Senior/Staff Software Development Engineer - macOS Endpoint- Remote
About the role
Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected. We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
Responsibilities
- Design, build, and own our Endpoint Security client: process execution, file, and signal events, plus the synchronous authorization events where you allow or deny inline.
- Own the enforcement decision path: event capture from Endpoint Security, policy evaluation, and deny decisions applied within Apple's authorization deadline so a slow verdict never stalls the system or gets auto-allowed.
- Drive down enforce-mode latency on the authorization path as we scale across large fleets. That means process enrichment, code-signature and hash caching with eviction under heavy process-churn, and process-ancestry resolution.
- Extend enforcement across network and content control: a Network Extension content filter for socket- and flow-level policy, tied to the same identity and process context as your Endpoint Security decisions. Much of this integration is greenfield, and it sits at the center of the role.
- Partner with the Linux and Windows enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, the common Rust agent. You'll represent macOS in cross-org architecture reviews.
- Raise the engineering bar. You'll take end-to-end ownership from design through production, and you'll carry extra weight where a bug means a wrong security decision or a hung endpoint across the fleet, not just a crash of one process.
- Mentor senior and mid-level engineers on macOS systems and Endpoint Security craft.
Requirements
- This is a macOS specialist role, so the depth requirements are real: Deep macOS system internals - the Endpoint Security framework, System and Network Extensions, the code-signing and notarization model, launchd and XPC, TCC and entitlements - backed by production systems programming in C, C++, Objective-C, Swift, or Rust.
- Hands-on work with Endpoint Security for enforcement, with real comfort on the synchronous authorization path: handling AUTH events within Apple's deadline, reasoning about the allow/deny verdict model, and keeping the client off the path that hangs or gets killed. Experience building a System Extension end to end transfers directly.
- The macOS deployment reality: System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization, plus the operational cost of shipping this to a large managed fleet.
- The macOS isolation and security model - the App Sandbox, TCC, SIP, and how they intersect with endpoint security tooling.
- Debugging and performance tooling: lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis.
- 8+ years in systems-level software engineering, with real depth in macOS system software.
- Demonstrated AI-first development. We build this platform through agentic tooling. AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates are how work ships here, not a side experiment. You use Claude Code or a comparable tool as a core part of your daily workflow, and you can speak concretely to how it raises both your velocity and your rigor. That matters most in correctness- and security-critical enforcement code, where you have to know exactly when to stop and verify by hand.
- Full-lifecycle experience, including product release, in an agile environment.
- A track record of technical leadership on complex, ambiguous initiatives that span teams.
Qualifications
- Deep understanding of macOS system internals, including the Endpoint Security framework, System and Network Extensions, code-signing and notarization model, launchd and XPC, TCC and entitlements.
- Experience building System Extensions end to end.
- Hands-on experience with macOS deployment, including System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization.
- Experience with debugging and performance tooling, including lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis.
- Experience with systems-level software engineering, including C, C++, Objective-C, Swift, or Rust.
- Experience with AI-driven development, including AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates.
- Experience with systems-level software engineering, including C, C++, Objective-C, Swift, or Rust.
- Experience with full-lifecycle product release in an agile environment.
- Experience with technical leadership on complex, ambiguous initiatives that span teams.
Skills
- Deep understanding of macOS system internals, including the Endpoint Security framework, System and Network Extensions, code-signing and notarization model, launchd and XPC, TCC and entitlements.
- Experience building System Extensions end to end.
- Hands-on experience with macOS deployment, including System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization.
- Experience with debugging and performance tooling, including lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis.
- Experience with systems-level software engineering, including C, C++, Objective-C, Swift, or Rust.
- Experience with AI-driven development, including AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates.
- Experience with systems-level software engineering, including C, C++, Objective-C, Swift, or Rust.
- Experience with full-lifecycle product release in an agile environment.
- Experience with technical leadership on complex, ambiguous initiatives that span teams.
Benefits
- We offer competitive compensation packages, including base salary, bonus opportunities, and equity.
- We provide comprehensive benefits, including health insurance, retirement plans, and paid time off.
- We foster a culture of diversity, inclusion, and belonging, and we actively seek to hire and retain a diverse workforce.
Pay
- Competitive compensation packages, including base salary, bonus opportunities, and equity.
Schedule
- Full-time schedule.
Company Information
About Us
BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. Learn more at www.beyondtrust.com.