Назад
Company hidden
9 часов назад

Endpoint Engineer, EDR (macOS)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Endpoint Engineer, EDR (macOS) (Swift/C++/macOS Security): Design and ship privileged daemons, per-user agents, and system extensions that capture endpoint activity and enforce EDR-class detection and prevention with an accent on macOS internals, low-level telemetry, and tamper resistance. Focus on building multi-process sensor architecture, processing thousands of events per second under strict deadlines, and integrating signals with on-device ML, policy enforcement, and investigation timelines.

Location: Remote across North America; positions are also available in the San Francisco office.

Company

hirify.global builds an intent-aware workspace security platform that protects human- and AI-driven work by detecting and preventing risks before incidents occur.

What you will do

  • Design, build, and ship macOS privileged daemons, per-user agents, and system extensions that observe process, file, network, device, and user-interaction activity.
  • Own EDR detection and prevention end to end, including Endpoint Security instrumentation, event enrichment, on-box correlation, rule evaluation, and interception logic.
  • Build and maintain multi-process architecture using launchd, XPC, code-signing-based peer authentication, and safe handling of untrusted input in privileged processes.
  • Harden the agent against tampering, bypass, and evasion while maintaining strict CPU, memory, I/O, and event-processing budgets.
  • Create VM-based end-to-end test harnesses, automated regression coverage, and permanent fixes for customer escalations involving crashes, hangs, performance, detection, permissions, and deployment.
  • Partner with security research, AI, platform, and product teams to connect sensor signals with on-device ML classification, policy enforcement, interventions, and investigation timelines; review code, mentor engineers, and support release quality and on-call.

Requirements

  • 10+ years designing and delivering production native systems software using Swift, C, C++, or Objective-C, including substantial endpoint security, OS internals, or performance-critical experience.
  • Strong current Swift experience, including actors, Sendable, structured concurrency, and concurrent programming under load.
  • Deep knowledge of macOS internals, including process and thread lifecycle, memory management, file systems, code signing, entitlements, launchd, XPC, Mach primitives, and TCC.
  • Production experience with Endpoint Security and/or Network Extensions, plus understanding of the system extension lifecycle.
  • Experience building or operating EDR, EPP, XDR, DLP, insider-risk, or equivalent detection-and-response products, with practical knowledge of attacker TTPs.
  • Strong low-level debugging, performance tracing, scripting, enterprise deployment, MDM, notarization, staged rollout, and auto-update experience.

Nice to have

  • Reverse engineering, malware analysis, or exploit and vulnerability research experience.
  • Experience shipping on-device ML inference with Core ML, ONNX Runtime, or similar runtimes.
  • Browser extension or native-messaging integration experience.
  • Cross-platform endpoint agent experience on Windows or Linux.

Culture & Benefits

  • Distributed workplace with remote hiring across North America and an optional San Francisco office.
  • Meaningful equity in addition to salary.
  • Medical, dental, and vision coverage with 90% paid for employees and 75% for dependents.
  • Flexible PTO, paid parental leave, and a $100 monthly lifestyle account.
  • $500 home office stipend for remote employees.
  • Inclusive workplace with reasonable accommodations available throughout the hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →