368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$137k – $241k per year (Estimated)
Location
Remote (United States, Canada)
Seniority
Staff · 8+ years exp
Overview
Company
Impact
Profile match
BeyondTrust is a cybersecurity software company headquartered in Atlanta, Georgia, and founded in 2006. The organization provides a platform for privileged access management, identity security, and secure remote access to protect organizations from data breaches and internal threats. It operates globally across various sectors, serving thousands of customers including government agencies and large enterprises under the ownership of Francisco Partners.

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

The Role

As Staff Software Development Engineer, you'll be the macOS authority for the runtime enforcement layer of our Identity Security Platform. These components decide whether to permit or deny each action an identity or AI agent attempts on a macOS endpoint.

You'll set the technical direction for enforcement on macOS and own it end to end. That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads. Peer engineers own the Linux and Windows enforcement surfaces. You share one policy language, one event schema, and one userspace agent with them, but macOS is yours.

You know this layer better than anyone. You want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.

What You’ll Do

  • Design, build, and own our Endpoint Security client: process execution, file, and signal events, plus the synchronous authorization events where you allow or deny inline. You'll block operations by returning a deny verdict before the event completes, not by logging after the fact, and you'll build the userspace agent that installs and drives the extension.
  • Own the enforcement decision path: event capture from Endpoint Security, policy evaluation, and deny decisions applied within Apple's authorization deadline so a slow verdict never stalls the system or gets auto-allowed.
  • Drive down enforce-mode latency on the authorization path as we scale across large fleets. That means process enrichment, code-signature and hash caching with eviction under heavy process-churn, and process-ancestry resolution.
  • Extend enforcement across network and content control: a Network Extension content filter for socket- and flow-level policy, tied to the same identity and process context as your Endpoint Security decisions. Much of this integration is greenfield, and it sits at the center of the role.
  • Harden portability and stability across macOS versions and both Apple Silicon and Intel, so enforcement loads and behaves correctly on the OS versions customers actually run. You'll deal with Endpoint Security event and capability drift across releases, System Extension activation and approval flows, TCC and entitlement requirements, and graceful degradation when a capability isn't available.
  • Partner with the Linux and Windows enforcement engineers and the policy-backend team on the shared plane: policy semantics, cross-stack conformance, event schema, the common Rust agent. You'll represent macOS in cross-org architecture reviews.
  • Read requirements to find gaps and risks, propose simplifications, and explain tradeoffs to technical and non-technical stakeholders.
  • Raise the engineering bar. You'll take end-to-end ownership from design through production, and you'll carry extra weight where a bug means a wrong security decision or a hung endpoint across the fleet, not just a crash of one process.
  • Mentor senior and mid-level engineers on macOS systems and Endpoint Security craft

What You’ll Bring

This is a macOS specialist role, so the depth requirements are real:

  • Deep macOS system internals - the Endpoint Security framework, System and Network Extensions, the code-signing and notarization model, launchd and XPC, TCC and entitlements - backed by production systems programming in C, C++, Objective-C, Swift, or Rust.
  • Hands-on work with Endpoint Security for enforcement, with real comfort on the synchronous authorization path: handling AUTH events within Apple's deadline, reasoning about the allow/deny verdict model, and keeping the client off the path that hangs or gets killed. Experience building a System Extension end to end transfers directly.
  • The macOS deployment reality: System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization, plus the operational cost of shipping this to a large managed fleet.
  • The macOS isolation and security model - the App Sandbox, TCC, SIP, and how they intersect with endpoint security tooling.
  • Debugging and performance tooling: lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis.
  • 8+ years in systems-level software engineering, with real depth in macOS system software.
  • Demonstrated AI-first development. We build this platform through agentic tooling. AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates are how work ships here, not a side experiment. You use Claude Code or a comparable tool as a core part of your daily workflow, and you can speak concretely to how it raises both your velocity and your rigor. That matters most in correctness- and security-critical enforcement code, where you have to know exactly when to stop and verify by hand.
  • A working grasp of systems design patterns and their tradeoffs at the OS-enforcement boundary.
  • Full-lifecycle experience, including product release, in an agile environment.
  • A track record of technical leadership on complex, ambiguous initiatives that span teams.

Who You Are

  • You share successes and failures openly, and you work well with people. You adapt when the situation and the requirements shift. You fix issues before anyone assigns them to you, and you stay persistent through roadblocks, pulling in others when you need to.
  • You hold a high bar and push your teams to ship reliable systems, especially where an enforcement bug carries outsized risk. You know systems software best practices, from rigorous testing to sharp peer review to architecture that survives contact with production.
  • You reach for AI tools to move faster and think more clearly, and you keep the judgment to slow down and verify by hand when the code demands it. You weigh speed against risk and decide from data.
  • You feel the weight of enforcement code. You'd rather ship a correct block a day late than a wrong one now, and you choose your failure modes - fail-open or fail-closed - on purpose instead of by accident.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$148k – $267k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Sunnyvale • Boston • Austin • Toronto • New York
AI/ML
AI Agents
Claude
Claude Code
Lovable
Replit
Cybersecurity
BeyondTrust
Crowdstrike
CyberArk
Delinea
Microsoft Entra ID
Okta
PCI DSS
SOC 2
Threat Modeling
Apply
$142k – $215k per year • In office • Full-Time • 12+ years exp • Princeton
JavaScript
TypeScript
Java
Java
Gradle
Hibernate
Maven
Spring Boot
Databases
Databricks
Snowflake
AI/ML
AI Agents
Claude
Claude Code
Frontend
Angular
React.js
Vue.js
DevOps
Amazon CloudWatch
Amazon ECS
Amazon EKS
Amazon EventBridge
Amazon S3
API Gateway
AWS
AWS Lambda
AWS Step Functions
Azure
CI/CD
IAM
Platform Engineering
Rest API
Kubernetes
Apply
$305k per year • In office • 8+ years exp • Bachelor's Degree • San Francisco
AI/ML
AI Agents
Anthropic
Claude
LLM
Multimodal AI
Apply
$99k – $186k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Lincoln • Alpharetta
AI/ML
Claude
AI Agents
OpenAI
DevOps
AWS
Azure
Docker
Git
Kubernetes
Rest API
Management
Confluence
QA
Postman
Swagger
Apply
Lead AI Engineer 8 hours ago
$106k – $227k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Omaha • Alpharetta
Java
Python
C#
TypeScript
JavaScript
Java
Spring Boot
C#
.NET
AI/ML
Claude
Copilot
LLM
Anthropic
OpenAI
Frontend
Angular
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitLab CI
Jenkins
Kubernetes
OpenShift
Rest API
GitLab
Apply
Cloud Engineer 3 days ago
$66k – $179k per year (Estimated) • Remote • 3+ years exp • Bachelor's Degree
PowerShell
Python
AI/ML
Claude
Claude Code
Copilot
DevOps
AWS
Azure
CI/CD
Datadog
GCP
Git
GitHub Actions
Prometheus
Terraform
Amazon CloudWatch
GitHub
IAM
Cybersecurity
BeyondTrust
FedRAMP
ISO 27001
NIST CSF
SOC 2
Apply
$100k – $195k per year (Estimated) • Remote
C#
Go
JavaScript
TypeScript
AI/ML
AI Agents
Claude
Claude Code
Frontend
Angular
React.js
Vue.js
DevOps
AWS
CI/CD
CloudFormation
Terraform
IAM
Cybersecurity
BeyondTrust
Microsoft Entra ID
Apply
$94k – $176k per year (Estimated) • Remote • 7+ years exp • Bachelor's Degree • New York
Cybersecurity
BeyondTrust
Apply
$78k – $176k per year (Estimated) • Remote
Java
TypeScript
JavaScript
Java
Spring Boot
AI/ML
Claude
Claude Code
Copilot
Frontend
Angular
Mobile
JUnit
DevOps
AWS
Azure
Git
Cybersecurity
BeyondTrust
Apply
SOC Analyst 11 days ago
$54k – $138k per year (Estimated) • Remote • 2+ years exp
PowerShell
Python
AI/ML
AI Agents
LLM
Prompt Engineering
Cybersecurity
BeyondTrust
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.