Back to Jobs
DomainTools
Engineering & Architecture Just now

Solutions Engineer (North America) - Cybersecurity & Internet Intelligence

DomainTools
United StatesUnited States
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

RESTful APIsSIEMPython ScriptingThreat Intelligence Platform (TIP)Integration ArchitecturesCybersecuritySOAR

Want to know if you're a match for this job?

Calculate My Match Score

The internet is the world's most dangerous attack surface. DomainTools maps it—and we're moving faster than ever.

For over 25 years, the world's most advanced security teams have relied on DomainTools to identify malicious infrastructure before attacks happen. This is not a legacy company; we're in an active growth phase, shipping new products, expanding our intelligence platform beyond DNS, and positioning our data at the center of cybersecurity in the age of AI.

DomainTools delivers a comprehensive internet intelligence platform covering domains, IPs, hostnames, SSL certificates, passive DNS, real-time threat feeds, and AI-native integrations, with global visibility driven by massively scaled active and passive data observations. Our platforms like Iris Investigate, DNSDB/Farsight passive DNS, real-time threat feeds, IrisQL, and MCP Server serve the most demanding security teams worldwide.

We're not a startup chasing trends—we're the category, and we're accelerating.

We're hiring a Solutions Engineer to partner with Enterprise and Strategic Account Executives in North America. This role is the technical face of DomainTools for high-resource buyers—security teams at financial institutions, governments, tech platforms, and defense organizations. They don’t want a pitch; they want a peer.

You will own the technical win. Responsibilities include:

What You'll Own

Technical Wins:

  • Own discovery, technical qualification, solution design, demo, and proof-of-concept (POV) for enterprise and strategic opportunities.
  • Translate customer pain points—such as phishing, brand abuse, C2 discovery, third-party risk, fraud, DFIR, threat hunting, and exposure management—into concrete DomainTools workflows across Iris Investigate, DNSDB/Farsight passive DNS, real-time threat feeds, and MCP Server.
  • Design and defend integration architectures with SIEM, SOAR, TIP, XDR, and data platforms like Splunk, CrowdStrike, Google SecOps, Palo Alto Cortex, Anomali, Elastic, Microsoft Sentinel, Snowflake, and Databricks.

Customer Advocacy:

  • Be the trusted technical advisor from the first call through renewal. Earn the trust of paranoid buyers who need evidence to defend internally.
  • Partner with Customer Success and Support to ensure wins translate into production success.
  • Conduct executive briefings and technical deep-dives with equal fluency, often on the same day.

Product & Market Feedback:

  • Serve as the field's voice to Product and Engineering, shaping the roadmap based on real-world feedback.
  • Build reusable technical assets—demo environments, integration recipes, IrisQL playbooks, MCP workflows, and reference architectures—to improve the entire SE team.

Regional Leadership:

  • Collaborate with Account Executives to develop technical strategies, including named-account plans, competitive posture, executive relationships, and pipeline health.
  • Represent DomainTools at industry events, customer advisory boards, and practitioner communities.

Requirements

Must-haves:

  • 4+ years in a customer-facing technical role, such as Solutions Engineer, Sales Engineer, Solutions Architect, Technical Account Manager (TAM), or a threat intelligence/SOC practitioner transitioning into pre-sales.
  • Fluency with security buyers—ability to engage with SOC directors, threat intel leads, and CISOs in the same meeting.
  • Working knowledge of DNS, WHOIS/RDAP, passive DNS, SSL/TLS, HTTP, and how internet infrastructure is abused by adversaries.
  • Hands-on experience with at least one SIEM, one SOAR, and one Threat Intelligence Platform (TIP). Experience building or debugging integrations, not just theoretical knowledge.
  • Comfort with RESTful APIs, JSON, and scripting (Python preferred). Ability to read code, prototype with it, and demo live without shipping production code.
  • Excellent demo and whiteboard skills to build compelling narratives from scratch.
  • Willingness to travel ~25% for customer meetings, events, and quarterly business reviews (QBRs).

Strong plus:

  • Prior experience at a threat intelligence, DNS, network security, or SOC-tooling vendor.
  • Experience with agentic/LLM-driven security workflows, MCP servers, or security data lakes.
  • Familiarity with federal, DoD, IC, or allied-government buying motions and accreditation requirements (e.g., FedRAMP, IL4/5, IRAP).
  • Background as a former analyst, incident responder, threat hunter, or CTI practitioner.

How would you rate this job post?

See what other professionals think about this role.

banner

DomainTools is a leading provider of domain name research and monitoring tools, offering a comprehensive suite of products and services designed to help individuals and organizations protect their online presence and reputation. With a strong focus on cybersecurity and threat intelligence, DomainTools empowers its customers to identify and mitigate potential risks associated with domain names, IP addresses, and other online identifiers. The company's innovative solutions include domain name registration and monitoring, WHOIS lookup and search, DNS research, and threat intelligence feeds. By leveraging cutting-edge technology and a vast database of domain name and IP address information, DomainTools enables its customers to stay one step ahead of cyber threats and maintain a secure online presence. Whether you are an individual, a small business, or a large enterprise, DomainTools provides the tools and expertise needed to navigate the complex and ever-evolving online landscape. With a commitment to delivering high-quality products and exceptional customer support, DomainTools has established itself as a trusted leader in the cybersecurity industry.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More