Remote job
Endpoint Engineer, EDR (macOS)
Job details
About this role
Role overview
Design and ship the privileged daemon, per-user agents, and system extensions that form the macOS endpoint sensor for an intent-aware EDR capability. This role owns EDR-class detection and prevention end to end — instrumentation through the Endpoint Security framework, Network Extensions, FSEvents, and IOKit, plus the interception logic that stops malicious or policy-violating activity before it completes.
Responsibilities
- Build the privileged daemon, per-user agents, and system extensions that observe process, file, network, device, and user-interaction activity and turn it into intent signals. - Own EDR-class detection and prevention end to end: sensor instrumentation, event enrichment, on-box correlation, rule evaluation, and interception logic including Endpoint Security AUTH decisions and network flow filtering. - Instrument telemetry at the OS boundary using Endpoint Security, Network Extensions (NEFilterDataProvider), FSEvents, IOKit, and event taps. - Design and maintain the multi-process architecture: launchd-managed daemon and agents, XPC protocols, code-signing-based peer authentication, and safe handling of untrusted input inside a privileged process. - Harden the agent against tamper, bypass, and evasion using self-protection, integrity validation, and update-chain security. - Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second against hard real-time constraints. - Drive high-severity customer escalations to root cause at the code and OS-internals level and convert patterns into permanent fixes.
Requirements
- 10+ years designing, building, and delivering production C/C++ or Swift systems software, a substantial portion in endpoint security, OS internals, or comparable performance-critical native code. - Deep working knowledge of macOS internals, including the Endpoint Security framework, Network Extensions, FSEvents, and IOKit. - Demonstrated experience building or operating an EDR, EPP, XDR, or AV product. - Practical fluency in attacker TTPs and ability to reason about attacks in raw telemetry. - Strong low-level debugging skills, performance tracing, and crash-dump analysis. - Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, actor isolation, and object lifetime management. - Track record of code running on large fleets without degrading user experience; familiarity with enterprise deployment realities including MDM profiles, notarization, staged rollout, and auto-update. - Scripting fluency in Python, shell, or equivalent.
Nice to have
- Reverse engineering, malware analysis, or exploit and vulnerability research background. - Experience shipping on-device ML inference (Core ML, ONNX Runtime, llama.cpp-class runtimes) inside a resource-constrained agent. - Experience with browser extension or native-messaging integrations for telemetry capture. - Cross-platform endpoint agent experience with Windows or Linux sensors alongside macOS.
Benefits and work setup
- Distributed workplace with remote hiring across North America and a San Francisco office option. - Meaningful equity on top of salary. - 90% employer coverage of medical, dental, and vision premiums; 75% for dependents. - Flexible PTO, 12 weeks paid parental leave for birth, adoption, or foster placements, and a $100 monthly lifestyle account. - $500 home office stipend for remote hires.