Remote job
Endpoint Engineer, EDR (Windows)
Job details
About this role
Role overview A senior engineering position focused on the Windows endpoint sensor layer of an intent-aware security platform. The work centers on kernel- and user-mode components that observe process, file, registry, network, and identity activity, then convert that telemetry into high-fidelity signals used for detection, prevention, and real-time policy enforcement. The role spans OS-boundary instrumentation, on-box correlation, hardening against tampering, and performance engineering under tight CPU, memory, and I/O budgets.
Responsibilities - Design, build, and ship kernel- and user-mode components that observe endpoint activity and translate it into structured signals for downstream detection and intervention systems. - Implement OS-level telemetry using ETW, kernel callbacks, and minifilters, then enrich and correlate events on the endpoint itself. - Develop interception logic that blocks malicious activity before completion, alongside sensor hardening for tamper resistance, integrity validation, and safe handling of untrusted input inside a privileged process. - Profile hot paths, hold CPU, memory, and I/O inside strict budgets at thousands of events per second, and prevent performance regressions from reaching production. - Build automated test harnesses and regression coverage so efficacy claims are continuously verified. - Drive high-severity customer escalations (crashes, hangs, missed detections, performance regressions) to root cause at the code and OS-internals level, and turn recurring patterns into permanent fixes. - Partner with security research, AI, platform, and product teams to feed sensor signals into policy enforcement and investigation workflows, while reviewing code and mentoring peers.
Requirements - 10+ years building production C/C++ systems software, with significant time spent in endpoint security, OS internals, or comparable performance-critical native code. - Deep knowledge of operating system internals including process and thread lifecycle, memory management, and the Windows kernel surface. - Practical fluency in attacker tactics, techniques, and procedures, with the ability to reason about attacks from raw telemetry rather than written reports alone. - Strong low-level debugging skills, performance tracing, and crash-dump analysis. - Hands-on experience with multi-threaded and concurrent programming under load, including synchronization, lock contention, race conditions, and object lifetime management. - A track record of stable code running on large fleets without degrading end-user experience. - Scripting fluency for tooling and test automation in Python or an equivalent language. - Clear written and verbal communication with distributed teams and, when needed, directly with customers during escalations.
Nice to have - Shipped kernel-mode driver or kernel extension development to production at scale. - Background in reverse engineering, malware analysis, or exploit and vulnerability research. - Experience with anti-tamper, code integrity, driver signing, and WHQL attestation.
Benefits and work setup - Distributed workplace with some positions based in a San Francisco office and others hired remotely across North America. - Meaningful equity on top of salary for every teammate. - Employer covers the majority of medical, dental, and vision premiums, with partial coverage available for dependents. - Flexible paid time off, 12 weeks of fully paid maternity leave for birth, adoption, or foster placements, and 8 weeks of fully paid paternity leave. - A monthly lifestyle stipend and a home office stipend for remote hires at onboarding. - Commitment to a diverse, inclusive, and equitable hiring process, with reasonable accommodations available on request.