BeyondTrust · 1 week ago
Staff Software Development Engineer - macOS Endpoint
United States+1 more
Full-time
Remote
Lead/Staff
8+ years exp
BeyondTrust is the global identity security leader protecting Paths to Privilege™. As a Staff Software Development Engineer, you'll be the macOS authority for the runtime enforcement layer of our Identity Security Platform, responsible for the design and implementation of the Endpoint Security client and ensuring robust enforcement across macOS environments.
Cloud ComputingCyber SecuritySoftwareCloud SecuritySecurity
Growth OpportunitiesH1B Sponsor Likely
Responsibilities
Design, build, and own our Endpoint Security client: process execution, file, and signal events, plus the synchronous authorization events where you allow or deny inline. You'll block operations by returning a deny verdict before the event completes, not by logging after the fact, and you'll build the userspace agent that installs and drives the extension
Own the enforcement decision path: event capture from Endpoint Security, policy evaluation, and deny decisions applied within Apple's authorization deadline so a slow verdict never stalls the system or gets auto-allowed
Drive down enforce-mode latency on the authorization path as we scale across large fleets. That means process enrichment, code-signature and hash caching with eviction under heavy process-churn, and process-ancestry resolution
Extend enforcement across network and content control: a Network Extension content filter for socket- and flow-level policy, tied to the same identity and process context as your Endpoint Security decisions. Much of this integration is greenfield, and it sits at the center of the role
Harden portability and stability across macOS versions and both Apple Silicon and Intel, so enforcement loads and behaves correctly on the OS versions customers actually run. You'll deal with Endpoint Security event and capability drift across releases, System Extension activation and approval flows, TCC and entitlement requirements, and graceful degradation when a capability isn't available
Partner with the Linux and Windows enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, the common Rust agent. You'll represent macOS in cross-org architecture reviews
Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders
Raise the engineering bar. You'll take end-to-end ownership from design through production, and you'll carry extra weight where a bug means a wrong security decision or a hung endpoint across the fleet, not just a crash of one process
Mentor senior and mid-level engineers on macOS systems and Endpoint Security craft
Qualification
MacOS system internalsEndpoint Security frameworkSystem ExtensionsNetwork ExtensionsCode-signingNotarizationLaunchdXPCTCCEntitlementsC programmingC++ programmingObjective-CSwiftRust programmingSynchronous authorization pathSystem Extension developmentMDM deploymentApp SandboxSIPLldbInstrumentsDtraceUnified logging systemSpindumpSystems-level software engineeringAI-driven code generationSystems design patternsAgile development
Required
Deep macOS system internals - the Endpoint Security framework, System and Network Extensions, the code-signing and notarization model, launchd and XPC, TCC and entitlements - backed by production systems programming in C, C++, Objective-C, Swift, or Rust
Hands-on work with Endpoint Security for enforcement, with real comfort on the synchronous authorization path: handling AUTH events within Apple's deadline, reasoning about the allow/deny verdict model, and keeping the client off the path that hangs or gets killed. Experience building a System Extension end to end transfers directly
The macOS deployment reality: System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization, plus the operational cost of shipping this to a large managed fleet
The macOS isolation and security model - the App Sandbox, TCC, SIP, and how they intersect with endpoint security tooling
Debugging and performance tooling: lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis
8+ years in systems-level software engineering, with real depth in macOS system software
Demonstrated AI-first development. We build this platform through agentic tooling. AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates are how work ships here, not a side experiment. You use Claude Code or a comparable tool as a core part of your daily workflow, and you can speak concretely to how it raises both your velocity and your rigor. That matters most in correctness- and security-critical enforcement code, where you have to know exactly when to stop and verify by hand
A working grasp of systems design patterns and their tradeoffs at the OS-enforcement boundary
Full-lifecycle experience, including product release, in an agile environment
A track record of technical leadership on complex, ambiguous initiatives that span teams
Company
BeyondTrust
Identity security software for enterprise privilege management.
H1B Sponsorship
BeyondTrust has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
63%
Represents job field similar to this job
Engineering and Development
Accounting and Finance
Product Management
Trends of Total Sponsorships
*2025 (3)
2024 (1)
2022 (3)
2020 (1)
Funding
Current Stage
Late StageTotal Funding
unknownKey Investors
Clearlake Capital Group
2021-06-01Private Equity
2018-09-13Acquired
2012-01-01Private Equity
Recent News
2026-08-26
Company data provided by crunchbase