About the Role
As Staff Software Development Engineer, you'll be the Windows kernel authority for the runtime enforcement layer of our Identity Security Platform. These components decide, in-kernel, whether to permit or deny each action an identity or AI agent attempts on a Windows endpoint. You'll set the technical direction for kernel-mode enforcement on Windows and own it end to end. You know this layer better than anyone and want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.
Responsibilities
- Design, build, and own kernel-mode enforcement drivers: file-system, process and thread creation, handle operations, and registry access.
- Block operations inline in the kernel rather than logging them after the fact.
- Build the userspace agent that installs and drives kernel-mode enforcement drivers.
- Own the kernel/user-mode enforcement boundary, including kernel-side event capture, policy evaluation in user mode, and deny decisions pushed back into the driver.
- Drive down enforce-mode latency on the operation hot path as we scale across large fleets.
- Extend enforcement into containers and isolation, including Windows containers, Host Compute Service workloads, silo- and job-object-aware policy, and container identity on kernel events.
- Harden portability and stability across Windows builds so enforcement loads and behaves correctly on customer-run versions.
- Partner with Linux and macOS enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, and the common Rust agent.
- Represent Windows in cross-org architecture reviews.
- Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to stakeholders.
- Raise the engineering bar by taking end-to-end ownership from design through production.
- Mentor senior and mid-level engineers on Windows systems and kernel-driver craft.
Requirements
- Deep Windows kernel internals knowledge, including the I/O manager and IRP flow, the object manager, process and thread structures, memory management, and the Windows security model (tokens, SIDs, ACLs).
- Production kernel-mode driver development experience in C, C++, or Rust.
- Hands-on kernel-mode driver work for security enforcement, including shipping a file-system minifilter or comparable callback-based driver.
- Ability to reason about IRQL, synchronization, safe user-buffer access, and reentrancy in the kernel.
- Knowledge of how to prevent a driver from causing a crash when a dependency misbehaves.
- Experience with driver signing and deployment realities: WHQL attestation, EV code signing, WDK and WDF/KMDF.
- Understanding of the Windows isolation model (job objects, silos, Windows containers, AppContainer) and its intersection with kernel-level security tooling.
- Proficiency in kernel debugging and performance tooling: WinDbg and KD, live-kernel and crash-dump analysis, ETW, Driver Verifier, and the checked-build workflow.
- 8+ years in systems-level software engineering with depth in Windows kernel development.
- Demonstrated AI-first development experience, using AI tools like Claude Code as a core part of the daily workflow for design exploration, code generation, adversarial plan review, and automated quality gates.
- Ability to speak concretely about how AI tools raise velocity and rigor, especially in correctness- and security-critical kernel code.
- A working grasp of systems design patterns and their tradeoffs at the kernel/user-mode boundary.
- Full-lifecycle experience, including product release, in an agile environment.
- A track record of technical leadership on complex, ambiguous initiatives that span teams.
Skills
- Windows kernel internals
- Kernel-mode driver development
- C
- C++
- Rust
- File-system minifilter
- Callback-based driver development
- IRQL management
- Synchronization
- Safe user-buffer access
- Reentrancy
- Driver signing
- WHQL attestation
- EV code signing
- WDK
- WDF/KMDF
- Windows isolation model
- Job objects
- Silos
- Windows containers
- AppContainer
- Kernel debugging
- WinDbg
- KD
- Live-kernel analysis
- Crash-dump analysis
- ETW
- Driver Verifier
- Checked-build workflow
- AI-first development
- AI code generation
- Systems design patterns
- Agile methodologies
- Technical leadership
Location
- Remote
Work Type
- Full-time
Experience Level
- Staff
- 8+ years in systems-level software engineering
- Senior
- Mid-level
About the Company
- BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
- BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies.
- We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
- Learn more at www.beyondtrust.com.
Equal Opportunity
- Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
- We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
