Назад
Company hidden
9 часов назад

Endpoint Engineer (Linux)

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Endpoint Engineer (Linux): Building and hardening the Linux sensor at the core of an EDR platform, covering kernel and user-mode components, eBPF, LSM, audit telemetry, detection, and prevention with an accent on endpoint security, performance, and high-fidelity intent signals. Focus on designing tamper-resistant agents, processing thousands of events per second, validating detection efficacy through automated testing, and resolving OS-level customer escalations.

Location: Remote across North America; positions are also available in the San Francisco office.

Company

hirify.global develops an intent-aware workspace security platform that protects human and AI-driven work, with an EDR capability used by Global 2000 customers.

What you will do

  • Design, build, and ship kernel- and user-mode components of the Linux Ent agent.
  • Develop EDR detection and prevention through sensor instrumentation, event enrichment, correlation, and interception logic.
  • Instrument Linux telemetry using eBPF, LSM, and audit subsystems across workstations, servers, containers, and cloud workloads.
  • Harden the agent against tampering, bypass, evasion, unsafe input, and integrity failures.
  • Keep CPU, memory, and I/O usage within strict budgets while processing thousands of events per second.
  • Build automated regression coverage, resolve high-severity customer escalations, and collaborate with security research, AI, platform, and product teams.

Requirements

  • 10+ years designing, building, and delivering production C/C++ or Rust systems software, including substantial endpoint security, OS internals, or performance-critical native code experience.
  • Deep knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
  • Hands-on production experience with eBPF and experience building or operating EDR, EPP, XDR, AV, or equivalent detection-and-response products.
  • Strong knowledge of attacker TTPs, low-level debugging, performance tracing, crash-dump analysis, and concurrent programming under load.
  • Experience operating software across large fleets while maintaining stability and end-user performance.
  • Fluency in Python or equivalent scripting for tooling and test automation, plus clear written and verbal communication.

Nice to have

  • Production-scale kernel-mode driver or kernel extension development.
  • Reverse engineering, malware analysis, exploit research, or vulnerability research experience.
  • Experience with anti-tamper mechanisms and code integrity.

Culture & Benefits

  • Distributed workplace with remote hiring across North America and office positions in San Francisco.
  • Meaningful equity in addition to salary.
  • Ent pays 90% of medical, dental, and vision coverage and 75% for dependents.
  • Flexible PTO, paid parental leave, and a $100 monthly lifestyle account.
  • $500 home office stipend for remote employees.
  • Inclusive workplace with reasonable accommodations throughout the hiring process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →