Join a team building a high‑performance DNS‑over‑HTTPS resolver that powers filtering for millions of students. You’ll design and deliver a production‑grade, identity‑aware DNS service that runs on AWS and interfaces with our policy engine. The role requires deep knowledge of DNS, Go, and cloud infrastructure.
What You’ll Do
- Architect and deploy a production‑grade DoH resolver in Go integrated with our DNS engine.
- Extract identity from Chrome DnsOverHttpsTemplatesWithIdentifiers for device/user mapping.
- Build Unbound plugin for filtering logic using identity parameters.
- Integrate Redis for policy lookups, state, and feature flags.
- Own TLS termination, certificate provisioning, and Chrome validation.
- Lead POC, hardening, and ADR documentation with senior engineers.
- Mentor junior staff on DNS, Go, and IaC practices.
What You Need
- 5+ years Go (Golang) production experience.
- Deep knowledge of DNS protocols, RFC 1035, DNSSEC, Unbound.
- Expertise in DNS‑over‑HTTPS (RFC 8484) and HTTP/2 transport.
- Redis data modeling, pipelines, and failure handling.
- TLS certificate provisioning, renewal, and client validation.
- Strong architectural decision writing (ADRs, diagrams).
- CloudFormation, NLB, ASG, Route53 experience.
Good to Have
- Unbound DNS server operational experience.
- SmartPAC/PAC proxy architecture knowledge.
- C/C++ familiarity for low‑level module work.
The Opportunity
Securly protects 20+ million students worldwide; joining this team means shaping the future of safe, scalable web filtering for education.
