Staff/Principal Software Engineer-Windows Endpoint Agent
Cloudzero · Remote · Remoto
Es un puesto remoto.
El aviso publica el sueldo: USD 220.000 a 290.000 por año.
Por el título, buscan un perfil principal o head.
Lo publica Cloudzero y está vigente desde el 31 de agosto de 2026.
Toca Postularme y entra con tu cuenta de Google: te llevamos al aviso en Ashby y te ayudamos a armar el CV para este puesto.
PostularmeDescripción del puesto
ABOUT THE ROLE
CloudZero's AI cost intelligence starts at the endpoint. Our macOS collector already captures what coding agents and AI workloads actually cost on the developer's machine: token usage, cost per workflow, latency, and where the value goes. Windows is next, and it is the platform most of our enterprise customers run on.
We are not starting from zero. We have a working proof of concept, a Windows Filtering Platform callout driver that redirects AI provider traffic to a user-mode relay, and that relay shares the same Go capture core as our macOS agent. What we need now is an engineer who can take that from a test-signed lab prototype to something we can sign, ship, and run on customer machines without ever getting in the user's way.
This is real Windows systems work. You will own the kernel-mode driver, the user-mode service, the signing and packaging story, and the fail-open behavior that keeps a customer's network working even when our agent does not. A bug here can blue-screen a machine or break someone's connectivity, so the bar for care is high and the ownership is real. You will set the pattern that every endpoint after Windows follows.
WHAT YOU’LL DO
- Take the Windows agent from proof of concept to a signed, installable, auto-updating product that runs on Windows.
- Own the WFP callout driver (KMDF, C/C++) and the user-mode Go relay that reuses our shared capture core, and keep the two in lockstep as both evolve
- Solve production kernel-mode driver signing, EV certificate, Microsoft attestation, Secure Boot, without weakening code integrity on the customer's machine
- Build the installer, update, and clean uninstall path (MSI or MSIX), and the enterprise deployment story
- Design for fail-open. Non-AI traffic must never touch our code, and a driver or service failure must never break the endpoint
- Manage local CA trust and TLS interception, so it is safe, transparent, and fully reversible
- Build the endpoint client in Electron and TypeScript, and work directly with product on what the Windows agent exposes to the customer and where it needs to reach parity with macOS
- Raise the bar for the engineers around you through code review, design feedback, and direct mentorship
WHAT YOU BRING
- Deep Windows systems experience. You have shipped software that runs as a service, a driver, or an endpoint agent on Windows, not just applications on top of it
- Kernel-mode or low-level Windows development. KMDF or WDM, the Windows Driver Kit, and comfort debugging with WinDbg
- Working knowledge of Windows networking internals, the Windows Filtering Platform or a comparable traffic interception approach
- Proficiency in C or C++ for the driver side, in Go or another systems language for the user-mode side. You can read and reason about code in a language you did not write
- Comfort spanning the stack from a kernel driver to a desktop UI, or the self-awareness to say which end is your strength and where you will lean on the team
- Hands-on experience with Windows code signing and the realities of shipping a signed kernel driver, Authenticode, EV certificates, and Microsoft's attestation or WHQL process
- A track record of shipping endpoint software to machines you do not control, with the instinct to design for failure, cleanup, and least privilege
- The judgment to know when a kernel-level solution is worth it and when it is not, and the ability to explain that tradeoff to engineers, product, and leadership
- A track record of shipping, not just designing
BONUS IF YOU HAVE...
- Built endpoint security, EDR, DLP, or network monitoring agents at enterprise scale
- Experience with TLS interception, MITM proxies, or certificate trust management
- Packaging and distribution experience with MSIX, MSI or WiX, or auto-update frameworks
- Familiarity with enterprise Windows deployment through Intune, MDM, or Group Policy
- Cross-platform endpoint experience spanning Windows and m
Toca Postularme y entra con tu cuenta de Google: te llevamos al aviso en Ashby y te ayudamos a armar el CV para este puesto.
PostularmePreguntas frecuentes
¿Es remoto el puesto de Staff/Principal Software Engineer-Windows Endpoint Agent?
Es un puesto remoto.
¿Cuánto paga?
El aviso publica USD 220.000 a 290.000 por año.
¿Dónde se publicó este aviso?
En Ashby. DameTrabajo lo encontró ahí y te lleva a postularte en el aviso original.