
Endpoint Engineer, EDR – macOS
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in North America.
• Design, develop, and deploy the privileged daemon, individual agents, and system extensions that form the macOS agent.
• Monitor process, file, network, device, and user interaction activities, translating them into intent signals.
• Take full ownership of EDR-class detection and prevention throughout the entire process, which includes instrumentation, event enrichment, correlation, rule evaluation, and interception logic.
• Implement telemetry using the Endpoint Security framework, Network Extensions, FSEvents, IOKit, and event taps.
• Design and manage the launchd-controlled, multi-process architecture and XPC protocols.
• Implement peer authentication based on code-signing and safely manage untrusted input in privileged processes.
• Strengthen the agent against tampering, bypassing, and evasion attempts.
• Maintain strict CPU, memory, and I/O usage limits while processing thousands of events each second.
• Develop test harnesses and automated regression tests, including VM-based end-to-end testing.
• Address high-severity customer escalations related to crashes, hangs, performance degradations, missed detections, permission issues, and deployment failures.
• Collaborate with security research, AI, platform, and product teams on machine learning classification, policy enforcement, interventions, and investigation timelines.
• Review code, mentor engineers, document design choices, and collectively ensure release quality and on-call responsibilities.
• Over 10 years of experience in designing, developing, and delivering production-grade native systems software.
• Proficient in Swift, with a strong grasp of modern concurrency concepts (actors, Sendable, structured concurrency).
• Significant background in endpoint security, OS internals, or similar performance-sensitive programming.
• In-depth understanding of macOS internals, encompassing process and thread lifecycle, memory management, file systems, code signing and entitlements, launchd, XPC and Mach IPC, and the TCC permission model.
• Practical experience with the Endpoint Security framework and/or Network Extensions.
• Familiarity with the system extension lifecycle that has succeeded kernel extensions.
• Experience in building or managing an EDR, EPP, XDR, DLP, or insider-risk product, or equivalent detection-and-response engineering.
• Solid understanding of attacker TTPs.
• Low-level debugging capabilities using lldb, crash-dump and hang analysis, as well as Instruments or similar tools.
• Experience with multithreaded and concurrent programming under load conditions.
• Proven history of deploying code across large fleets without compromising end-user experience.
• Insight into enterprise deployment realities, including MDM profiles, notarization processes, staged rollouts, and auto-updates.
• Proficient in scripting languages such as Python, shell, or similar.
• Strong written and verbal communication skills, especially when interacting with distributed teams and customers as required.
• Background in reverse engineering, malware analysis, or exploit and vulnerability research is a plus.
• Experience with on-device ML inference (Core ML, ONNX Runtime, or llama.cpp-class runtimes) in a resource-limited agent is a bonus.
• Familiarity with browser extensions or native messaging integrations for telemetry collection is advantageous.
• Cross-platform endpoint agent experience, particularly with Windows or Linux sensors alongside macOS, is a bonus.
• Meaningful equity in addition to salary.
• Ent covers 90% of medical, dental, and vision insurance costs.
• 75% coverage provided for dependents.
• Flexible paid time off (PTO).
• 12 weeks of fully paid maternity leave (for birth, adoption, or foster care).
• 8 weeks of fully paid paternity leave.
• A monthly $100 lifestyle account for fitness, wellness, learning, and additional expenses.
• A $500 stipend for home office setup for remote employees.
Miratech
Get handpicked remote jobs straight to your inbox weekly.