CybereasonCY

Senior Windows Internals Engineer

Cybereason is a cybersecurity company founded in 2012 that provides endpoint prevention, detection, and incident response solutions, including XDR, EDR, and NGAV, to help organizations combat cyber-attacks.

Cybereason

Employee count: 501-1000

Japan only

About the Role:

We’re looking for a Senior Windows Internals Engineer to join our Endpoint team and help build the core technology behind Cybereason’s Windows agent. In this role, you’ll design and implement low-level Windows components, including kernel drivers and user-mode services, that power advanced threat detection and response capabilities. You’ll work closely with security researchers, sensor developers, and platform engineers to ensure our agent is stable, stealthy, and performant across all supported environments.

This role demands strong C++ expertise, deep knowledge of Windows OS internals, and a passion for building secure, high-impact software.

Key Responsibilities:

  • Design and develop low-level components for the Windows endpoint sensor, focusing on stability, performance, and stealth

  • Build drivers and user-mode services that collect, filter, and analyze endpoint telemetry

  • Implement robust techniques for process/thread monitoring, registry tracking, file system interception, and network event visibility
  • Debug complex kernel-mode and user-mode issues across Windows versions

  • Collaborate with researchers and product teams to translate threat intelligence into product features

  • Conduct code reviews, mentor engineers, and contribute to architecture decisions

  • Stay current with Windows internals, security trends, and system programming practices

Required Qualifications:

  • 5+ years of hands-on experience in C++ development (C++11 or later)

  • In-depth understanding of Windows internals: kernel architecture, system calls, memory management, drivers

  • Proven experience in kernel-mode development (e.g., Windows Drivers, Windows Filtering Platform, minifilters, ETW)

  • Strong debugging and reverse engineering skills (WinDbg, Process Monitor, Process Explorer, IDA/Ghidra)

  • Familiarity with Windows security mechanisms: integrity levels, UAC, AppLocker, and secure boot

  • Experience using Visual Studio, Windows Driver Kit (WDK), and related build/debug environments

Preferred Qualifications:

  • Experience building or contributing to endpoint security products (EDR, AV, EPP, etc.)

  • Familiarity with Windows telemetry, event logs, Sysmon, and ETW tracing

  • Experience with malware analysis, Windows exploit techniques, or SOC/DFIR workflows

  • Scripting capabilities in PowerShell or Python for automation and testing

  • Understanding of kernel-mode security evasion techniques and defenses

  • Background in code signing, driver deployment, and secure update mechanisms

  • Bachelor’s degree in Computer Science, Software Engineering, or equivalent experience

What We Offer:

  • Competitive salary and comprehensive benefits package

  • Flexible working hours with remote work options

  • Opportunities for professional growth and continuous learning

  • A collaborative and innovative team culture

More About Cybereason:

Our culture and how we operate reflects in our shared values. Our #Defenders are individuals with diverse skill sets and backgrounds who are driven to innovate and scale with our growing organization. We are a team that strives to learn from each other, solve challenging problems, and work collaboratively toward our goal of reversing the adversary advantage.

Core Values:

  • Win As One: The power of an individual is less than the power of a team.
  • Ever Evolving: Change keeps us at the forefront, so we encourage it.
  • Daring: To achieve the impossible, we must dare to be different.
  • Obsessed with Customers: We believe gaining our customers’ trust is the most important part of what we do.
  • Never Give Up: We are tenacious and resilient, and we never stop.
  • UbU: We believe people can only unlock their full potential when they work somewhere that accepts who they are.

If these values resonate with you and our vision excites you, join us today and help us end cyber attacks from the endpoint to everywhere! #Defenders

Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Cybereason we are dedicated to building a diverse, inclusive, and authentic workplace (#uBu), so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Location requirements

Hiring timezones

Japan +/- 0 hours

About Cybereason

Learn more about Cybereason and their company culture.

View company profile

Cybereason's journey began in 2012, born from the minds of Lior Div, Yonatan Striem-Amit, and Yossi Naar, individuals with deep experience in military cybersecurity, including the Israeli Defense Force's elite Unit 8200. Their mission was to revolutionize how organizations fight cyber threats. They envisioned a future where defenders could gain the upper hand against increasingly sophisticated adversaries. This vision translated into building an endpoint detection and response platform designed to proactively hunt for threats rather than just react to them. The company established its initial headquarters in Boston, Massachusetts, in 2014, marking a significant step in its global expansion.

The core of Cybereason's offering became its AI-driven Cybereason Defense Platform. This platform was engineered to ingest vast amounts of data from endpoints, the cloud, and across the entire enterprise ecosystem. By leveraging artificial intelligence and machine learning, it aimed to provide predictive prevention, detection, and response capabilities. The company focused on an 'operation-centric' approach, meaning it pieces together the full story of an attack (a 'MalOp' or malicious operation) rather than just flagging isolated alerts. This allows security teams to understand the root cause and scope of an attack quickly and remediate it effectively. Over the years, Cybereason expanded its product suite to include next-generation antivirus (NGAV), endpoint detection and response (EDR), extended detection and response (XDR), and managed detection and response (MDR) services. The company also emphasized proactive threat hunting and digital forensics and incident response (DFIR) capabilities. Throughout its growth, Cybereason secured significant funding from investors like SoftBank, Liberty Strategic Capital, and Google Cloud, enabling further innovation and market expansion. Despite facing the dynamic and competitive cybersecurity landscape, including leadership changes and market fluctuations, Cybereason has remained committed to its goal of empowering defenders and reversing the adversary advantage, serving customers across numerous countries.

Employee benefits

Learn about the employee benefits and perks provided at Cybereason.

View benefits

401(K)

Cybereason offers a 401(K) plan.

Health Insurance

Cybereason offers health insurance.

Ample time off

Ample time off to relax and recharge.

Performance bonus

Cybereason offers performance bonuses.

View Cybereason's employee benefits
Claim this profileCybereason logoCY

Cybereason

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

9 remote jobs at Cybereason

Explore the variety of open remote roles at Cybereason, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Cybereason

Remote companies like Cybereason

Find your next opportunity by exploring profiles of companies that are similar to Cybereason. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan
Cybereason hiring Senior Windows Internals Engineer • Remote (Work from Home) | Himalayas