9 часов назад
Endpoint Engineer (Linux)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Endpoint Engineer (Linux): Building and hardening the Linux sensor at the core of an EDR platform, covering kernel and user-mode components, eBPF, LSM, audit telemetry, detection, and prevention with an accent on endpoint security, performance, and high-fidelity intent signals. Focus on designing tamper-resistant agents, processing thousands of events per second, validating detection efficacy through automated testing, and resolving OS-level customer escalations.
Location: Remote across North America; positions are also available in the San Francisco office.
Company
develops an intent-aware workspace security platform that protects human and AI-driven work, with an EDR capability used by Global 2000 customers.
What you will do
- Design, build, and ship kernel- and user-mode components of the Linux Ent agent.
- Develop EDR detection and prevention through sensor instrumentation, event enrichment, correlation, and interception logic.
- Instrument Linux telemetry using eBPF, LSM, and audit subsystems across workstations, servers, containers, and cloud workloads.
- Harden the agent against tampering, bypass, evasion, unsafe input, and integrity failures.
- Keep CPU, memory, and I/O usage within strict budgets while processing thousands of events per second.
- Build automated regression coverage, resolve high-severity customer escalations, and collaborate with security research, AI, platform, and product teams.
Requirements
- 10+ years designing, building, and delivering production C/C++ or Rust systems software, including substantial endpoint security, OS internals, or performance-critical native code experience.
- Deep knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
- Hands-on production experience with eBPF and experience building or operating EDR, EPP, XDR, AV, or equivalent detection-and-response products.
- Strong knowledge of attacker TTPs, low-level debugging, performance tracing, crash-dump analysis, and concurrent programming under load.
- Experience operating software across large fleets while maintaining stability and end-user performance.
- Fluency in Python or equivalent scripting for tooling and test automation, plus clear written and verbal communication.
Nice to have
- Production-scale kernel-mode driver or kernel extension development.
- Reverse engineering, malware analysis, exploit research, or vulnerability research experience.
- Experience with anti-tamper mechanisms and code integrity.
Culture & Benefits
- Distributed workplace with remote hiring across North America and office positions in San Francisco.
- Meaningful equity in addition to salary.
- Ent pays 90% of medical, dental, and vision coverage and 75% for dependents.
- Flexible PTO, paid parental leave, and a $100 monthly lifestyle account.
- $500 home office stipend for remote employees.
- Inclusive workplace with reasonable accommodations throughout the hiring process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Security Engineer, Corporate Security (Cybersecurity)
130 950 - 202 125$
3 часа назад
Staff Security Engineer (Cybersecurity)
20 часов назад
Embedded Cybersecurity Engineer
124 000 - 170 500$
1 день назад
Research Engineer I - Python & Security (Cybersecurity)
2 дня назад
Senior Detection and Response Platform Engineer
2 дня назад
Senior Security Engineer (Enterprise Security)
162 000 - 260 000$