Beyondtrust
Staff Software Development Engineer – Linux Endpoint
Remote Canada | Remote United States · Staff+
Sponsorship not specifiedDetected 15 hours ago
Code ReviewKubernetesLinuxLeadership
About the role
- As Staff Software Development Engineer, you'll be the Linux kernel authority for the runtime enforcement layer of our Identity Security Platform.
- These components decide, in-kernel, whether to permit or deny each action an identity or AI agent attempts on a Linux endpoint.
- That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads.
Responsibilities
- Design, build, and own our eBPF programs and BPF LSM hooks (bprm_check_security, file_open, socket_connect).
- You'll enforce policy synchronously in the kernel by returning -EPERM to block, rather than logging after the fact, and you'll build the userspace agent that loads and drives them.
- Own the kernel/userspace enforcement boundary: kernel-side event capture over ring buffers, policy evaluation in userspace, and deny decisions pushed back into the kernel as hash-keyed caches so subsequent hits block inline.
- Drive down enforce-mode latency on the syscall hot path as we scale across large fleets. That means process enrichment, binary-hash caching and eviction under heavy fork/exec pressure, and process-ancestry resolution.
- Partner with the macOS and Windows enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, the common Rust agent. You'll represent Linux in cross-org architecture reviews.
- Raise the engineering bar. You'll take end-to-end ownership from design through production, and you'll carry extra weight where a kernel bug means a wrong security decision instead of just a crash.
Requirements
- You can write programs that pass BPF_PROG_LOAD across kernel versions and reason about the stack limit, bounded loops, and helper-behavior differences.
- You share successes and failures openly, and you work well with people.
- You know systems software best practices, from rigorous testing to sharp peer review to architecture that survives contact with production.
- 8+ years in systems-level software engineering, with real depth in Linux kernel development and eBPF.
- That matters most in correctness- and security-critical kernel code, where you have to know exactly when to stop and verify by hand.
- A track record of technical leadership on complex, ambiguous initiatives that span teams.
Nice to have
- Container runtime internals - namespaces, cgroups, seccomp - and how they intersect with kernel-level security tooling.
- BTF and CO-RE, plus the practical realities of portability: task_struct layout drift, LSM config availability, tracepoint ABI.
Company info
- BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
- BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
- Learn more at www.beyondtrust.com.
- BeyondTrust is the global identity security leader protecting Paths to Privilege™.
- Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
- BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies.
- We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
- Harden portability across kernel versions and distributions so enforcement loads and behaves correctly on the kernels customers actually run.
Apply directly at Beyondtrust →Create a free account for alerts like thisView Beyondtrust immigration profile
This listing is sourced directly from Beyondtrust's careers page and normalized into a canonical job model.