BeyondTrust
Staff Software Development Engineer - Windows Endpoint
Remote work allowed only within certain countries or regions.
Employer listed it 6 weeks ago · Added 5 days ago
Been open since 6 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
Timezone
US East
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 596 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in Canada, United States.
What the employer says
- Source listing states candidate location: "Remote Canada | Remote United States, Remote Canada, Remote United States"
What Nomaders makes of it
- Applications outside the listed area are usually rejected
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
The Role
As Staff Software Development Engineer, you'll be the Windows kernel authority for the runtime enforcement layer of our Identity Security Platform. These components decide, in-kernel, whether to permit or deny each action an identity or AI agent attempts on a Windows endpoint.
You'll set the technical direction for kernel-mode enforcement on Windows and own it end to end. That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads. Peer engineers own the macOS and Linux enforcement surfaces. You share one policy language, one event schema, and one userspace agent with them, but Windows kernel-space is yours.
You know this layer better than anyone. You want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.
What You’ll Do
Design, build, and own our kernel-mode enforcement drivers: file-system, process and thread creation, handle operations, and registry access. You'll block operations inline in the kernel rather than logging them after the fact, and you'll build the userspace agent that installs and drives them.
Own the kernel/user-mode enforcement boundary: kernel-side event capture, policy evaluation in user mode, and deny decisions pushed back into the driver as hash-keyed caches so subsequent hits block inline.
Drive down enforce-mode latency on the operation hot path as we scale across large fleets. That means process enrichment, image-hash caching and eviction under heavy process-churn, and process-ancestry resolution across PPID spoofing.
Extend enforcement into containers and isolation: Windows containers and Host Compute Service workloads, silo- and job-object-aware policy, and container identity on kernel events. Most of this is greenfield, and it sits at the center of the role.
Harden portability and stability across Windows builds so enforcement loads and behaves correctly on the versions customers actually run. You'll deal with structure-versioning across Windows releases, PatchGuard constraints, Driver Verifier and HVCI compliance, WHQL attestation signing, and graceful degradation when a capability isn't available.
Partner with the Linux and macOS enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, the common Rust agent. You'll represent Windows in cross-org architecture reviews.
Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders.
Raise the engineering bar. You'll take end-to-end ownership from design through production, and you'll carry extra weight where a kernel bug means a wrong security decision or a bugcheck across the fleet, not just a crash of one process.
Mentor senior and mid-level engineers on Windows systems and kernel-driver craft.
What You’ll Bring
This is a Windows specialist role, so the depth requirements are real:
Deep Windows kernel internals - the I/O manager and IRP flow, the object manager, process and thread structures, memory management, the Windows security model (tokens, SIDs, ACLs) - backed by production kernel-mode driver development in C, C++, or Rust.
Hands-on kernel-mode driver work for security enforcement. You've shipped a file-system minifilter or comparable callback-based driver, and you can reason about IRQL, synchronization, safe user-buffer access, and reentrancy in the kernel. You know how to keep a driver off the crash path when a dependency misbehaves.
Driver signing and deployment reality: WHQL attestation, EV code signing, the WDK and WDF/KMDF, and the operational cost of shipping kernel code to a large install base.
The Windows isolation model - job objects, silos, Windows containers, AppContainer - and how it intersects with kernel-level security tooling.
Kernel debugging and performance tooling: WinDbg and KD, live-kernel and crash-dump analysis, ETW, Driver Verifier, and the checked-build workflow.
8+ years in systems-level software engineering, with real depth in Windows kernel development.
Requirements
- ·This is a Windows specialist role, so the depth requirements are real:
- ·Driver signing and deployment reality: WHQL attestation, EV code signing, the WDK and WDF/KMDF, and the operational cost of shipping kernel code to a large install base.
- ·The Windows isolation model - job objects, silos, Windows containers, AppContainer - and how it intersects with kernel-level security tooling.
- ·Kernel debugging and performance tooling: WinDbg and KD, live-kernel and crash-dump analysis, ETW, Driver Verifier, and the checked-build workflow.
- ·8+ years in systems-level software engineering, with real depth in Windows kernel development.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at BeyondTrust, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year · You'll be taken to the employer's careers page.