Remotery

Senior/Staff Software Development Engineer - macOS Endpoint

Posted 4 hours ago

This is a fully remote position, open to applicants in Canada.

πŸ“‹ Description

β€’ Create, develop, and take ownership of our Endpoint Security client, which includes process execution, file and signal events, along with synchronous authorization events where you can either permit or restrict actions. You'll prevent operations by issuing a deny verdict before the event is completed, rather than logging it afterward, and will construct the userspace agent responsible for installing and managing the extension.

β€’ Manage the enforcement decision pathway: capturing events from Endpoint Security, evaluating policies, and implementing deny decisions within Apple's authorization timeframe to ensure that a delayed verdict does not hinder the system or trigger automatic allowances.

β€’ Reduce enforcement mode latency on the authorization pathway as we expand across large fleets. This will involve enriching processes, caching code signatures and hashes with eviction during heavy process churn, and resolving process ancestry.

β€’ Broaden enforcement across network and content control through a Network Extension content filter for socket- and flow-level policies, linked to the same identity and process context as your Endpoint Security decisions. Much of this integration is new and is central to the role.

β€’ Strengthen portability and stability across various macOS versions and both Apple Silicon and Intel architectures, ensuring that enforcement loads and functions properly on the OS versions utilized by customers. You will address Endpoint Security event and capability variations across releases, manage System Extension activation and approval processes, TCC and entitlement requirements, and implement graceful degradation when a capability is unavailable.

β€’ Collaborate with Linux and Windows enforcement engineers and the policy-backend team on shared frameworks: policy semantics, cross-stack conformity, event schema, and the common Rust agent. You will represent macOS during cross-organization architecture evaluations.

β€’ Analyze requirements to identify gaps and risks, propose simplifications, and articulate trade-offs to both technical and non-technical stakeholders.

β€’ Elevate the engineering standards. You will assume end-to-end responsibility from design to production and will bear additional responsibility in cases where a bug could lead to incorrect security decisions or a stalled endpoint across the fleet, beyond just a single process crash.

β€’ Coach senior and mid-level engineers on macOS systems and Endpoint Security expertise.


⛳️ Requirements

β€’ Extensive knowledge of macOS system internals, including the Endpoint Security framework, System and Network Extensions, the code-signing and notarization processes, launchd and XPC, TCC, and entitlements, supported by hands-on systems programming experience in C, C++, Objective-C, Swift, or Rust.

β€’ Practical experience with Endpoint Security for enforcement, particularly comfortable with the synchronous authorization pathway: managing AUTH events within Apple's deadlines, reasoning about the allow/deny verdict model, and preventing the client from entering pathways that may hang or be terminated. Experience in building a System Extension from start to finish is directly applicable.

β€’ Understanding of the macOS deployment landscape, including System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization, along with the operational implications of deploying this to a large managed fleet.

β€’ Familiarity with the macOS isolation and security model, including the App Sandbox, TCC, SIP, and how these interact with endpoint security tools.

β€’ Proficiency in debugging and performance tools: lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for analyzing hangs.

β€’ 8+ years of experience in systems-level software engineering, demonstrating significant depth in macOS system software.

β€’ Proven experience in AI-first development. We build this platform through agentic tools. AI-driven design exploration, code generation, adversarial plan review, and automated pre-merge quality gates are integral to our processes. You utilize Claude Code or a similar tool as a fundamental part of your daily activities and are able to articulate how it enhances both your speed and thoroughness. This is especially crucial in correctness- and security-sensitive enforcement code, where you must know precisely when to halt and verify manually.

β€’ A solid understanding of systems design patterns and their trade-offs at the OS-enforcement interface.

β€’ Comprehensive experience throughout the product lifecycle, including product releases, in an agile environment.

β€’ A history of technical leadership in intricate, ambiguous projects that span multiple teams.


🏝️ Benefits

β€’ Health insurance

β€’ Retirement plans

β€’ Paid time off

β€’ Flexible work arrangements

β€’ Professional development

β€’ Bonuses

People also viewed

Spartech LLC4 hours ago

Senior Process Engineer

US flagMaryland, +1 more stateFull-timeFull-stack Engineer
ApplyView job
Montreal Oficial4 hours ago

Senior Software Developer

BR flagBrazil OnlyFull-timeFull-stack Engineer
ApplyView job
HappyOps4 hours ago

Senior Full Stack Software Developer – German, French (C1+)

DE flagGermany OnlyFull-timeFull-stack Engineer€70k – €100k/year
ApplyView job
Medallion4 hours ago

Software Engineer

US flagUnited States OnlyFull-timeFull-stack Engineer$145k – $175k/year
ApplyView job
Smile Digital Health4 hours ago

Senior Software Developer

CA flagCanada OnlyFull-timeFull-stack Engineer$115k – $135k/year
ApplyView job
CVS Health4 hours ago

Senior Software Development Engineer

US flagNew Jersey OnlyFull-timeFull-stack Engineer$102k – $203.9k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers