Stop applying to remote jobs that are already dead.
Every listing shows the evidence: when we last checked it, how, and when it was posted and closed.

All listings

DomainTools via Workable

Solutions Engineer

United Kingdom Travel up to 25% Level not stated
still open verified 10h ago posted 20d ago seen just now
Apply at apply.workable.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 10h ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 20d ago

The date the source published, not the day we noticed it (2026-09-21). Last seen at its source just now.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

United Kingdom

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay £70.6k–127.4k/yr

Middle 50% of 64 listings that do state pay — Engineering · all levels · United Kingdom · GBP/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

Business ReviewsCustomer SuccessDatabricksOnboardingPythonRESTSIEMSnowflakeSplunkTechnical Support

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

The internet is the world's most dangerous attack surface. DomainTools maps it — and we're moving faster than ever.

The world's most advanced security teams rely on DomainTools to identify malicious infrastructure before attacks happen. We're in an active growth phase: shipping new products, expanding our intelligence platform well beyond our DNS roots, and positioning our data at the center of where cybersecurity is heading in the age of AI.

Today, DomainTools delivers a comprehensive internet intelligence platform covering domains, IPs, hostnames, SSL certificates, passive DNS, real-time threat feeds, and AI-native integrations, with global visibility driven by massively scaled active and passive data observations. Our Iris Investigate platform, DNSDB / SIE passive DNS, real-time threat feeds, IrisQL, and newly launched MCP Server are the intelligence backbone for the most demanding security teams on earth.

We're hiring a Solutions Engineer to partner with our Account Executives, and Customer Success Managers for Europe. This is the technical face of DomainTools in front of the organisations we're built for. These are technical, skeptical, well-resourced buyers — the security teams at the world's largest financial institutions, governments, technology platforms, and defense organizations. They don't want a pitch. They want a peer. 

You will own the technical win. You'll run discovery, design solutions, deliver demos that earn analyst respect on the first call, run POVs that produce evidence a customer can defend internally, and be the trusted technical peer through renewal and expansion. 

You will have mentors and resources to assist with learning but your success will depend heavily on your ability to consume new information independently and using your initiative to reach out to experts within the organisation for specialist knowledge transfer. 

Our platform is expanding fast — real-time threat feeds, IrisQL, the MCP Server for AI-native security workflows, deepening integrations with Splunk, CrowdStrike, Google SecOps, Anomali, Cortex XSOAR, and more. The SE team is where product velocity meets customer reality. You'll shape both.

Technical Wins

  • Own discovery, technical qualification, solution design, demo, and POV for enterprise and strategic opportunities.
  • Translate customer pain — phishing, brand abuse, C2 discovery, third-party risk, fraud, DFIR, threat hunting, exposure management — into concrete DomainTools workflows across Iris Investigate, DNSDB / Farsight passive DNS, real-time threat feeds, and the MCP Server.
  • Design and defend integration architectures with SIEM, SOAR, TIP, XDR, and data platforms (Splunk, CrowdStrike, Google SecOps, Palo Alto Cortex, Anomali, Elastic, Microsoft Sentinel, Snowflake, Databricks, and the customer's homegrown stack).
  • Lead focused beginner through advanced training, onboarding, and education sessions to guide adoption of our solution set. 

Customer Advocacy

  • Be the technical trusted advisor from first call through renewal. The buyers in this seat are paranoid for good reason; earn the trust that gets you invited back.
  • Partner with Customer Success and Support to be a key provider of expert technical support and make sure the win on paper becomes a win in production. 
  • Run executive briefings and technical deep-dives with equal fluency — the same day if needed.

Product & Market Feedback

  • Be the customer’s voice into Product and Engineering. Bring back the signal that shapes the roadmap.
  • Build reusable technical assets — demo environments, integration recipes, IrisQL playbooks, MCP workflows, reference architectures — that make the whole SE team better.

Regional Leadership

  • Partner with your AEs to build the technical strategy: named-account plans, competitive posture, executive relationships, and pipeline health.
  • Represent DomainTools at events, customer advisory boards, and practitioner communities.

Requirements

Must-haves

  • 3+ years in a customer-facing technical role — Solutions Engineer, Sales Engineer, Solutions Architect, TAM, or a threat intel / SOC practitioner who has moved into pre-sales.
  • Experience and knowledge of the cybersecurity landscape that underpins a strong fluency with the security buyer. You can hold your own in a room with a SOC director, a threat intel lead, and a CISO — in the same meeting.
  • Working knowledge of DNS, WHOIS/RDAP, passive DNS, SSL/TLS, HTTP, and the fundamentals of how internet infrastructure is abused by adversaries.
  • Hands-on comfort with at least one SIEM, one SOAR, and one TIP. You've built or debugged an integration, not just talked about one.
  • Comfort with RESTful APIs, JSON, and scripting (Python preferred). You don't need to ship production code; you do need to read it, prototype with it, and demo it live.
  • Excellent demo and whiteboard skills. You can build a compelling narrative from a blank browser tab.
  • Willingness to travel ~25% for customer meetings, events, and QBRs.

Strong plus

  • Prior experience at a threat intelligence, DNS, network security, or SOC-tooling vendor.
  • Experience with agentic / LLM-driven security workflows, MCP servers, or building on top of security data lakes.
  • Background as a former analyst, incident responder, threat hunter, or CTI practitioner.
  • Fluency in French, or other European languages.
Apply at apply.workable.com