BeyondTrust Logo

BeyondTrust

Staff Software Development Engineer - Windows Endpoint

Reposted One Month Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Own design, implementation, and production support of Windows kernel-mode enforcement drivers (filesystem, process/thread, handles, registry) and the kernel/user-mode enforcement boundary. Reduce enforcement latency at scale, extend enforcement to containers and isolation, ensure compatibility across Windows builds, handle driver signing and deployment, collaborate cross-platform on policy and the Rust userspace agent, and mentor engineers while driving technical direction and operational stability.
The summary above was generated by AI

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

The Role


As Staff Software Development Engineer, you'll be the Windows kernel authority for the runtime enforcement layer of our Identity Security Platform. These components decide, in-kernel, whether to permit or deny each action an identity or AI agent attempts on a Windows endpoint.

You'll set the technical direction for kernel-mode enforcement on Windows and own it end to end. That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads. Peer engineers own the macOS and Linux enforcement surfaces. You share one policy language, one event schema, and one userspace agent with them, but Windows kernel-space is yours.

You know this layer better than anyone. You want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.

What You’ll Do

  • Design, build, and own our kernel-mode enforcement drivers: file-system, process and thread creation, handle operations, and registry access. You'll block operations inline in the kernel rather than logging them after the fact, and you'll build the userspace agent that installs and drives them.
  • Own the kernel/user-mode enforcement boundary: kernel-side event capture, policy evaluation in user mode, and deny decisions pushed back into the driver as hash-keyed caches so subsequent hits block inline.
  • Drive down enforce-mode latency on the operation hot path as we scale across large fleets. That means process enrichment, image-hash caching and eviction under heavy process-churn, and process-ancestry resolution across PPID spoofing.
  • Extend enforcement into containers and isolation: Windows containers and Host Compute Service workloads, silo- and job-object-aware policy, and container identity on kernel events. Most of this is greenfield, and it sits at the center of the role.
  • Harden portability and stability across Windows builds so enforcement loads and behaves correctly on the versions customers actually run. You'll deal with structure-versioning across Windows releases, PatchGuard constraints, Driver Verifier and HVCI compliance, WHQL attestation signing, and graceful degradation when a capability isn't available.
  • Partner with the Linux and macOS enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, the common Rust agent. You'll represent Windows in cross-org architecture reviews.
  • Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders.
  • Raise the engineering bar. You'll take end-to-end ownership from design through production, and you'll carry extra weight where a kernel bug means a wrong security decision or a bugcheck across the fleet, not just a crash of one process.
  • Mentor senior and mid-level engineers on Windows systems and kernel-driver craft.

What You’ll Bring

This is a Windows specialist role, so the depth requirements are real:

  • Deep Windows kernel internals - the I/O manager and IRP flow, the object manager, process and thread structures, memory management, the Windows security model (tokens, SIDs, ACLs) - backed by production kernel-mode driver development in C, C++, or Rust.
  • Hands-on kernel-mode driver work for security enforcement. You've shipped a file-system minifilter or comparable callback-based driver, and you can reason about IRQL, synchronization, safe user-buffer access, and reentrancy in the kernel. You know how to keep a driver off the crash path when a dependency misbehaves.
  • Driver signing and deployment reality: WHQL attestation, EV code signing, the WDK and WDF/KMDF, and the operational cost of shipping kernel code to a large install base.
  • The Windows isolation model - job objects, silos, Windows containers, AppContainer - and how it intersects with kernel-level security tooling.
  • Kernel debugging and performance tooling: WinDbg and KD, live-kernel and crash-dump analysis, ETW, Driver Verifier, and the checked-build workflow.
  • 8+ years in systems-level software engineering, with real depth in Windows kernel development.
  • Demonstrated AI-first development. We build this platform through agentic tooling. AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates are how work ships here, not a side experiment. You use Claude Code or a comparable tool as a core part of your daily workflow, and you can speak concretely to how it raises both your velocity and your rigor. That matters most in correctness- and security-critical kernel code, where you have to know exactly when to stop and verify by hand.
  • A working grasp of systems design patterns and their tradeoffs at the kernel/user-mode boundary.
  • Full-lifecycle experience, including product release, in an agile environment.
  • A track record of technical leadership on complex, ambiguous initiatives that span teams.

Who You Are


  • You share successes and failures openly, and you work well with people. You adapt when the situation and the requirements shift. You fix issues before anyone assigns them to you, and you stay persistent through roadblocks, pulling in others when you need to.
  • You hold a high bar and push your teams to ship reliable systems, especially where a kernel bug carries outsized risk. You know systems software best practices, from rigorous testing to sharp peer review to architecture that survives contact with production.
  • You reach for AI tools to move faster and think more clearly, and you keep the judgment to slow down and verify by hand when the code demands it. You weigh speed against risk and decide from data.
  • You feel the weight of enforcement code. You'd rather ship a correct block a day late than a wrong one now, and you choose your failure modes - fail-open or fail-closed - on purpose instead of by accident.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
Learn more at www.beyondtrust.com.


Similar Jobs

37 Minutes Ago
Easy Apply
Remote
Easy Apply
Senior level
Senior level
Artificial Intelligence • Enterprise Web • Information Technology • Productivity • Sales • Software • Database
Design and implement scalable backend services, data pipelines, distributed integrations, and high-throughput infrastructure. Own projects across requirements, architecture, development, testing, deployment, observability, and maintenance. Collaborate cross-functionally, lead technical discussions, improve performance and automation, mentor teammates, and use AI tools throughout software development. Build highly available systems using modern databases, cloud infrastructure, messaging, monitoring, and containerization technologies.
Top Skills: AnsibleDockerElasticsearchGCPGithub ActionsGoGrafanaKafkaKibanaKubernetesMicroservicesMongoDBNoSQLPythonReactRedisRestful ServicesRuby On RailsSQLTerraformTypescript
44 Minutes Ago
Remote or Hybrid
Senior level
Senior level
Gaming • Information Technology • Mobile • Software • Esports
Lead a small engineering team while coding hands-on to extend Unreal Engine’s Gauntlet automation framework. Build test harnesses, input simulation, AI-driven test agents, telemetry, reporting, and scalable test infrastructure. Partner with studios and technical leaders, communicate risks and tradeoffs, manage the platform roadmap, and reduce technical debt. The role requires deep Unreal Engine and C++ expertise, engine-level testing experience, team leadership, and software telemetry or instrumentation experience.
Top Skills: C++GitPerforceUnreal EngineUnreal Engine GauntletUnreal Functional TestingUnreal Learning Agents
48 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
139K-235K Annually
Expert/Leader
139K-235K Annually
Expert/Leader
Cloud • Security • Software • Cybersecurity • Automation
Leads Professional Services operations by building scalable planning, forecasting, capacity, resource management, delivery, financial, and reporting processes. Partners with Finance, Sales, Customer Success, Engineering, and Delivery to improve PSA, CRM, time-tracking, automation, service pricing, revenue recognition, and go-to-market alignment. Provides leadership visibility into pipeline, staffing, utilization, project economics, margins, and growth while driving operational maturity across distributed services organizations.
Top Skills: Crm SystemsKantataProfessional Services Automation (Psa) PlatformsTime-Tracking Systems

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account