Jobs Companies Newxel Senior Windows Endpoint Developer — Workforce AI Security (NXJ-197)

Über diese Senior Windows Endpoint Developer — Workforce AI Security (NXJ-197) Stelle bei Newxel

Newxel · Remote · Europe

The Role

The Windows agent runs on hundreds of thousands of enterprise machines, enforcing data-loss policies and providing visibility over employee AI usage. The hard part isn’t standard application logic — it’s building deep systems-level software, privileged services, and network interception mechanisms that execute reliably across highly heterogeneous enterprise environments without breaking host operations. The role owns the Windows agent end-to-end, serving as the technical authority for the platform while engineering silent installation and updates, certificate trust and TLS interception, system proxy configuration, and seamless coexistence with third-party security software.

About the Product

The platform provides enterprise-wide visibility and governance over employee interactions with generative AI tools and developer environments. Operating at global enterprise scale, it monitors endpoint AI usage, enforces real-time DLP policies, and inspects network traffic directly on managed devices. The Windows agent must operate reliably across highly varied corporate environments, alongside existing antivirus, EDR, VPN, proxy, and device-management software, without disrupting users or corporate connectivity.

Technology Stack:

The core endpoint architecture is built primarily in C# and C++, with Python and PowerShell powering tooling and automation. The Windows platform includes privileged Windows services, registry, COM, WMI, UAC and elevation, WinHTTP and WinInet, certificate stores, system proxy configuration, and browser integrations for Edge and Chrome. Network-level interception and inspection may involve Windows Filtering Platform and related system components. Shared cross-platform logic increasingly relies on Python and Rust.

Deployment and field execution are managed through enterprise tooling such as Intune, Configuration Manager, Group Policy, and Tanium. The engineering toolkit includes Visual Studio, MSI and InstallShield, WiX, signtool, WinDbg, Process Monitor, Process Explorer, Wireshark, Git, and GitHub Actions.

What You’ll Be Doing

  • Own the Windows agent end-to-end, leading architecture for privileged services, inter-process communication, installation, and unattended auto-update pipelines

  • Architect certificate trust and TLS interception on Windows, including correct handling of machine and user certificate stores, trust chains, and applications that resist interception

  • Design resilient state-reconciliation logic for system proxy configuration, including coexistence with VPN clients, cloud proxies, and other software competing for proxy state

  • Build deep integrations into AI developer tools such as Claude Desktop, Cursor, and VS Code to inspect and govern local AI activity

  • Ensure reliable coexistence with antivirus, EDR, VPN, proxy, and other endpoint security products, fixing compatibility issues in the product rather than relying on customer-side exclusions

  • Drive field root-cause engineering, using logs, diagnostics, and evidence from real customer environments to turn recurring deployment and runtime failures into permanent product fixes

  • Own the Windows installation and update experience, including silent installation, upgrades, rollback scenarios, and enterprise deployment edge cases

  • Act as the definitive Windows technical owner, establishing engineering standards, conducting code reviews, and contributing to the technical direction of the agent

  • Help ensure the product follows a fail-open philosophy, with every error path designed to degrade gracefully rather than interrupt customer connectivity or access to corporate resources

What We Expect

Must-have

  • 8+ years of systems-level development experience preferred, including strong production experience building Windows software or endpoint products. 5+ years may be considered for candidates with a strong security background

  • Deep, practical expertise in Windows internals and architecture — this is critical. The role requires someone who understands Windows at the system level, not just someone who has built applications for Windows

  • Professional-level C# proficiency is mandatory and will be the primary development language, with strong C++ systems experience

  • Proven production experience developing Windows software, endpoint agents, or security products

  • Deep foundational knowledge of Windows security architecture, including privileged services, registry, COM, WMI, UAC, elevation, and certificate management

  • Proven track record of owning endpoint features end-to-end, from technical decisions and architecture through implementation and production delivery

  • Ability to work independently and debug complex field issues without constant guidance or direct access to customer machines

  • Strong communication and collaboration skills, especially in a remote and cross-functional environment

  • CS degree or equivalent practical engineering background

Nice-to-have

  • In-depth expertise with Windows installer technologies such as MSI, InstallShield, or WiX, including custom actions, transforms, silent installation, upgrades, and rollback scenarios

  • Hands-on experience with enterprise deployment tooling such as Intune, Configuration Manager/SCCM, Group Policy, or Tanium

  • Experience troubleshooting antivirus and EDR coexistence, including understanding which endpoint behaviors and installer patterns commonly trigger security products

  • Strong knowledge of Windows certificate stores and code signing, including machine versus user stores, EV signing, and SmartScreen reputation

  • Production experience with TLS interception, trust-chain management, certificate pinning, and related edge cases

  • Experience with Windows Filtering Platform, network drivers, or kernel-mode components

  • Python or Rust experience

  • Hands-on experience with AI developer tooling such as Claude Desktop, Cursor, VS Code extensions, or Model Context Protocol (MCP)

  • Browser extension development for Edge or Chrome

  • Network traffic inspection or packet analysis experience

  • Previous experience at a cybersecurity vendor, particularly with DLP, CASB, EDR, or browser security products

  • macOS or cross-platform endpoint development experience

How The Team Works

  • Fail open, always. Nothing shipped may prevent a customer from browsing the internet or reaching corporate resources. Every error path should degrade gracefully

  • Fix the product, not the customer. When the agent conflicts with another vendor’s software, the engineering team owns the fix rather than asking the customer to add an exclusion

  • Read the logs before theorizing. Diagnosis starts with evidence from the actual machine, not assumptions

  • Tests are how the team ships confidently into environments it cannot log into. Reproducibility, diagnostics, and automated testing are essential to the development process

Team & Growth

  • You would join a small Windows-focused team with significant room to grow.

  • The current core team has two Windows developers and one macOS developer, with a plan to hire several additional Windows engineers.

  • The role itself is expected to remain focused on Windows development for at least the next 6–12 months, with the opportunity to have significant ownership as the team grows.

Bereit, sich bei Newxel zu bewerben?
Bei Newxel bewerben

Ähnliche Jobs

Newxel
.NET Backend Developer (NXJ-195)
Newxel
⚡ Früh bewerben Poland (Hybrid/Entity) Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 21 Std.
Newxel
Director of Finance & Legal (NXJ-189)
Newxel
⚡ Früh bewerben Poland · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 5 Tg.
Newxel
Software Testing Engineer (NXJ-196)
Newxel
⚡ Früh bewerben Ukraine · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 6 Tg.
Newxel
Senior DevOps Engineer (NXJ-171)
Newxel
⚡ Früh bewerben Ukraine · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
Newxel
Senior macOS Engineer — Workforce AI Security (NXJ-193)
Newxel
⚡ Früh bewerben Europe · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 2 Wo.
Newxel
Full-stack Software Engineer (NXJ-192)
Newxel
⚡ Früh bewerben Ukraine (Head office) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
OnHires
Mobile Engineer (iOS)
OnHires
⚡ Früh bewerben Europe · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
OnHires
Mobile Engineer (Android)
OnHires
⚡ Früh bewerben Europe Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.
OnHires
Machine Learning Engineer
OnHires
⚡ Früh bewerben Europe · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 5 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Newxel

Alle Jobs bei Newxel ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos