Build CenseCloud with us.
We're a small, opinionated team building the platform that finally makes SaaS governance and cost intelligence one decision. Honest about where we are. Direct about what we're looking for.
Honest about what we're building, opinionated about how.
We're not a marketplace integrator. We don't sit in your data path. We took a position on architecture and we ship from it. Working here is closer to working on a product than working on a tool.
Product over portfolio
One platform, two modules. No SKU sprawl, no land-and-expand theatre. CenseRisk and CenseCost share one inventory because that's how the buyer's problem actually sits.
Endpoint-first, by conviction
We observe from the endpoint up. Browser extension + agent + IdP signals. We don't proxy. We don't MITM. The architecture is the answer to a real question, not a feature list.
Compliance as a layer, not a bolt-on
KVKK is a dedicated risk layer in the engine, not a checkbox on a brochure. Same for ISO 27001 and NIST CSF. Reports come from one inventory.
Skill categories, not job postings.
We don't post fictional openings to look bigger than we are. Below are the skill categories where strong people consistently change the trajectory of what we ship. If you fit one — talk to us.
Backend & data platform
Node.js, SQLite at scale, migration design, identity graph correlation. The engine that turns four signal sources into one inventory lives here.
Endpoint & browser
Windows MSI engineering, MV3 browser extensions, low-overhead telemetry. The signal source the whole platform sits on top of.
Security & compliance research
SSPM, OAuth-consent risk, KVKK / ISO 27001 / NIST CSF mapping. You translate framework requirements into product-grade controls.
Product & design
Premium B2B SaaS interfaces. CISO and CFO are different readers; the same data should serve both without losing depth or losing speed.
A small team, opinionated defaults.
- Direct ownershipWhoever picks up a problem ships it end-to-end. No handoff theatre. No layers between engineering and the customer.
- Ground-truth over claimsSpecific numbers in marketing or product copy require a path back to the codebase. We don't invent timelines or industry averages.
- Boundaries we keepWe don't sit in the data path. We don't read content. The architecture is a deliberate choice — and it shapes hiring as much as engineering.
- Bilingual by defaultTurkish + English in the same product. We write release notes, customer comms and even internal docs in both, when it matters.
- Premium without excessToken-based design system, line-icons, opinionated whitespace. We ship one premium thing well, not three average things in parallel.
- No marketplace fictionIf we can't honestly say something is GA, we don't badge it GA. Same goes for customer counts, certifications, integration depth.
No open postings today.
We're not currently running a posting funnel — small team, careful additions. But if your background fits one of the categories above, write to us. We read every message, and conversations sometimes turn into roles before they turn into postings.
- A short note on which skill category you fit and why now.
- Links — GitHub, portfolio, a piece of writing, a product you shipped. One link is enough if it's the right one.
- What you'd want the first 90 days to look like. We pay attention to this.
