Staff Principal Software Engineer Windows
Fulltid
CloudZero
Responsibilities
- Take the Windows agent from proof of concept to a signed, installable, auto-updating product.
- Own the WFP callout driver and Go user-mode relay while keeping both components synchronized as they evolve.
- Handle production kernel-mode driver signing, EV certificates, Microsoft attestation, Secure Boot, and code integrity.
- Build the installer, update mechanism, clean uninstall path, and enterprise deployment story.
- Design fail-open behavior so non-AI traffic bypasses the agent and failures do not disrupt endpoint connectivity.
- Manage local CA trust and TLS interception in a safe, transparent, and reversible way.
- Build the endpoint client in Electron and TypeScript and define Windows-agent product parity with macOS.
- Raise engineering standards through code review, design feedback, and direct mentorship.
Requirements
- Deep experience shipping Windows services, drivers, or endpoint agents to customer-controlled machines.
- Experience with kernel-mode or low-level Windows development using KMDF or WDM, the Windows Driver Kit, and WinDbg.
- Working knowledge of Windows networking internals and the Windows Filtering Platform or a comparable traffic-interception approach.
- Proficiency in C or C++ for driver development and Go or another systems language for user-mode development.
- Ability to work across a kernel driver, user-mode service, and desktop UI, or clearly communicate areas of strength and support needed.
- Hands-on experience with Windows code signing, Authenticode, EV certificates, Microsoft attestation, or the WHQL process.
- Track record of shipping endpoint software with attention to failure handling, cleanup, least privilege, and production reliability.
- Ability to evaluate kernel-level tradeoffs and explain them to engineering, product, and leadership stakeholders.
- Track record of shipping production software, not just designing it.
- Preferred experience building enterprise-scale endpoint security, EDR, DLP, or network-monitoring agents.
- Preferred experience with TLS interception, MITM proxies, certificate trust management, MSIX, MSI, WiX, auto-update frameworks, Intune, MDM, Group Policy, or Windows/macOS endpoint software.
- Experience using AI coding tools and articulating their workflow and limitations is a bonus.
Benefits
- Collaborative, fast-moving environment with direct impact on the product.
- Opportunity to work with cutting-edge technology on complex cloud and AI-cost challenges.
- Opportunity to grow with a rapidly scaling company.
Ledig stilling lagt ut 6 dager siden