Remote job
Endpoint Engineer, EDR (linux)
Job details
About this role
Role overview
Own the Linux sensor at the core of an EDR capability within an intent-aware workspace security platform. This senior role builds detection and prevention on eBPF, LSM, and the audit subsystem across workstations, servers, containers, and cloud workloads, owning the tradeoffs between detection efficacy, false positives, and performance with measured evidence.
Responsibilities
- Design, build, and ship kernel- and user-mode components of the agent that observe process, file, network, and identity activity for Linux and turn it into high-fidelity intent signals. - Own EDR-class detection and prevention end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes. - Instrument telemetry at the OS boundary using eBPF, LSM, and the audit subsystems. - Harden the agent against tamper, bypass, and evasion through self-protection, integrity validation, and safe handling of untrusted input inside a privileged process. - Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions. - Build test harnesses and automated regression coverage so every efficacy claim is continuously verified. - Drive high-severity customer escalations to root cause and convert recurring patterns into permanent fixes.
Requirements
- 10+ years designing, building, and delivering production C/C++ or Rust systems software, with substantial endpoint security, OS internals, or performance-critical native code experience. - Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC. - Hands-on production experience with eBPF. - Demonstrated experience building or operating an EDR, EPP, XDR, or AV product. - Practical fluency in attacker TTPs and ability to reason about attacks in raw telemetry. - Strong low-level debugging skills, performance tracing, and crash-dump analysis. - Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, and object lifetime management. - Scripting fluency for tooling and test automation in Python or equivalent.
Nice to have
- Kernel-mode driver or kernel extension development shipped to production at scale. - Reverse engineering, malware analysis, or exploit and vulnerability research background. - Experience with anti-tamper and code integrity.
Benefits and work setup
- Distributed workplace with remote hiring across North America and a San Francisco office option. - Meaningful equity on top of salary. - 90% employer coverage of medical, dental, and vision premiums; 75% for dependents. - Flexible PTO, 12 weeks paid parental leave for birth, adoption, or foster placements, and a $100 monthly lifestyle account. - $500 home office stipend for remote hires.