About the Role
Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
The Role
As Staff Software Development Engineer, you'll be the Linux kernel authority for the runtime enforcement layer of our Identity Security Platform. These components decide, in-kernel, whether to permit or deny each action an identity or AI agent attempts on a Linux endpoint.
You'll set the technical direction for eBPF enforcement on Linux and own it end to end. That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads. Peer engineers own the macOS and Windows enforcement surfaces. You share one policy language, one event schema, and one userspace agent with them, but Linux kernel-space is yours.
You know this layer better than anyone. You want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.
What You’ll Do
- Design, build, and own our eBPF programs and BPF LSM hooks (bprm_check_security, file_open, socket_connect).
- Own the kernel/userspace enforcement boundary: kernel-side event capture over ring buffers, policy evaluation in userspace, and deny decisions pushed back into the kernel as hash-keyed caches.
- Drive down enforce-mode latency on the syscall hot path as we scale across large fleets.
- Extend enforcement into containers and namespaces: cgroup- and namespace-aware policy, container identity on kernel events, Kubernetes workloads.
- Harden portability across kernel versions and distributions.
- Partner with the macOS and Windows enforcement engineers and the policy-backend team on the shared plane.
- Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to stakeholders.
- Raise the engineering bar and take end-to-end ownership from design through production.
- Mentor senior and mid-level engineers on Linux systems and eBPF craft.
What You’ll Bring
This is a Linux specialist role, so the depth requirements are real:
- Deep Linux kernel internals - scheduling, memory management, the networking stack, syscalls, the LSM framework.
- Hands-on eBPF for security enforcement, with real comfort at the verifier level.
- BTF and CO-RE, plus the practical realities of portability.
- Container runtime internals - namespaces, cgroups, seccomp.
Requirements
Linux kernel internals
Deep understanding of scheduling, memory management, and syscalls.
eBPF expertise
Hands-on experience with eBPF for security enforcement.
C or Rust programming
Proficiency in systems programming using C, Rust, or both.
Container runtime knowledge
Familiarity with namespaces, cgroups, and seccomp.
Nice to Have
Ability to write programs that pass BPF_PROG_LOAD across kernel versions.
Experience mentoring engineers on Linux systems and eBPF.
Benefits
Diversity and inclusion
A culture that values diverse backgrounds and perspectives.
Employee care
Support for employees to ensure they can take care of customers.