About the Role
Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
The Role
As Staff Software Development Engineer, you'll be the Windows kernel authority for the runtime enforcement layer of our Identity Security Platform. These components decide, in-kernel, whether to permit or deny each action an identity or AI agent attempts on a Windows endpoint.
You'll set the technical direction for kernel-mode enforcement on Windows and own it end to end. That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads. Peer engineers own the macOS and Linux enforcement surfaces. You share one policy language, one event schema, and one userspace agent with them, but Windows kernel-space is yours.
You know this layer better than anyone. You want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.
What You’ll Do
- Design, build, and own our kernel-mode enforcement drivers: file-system, process and thread creation, handle operations, and registry access.
- Own the kernel/user-mode enforcement boundary: kernel-side event capture, policy evaluation in user mode, and deny decisions pushed back into the driver as hash-keyed caches.
- Drive down enforce-mode latency on the operation hot path as we scale across large fleets.
- Extend enforcement into containers and isolation: Windows containers and Host Compute Service workloads.
- Harden portability and stability across Windows builds so enforcement loads and behaves correctly on the versions customers actually run.
- Partner with the Linux and macOS enforcement engineers and the policy-backend team on the shared plane.
- Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders.
- Raise the engineering bar by taking end-to-end ownership from design through production.
- Mentor senior and mid-level engineers on Windows systems and kernel-driver craft.
What You’ll Bring
This is a Windows specialist role, so the depth requirements are real:
- Deep Windows kernel internals - the I/O manager and IRP flow, the object manager, process and thread structures, memory management, the Windows security model.
- Hands-on kernel-mode driver work for security enforcement.
Requirements
Windows kernel internals
You must have deep knowledge of Windows kernel internals including I/O manager and IRP flow.
Kernel-mode driver development
Experience in production kernel-mode driver development in C, C++, or Rust is essential.
Security enforcement experience
Hands-on experience with kernel-mode drivers for security enforcement is required.
Technical mentoring
Ability to mentor senior and mid-level engineers on Windows systems and kernel-driver craft.
Nice to Have
Experience working with Linux and macOS enforcement teams is a plus.
Familiarity with shared policy languages and event schemas is beneficial.
Benefits
Diversity and inclusion
A strong commitment to diversity and inclusion in the workplace.
Employee care
Supportive environment that prioritizes employee well-being.