Назад
Company hidden
9 часов назад

Endpoint Engineer (EDR)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Endpoint Engineer (EDR) (Windows security/C++): Designing and shipping kernel- and user-mode components for a Windows endpoint agent that observes system activity and produces high-fidelity intent signals, with an accent on EDR detection, prevention, and OS-level instrumentation. Focus on building tamper-resistant sensors, processing thousands of events per second within strict resource budgets, and diagnosing crashes, performance regressions, and missed detections at the operating-system level.

Location: Remote across North America; positions are also available in the San Francisco office.

Company

hirify.global develops an intent-aware workspace security platform that protects human- and AI-driven work by detecting and preventing risk at the moment it occurs.

What you will do

  • Design, build, and ship Windows kernel- and user-mode components for the Ent endpoint agent.
  • Develop EDR detection and prevention capabilities, including sensor instrumentation, event enrichment, on-box correlation, and interception logic.
  • Instrument process, file, registry, network, and identity activity using ETW, kernel callbacks, and minifilters.
  • Harden the agent against tampering, bypasses, and evasion while maintaining strict CPU, memory, and I/O budgets at high event volumes.
  • Build test harnesses and automated regression coverage, and resolve customer escalations involving crashes, hangs, performance regressions, and missed detections.
  • Partner with security research, AI, platform, and product teams; review code, mentor engineers, and share ownership of release quality and on-call.

Requirements

  • 10+ years of production C/C++ systems software development, including substantial experience in endpoint security, OS internals, or comparable performance-critical native code.
  • Deep knowledge of operating system internals, including process and thread lifecycles, memory management, file systems, drivers or kernel extensions, and IPC.
  • Production experience with kernel callbacks and minifilters, plus experience building or operating EDR, EPP, XDR, AV, or equivalent detection-and-response products.
  • Strong low-level debugging, performance tracing, crash-dump analysis, multithreaded programming, and concurrency skills.
  • Experience operating software across large customer fleets while maintaining stability and end-user performance.
  • Python or equivalent scripting skills for tooling and test automation, plus clear communication with distributed teams and customers.

Nice to have

  • Production-scale kernel-mode driver or kernel extension development.
  • Reverse engineering, malware analysis, exploit research, or vulnerability research experience.
  • Experience with anti-tamper mechanisms, code integrity, driver signing, or WHQL attestation.

Culture & Benefits

  • Distributed workplace with remote hiring across North America and positions in the San Francisco office.
  • Meaningful equity in addition to salary.
  • Ent pays 90% of medical, dental, and vision coverage and 75% of dependent coverage.
  • Flexible PTO, paid parental leave, and a $100 monthly lifestyle account.
  • $500 home office stipend for remote employees.
  • Inclusive workplace with reasonable accommodations available throughout the hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →