Full-Time

Senior Systems Engineer 2

Edge Platform & Packaging

Dispel

Dispel

51-200 employees

Zero-Trust remote access for OT security

Compensation Overview

$150k - $159k/yr

+ Performance bonus + Equity

Remote in USA

Remote

Remote within the United States, with 15–20% travel for on-premises purposes.

Category
DevOps & Infrastructure (1)
Required Skills
Kubernetes
Rust
Python
GitHub Actions
Computer Networking
Infrastructure as Code (IaC)
Go
Terraform
Observability
Ansible
C/C++
DevOps
Linux/Unix

Get referred to Dispel

See people who can refer or advise you

Requirements
  • At least 5 years of professional engineering experience shipping software that runs on infrastructure the organization does not operate.
  • Experience owning a release and update mechanism for deployed edge, appliance, embedded, or on-premises enterprise systems, including handling field failures.
  • Deep Linux systems fluency covering systemd, the boot and init path, filesystem and partition layout, kernel and package lifecycle, and distribution assembly.
  • Strong packaging and distribution experience with Debian/apt packaging, OCI images, image-based or A/B update schemes, or equivalent, including artifact signing and repository operation.
  • Proficiency in at least one systems-capable language: Go, Rust, Python, or C, with the ability to read code across packaged layers.
  • Experience using coding agents such as GitHub Copilot or Claude Code in daily workflow.
  • Proficiency with infrastructure as code, primarily Ansible and Terraform.
  • Container runtime and orchestration experience, including selecting appropriate approaches for constrained single nodes versus datacenters.
  • Infrastructure-as-code and continuous integration/continuous delivery experience with Terraform, GitHub Actions, or similar, including pipelines that produce release artifacts.
  • Solid network fundamentals covering routing, DNS, firewalls, and VPN concepts.
  • Ability to work with cross-team stakeholders to define requirements and deliver results with minimal oversight.
  • Willingness to accept failure and feedback, learn, and try again.
  • Passion for learning new disciplines and developing a deep understanding of how other team members work.
  • Ability to communicate clearly and succinctly in person and through team chat.
Responsibilities
  • Own the build and packaging pipeline for on-premises deliverables, including OS images, packages, container images, and installable release bundles.
  • Make on-premises builds reproducible and verifiable through pinned inputs, deterministic outputs, signed artifacts, and a software bill of materials for each release.
  • Design a versioning and compatibility model for interoperability among appliance versions, cloud-side components, and orchestration components.
  • Reduce bespoke, per-project packaging to a small number of supported paths.
  • Automate appliance provisioning so it is idempotent rather than a documented manual procedure.
  • Own the update mechanism end to end, including delivery, staging, application, verification, and rollback for constrained links, maintenance windows, and air-gapped appliances.
  • Design update failure handling so interrupted or bad updates leave the appliance in a known-good, recoverable state without a site visit.
  • Build fleet-level release control with staged rollouts, cohorts, canaries, version and drift visibility, and the ability to hold or reverse an active rollout.
  • Reduce and measure the interval between CVE publication and fleet patching.
  • Maintain update functionality across the operating-system baseline and kernel lifecycle, not only the application layer.
  • Extend the appliance runtime for local telemetry collection and preprocessing, buffering and store-and-forward, and local decisioning with reconciliation after connectivity returns.
  • Define the boundary between edge and cloud processing using evidence about bandwidth, latency, and customer data-residency constraints.
  • Manage appliance resource usage so network functions are not starved by added workloads.
  • Design local observability that enables support engineers to reconstruct appliance behavior without shell access.
  • Own the integrity of the on-premises supply chain, including signing keys, trust roots, artifact provenance, and audit readiness.
  • Build appliance-in-the-loop testing, CI upgrade and downgrade testing, and hardware or near-hardware validation before customer release.
  • Ensure on-premises systems meet performance, scalability, and security requirements where packaging and runtime choices affect the network data path.
  • Participate in incident response and root cause analysis, particularly for remote field failures with limited evidence.
  • Participate in an on-call rotation, including incident response and after-hours troubleshooting as needed.
  • Partner with field, support, and customer-facing engineering teams to identify and address operational friction.
  • Work with security and compliance teams to make on-premises releases evidence-producing by default.
  • Inform product and engineering leadership about edge capabilities and limitations early enough to influence plans.
  • Write runbooks, upgrade notes, and architecture documentation for engineers and field teams.
  • Mentor IC1 and IC2 engineers through code review, pairing, and technical context sharing.
  • Participate in evaluation portions of interview loops.
Desired Qualifications
  • Experience shipping into operational technology, industrial control systems, or industrial environments, including change-control and network-segmentation realities.
  • Experience with air-gapped or intermittently connected deployments, offline mirrors, and sneakernet update paths.
  • Background in security-focused products involving reliability and regulatory compliance, including IEC 62443, NERC CIP, FIPS-validated cryptography, or FedRAMP-adjacent work.
  • Supply-chain security experience with SLSA, in-toto, Sigstore, software bill of materials generation and consumption, and reproducible builds.
  • Experience with lightweight Kubernetes distributions or single-node edge orchestration, including K3s, MicroShift, or Talos.
  • Experience with image-based Linux and atomic update systems such as OSTree, Mender, RAUC, or SWUpdate.
  • On-premises virtualization, hardware bring-up, or hardware qualification experience.
  • Edge telemetry pipeline experience involving agent-based collection, buffering, and forwarding to customer security information and event management systems.
  • Experience building or operating commercial VPN, zero-trust network access, or secure remote-access products.

Dispel provides secure remote access to industrial control systems and operational technology using a Zero Trust framework. Its platform uses Moving Target Defense to continuously shift network configurations, eliminating static entry points and reducing exposure to threats. The company differentiates itself by building a dynamic, non-static OT network and by collaborating with other security vendors, backed by a large patent portfolio. Its goal is to protect critical infrastructure for manufacturers, utilities, and government entities with a scalable access control solution.

Company Size

51-200

Company Stage

Series A

Total Funding

$3M

Headquarters

New York City, New York

Founded

2014

Get referred to Dispel

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Dispel launched Armis integration on August 4, 2026, adding asset visibility to access.
  • Dispel appointed Benjamin Burke president on March 30, 2026, sharpening growth execution.
  • Dispel's 2026 releases target NERC CIP, IEC 62443, NIST, and NIS2 audit automation.

What critics are saying

  • Palo Alto, Cisco, and ServiceNow bundle remote access and identity, squeezing Dispel's pricing.
  • Air-gapped and regulated deployments lengthen sales cycles; Dispel's June 2026 on-prem launch signals necessity.
  • If compliance automation commoditizes, Dispel becomes a feature inside OT suites, not a standalone company.

What makes Dispel unique

  • Dispel's June 17, 2026 Site Console enables fully local OT remote access for air-gapped sites.
  • Dispel's May 14, 2026 Session Forensics scores identity, device, and connection in real time.
  • Dispel integrates Nozomi, Dragos, Armis, Forescout, and TXOne into access decisions.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Unlimited Paid Time Off

Flexible Work Hours

Remote Work Options

Paid Vacation

Paid Holidays

Company Equity

Performance Bonus

Parental Leave

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

4%

2 year growth

12%
Associated Press
May 14th, 2026
Dispel launches Session Forensics with real-time risk scoring for OT remote access to counter AI threats

Dispel, a secure remote access provider for operational technology, has launched Session Forensics with Dynamic Risk Scoring, a new capability that continuously evaluates remote access sessions in real time. The feature is now available as part of Dispel's Zero Trust Engine platform. Session Forensics assigns dynamic risk scores to every remote access session across three dimensions: identity, device and connection. The system monitors behavioural signals including multi-factor authentication levels, impossible travel, concurrent sessions and deviations from user baselines, presenting results through a green-yellow-red stoplight model. The capability also provides complete session provenance records, including authentication events and failed access attempts, designed to meet NERC CIP, IEC 62443 and NIST SP 800-82 compliance requirements. Founded in 2015, Dispel currently protects over $500 billion in manufactured goods annually.

PR Newswire
Apr 19th, 2023
Dispel Achieves Iso 27001 Information Security Certification

The World's Leading Industrial Secure Remote Access Provider Verifies its Standards and SystemsAUSTIN, Texas, April 19, 2023 /PRNewswire/ -- Dispel, the leading provider of zero trust secure remote access to industrial control systems, is pleased to announce it is a ISO/IEC 27001:2013 certified provider whose Information Security Management System (ISMS) received third-party accreditation from the International Standards Organization.This milestone reflects Dispel's ongoing commitment to maintaining the highest levels of security for its clients, while also reaffirming its position as a trusted leader in the field of operational technology cybersecurity.ISO 27001 certification is an internationally recognized standard for information security management, and achieving this certification requires a rigorous process of assessing and improving an organization's security practices. Dispel's successful certification is a testament to its dedication to protecting client data and ensuring the confidentiality, integrity, and availability of its systems."At Dispel, we understand that our clients rely on us to provide secure, reliable, and resilient remote access," said Ethan Schmertzler, CEO of Dispel. "Achieving our 2023 ISO 27001 underscores our ongoing commitment to supporting the industry's highest security standards and protecting operational technology."Dispel's innovative Moving Target Defense-based approach to securing remote access is designed to meet the specific needs of its clients across a wide range of industries, including discrete manufacturing, oil & gas, energy, food & beverage, and government.To learn more about Dispel's zero trust remote access platform and the company's commitment to protecting client data, visit https://dispel.com/security or contact a Dispel representative today.About DispelDispel, founded in 2015, is the world's leading remote access platform securing industrial control systems and critical infrastructure networks with Moving Target Defense providing global services for government, manufacturing and utilities. Designed, built and maintained in the United States with offices in New York, Austin, Washington D.C., and Tokyo, Dispel secures critical assets all over the world serving over 40 million people and partners. For more information, visit dispel.io.Media ContactRyann Checchi, Interdependence PR[email protected](708)420-4776SOURCE Dispel