beyondtrust

Staff Software Development Engineer - macOS Endpoint

Apply Now

At a Glance

Location
Canada | Remote United States
Work Regime
remote
Experience
8+ years
Posted
2026-07-21T14:03:41-04:00

Key Requirements

Required Skills

AgileRustSwift

Domain Knowledge

  • Engineering

Requirements

Deep macOS system internals - the Endpoint Security framework, System and Network Extensions, the code-signing and notarization model, launchd and XPC, TCC and entitlements - backed by production systems programming in C, C++, Objective-C, Swift, or Rust.

Hands-on work with Endpoint Security for enforcement, with real comfort on the synchronous authorization path: handling AUTH events within Apple's deadline, reasoning about the allow/deny verdict model, and keeping the client off the path that hangs or gets killed.

Experience building a System Extension end to end transfers directly.

The macOS deployment reality: System Extension activation and user approval, MDM-managed deployment, entitlement provisioning, code signing, and notarization, plus the operational cost of shipping this to a large managed fleet.

The macOS isolation and security model - the App Sandbox, TCC, SIP, and how they intersect with endpoint security tooling.

Debugging and performance tooling: lldb, Instruments, dtrace, the unified logging system (log / Console), and spindump for hang analysis.

Responsibilities

As Staff Software Development Engineer, you'll be the macOS authority for the runtime enforcement layer of our Identity Security Platform.

These components decide whether to permit or deny each action an identity or AI agent attempts on a macOS endpoint.

You'll set the technical direction for enforcement on macOS and own it end to end.

That means hooks that make the right call in real time, across the fleet, without breaking legitimate workloads.

Peer engineers own the Linux and Windows enforcement surfaces.

You want your code to be the thing that stops a compromised credential or a runaway AI coding agent before it impacts production.

About the Company

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at

www.beyondtrust.com

.