Staff Software Development Engineer - Windows Endpoint

BeyondTrust
Toronto, United States
Workplace: RemoteFull timeFunction: Product ManagementExperience: 8+ yearsSkills: ["Technical leadership","Mentorship","Stakeholder communication","Problem solving","Peer review"]

Own the Windows kernel runtime enforcement layer for an identity security platform, deciding in-kernel whether to permit or deny actions by identities and AI agents. Design and build kernel-mode enforcement drivers and the userspace agent, optimize enforce-mode latency across large fleets, and extend enforcement into containers and isolation. Partner across Windows, macOS, and Linux enforcement teams, harden portability across Windows builds, and mentor engineers while representing Windows in architecture reviews.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BeyondTrust
BeyondTrust
1 month ago

Staff Software Development Engineer - Windows Endpoint

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Own the Windows kernel runtime enforcement layer for an identity security platform, deciding in-kernel whether to permit or deny actions by identities and AI agents. Design and build kernel-mode enforcement drivers and the userspace agent, optimize enforce-mode latency across large fleets, and extend enforcement into containers and isolation. Partner across Windows, macOS, and Linux enforcement teams, harden portability across Windows builds, and mentor engineers while representing Windows in architecture reviews.
Location: Toronto, United States
Workplace: Remote
Employment Type: Full time
Job Function: Product Management
Seniority: Sr. Manager level

Key Responsibilities

  • •Set the technical direction for Windows kernel-mode enforcement and own the runtime enforcement layer end to end.
  • •Design, build, and own kernel-mode enforcement drivers for file-system, process/thread creation, handle operations, and registry access, including the userspace agent to install and drive them.
  • •Own the kernel/user-mode enforcement boundary: kernel event capture, user-mode policy evaluation, and pushing deny decisions back into driver caches for inline blocking.
  • •Drive down enforce-mode latency on the hot path at fleet scale, including process enrichment, image-hash caching/eviction, and process-ancestry resolution across PPID spoofing.
  • •Harden portability and stability across Windows builds and partner cross-platform (Linux/macOS) on shared policy semantics, event schema, and architecture reviews, while mentoring engineers.

Key Requirements

  • •8+ years in systems-level software engineering with real depth in Windows kernel development.
  • •Deep Windows kernel internals (I/O manager and IRP flow, object manager, process/thread structures, memory management, security model) plus production kernel-mode driver development in C, C++, or Rust.
  • •Hands-on kernel-mode driver work for security enforcement, including shipping a file-system minifilter or comparable callback-based driver; reasoning about IRQL, synchronization, safe user-buffer access, and reentrancy.
  • •Experience with driver signing and deployment, including WHQL attestation, EV code signing, and the WDK with WDF/KMDF.
  • •Hands-on debugging/performance tooling (WinDbg/KD, crash-dump analysis, ETW, Driver Verifier) and demonstrated AI-first development using Claude Code or a comparable tool.
Experience:8+ yearsSystems-level software engineeringWindows kernel developmentSecurity enforcementIdentity securityAI-first development
Skills:Technical leadershipMentorshipStakeholder communicationProblem solvingPeer review
Languages:English
Tech Stack:WindowsWindows kernelCC++RustRust agentKernel-mode driversFile-system minifilterI/O managerIRPObject managerWinDbgKDETWDriver VerifierWDKWDFKMDFPatchGuardHVCI

Company Brief

BeyondTrust
Provides privileged access management, vulnerability management, and secure remote access solutions to help organizations protect credentials, manage privileges, and secure endpoints across on-premises and cloud environments.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Phoenix, United States
WebsiteLinkedIn