Staff Software Development Engineer – Linux Endpoint

BeyondTrust
Toronto, United States, Canada
Workplace: RemoteFull timeFunction: Design (Product/UX/UI/Visual)Experience: 8+ yearsSkills: ["Technical leadership","Mentoring","Collaboration","Risk-focused decision-making","Judgment with AI-assisted development"]

Own the Linux runtime enforcement layer of an identity security platform, making in-kernel allow/deny decisions for identity and AI agent actions. Set the technical direction for eBPF enforcement, build kernel/userspace enforcement boundaries, and optimize syscall hot-path latency. Extend policy enforcement into containers and namespaces (cgroups, namespaces, Kubernetes workloads) while hardening portability across Linux kernel versions. Mentor engineers and partner on cross-stack policy semantics.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BeyondTrust
BeyondTrust
1 month ago

Staff Software Development Engineer – Linux Endpoint

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Own the Linux runtime enforcement layer of an identity security platform, making in-kernel allow/deny decisions for identity and AI agent actions. Set the technical direction for eBPF enforcement, build kernel/userspace enforcement boundaries, and optimize syscall hot-path latency. Extend policy enforcement into containers and namespaces (cgroups, namespaces, Kubernetes workloads) while hardening portability across Linux kernel versions. Mentor engineers and partner on cross-stack policy semantics.
Location: Toronto, United States, Canada
Workplace: Remote
Employment Type: Full time
Job Function: Design (Product/UX/UI/Visual)
Seniority: Mid level

Key Responsibilities

  • •Design, build, and own eBPF programs and BPF LSM hooks to enforce policy synchronously in-kernel and drive them from a userspace agent.
  • •Own the kernel/userspace enforcement boundary, including event capture via ring buffers, policy evaluation in userspace, and deny decisions pushed back into the kernel via caches.
  • •Reduce enforce-mode latency on the syscall hot path at fleet scale through process enrichment, binary-hash caching/eviction, and process-ancestry resolution.
  • •Extend enforcement into containers and namespaces using cgroup- and namespace-aware policy, container identity on kernel events, and Kubernetes workload support.
  • •Mentor senior and mid-level engineers and raise the engineering bar across end-to-end delivery from design through production.

Key Requirements

  • •Deep Linux kernel internals (scheduling, memory management, networking, syscalls) and production systems programming in C, Rust, or both.
  • •Hands-on eBPF security enforcement with verifier fluency (e.g., passing BPF_PROG_LOAD across kernel versions, bounded loops, helper behavior).
  • •Proficiency with BTF and CO-RE for portability, including handling layout drift, LSM config availability, and tracepoint ABI differences.
  • •Experience with container runtime internals (namespaces, cgroups, seccomp) and how they intersect with kernel security tooling.
  • •8+ years in systems-level software engineering with depth in Linux kernel development and eBPF.
Experience:8+ years
Skills:Technical leadershipMentoringCollaborationRisk-focused decision-makingJudgment with AI-assisted development
Languages:En
Tech Stack:Linux kernelEBPFBPF LSMBprm_check_securityFile_openSocket_connect-EPERMRing buffersRustCAyaAya-ebpfNo_stdLibbpfBCCCilium eBPFBTFCO-RETask_structLSM

Company Brief

BeyondTrust
Provides privileged access management, vulnerability management, and secure remote access solutions to help organizations protect credentials, manage privileges, and secure endpoints across on-premises and cloud environments.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Phoenix, United States
WebsiteLinkedIn