About the Linux Behavioural Engine team
The Linux Behavioural Engine team builds the runtime detection capability that protects Linux servers, workloads and containers. Our engine watches process, file, network and kernel-level activity as it happens, correlates it into meaningful behaviour, and decides in real time whether something is benign or an attack in progress.
That means we live close to the kernel, across a wide spread of distributions, kernel versions and deployment shapes bare metal, VMs, containers and managed Kubernetes. Getting this right at scale is as much a testing and infrastructure problem as it is a detection problem: a change that behaves perfectly on Ubuntu 24.04 may behave very differently on a hardened RHEL kernel or inside a locked-down EKS node.
We are a small, autonomous team that owns its own CI, its own test estate and its own quality bar. It is a good place to broaden quickly. You will get exposure to CI, cloud infrastructure, Kubernetes and low-level Linux security in one role, with senior engineers close at hand to learn from.
Role Summary
We are looking for a Software Development Engineer in Test to help run and grow the automated testing and test infrastructure behind the Linux Behavioural Engine.
The role has two halves. One is keeping the lights on: helping maintain our Buildkite CI, our multi-account AWS estate and our Kubernetes clusters (EKS, AKS and GKE) so that the team's builds and tests run reliably every day. The other is building: adding new test pipelines, writing new automated tests, and extending coverage into areas we cannot currently reach.
You will work on well-defined pieces of this independently and take on larger design work alongside more senior engineers, with the expectation that your scope grows as you get to know the system.This is a hands-on role for someone who enjoys automation and infrastructure and wants to go deeper on both.
What You Will Do
- Help maintain and improve our Buildkite CI: pipelines, agents, queues, plugins, build performance and day-to-day reliability.
- Support the cloud estate our manual, automated and CI systems run on, including routine upgrades and monitoring.
- Build new test pipelines for new features and platforms, working with senior engineers on the overall design and owning the implementation.
- Write new automated tests at a range of levels: component, integration, end-to-end and longer-running stability tests.
- Extend our platform coverage across Linux distributions, kernel versions and container runtimes, and help make adding a new target a routine task.
- Contribute to the test tooling that let engineers reproduce and run tests and scenarios easily.
- Investigate flaky tests and unreliable infrastructure, get to the actual cause, and fix it rather than retrying around it.
- Help instrument CI so the team can see build health, duration trends and failure patterns without digging.
- Work with infrastructure as code and help bring any remaining hand-built pieces onto that footing.
- Work day to day with developers and release engineering on testability and release readiness, and flag quality risks early.
- Share in keeping CI and the test estate running, alongside the rest of the team.
Skills and attributes for success
What You Will Bring
- A few years' commercial experience in test automation, SDET, QA engineering or a similar role, with a track record of writing and maintaining automated tests.
- Working programming ability in either Python, Go, C++ or Rust, and willingness to pick up the others.
- Hands-on experience with CI/CD pipelines in any modern system - Buildkite, Jenkins, GitLab CI, GitHub Actions or similar.
- Some practical cloud experience, ideally AWS, covering the basics of IAM, compute, networking and storage.
- Familiarity with containers and Kubernetes, and an appetite to work across EKS, AKS and GKE.
- Exposure to infrastructure as code such as Terraform, CloudFormation or Ansible, or a clear interest in learning it.
- Comfort with Git and modern code review workflows.
- Linux fundamentals: processes, filesystems, networking, systemd, permissions, packaging and command-line troubleshooting.
Nice to Have
- Familiarity with eBPF or other kernel-level telemetry sources.
- Experience testing across several Linux distributions (RHEL, Ubuntu, Debian, SUSE, Amazon Linux) or multiple kernel versions.
- Experience designing a test framework or harness rather than only working within an existing one.
- Observability tooling: Prometheus, Grafana, OpenTelemetry or similar.

