Skip to main content
BeyondTrust

Staff Software Development Engineer - Windows Endpoint

RemoteCanada, United States only
Published
Role
Backend
Experience
Staff
Salary not disclosed
Check eligibility

Open to CA, US only. Set where you work from to check your eligibility.

No BS summary

Staff-level Windows kernel engineer with 8+ years in systems software and deep production driver experience in C, C++, or Rust. Must own kernel-mode security enforcement for Windows endpoints, including minifilters/callback drivers, signing/deployment, debugging, performance, and Windows isolation. Remote role hiring in Canada or the United States; AI-first development workflow is required.

Core skills

Windows kernel internalsKernel-mode driver developmentWindows containers

Required skills

C/C++/RustFile-system minifilter/Callback-based driverIRQLSynchronizationUser-buffer accessDriver signingWHQL attestationEV code signingWDKWDFKMDFJob objectsSilosAppContainerWinDbgKDCrash-dump analysisETWDriver VerifierClaude Code

What you'll do

  • Design, build, and own kernel-mode enforcement drivers for file-system, process and thread creation, handle operations, and registry access.
  • Block operations inline in the kernel rather than logging them after the fact.
  • Build the userspace agent that installs and drives the kernel-mode enforcement drivers.
  • Own the kernel/user-mode enforcement boundary, including kernel-side event capture, policy evaluation in user mode, and deny decisions pushed back into the driver as hash-keyed caches.
  • Drive down enforce-mode latency on the operation hot path as the platform scales across large fleets.
  • Handle process enrichment, image-hash caching and eviction under heavy process-churn, and process-ancestry resolution across PPID spoofing.
  • Extend enforcement into Windows containers and Host Compute Service workloads.
  • Build silo- and job-object-aware policy and container identity on kernel events.
  • Harden portability and stability across Windows builds so enforcement loads and behaves correctly on customer versions.
  • Handle structure-versioning across Windows releases, PatchGuard constraints, Driver Verifier and HVCI compliance, WHQL attestation signing, and graceful degradation when capabilities are unavailable.
  • Partner with Linux and macOS enforcement engineers and the policy-backend team on policy semantics, cross-stack conformance, event schema, and the common Rust agent.
  • Represent Windows in cross-org architecture reviews.
  • Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders.
  • Raise the engineering bar through end-to-end ownership from design through production.
  • Carry extra weight where kernel bugs can mean wrong security decisions or bugchecks across the fleet.
  • Mentor senior and mid-level engineers on Windows systems and kernel-driver craft.

What they require

  • Deep Windows kernel internals knowledge, including the I/O manager and IRP flow, object manager, process and thread structures, memory management, and the Windows security model with tokens, SIDs, and ACLs.
  • Production kernel-mode driver development in C, C++, or Rust.
  • Hands-on kernel-mode driver work for security enforcement.
  • Shipped a file-system minifilter or comparable callback-based driver.
  • Ability to reason about IRQL, synchronization, safe user-buffer access, and reentrancy in the kernel.
  • Ability to keep a driver off the crash path when a dependency misbehaves.
  • Driver signing and deployment experience, including WHQL attestation, EV code signing, WDK, WDF/KMDF, and the operational cost of shipping kernel code to a large install base.
  • Knowledge of the Windows isolation model, including job objects, silos, Windows containers, AppContainer, and how it intersects with kernel-level security tooling.
  • Kernel debugging and performance tooling experience, including WinDbg and KD, live-kernel and crash-dump analysis, ETW, Driver Verifier, and the checked-build workflow.
  • 8+ years in systems-level software engineering, with real depth in Windows kernel development.
  • Demonstrated AI-first development.
  • Experience using agentic tooling for AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates.
  • Use Claude Code or a comparable tool as a core part of daily workflow.
  • Ability to explain concretely how AI tooling raises velocity and rigor.
  • Judgment to know when to stop and verify by hand in correctness- and security-critical kernel code.
  • Working grasp of systems design patterns and their tradeoffs at the kernel/user-mode boundary.
  • Full-lifecycle experience, including product release, in an agile environment.
  • Track record of technical leadership on complex, ambiguous initiatives that span teams.
  • Shares successes and failures openly and works well with people.
  • Adapts when the situation and requirements shift.
  • Fixes issues before they are assigned and stays persistent through roadblocks, pulling in others when needed.
  • Holds a high bar and pushes teams to ship reliable systems, especially where kernel bugs carry outsized risk.
  • Knows systems software best practices, from rigorous testing to sharp peer review to architecture that survives contact with production.
  • Uses AI tools to move faster and think more clearly while keeping the judgment to slow down and verify by hand when code demands it.
  • Weighs speed against risk and decides from data.
  • Understands the weight of enforcement code and prefers shipping a correct block late over a wrong one now.
  • Chooses failure modes, fail-open or fail-closed, intentionally.

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Its identity-centric cybersecurity SaaS portfolio helps organizations manage the identity attack surface and neutralize threats from external attacks or insiders.

CybersecurityEnterprisebeyondtrust.com/

Details

Apply routeGreenhouse
Salary not disclosed