05 Sep
|
Starcom consulting
|
India
05 Sep
Starcom consulting
India
The Role The client is hiring an architect-level lead engineer to work at the deepest layer of the product. This is genuinely rare-skills work: software that runs when there is no working operating system, boots over the internet, takes over Windows setup flows, and hooks low-level OS mechanics to update machines without interrupting the people using them. The role sits at the intersection of software engineering and enterprise IT operations, so you need to understand both how Windows works internally and how large IT organizations actually deploy, patch, and manage fleets. You will collaborate directly and frequently with the co-founder/CTO and Head of Product to turn product concepts into technical designs, and you will help lead the engineers building alongside you. The domain is unusual enough that even engineers with near-ideal backgrounds have taken several months to become fully productive. The client is looking for someone who wants to go deep on one hard product and stay.
*Development Responsibilities* The on-endpoint decision engine: endpoint state scanning, desired-state policy interpretation, vulnerability-driven (CVE) prioritization, and self-generated task sequences with dependency ordering and multi-reboot orchestration. Zero-disruption update mechanics: detecting in-use applications, deferring and retrying patches, and hooking the Windows startup sequence to complete updates that cannot run while someone is working. Bare-metal OS deployment and internet boot: a WinPE-based recovery environment, Microsoft-signed boot code, and fully programmatic (image-free) Windows installation, including recovery when the OS is unbootable or the drive is gone. Windows Autopilot completion: the product's takeover of Autopilot's single-reboot setup flow to deliver ordered, dependency-aware, fully configured builds,
including hands-off staging by device suppliers. Pre-boot identity: Microsoft Entra ID (Azure AD) device-code authentication from the recovery workplace, where the device has no OS, certificates, or domain trust. Content delivery infrastructure: Azure Blob storage and CDN-backed cloud repositories, plus on-premises local repositories and distribution points with network-aware source selection. Hardware enablement: driver, firmware, and BIOS/UEFI update automation across supported OEM device families. Virtual endpoints: provisioning for VDI, Windows 365 Cloud PCs, and Azure Virtual Desktop. Roadmap exploration: future platform expansion, including a potential macOS edition of the product.
*What We're Looking For* Minimum of 10+ years of professional software engineering experience in systems-level Windows work. Very deep Windows internals expertise: boot sequence, services, registry, security tokens and privilege management, and kernel-adjacent (ring 0/ring 1) development.(mandatory) Hands-on mastery of Windows OS deployment: WinPE, task sequencing, unattended installation, driver management, and application packaging with install-order dependencies. (mandatory) Working knowledge of the endpoint management ecosystem: Microsoft Intune, Configuration Manager (SCCM), Windows Autopilot, and/or comparable platforms such as BigFix or Kaseya, plus an understanding of the gaps enterprises hit with them.
Expert in systems programming on Windows (e.g., C/C++ and/or C#/.NET) plus advanced PowerShell. (mandatory) Experience with code signing and secure-boot requirements (EV certificates, Microsoft signing and external security review processes), or the demonstrated depth to own them. Architect-level design ability: you can take a loosely specified product concept, pressure-test it, and turn it into a sound technical design in direct discussion with the CTO. Experience leading or mentoring a small engineering team. Fluent English and strong real-time verbal collaboration; this role runs on frequent, direct design conversations, not ticket queues. Very Strongly Nice to Have Prior work building commercial Windows deployment, patching, or endpoint management products. Vulnerability management background (CVE/CVSS-driven prioritization and remediation). Azure infrastructure and CDN experience. Device driver or firmware update development. macOS internals and Apple developer ecosystem experience (code signing, notarization, mass-deployment approvals), which is valuable for the client's future Mac roadmap. Location, Hours, and Commitment Fully remote. The client's development team is remote-first and no office attendance is required; a reliable home office setup (power and internet) is expected. Time zones matter. The role involves daily, real-time design discussions with U.S.-based leadership in Central and Pacific time; candidates in Americas time zones are strongly preferred. Fully dedicated. This is a 100% dedicated, full-time engagement, not a shared or fractional allocation. Long-term. Ramp-up on this codebase takes months even for ideally qualified engineers; the client is investing in someone who will commit for the long haul.
📌 Lead Software Engineer/Architect - Windows OS Internals & Endpoint Automation (India)
🏢 Starcom consulting
📍 India