Live opening · Posted 9 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
We are looking for 3 Backend / Endpoint Engineers who will design and develop the core components of our XDR platform from lightweight endpoint agents running on Windows and Linux systems to the high- throughput backend services that process and analyse security telemetry. You will work at the intersection of systems programming and cloud-native backend development, building software that powers real-time threat detection for enterprise customers.
The candidate will have responsibilities across the following functions:
Endpoint Agent Development:
Design, develop, and maintain lightweight endpoint agents for Windows and Linux environments using C++ and Go.
Implement kernel-level and user-space hooks for process monitoring, file system events, network traffic capture, and registry changes.
Optimise agent footprint for minimal CPU, memory, and disk impact on production endpoints.
Build secure agent-to-cloud communication channels with robust encryption and authentication.
Develop agent update, rollback, and remote configuration management capabilities.
Backend Services and Data Pipelines:
Architect and implement high-throughput backend microservices in Python and Go to ingest, process, and enrich endpoint telemetry at scale.
Build event streaming pipelines using Kafka / Pulsar for real-time telemetry processing and detection rule evaluation.
Design and optimise data storage strategies for high-volume security events (ClickHouse, Elasticsearch, PostgreSQL).
Develop RESTful and gRPC APIs for integration with SIEM, SOAR, and third-party security tools.
Implement detection engine components that evaluate behavioural rules, YARA signatures, and ML- based anomaly scores.
Detection and Response Engineering:
Collaborate with the threat intelligence and SOC teams to translate detection logic into efficient, low- latency rules.
Build automated response action frameworks, process kill, file quarantine, and network isolation triggered from the backend.
Implement forensic data collection capabilities for incident investigation workflows.
Develop testing harnesses and simulation environments for validating detection efficacy.
Platform Reliability and Security:
Conduct code reviews with a strong focus on security, correctness, and performance.
Implement CI/CD pipelines for agent and backend service deployments.
Participate in on-call rotation for production platform incidents.
Maintain comprehensive technical documentation for all components.
The core requirements for the job include the following:
Languages:
Python (primary backend language).
Go (services and agent components).
C / C++ (endpoint agent and kernel).
Bash / PowerShell scripting.
Platform and OS:
Windows internals (Win32 API, ETW, WFP).
Linux internals (eBPF, netfilter, inotify).
Cross-platform development experience.
Container environments (Docker, K8S).
Backend and APIs:
REST API design and development.
gRPC / Protobuf.
Kafka / event streaming.
Microservices architecture.
Security Domain:
Understanding of EDR/XDR concepts.
Malware behaviour and evasion techniques.
MITRE ATT and CK framework.
YARA rules and detection logic.
Mandatory Requirements:
Systems Programming Proficiency.
Hands-on experience in C/C++ or Go for systems-level or performance-critical software.
Experience with Windows or Linux internals is non-negotiable.
Backend Engineering at Scale: Proven ability to build and operate high-throughput backend services processing millions of events per second in a production environment.
Security Domain Awareness: Working knowledge of endpoint security concepts, threat detection approaches, and familiarity with the MITRE.
ATT and CK framework:
API Development.
Strong experience designing and building REST or gRPC APIs consumed by external tools and internal platform components.
Qualifications:
B. Tech / B. E. / M. Tech in Computer Science, Information Security, or equivalent.
3-7 years of hands-on software engineering experience with at least 2 years in systems or security engineering.
Strong fundamentals in data structures, algorithms, concurrency, and distributed systems.
Experience working in Agile/Scrum engineering teams with CI/CD workflows.
Prior exposure to EDR, SIEM, or security platform engineering is a strong plus.
Experience
4-7 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.