Endpoint Engineer, EDR (macOS)
New
E
EntCybersecurity
We also hire remotely across North AmericaFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years
- Required Skills
- Objective-CSwiftC++
Requirements
- 10+ years designing, building, and delivering production native systems software (Swift, C, C++, or Objective-C).
- Substantial experience in endpoint security, OS internals, or performance-critical code.
- Strong, current Swift experience, including modern concurrency (actors, Sendable, structured concurrency).
- Deep working knowledge of macOS internals: process and thread lifecycle, memory management, file systems, code signing, launchd, IPC (XPC/Mach), and TCC.
- Hands-on production experience with Endpoint Security framework and/or Network Extensions.
- Demonstrated experience building or operating an EDR, EPP, XDR, or DLP product.
- Practical fluency in attacker TTPs and reasoning about raw telemetry.
- Strong low-level debugging skills: lldb, crash-dump/hang analysis, and performance tracing with Instruments.
- Expertise in multi-threaded programming: synchronization, lock contention, race conditions, and actor isolation.
- Track record of deploying code to large fleets without degrading end-user experience.
- Scripting fluency for tooling and test automation (Python, shell, or equivalent).
- Clear communication skills for distributed teams and customer interaction.
Responsibilities
- Design, build, and ship the privileged daemon, per-user agents, and system extensions that make up the macOS agent.
- Own EDR-class detection and prevention capability end to end, including sensor instrumentation and interception logic.
- Instrument telemetry at the OS boundary using Endpoint Security framework, Network Extensions, FSEvents, and IOKit.
- Design and maintain the multi-process architecture, including XPC protocols and code-signing-based peer authentication.
- Harden the agent against tamper, bypass, and evasion using self-protection and integrity validation.
- Optimize sensor CPU, memory, and I/O usage to meet real-time performance constraints.
- Build test harnesses and automated regression coverage, including VM-based end-to-end testing.
- Drive high-severity customer escalations to root cause and implement permanent fixes.
- Partner with security research, AI, and platform teams to integrate on-device ML and policy enforcement.
- Review code, mentor engineers, and document design decisions.
View Full Description & ApplyYou'll be redirected to the employer's site