Recognized as a 2026 Gartner® Peer Insights™ Customers’ Choice for DSPM
Get the Report
Decor Banner

Senior / Staff Software Engineer — Endpoint Agent Platform

We are building a cross-platform endpoint agent platform for enterprise data security. You will join the Endpoint Agent Services team, which owns the user-space management agent that runs continuously on every managed device. This agent is responsible for authentication, policy sync, telemetry, self-update, health monitoring, local coordination, and user notifications across macOS and Windows fleets.

This role is focused on the user-space endpoint agent/service, not kernel drivers or interception layers. The agent coordinates with native enforcement components and cloud services, but the candidate does not need to build macOS Network Extensions, Windows WFP/MiniFilter drivers, or packet/file-system interception components. We are prioritizing engineers who have built reliable endpoint agents, desktop services, device-management clients, security clients, VPN/ZTNA/SASE clients, MDM/UEM agents, or observability agents that operate safely at fleet scale.

Experience of years: 5 to 12 years

What You'll Do:

  • Design and build the core endpoint agent service, running as a privileged background daemon/service on macOS and Windows
  • Implement device and user authentication flows (e.g., mTLS, OAuth/OIDC device flows, certificate-based identity) between the endpoint and cloud services
  • Build the policy client: fetching, caching, versioning, and safely applying policies from the backend, with rollback and offline-resilience support
  • Own telemetry pipelines: structured event collection, batching, local buffering, and reliable upload with backpressure handling
  • Build the self-update mechanism for the endpoint agent, including staged rollout, signature verification, rollback-on-failure, and safe recovery from partial updates
  • Implement health-check and watchdog logic — detecting crashed or hung components, restarting services when safe, and reporting endpoint health upstream
  • Design local IPC/RPC interfaces that allow the user-space agent to coordinate cleanly with native macOS and Windows components
  • Build the notification/UI surface layer (system tray, native notification APIs) for policy prompts, block notices, and user consent flows
  • Coordinate with native enforcement components and cloud services to manage device identity, local trust anchors, proxy credentials, and policy-driven behavior
  • Collaborate closely with macOS, Windows, backend, proxy, and security teams to define stable cross-component contracts
  • Contribute to architecture decisions around resilience, tamper-resistance, minimal privilege, and performance (CPU/memory footprint on constrained enterprise laptops)
  • Participate in incident response and root-cause analysis for production fleet issues
  • Mentor engineers, review designs/code, and (at Staff level) drive technical strategy across the service team

Required Qualifications:

  • 6+ years (Senior) / 9+ years (Staff) of professional software engineering experience
  • Strong experience building endpoint agents, desktop services, device-management clients, security clients, VPN/ZTNA/SASE clients, MDM/UEM agents, or observability agents — you understand fleet heterogeneity, service lifecycle management, tamper resistance, low-resource operation, and the operational realities of running software on end-user machines
  • Proven experience building long-running user-space background services/daemons on macOS and/or Windows, including launchd/LaunchDaemon/LaunchAgent, Windows Services, service lifecycle management, and safe recovery patterns, in any systems language such as Go, C++, Rust, C#, or Swift
  • Experience with secure authentication/identity patterns: OAuth2/OIDC, mTLS client auth, token refresh/rotation, secure credential storage (Keychain/DPAPI/Credential Manager) 
  • Experience designing systems for reliability under adverse conditions: intermittent connectivity, partial failures, crash recovery, safe rollback
  • Solid grasp of concurrency and resource lifecycle management in your primary language — this runs on end-user machines, so leaks and runaway CPU/memory are unacceptable
  • Experience shipping and operating auto-update systems with cryptographic signature verification
  • Familiarity with observability: structured logging, metrics, tracing, and building telemetry pipelines with local buffering/backpressure
  • Security mindset: comfortable reasoning about attack surface, tamper resistance, privilege separation, and secure-by-default design — this is security-adjacent software running with elevated privileges
  • Strong cross-team collaboration skills — this role sits at the intersection of endpoint platform, native OS, backend, proxy, and security teams, so clear API/contract design and communication matter as much as code

Strongly Preferred:

  • Production experience writing Go, or strong willingness/aptitude to adopt it as the team’s primary language
  • Experience with DLP, EDR, XDR, VPN, ZTNA, SASE, secure web gateway, MDM/UEM, or endpoint observability products
  • Experience with code signing, notarization (macOS), and Authenticode (Windows) for shipping privileged binaries
  • Familiarity with remote/forward-proxy architectures (e.g., Envoy) and how an endpoint agent coordinates with a remote proxy for traffic redirection, CA trust distribution, and proxy authentication
  • Familiarity with macOS Network Extension or Windows WFP/MiniFilter internals is helpful, but this role does not require owning kernel drivers or interception layers
  • Experience with policy-as-data systems — versioned policy schemas, safe migration, staged/canary rollout of policy changes
  • Familiarity with enterprise device management concepts (MDM profiles, Intune/Jamf integration, compliance reporting)
  • Experience building native OS notification UX (menu bar apps, system tray apps) — often via cgo/Objective-C bridges on macOS or Windows syscall/COM interop

What Success Looks Like in 6–12 Months:

  • The user-space endpoint agent reliably authenticates, fetches policy, updates itself, and reports telemetry across a large, heterogeneous fleet with minimal support escalations
  • Clean, versioned contracts exist between the endpoint agent, native macOS/Windows components, backend services, and proxy services, reducing cross-team friction
  • Self-update and rollback have been proven safe in production with zero fleet-bricking incidents
  • CPU/memory footprint stays within agreed budgets on low-end enterprise hardware

Notice: Concentric AI never asks for money nor paid certifications during the interview process; such behavior is a known scam of which we’ve been made aware.

Other positions

Test Automation Engineer (Full-Time)
Bengaluru & Pune

The ideal candidate is a Python expert with hands-on experience in automation frameworks, CI/CD, and Linux systems. This role requires a strong understanding of microservices and Kubernetes, with exposure to cloud infrastructure and system-level automation.

Learn More
Principal Engineer — Cloud Data Plane & Traffic Processing

We are building the inline cloud data plane that powers a next-generation AI security platform. This service terminates TLS, inspects and processes enterprise AI traffic in real time, and applies policy, classification, orchestration, auditing, and analytics — at millisecond latencies under production SaaS load across multiple global regions.

Learn More