20 Aug
|
Concentric AI
|
Bengaluru
20 Aug
Concentric AI
Bengaluru
We are building a cross-platform endpoint agent platform for enterprise data security. You will join the Endpoint Agent Services team, which owns the user-space management agent that runs continuously on every managed device. This agent is responsible for authentication, policy sync, telemetry, self-update, health monitoring, local coordination, and user notifications across macOS and Windows fleets.
Apply Here
Apply Here
Apply Here
This role is focused on the user-space endpoint agent/service, not kernel drivers or interception layers. The agent coordinates with native enforcement components and cloud services, but the candidate does not need to build macOS Network Extensions, Windows WFP/MiniFilter drivers, or packet/file-system interception components. We are prioritizing engineers who have built reliable endpoint agents, desktop services, device-management clients, security clients, VPN/ZTNA/SASE clients, MDM/UEM agents, or observability agents that operate safely at fleet scale.
Experience of years: 5 to 12 years
What You'll Do:
- Design and build the core endpoint agent service, running as a privileged background daemon/service on macOS and Windows
- Implement device and user authentication flows (e.g., mTLS, OAuth/OIDC device flows, certificate-based identity) between the endpoint and cloud services
- Build the policy client: fetching, caching, versioning, and safely applying policies from the backend, with rollback and offline-resilience support
- Own telemetry pipelines: structured event collection, batching, local buffering, and reliable upload with backpressure handling
- Build the self-update mechanism for the endpoint agent, including staged rollout, signature verification, rollback-on-failure, and safe recovery from partial updates
- Implement health-check and watchdog logic — detecting crashed or hung components, restarting services when safe, and reporting endpoint health upstream
- Design local IPC/RPC interfaces that allow the user-space agent to coordinate cleanly with native macOS and Windows components
- Build the notification/UI surface layer (system tray, native notification APIs) for policy prompts, block notices, and user consent flows
- Coordinate with native enforcement components and cloud services to manage device identity, local trust anchors, proxy credentials, and policy-driven behavior
- Collaborate closely with macOS, Windows, backend, proxy, and security teams to define stable cross-component contracts
- Contribute to architecture decisions around resilience, tamper-resistance, minimal privilege,
and performance (CPU/memory footprint on constrained enterprise laptops)
- Participate in incident response and root-cause analysis for production fleet issues
- Mentor engineers, review designs/code, and (at Staff level) drive technical strategy across the service team
Required Qualifications:
- 6+ years (Senior) / 9+ years (Staff) of professional software engineering experience
- Robust experience building endpoint agents, desktop services, device-management clients, security clients, VPN/ZTNA/SASE clients, MDM/UEM agents, or observability agents — you understand fleet heterogeneity, service lifecycle management, tamper resistance, low-resource operation, and the operational realities of running software on end-user machines
- Proven experience building long-running user-space background services/daemons on macOS and/or Windows, including launchd/LaunchDaemon/LaunchAgent, Windows Services, service lifecycle management, and safe recovery patterns, in any systems language such as Go, C++, Rust, C#, or Swift
- Experience with secure authentication/identity patterns: OAuth2/OIDC, mTLS client auth, token refresh/rotation, secure credential storage (Keychain/DPAPI/Credential Manager)
- Experience designing systems for reliability under adverse conditions: intermittent connectivity, partial failures, crash recovery, safe rollback
- Solid grasp of concurrency and resource lifecycle management in your primary language — this runs on end-user machines, so leaks and runaway CPU/memory are unacceptable
- Experience shipping and operating auto-update systems with cryptographic signature verification
- Familiarity with observability: structured logging, metrics, tracing, and building telemetry pipelines with local buffering/backpressure
- Security mindset: comfortable reasoning about attack surface, tamper resistance, privilege separation, and secure-by-default design — this is security-adjacent software running with elevated privileges
- Strong cross-team collaboration skills — this role sits at the intersection of endpoint platform, native OS, backend, proxy, and security teams, so clear API/contract design and communication matter as much as code
Strongly Preferred:
- Production experience writing Go,
or strong willingness/aptitude to adopt it as the team’s primary language
- Experience with DLP, EDR, XDR, VPN, ZTNA, SASE, secure web gateway, MDM/UEM, or endpoint observability products
- Experience with code signing, notarization (macOS), and Authenticode (Windows) for shipping privileged binaries
- Familiarity with remote/forward-proxy architectures (e.g., Envoy) and how an endpoint agent coordinates with a remote proxy for traffic redirection, CA trust distribution, and proxy authentication
- Familiarity with macOS Network Extension or Windows WFP/MiniFilter internals is helpful, but this role does not require owning kernel drivers or interception layers
- Experience with policy-as-data systems — versioned policy schemas, safe migration, staged/canary rollout of policy changes
- Familiarity with enterprise device management concepts (MDM profiles, Intune/Jamf integration, compliance reporting)
- Experience building native OS notification UX (menu bar apps, system tray apps) — often via cgo/Objective-C bridges on macOS or Windows syscall/COM interop
What Success Looks Like in 6–12 Months:
- The user-space endpoint agent reliably authenticates, fetches policy, updates itself, and reports telemetry across a large, heterogeneous fleet with minimal support escalations
- Clean, versioned contracts exist between the endpoint agent, native macOS/Windows components, backend services, and proxy services, reducing cross-team friction
- Self-update and rollback have been proven safe in production with zero fleet-bricking incidents
- CPU/memory footprint stays within agreed budgets on low-end enterprise hardware
Notice: Concentric AI never asks for money nor paid certifications during the interview process; such behavior is a known scam of which we’ve been made aware.
Other positions
View All
Test Automation Engineer (Full-Time)
Bengaluru & Pune The ideal candidate is a Python expert with hands-on experience in automation frameworks, CI/CD, and Linux systems. This role requires a strong understanding of microservices and Kubernetes, with exposure to cloud infrastructure and system-level automation.
Learn More
Principal Engineer — Cloud Data Plane & Traffic Processing
We are building the inline cloud data plane that powers a next-generation AI security platform. This service terminates TLS, inspects and processes enterprise AI traffic in real time, and applies policy, classification, orchestration, auditing, and analytics — at millisecond latencies under production SaaS load across multiple global regions.
Learn More
View All
📌 Senior (Bengaluru)
🏢 Concentric AI
📍 Bengaluru