Endpoint Engineer, EDR (macOS)

New
E
EntCybersecurity
We also hire remotely across North AmericaFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
10+ years
Required Skills
Objective-CSwiftC++

Requirements

  • 10+ years designing, building, and delivering production native systems software (Swift, C, C++, or Objective-C).
  • Substantial experience in endpoint security, OS internals, or performance-critical code.
  • Strong, current Swift experience, including modern concurrency (actors, Sendable, structured concurrency).
  • Deep working knowledge of macOS internals: process and thread lifecycle, memory management, file systems, code signing, launchd, IPC (XPC/Mach), and TCC.
  • Hands-on production experience with Endpoint Security framework and/or Network Extensions.
  • Demonstrated experience building or operating an EDR, EPP, XDR, or DLP product.
  • Practical fluency in attacker TTPs and reasoning about raw telemetry.
  • Strong low-level debugging skills: lldb, crash-dump/hang analysis, and performance tracing with Instruments.
  • Expertise in multi-threaded programming: synchronization, lock contention, race conditions, and actor isolation.
  • Track record of deploying code to large fleets without degrading end-user experience.
  • Scripting fluency for tooling and test automation (Python, shell, or equivalent).
  • Clear communication skills for distributed teams and customer interaction.

Responsibilities

  • Design, build, and ship the privileged daemon, per-user agents, and system extensions that make up the macOS agent.
  • Own EDR-class detection and prevention capability end to end, including sensor instrumentation and interception logic.
  • Instrument telemetry at the OS boundary using Endpoint Security framework, Network Extensions, FSEvents, and IOKit.
  • Design and maintain the multi-process architecture, including XPC protocols and code-signing-based peer authentication.
  • Harden the agent against tamper, bypass, and evasion using self-protection and integrity validation.
  • Optimize sensor CPU, memory, and I/O usage to meet real-time performance constraints.
  • Build test harnesses and automated regression coverage, including VM-based end-to-end testing.
  • Drive high-severity customer escalations to root cause and implement permanent fixes.
  • Partner with security research, AI, and platform teams to integrate on-device ML and policy enforcement.
  • Review code, mentor engineers, and document design decisions.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now