About the team and the mission
Every company on earth is going through an AI transformation, and almost none of them can see what their employees are actually doing with AI. We are building the endpoint that gives them that visibility and control — and Workforce AI Security is the fastest-growing area in company.
You would join a multidisciplinary group of AI researchers, cloud engineers, and OS specialists across Israel and our acquisitions, including Lakera.
The product you would work on
Our Windows agent runs on hundreds of thousands of managed Windows machines. It monitors and controls how employees use generative AI tools, enforces data-loss policy on the endpoint, and has to coexist with whatever security stack the customer already runs.
Windows is our largest deployed surface and by far our most heterogeneous one. Every customer arrives with a different combination of management tooling, antivirus, VPN and proxy already in place, and the agent has to install cleanly and stay healthy across all of them.
The work is deep platform engineering: privileged services, installation and update chains that run unattended, network interception, certificate trust, and integration with the AI developer tools people actually use.
What you would own
- The Windows agent end to end — its privileged services, the communication between them, and the installation and update path that keeps them healthy on machines you cannot log into
- Certificate trust and TLS interception on Windows — delivering and evaluating trust correctly across machine and user stores, and handling the applications that resist it
- System proxy configuration — including reconciling our state with whatever else on the machine is competing for it, long after install time
- Integration with AI developer tools — the Windows side of how we see and control what those tools do
- Coexistence — making the agent work alongside other endpoint security products, VPN clients, and cloud proxies, including the ones that treat us as something to block
- Field root-cause work — turning recurring customer deployment failures into permanent product fixes rather than per-customer workarounds
- Windows technical ownership — when R&D asks "how should this behave on Windows?", you are one of the people who answers
- Code reviews for other team members and contribution to the technical direction of the Windows agent.
What we are looking for
We mean these five. If you have them, apply — we would rather talk than have you screen yourself out on the list below.
- 8+ years of systems-level development experience preferred, including strong production Windows experience. 5+ years can be acceptable if the candidate has a strong security background
- Deep expertise in Windows internals — this is critical. We are looking for someone who understands Windows at the system level, not just someone who has built applications for Windows
- Professional-level C# proficiency is mandatory and will be the primary development language
- Production experience with Windows software / endpoint development
- Strong understanding of Windows security architecture, ideally gained through experience in a cybersecurity or security product company
- Experience owning features end to end, from technical decisions through implementation and delivery
- Ability to work independently and adapt quickly without constant guidance
- Strong communication and collaboration skills, especially in a remote and cross-functional environment
- A CS degree or equivalent practical background.
Strong plus
- Windows installer technology in depth — MSI, InstallShield or WiX, custom actions, transforms, silent install, and the upgrade and rollback cases that only show up in the field
- Enterprise deployment at scale — Intune, Configuration Manager, Group Policy, Tanium, and what each of them does to software it did not install
- Antivirus and EDR coexistence — you know which patterns get an installer flagged and which ones do not, and you fix the pattern rather than asking for an exclusion
- Windows certificate stores and code signing — machine versus user stores, EV signing, SmartScreen reputation
- TLS interception in production — trust chain management, certificate pinning, and the edge cases that come with it
- Windows Filtering Platform, network drivers, or kernel-mode components
- Python or Rust — other parts of the endpoint are built in them, and shared logic is increasingly written there
- Model Context Protocol (MCP), or hands-on experience with AI developer tooling (Claude Desktop, Cursor, VS Code extensions) — it helps to have been a user of what you are protecting
- Browser extension development (Edge, Chrome)
- Network traffic inspection or packet analysis
- Prior security vendor experience — DLP, CASB, EDR, or browser security
- macOS or cross-platform endpoint experience — useful for keeping behavior consistent across platforms, not a substitute for Windows depth
How we work
- Fail open, always. Nothing we ship may stop a customer from browsing the internet or reaching their corporate resources. Every error path degrades gracefully. This is a hard product principle, and it shapes how you would design.
- Fix the product, not the customer. When our agent conflicts with another vendor's tool, we own the fix rather than asking the customer to add an exclusion.
- Read the logs before theorizing. Diagnosis starts with evidence from the actual machine.
- Tests are how we ship confidently into an environment we cannot log into.
Technical environment
- Languages: C# and C++, plus Python and PowerShell for tooling
- Platform: Windows services, registry, COM, WMI, WinHTTP and WinInet, certificate stores, UAC and elevation, browser extensions
- Tooling: Visual Studio, MSI and InstallShield, signtool, WinDbg, Process Monitor and Process Explorer, Wireshark, Git, GitHub Actions
- Target OSes: Windows 10 and Windows 11, on the builds enterprises actually run
- Deployment: Intune, Configuration Manager, Group Policy, Tanium
- Test environment: Virtualised Windows 10 and 11 for clean-state reproduction of customer environments
Team & growth
You would join a small Windows-focused team with significant room to grow. The current core team has two Windows developers and one macOS developer, with a plan to hire several additional Windows engineers. The role itself is expected to remain focused on Windows development for at least the next 6–12 months, with the opportunity to have significant ownership as the team grows.