Opens an external site
- Employment type
- Full-time
- Experience level
- Mid-level · 2+ years
- Posting language
- English
- Working hours
- 40 hours per week
- Location requirements
- Country, Japan
- Application method
- Direct apply is available
Job summary
The role involves designing, building, and shipping new features for the Ennote CLI and developing future Go-based developer tools. You will also implement client-side cryptographic flows and maintain gRPC communication with the backend.
Job details
About Ennote Ennote Security is the identity-driven secret manager unifying human collaboration and machine automation. Our platform centralizes governance for passwords, environment variables, API keys, and infrastructure certificates - replacing scattered .env files and legacy vaults with a single, hardware-backed source of truth. Ennote is live in production and used by engineering teams to manage secrets, with real-time sync, native SSO/RBAC, and immutable audit logging. Our architecture is built on a strict zero-persistence principle: plaintext secrets are never written to disk. Every credential is encrypted client-side using AES-256-GCM, encapsulated with Kyber-1024 (NIST post-quantum), and decapsulated only transiently in volatile memory inside a hardware-backed enclave before being re-wrapped for the requesting identity via ephemeral X25519/ECDH key agreement. We're building toward SOC 2 Type II and ISO 27001 certification, and we're growing our customer base among engineering teams who depend on us to protect their most sensitive infrastructure credentials. The Role The Ennote CLI is the primary way our customers actually touch the product - it's where developers pull secrets, sync environments, and interact with our client-side encryption on a daily basis. We're hiring a Go Developer to own and grow the CLI, and to build out future Go-based tooling as the product expands. This is a hands-on engineering role, not a maintenance job. You'll be building new CLI functionality, implementing client-side cryptographic flows correctly, and making sure the tools feel fast, reliable, and trustworthy to engineers who are using them to handle sensitive credentials every day. Responsibilities CLI development: Design, build, and ship new features for the Ennote CLI - the primary interface our customers use to interact with the platform. Future Go tooling: Design and build new Go-based tools beyond the CLI as our product surface grows. Client-side cryptography: Implement and maintain the client-side encryption flow - AES-256-GCM data encryption, Kyber-1024 key encapsulation, and X25519/ECDH-based identity and session key derivation with correctness as the top priority. gRPC integration: Build and maintain the CLI's gRPC communication with our backend. Reliability and UX: Treat CLI ergonomics as a first-class concern - clear error messages, sane defaults, and predictable behavior across platforms. Cross-functional collaboration: Work with the rest of engineering on protocol and API design decisions that affect client tooling, and with security on hardening the client against adversarial testing. Testing and tooling: Build strong test coverage around a security-sensitive codebase where correctness really matters. What We're Looking For Strong hands-on Go experience, ideally building CLI tools or developer-facing tooling. Working knowledge of gRPC - designing, consuming, or debugging gRPC services and streams. Solid understanding of applied cryptography fundamentals - symmetric/asymmetric encryption, key encapsulation mechanisms (KEMs), and ECDH-style key agreement. Direct experience with post-quantum primitives (e.g. Kyber/CRYSTALS-Kyber) is a strong plus, not a requirement. You care about the small details that make a CLI genuinely pleasant to use, not just functional. Comfortable working in a small team where you'll own real chunks of the product, not just tickets. Compensation (equity-only) Ennote is a live product with paying customers, currently closing our seed round. Until that round closes, this role is equity-only - no salary. We're offering a meaningful equity stake because this function is core to the product our customers use every day, and we want the person building it to have real ownership in what they're building. Once we close funding or reach sustainable revenue, our plan is to move this role to a paid position.
What you’ll do
The role involves designing, building, and shipping new features for the Ennote CLI and developing future Go-based developer tools. You will also implement client-side cryptographic flows and maintain gRPC communication with the backend.
Requirements
Candidates must have strong hands-on experience with Go and a working knowledge of gRPC. A solid understanding of applied cryptography fundamentals, such as symmetric/asymmetric encryption and key encapsulation, is required.
Benefits
- Equity
Listed skills
- Flows · Preferred
- Collaboration · Preferred
- Teams · Preferred
- Client · Preferred
- Communication · Preferred
- Development · Preferred
- future · Preferred
- Audit · Preferred
- Integration · Preferred
- Customer · Preferred
- Shipping · Preferred
- Cross-Functional Collaboration · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Go
- CLI Development
- gRPC
- Applied Cryptography
- AES-256-GCM
- Kyber-1024
- X25519
- ECDH
- Post-quantum Cryptography
- Software Testing
- API Design
- Security Engineering
Job areas
- Software
- Engineering
- Security & Safety
- Technology
More jobs from Ennote Security
Fundraising & Grants Advisor
- Remote
- Canada
- Posted Jul 22, 2026
Security Engineer
- Remote
- Canada
- Posted Jul 21, 2026
