About the Role
As Staff Software Development Engineer, you'll be the macOS authority for the runtime enforcement layer of our Identity Security Platform. These components decide whether to permit or deny each action an identity or AI agent attempts on a macOS endpoint. You'll set the technical direction for enforcement on macOS and own it end to end.
Responsibilities
- Design, build, and own our Endpoint Security client: process execution, file, and signal events, plus the synchronous authorization events where you allow or deny inline.
- Own the enforcement decision path: event capture from Endpoint Security, policy evaluation, and deny decisions applied within Apple's authorization deadline.
- Drive down enforce-mode latency on the authorization path as we scale across large fleets.
- Extend enforcement across network and content control: a Network Extension content filter for socket- and flow-level policy.
- Harden portability and stability across macOS versions and both Apple Silicon and Intel.
- Partner with the Linux and Windows enforcement engineers and the policy-backend team on the shared plane.
- Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders.
- Raise the engineering bar, taking end-to-end ownership from design through production.
- Mentor senior and mid-level engineers on macOS systems and Endpoint Security craft.
Requirements
- Deep macOS system internals - the Endpoint Security framework, System and Network Extensions, the code-signing and notarization model, launchd and XPC, TCC and entitlements - backed by production systems programming in C, C++, Objective-C, Swift, or Rust.
- Hands-on work with Endpoint Security for enforcement, with real comfort on the synchronous authorization path.
- Experience building a System Extension end to end.
- The macOS deployment reality: System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization.
- The macOS isolation and security model - the App Sandbox, TCC, SIP, and how they intersect with endpoint security tooling.
- Debugging and performance tooling: lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis.
- 8+ years in systems-level software engineering, with real depth in macOS system software.
- Demonstrated AI-first development, using AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates.
- A working grasp of systems design patterns and their tradeoffs at the OS-enforcement boundary.
- Full-lifecycle experience, including product release, in an agile environment.
- A track record of technical leadership on complex, ambiguous initiatives that span teams.
- Share successes and failures openly, and work well with people.
- Adapt when the situation and the requirements shift.
- Fix issues before anyone assigns them to you, and stay persistent through roadblocks.
- Hold a high bar and push teams to ship reliable systems.
- Know systems software best practices, from rigorous testing to sharp peer review to architecture that survives contact with production.
- Reach for AI tools to move faster and think more clearly, and keep the judgment to slow down and verify by hand when the code demands it.
- Weigh speed against risk and decide from data.
- Feel the weight of enforcement code.
- Choose failure modes - fail-open or fail-closed - on purpose instead of by accident.
Skills
- macOS system internals
- Endpoint Security framework
- System Extensions
- Network Extensions
- Code-signing
- Notarization
- launchd
- XPC
- TCC
- Entitlements
- C
- C++
- Objective-C
- Swift
- Rust
- Endpoint Security
- Synchronous authorization path
- System Extension development
- macOS deployment
- MDM-managed deployment
- App Sandbox
- SIP
- lldb
- Instruments
- dtrace
- Unified logging system
- spindump
- AI-first development
- Systems design patterns
- Agile environment
- Technical leadership
Experience Level
- 8+ years in systems-level software engineering
About the Company
- BeyondTrust is the global identity security leader protecting Paths to Privilege™.
- Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
- BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies.
- We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
- Learn more at www.beyondtrust.com.
Equal Opportunity
- Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
- We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
