988,386open jobs
59,033companies
162,644added this week
Browse all
Location
In office
Seniority
Principal · 6+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Aug 25, 2026.

Overview
Company
Impact
Profile match
Unleash your security superpowers. Reach finds and remediates misconfigured tools and configuration drift to supercharge your security posture.

Principal Support Engineer - Endpoint

DOMAIN SUBJECT-MATTER EXPERT · ESCALATION & ENABLEMENT

About the role

Reach Security tells organizations what their existing security tools should be doing with the products they already own - and proves it. As a Principal Support Engineer, Endpoint, you are Reach's senior domain authority on everything endpoint.

This is not an endpoint break/fix role. You won't spend your days administering endpoints, packaging agents, or chasing agent crashes. You've already done that work - for years - and that is exactly what qualifies you. Those years in the trenches are what let you look at a customer's endpoint configuration, their controls, and Reach's findings and say, with authority, what matters, what doesn't, and why.

In this role you put that hard-won judgment to work advising the field, guiding customers through their hardest problems, sharpening Reach's recommendations, and troubleshooting how Reach integrates with the endpoint products already in a customer's environment. It is a high-agency individual-contributor role for a proven expert who is energized by unfamiliar problems rather than thrown by them.

What this role really does

You'll serve three audiences at once, and the strongest people in this seat move fluidly between them:

  • Enable the field (Sales Engineering & POVs). Help SEs build the strongest possible POV from Reach's endpoint findings - translating raw product output into “here's the risk, here's why it's urgent, here's what to fix first.” Coach the technical field team to defend those findings under technical scrutiny and tell Engineering and Research what would make the next POV even more compelling.

  • Empower Customer Success. Be the deep technical resolver behind CS. When a customer hits a genuinely hard endpoint-related problem, you investigate to root cause, propose the solution, and hand Engineering a clean, reproducible diagnosis - so engineers validate and ship rather than doing front-line discovery.

  • Harden the product. Own your share of the escalation queue and close the loop: solve, reproduce, test, document, and enable - so each issue makes Reach more robust and each runbook makes the whole team faster.

How you'll spend your time

  • Serve as the endpoint subject-matter expert for the support team - review customer endpoint configurations, controls, and policies and make sage, prioritized recommendations grounded in real-world best practice.

  • Critique Reach's endpoint findings, so customers are presented only with what truly matters - separating signal from noise and articulating why a finding is urgent, or why it isn't.

  • Troubleshoot integrations between Reach and third-party endpoint and security products (EDR, DLP, MDM, and similar) - using your deep knowledge of how those products actually behave to pinpoint where an integration breaks and propose the fix. This is where your hands-on background is exercised most directly.

  • Diagnose deep, engineering-level customer issues end to end - using logs, telemetry, diagnostics, and OS-level reasoning to reach true root cause, then packaging a clear diagnosis and proposed fix that Engineering can act on quickly.

  • Uplevel the Sales Engineering team - teach the field to read and explain endpoint findings, defend recommendations to customer security teams, and translate product output into what matters to the customer.

  • Partner with Engineering and QA to report defects, validate fixes, confirm workarounds, and drive root-cause analysis.

  • Author and maintain runbooks, troubleshooting guides, and internal documentation that turn your field experience into repeatable team knowledge.

  • Maintain enough of a lab or test capability to validate hypotheses about endpoint behavior and integration edge cases.

The experience that qualifies you

The experience below is the foundation we're hiring for. You've done this work hands-on, at depth, earlier in your career - and in this role you'll leverage that judgment as a subject-matter expert rather than performing it day to day. We're screening for the expertise that experience produced, not for a desire to keep doing endpoint administration.

  • 6+ years of deep, hands-on experience with Windows and macOS endpoint agents and endpoint security in enterprise environments - enough to have developed genuine expertise, not passing familiarity.

  • Time in a senior individual-contributor role such as L3 Support Engineer, Endpoint Engineer, Windows/macOS Engineer, or Security Support Engineer.

  • Demonstrated command of endpoint agent behavior across Windows and macOS - installation, upgrades, persistence, OS compatibility, performance, and stability - and the judgment to know what “good” looks like.

  • Kernel-level understanding of Windows, including ETW, WFP, memory management, process/thread behavior, and driver interactions.

  • macOS internals experience, including the Endpoint Security framework, System Extensions, FSEvents, MDM interactions, notarization, code signing, and process lifecycle.

  • A track record of analyzing endpoint telemetry, logs, and diagnostics to reach root cause in complex system interactions.

  • Experience resolving interoperability issues between endpoint agents and security tools (EDR, DLP, MDM, or similar).

  • Working knowledge of Linux system administration, sufficient to reason about supporting services that interact with endpoint deployments.

  • Experience with enterprise-scale environments and large endpoint fleets.

  • The advisory instinct that defines this role: the ability to look at a set of findings and controls and tell a customer, clearly, which few things matter and why.

  • Strong written and verbal communication - you can make a complex endpoint issue clear to a customer, an SE, and an engineer, each in their own language.

  • Strong time management and a real sense of urgency in customer-impacting situations.

  • BS or MS in Computer Science, Engineering, or a related technical discipline - or equivalent practical experience.

Cross-domain fluency we value

Reach spans the whole security stack, and the best domain experts are curious well past their specialty. You don't need to be an expert in all of these, but comfort in several will make you far stronger here: identity and IDP troubleshooting (SSO, SAML/OIDC, layered and conditional access, MDM-to-IdP interactions); a working grasp of threats and vulnerabilities and how they manifest at the endpoint; and familiarity with email security controls. We'll gladly help you deepen the areas you're newer to.

Nice to have

  • Experience supporting endpoint security, insider risk, or behavioral-analytics platforms.

  • Experience reproducing customer issues in labs that mirror production endpoint configurations.

  • Exposure to cloud or hybrid enterprise environments (AWS, Azure, GCP).

  • Linux internals: kernel/user-space boundaries, eBPF, LSM (SELinux/AppArmor), cgroups and namespaces, netfilter, systemd, proc/sysfs, inotify/fanotify, auditd/seccomp, ELF/ptrace.

  • Hands-on experience with third-party endpoint security products such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar.

Who you'll thrive as

You're the person peers escalate to - and still the first to say “I haven't seen that before, let me dig in.” You think in systems, you're relentless about root cause, and you're generous with what you learn. You're as comfortable teaching the field how to defend a finding as you are reading a kernel trace. Curiosity, adaptability, and low ego matter to us as much as depth: the security stack keeps changing, and we're looking for someone who's genuinely excited by that.

Working at Reach Security:

  • Competitive salary, and equity package

  • Comprehensive benefits package including:

  • Medical, dental, and vision insurance, including plan options with company-paid employee coverage

  • FSA, HSA, and 401(k) plans

  • Company paid life insurance and disability coverage, along with buy up options

  • Voluntary benefits including pet insurance, identify theft coverage, and legal services

  • Unlimited PTO and sick time

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
988,386 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Support
Similar stack
Same company
In your city
$63k – $75k per year • Remote (United States) • Full-Time • United States
Management
Scrum
Apply
≈ $10k – $25k per year (Estimated) • In office • 4+ years exp • Noida
SQL
Databases
MySQL
PostgreSQL
Apply
≈ $47k – $119k per year (Estimated) • In office • Bachelor's Degree • Duluth
Management
Outlook
Microsoft Teams
Microsoft Office
Apply
≈ $44k – $90k per year (Estimated) • In office • 2+ years exp • Bachelor's Degree • Chandler
Python
Java
SQL
C#
Cybersecurity
HIPAA
Management
Outlook
Microsoft Teams
Microsoft Office
Apply
In office
DevOps
SLI/SLO/SLA
Cybersecurity
Active Directory
Management
ITIL
Service Desk
Apply
$19k per year • In office • 1+ year exp • Moscow
1C
DevOps
Linux
Windows
Apply
≈ $14k – $27k per year (Estimated) • In office • 1+ year exp • Moscow
1C
Databases
MS SQL
DevOps
Proxmox VE
Windows
DNS
DHCP
VPN
VLAN
Apply
≈ $25k – $55k per year (Estimated) • Hybrid • 3+ years exp • Moscow
Python
Python
Asyncio
AI/ML
LangGraph
Weights & Biases
LangChain
LoRA
Embeddings
Function Calling
AI Agents
NLP
Arize Phoenix
DeepEval
LangSmith
PEFT
QLoRA
PyTorch
LLM
RAG
Mixture of Experts
LLMOps
SFT
KV Cache
DevOps
CI/CD
Git
Linux
Apply
≈ $13k – $27k per year (Estimated) • Hybrid • Moscow
DevOps
Zabbix
Linux
VPN
BGP
OSPF
MPLS
Apply
Hybrid • Full-Time • Bengaluru
Python
Go
C++
DevOps
Linux
Apply
Equity • In office • Full-Time • 6+ years exp • Bachelor's Degree
Python
DevOps
GCP
Azure
AWS
Linux
TCP/IP
DNS
VPN
BGP
OSPF
Cybersecurity
Wireshark
Tcpdump
FortiGate
SIEM
Apply
≈ $178k – $370k per year (Estimated) • Equity • Hybrid • Full-Time • 10+ years exp • San Francisco
AI/ML
Red Teaming
Apply
≈ $188k – $340k per year (Estimated) • Equity • Hybrid • Full-Time • 8+ years exp • San Francisco
Python
DevOps
GCP
Azure
AWS
Apply
≈ $194k – $349k per year (Estimated) • Equity • Hybrid • Full-Time • 8+ years exp • San Francisco
Python
Databases
Apache Iceberg
Presto
Google BigQuery
Amazon Redshift
Trino
BigQuery
DevOps
Terraform
GCP
AWS CDK
Pulumi
Azure
AWS
Platform Engineering
Apply
≈ $192k – $346k per year (Estimated) • Equity • Hybrid • Full-Time • 7+ years exp • San Francisco
Python
Prolog
DevOps
GCP
AWS CDK
Pulumi
Azure
AWS
Platform Engineering
Apply
See all jobs
This is one of many
988,386 more open roles from verified company boards, updated every day.