcast semantics, and overlay/underlay separation.
Comfort proving things at the packet level — Wireshark/tcpdump/pcap analysis is a working tool for you, not a party trick.
Strong Linux skills and real cloud experience (AWS/Azure/GCP): VPCs, routing tables, security groups, and hybrid connectivity patterns.
Hands-on familiarity with at least two of: SD-WAN, zero-trust network access, VPN technologies (WireGuard, IPsec, OpenVPN), container networking, or embedded/IoT device connectivity.
Working knowledge of SSO and identity standards — OIDC and SAML flows, IdP integrations (Entra ID, Okta, Google Workspace), and conditional access policies — and how they intersect with network access in enterprise deployments.
Scripting and API fluency (Python, Bash, or similar) — you can automate a demo environment, exercise a REST API, and read example code in Go or Rust.
A solid working understanding of modern cryptography: symmetric vs. asymmetric encryption, key exchange, digital signatures, PKI, and TLS.
A practical grasp of the quantum threat model — why cryptographically relevant quantum computers break RSA/ECC, and why "harvest now, decrypt later" makes this a today problem for long-lived data.
Familiarity with the NIST post-quantum standards (FIPS 203 / ML-KEM, FIPS 204 / ML-DSA, FIPS 205 / SLH-DSA), hybrid classical + PQC schemes, and crypto-agility as an architectural principle.
Awareness of the compliance landscape driving adoption: CNSA 2.0 timelines, FIPS 140-3 validation, and PQC mandates emerging across government and regulated industries.
The ability to translate all of the above into plain-language business value for a non-cryptographer audience — without overselling or hand-waving.
Benefits
Hybrid office / remote work environment
Competitive salary and available equity compensation
Generous employer-paid health insurance, including preventative dental care for adults
401K Plan with employer matching
Flexible PTO policy
Flexible work hours (subject to management approval)
Career enhancement funds
Employee Referral Bonus
Skills Required
- 6+ years in solutions engineering, sales engineering, network engineering, or technical consulting with at least 3 years customer-facing pre-sales experience
- Deep networking fundamentals (OSI, TCP/IP, Ethernet Layer 2 vs Layer 3, routing, NAT traversal, firewalls, DNS, multicast/broadcast, overlay/underlay)
- Packet-level troubleshooting and analysis using Wireshark/tcpdump/pcap
- Strong Linux skills and cloud experience (AWS, Azure, GCP) including VPCs, routing tables, security groups, hybrid connectivity
- Hands-on familiarity with at least two of: SD-WAN, zero-trust network access, VPN technologies (WireGuard, IPsec, OpenVPN), container networking, or embedded/IoT device connectivity
- Working knowledge of SSO and identity standards (OIDC, SAML) and IdP integrations (Entra ID, Okta, Google Workspace) and conditional access policies
- Scripting and API fluency (Python, Bash, or similar); ability to automate demos, call REST APIs, and read sample code in Go or Rust
- Solid working understanding of modern cryptography (symmetric/asymmetric encryption, key exchange, digital signatures, PKI, TLS)
- Practical grasp of the quantum threat model and implications for long-lived data
- Familiarity with NIST post-quantum standards (FIPS 203/204/205), hybrid PQC schemes, and crypto-agility principles
- Awareness of compliance landscape (CNSA 2.0 timelines, FIPS 140-3 validation, PQC mandates) and ability to translate to architectures
- Ability to communicate technical and cryptographic concepts in plain language to non-technical stakeholders
What We Do
ZeroTier delivers secure software defined networking that works seamlessly and identically across both local and wide area networks. We are radically simplifying networking by treating the entire planet as a single data center.








