Full-Time

Windows Engineer

Tailscale

Tailscale

201-500 employees

WireGuard-based VPN for secure remote access

Compensation Overview

$143k - $179k/yr

Remote in USA

Remote

Category
Software Engineering (1)
Required Skills
Microsoft Windows
Computer Networking
C#
Go

Get referred to Tailscale

See people who can refer or advise you

Requirements
  • Four or more years of experience in software development.
  • A strong understanding of software development principles, capabilities, and limitations of the Windows platform.
  • Proficiency in C# and modern native user-interface frameworks, including WinUI, Universal Windows Platform, and Windows Presentation Foundation.
  • Experience with general networking concepts, including DNS, VPNs, IP networking, and routing.
  • Excellent written and verbal communication skills.
  • Ability to give and process constructive feedback and work independently.
  • Flexibility to adjust to the dynamic nature of a startup.
Responsibilities
  • Develop the Tailscale product by contributing to client code and backend services.
  • Work with engineers on a native Windows desktop client using Windows App SDK, WinUI, C#, XAML, and Go.
  • Implement support for the latest Windows platform features while maintaining compatibility with a subset of older versions.
  • Develop and optimize product features on Windows, focusing on UI components and platform integration.
  • Develop and maintain unit and integration tests using Microsoft Testing Platform v2 and xUnit.
  • Contribute to common, cross-platform Tailscale code.
Desired Qualifications
  • Experience with WinUI 3 and Windows App SDK.
  • Experience developing native Windows applications and services.
  • Familiarity with the Windows networking stack and Windows Filtering Platform.
  • Familiarity with the Windows security model, session isolation, access tokens, and related concepts.
  • Proficiency in Go.

Tailscale provides secure remote access by offering a WireGuard-based VPN that lets teams and individuals reach private resources such as virtual machines, containers, and databases from anywhere. The product works by creating a secure, encrypted network between devices so users can access private resources as if they were on a local network; setup is designed to be simple, and the service includes many integrations (over 100) to fit into various tech stacks. The company differentiates itself with a freemium model that lowers the barrier to entry, a focus on ease of use with minimal setup, and strong data security to protect all connections, along with features that support cross-cloud and multi-resource environments. Tailscale’s goal is to make secure remote access easy to deploy and manage for both organizations of any size and individual users, enabling safe data transfer and collaboration across diverse infrastructure.

Company Size

201-500

Company Stage

Series C

Total Funding

$275M

Headquarters

Toronto, Canada

Founded

2019

Get referred to Tailscale

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 2026 DNS Filtering by Control D expands monetization across existing business customers.
  • June 2026 Aperture targets shadow AI, riding enterprise demand for agent governance.
  • More than 30,000 businesses use Tailscale, creating distribution for PAM and SDK upsells.

What critics are saying

  • July 2026 TS-2026-009 SSH root bug damaged trust in Tailscale's security claims.
  • Border0 acquisition and Aperture sprawl into new categories, risking dilution against Okta and Zscaler.
  • Open-source Tailcat can commoditize Tailscale's core networking moat if adoption shifts downstream.

What makes Tailscale unique

  • Identity-based networking unifies VPN, DNS, PAM, and AI controls on one policy plane.
  • WireGuard plus peer-to-peer routing keeps connections direct, low-latency, and easier than legacy VPNs.
  • Tailscale spans laptops, servers, Kubernetes, and AI agents with the same identity model.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Flexible Work Hours

Remote Work Options

Unlimited Paid Time Off

Parental Leave

Professional Development Budget

Home Office Stipend

Phone/Internet Stipend

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
The IT Infrastructure Report
Aug 31st, 2026
Tailscale expands from VPN into full connectivity platform.

Tailscale expands from VPN into full connectivity platform. Application Infrastructure August 31, 2026 Highlights. * Tailscale is expanding beyond its original VPN product with new services introduced at its Tailscale Up conference. * The new offerings include DNS Filtering by Control D, Tailscale PAM, Aperture, Aperture Plus, Tailcat, and developer APIs and SDKs. * Tailscale said its identity-based access model now supports services for DNS control, privileged access, AI agents, and software development. Tailscale, which began in 2019 as a VPN provider based on open-source WireGuard technology, is moving beyond its original VPN pitch with a series of new products. The company raised $160 million last year to expand its WireGuard-based VPN platform and used its Tailscale Up conference last week to introduce new services built on identity-based access. Tailscale ties access to a device or user identity rather than to an IP address and applies policy based on that identity to determine what can be reached. The company said that model now underpins a broader set of tools, including DNS Filtering by Control D, Tailscale PAM, Aperture, Aperture Plus, Tailcat, and developer APIs and SDKs. DNS Filtering by Control D is sold and managed through existing Tailscale policy to block malicious and unapproved destinations. Tailscale PAM, now in beta, adds credential injection and just-in-time access for sensitive infrastructure. The company said it acquired Border0 in March 2026, and that Tailscale PAM lets teams grant one-click access to servers, databases, Kubernetes clusters, and web applications without handing out standing passwords or API keys. Aperture is Tailscale's AI gateway and reached general availability at the event. It gives AI agents an identity on a tailnet and routes their model calls and tool use through Tailscale's private network rather than the open internet. Aperture Plus extends the same access model into a browser, works without installing Tailscale as a system-level VPN, and isolates each session. Tailscale also introduced SDKs for Rust, Python, C, C++ and Elixir, along with a Tailnet Creation API and declarative tailnet sharing. company spotlight SoftIron. SoftIron makes the products that underpin the next evolution of IT infrastructure. Its blueprint is radical. Taking full control over design and manufacture of platforms optimised to transform IT infrastructure, its highly integrated products reduce space and energy footprints while delivering extraordinary performance. Challenging traditional IT manufacturing & organisational strategy, IT Infrastructure has developed a model that enables IT Infrastructure to create a more resilient and connected business for the customers IT Infrastructure serve. A commitment to openness, transparency, and simplicity helps address emerging multi-faceted threats while eliminating the vendor "lock-in" so common elsewhere.

Control D
Aug 28th, 2026
Control D is now available through Tailscale.

Control D is now available through Tailscale. Buy Control D directly through Tailscale and filter every device on your tailnet, with different policies by user, group, or tag. Control D can now be purchased directly through Tailscale. Point your tailnet at Control D and every device on it is filtered, with different policies for users, groups, and tags. Teams have been running Control D natively on their tailnets for some years now. While Tailscale connects your devices into a private network and controls what they can reach inside it, Control D handles the other half, providing controls and filters for access to the public internet. Running both meant managing two separate vendors and invoices. Today ControlD Inc is proud to make it official and partner with Tailscale. You can now buy Control D directly through them, and run it across every device on your tailnet from a single vendor. How the partnership works. In Control D, a Profile is the set of rules you want enforced, and an Endpoint is a resolver that enforces one. Every Endpoint has a Resolver ID. Add Control D as a nameserver in the Tailscale admin console, paste the resolver ID in, switch on Override DNS servers, and every device on your tailnet resolves through it, with nothing to install and no network changes. Its docs cover the details. What's new is the commercial side. Tailscale's team handles your day-to-day support, and ours behind them on anything deeper. Policy management stays where it is, in your Control D Dashboard and API. What Control D adds to your tailnet. Threats stopped at the resolver. Control D checks every query against curated threat feeds, then against the domains and IPs those campaigns are built on, so infrastructure caught once stays caught when it resurfaces under a new name. Unknown domains are scored by machine learning and blocked if they look high risk. Control D has consistently ranked first in independent malware filter tests, most recently with a 99.98% block rate. Beyond malware and phishing, 20+ native content categories and over 1,000 services and apps can each be allowed, blocked, or redirected individually for granular policy control. Policies that follow your tailnet. Different parts of your tailnet can enforce different rules. In your tailnet policy file, nodeAttrs maps users, groups, or tags to a Control D Endpoint, so filtering inherits the structure you already built for network access. Tag a machine and its policy follows, without enrolling each device in Control D separately. Where a device inherits more than one tag, priority values decide which one wins. This shares only device hostnames with Control D, and you control how much query data is kept. More than one tailnet. Plenty of teams run several, whether that is production and staging, one per subsidiary, one per department/team, or one per client if you are an MSP. Organizations and Sub-Organizations give each its own policy scope, Shared Profiles push a common baseline across all of them, and delegated administration lets whoever runs one manage it without touching the others. Getting started. Already using Tailscale? Talk to the Tailscale sales team about adding Control D to your plan.

ASCII
Aug 28th, 2026
Tailscale Open sources Tailcat, WireGuard netcat alternative.

Tailscale Open sources Tailcat, WireGuard netcat alternative. 1h ago Open Source Tl;dr. Tailscale releases Tailcat, a userspace tool combining WireGuard encryption and NAT traversal without requiring Tailscale's control plane, enabling encrypted peer-to-peer connections via simple token exchange. Key points. * Tailcat reuses Tailscale's magicsock (NAT traversal), userspace WireGuard, and gVisor netstack without requiring control plane or root access * Connection tokens encode server's WireGuard key and DERP relay info; clients bootstrap through DERP, upgrade to direct P2P UDP when possible

TechDay
Aug 26th, 2026
Tailscale launches DNS filtering add-on with Control D.

Tailscale launches DNS filtering add-on with Control D. Thu, 27th Aug 2026 (Today) Tailscale has launched a DNS filtering add-on for business customers in partnership with Control D. The product is called DNS Filtering by Control D. The add-on lets organisations block malicious, phishing and unwanted domains across users and devices, while applying different filtering profiles through Tailscale policy. Customers can buy the service through Tailscale instead of managing a separate purchasing process. The launch expands the companies' existing relationship and targets a growing security concern for distributed workforces. DNS filtering works when a device requests the address of an internet destination, giving administrators a way to block access before a connection is established. The issue has grown more important as staff connect from home networks, public networks and mobile devices rather than only through office infrastructure. The companies also pointed to automated workloads and AI agents as another area where organisations want tighter control over which outside destinations systems can reach. The Anti-Phishing Working Group recorded more than 970,000 phishing attacks in the first quarter of 2026, up 14% from the previous quarter, according to figures cited by the companies. They also pointed to recent attacks in which compromised home and small-office routers were used to hijack DNS requests. How It Works Organisations can create filtering policies in Control D and assign them through Tailscale policy based on user groups, tags and device attributes. A company could apply one rule set to employees, another to contractors and another to tagged machines running automated tasks. The filtering follows devices connected through Tailscale rather than relying on traffic passing through a central office network. DNS queries are sent directly from the device to Control D using DNS-over-HTTPS, an encrypted method for handling requests. Customers continue to manage blocklists, category filters, exceptions and DNS activity through the Control D dashboard. Organisations that already buy Control D separately can continue using the existing integration. Tailscale placed particular emphasis on DNS controls for AI systems that can browse the web, call application programming interfaces or download software without direct human action. In that setting, administrators may want to limit external destinations for the same reasons they do for employees. "AI agents are just another thing on the network, except they can make a lot of decisions very quickly," said Avery Pennarun, Co-founder and CEO, Tailscale. "If they can browse the web, call APIs, or download software, you need clear limits on where they can go. Tailscale provides the identity and policy context, and Control D can stop connections to known malicious or unapproved domains before they start. That gives organizations a practical guardrail for both people and agents without inspecting the contents of encrypted traffic." Control D said the combined approach brings identity and network policy together in one framework for customers already using Tailscale to manage access. "Tailscale already knows who a user or agent is, what device they're using, and what policy applies to them. Control D is really good at deciding which destinations should and shouldn't be reachable. Putting those together means customers don't have to maintain two separate policy worlds. The same identity that decides what you can connect to can also help decide where you're allowed to connect," said Catt Garrod, COO, Control D. Market Position Tailscale said it is used by more than 30,000 businesses globally, including large technology groups and media companies. Founded in 2019, the company focuses on private network access and identity-based controls built around WireGuard. Control D was spun out of Windscribe in 2021 and is based in Toronto. It sells DNS filtering and security tools to businesses, schools and managed service providers, and said its platform applies policies across major operating systems. The new add-on is available to existing Tailscale business customers through their account teams. Organisations new to Tailscale can register interest to be contacted.

Daily AI Tools
Jul 14th, 2026
TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access.

TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access. By jervant Tuesday, July 14, 2026 Hacker News Front Page Tailscale has patched a critical vulnerability in its SSH implementation where insecure argument handling allowed authenticated users to gain unauthorized root access. This underscores a rare lapse in the company's "zero trust" architecture; the bug effectively bypassed intended permission layers, highlighting that eve Hacker News Front Page