We are looking for a Senior Linux Security Developer to design and develop security capabilities deep inside the Linux OS - kernel internals, eBPF, OS telemetry, enforcement mechanisms, and security agents. You will own architecture decisions, investigate new attack
surfaces, prototype novel approaches, and turn successful concepts into production technologies.
Design and implement high-performance Linux security components in kernel and user space (kernel modules, eBPF, system services, security agents), including tamper-resistant mechanisms for adversarial environments.
Build scalable Linux endpoint capabilities for telemetry, detection, prevention, and policy enforcement.
Investigate Linux kernel subsystems to find opportunities for new detection and prevention capabilities, including protection of AI-agent workloads (autonomous processes, tool execution, privilege usage, filesystem/network activity).
Translate research ideas into efficient, production-grade implementations (performance, concurrency, reliability, security), and mentor engineers in systems programming and Linux security.
Requirements: 6+ years of professional development with significant hands-on C and/or C++.
3+ years of Linux kernel development or low-level Linux systems development, with hands-on experience in eBPF/BPF, LSM, kernel tracing/instrumentation, or security frameworks.
Deep understanding of Linux internals: processes, memory management, scheduling, syscalls, filesystems, networking, kernel/user-space interaction, namespaces, containers.
Strong debugging and performance analysis skills ( gdb , perf , strace , ftrace ).
Strong concurrency, synchronization, memory management, and performance optimization, building software that runs reliably under high load and adversarial conditions.
3+ years in endpoint/host security, malware or vulnerability research, or runtime security.
Ability to independently investigate unfamiliar areas and turn findings into working prototypes; strong English communication skills.
Comfortable reading kernel and security source code, analyzing attacker techniques, and validating defenses against performance, coverage, and evasion.
AI-Assisted Engineering
We actively use AI-assisted development tools in our R&D workflow. Experience with AI
coding assistants and agentic tools is an advantage; we value the ability to critically validate
AI-generated code, especially in security-sensitive, low-level software.
Nice to Have:
EDR/XDR agents or endpoint telemetry systems
Linux exploitation, malware, rootkits, persistence, or evasion techniques
Linux security mechanisms: SELinux, AppArmor, seccomp, capabilities, cgroups, Landlock
Container and cloud workload security; exploitation mitigations or runtime security controls
Reverse engineering, vulnerability research
Contributions to the Linux kernel, eBPF, or open-source security ecosystem; M.Sc./Ph.D., published research, patents, or talks.
This position is open to all candidates.