Skip to content

Open nowPosted 49 days ago

Senior macOS Engineer — Workforce AI Security (NXJ-193)

Newxel10 open roles

Where
Europe
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior macOS Engineer — Workforce AI Security (NXJ-193)Newxel · Europe
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Newxel's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Newxel postings stay open a median of 13 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 49 days ago

Newxel median: 13 days open

The posting

THE ROLE

You will own the macOS agent end-to-end, building privileged system services, custom IPC architecture, and reliable update mechanisms that maintain machine health at scale. The primary engineering challenge lies in delivering reliable certificate trust, TLS interception, and system proxy configuration on machines you cannot access directly, while gracefully coexisting with competing third-party security stacks.

ABOUT THE PRODUCT

The platform provides visibility and control over how enterprise employees interact with generative AI tools and safeguards data at the endpoint level. Operating across hundreds of thousands of managed Macs, the solution handles network interception and deep integration into AI developer tools without interrupting daily user workflows.

Technology Stack: The core macOS client is written natively in Swift with Objective-C modules across a codebase mid-migration, leveraging lower-level platform interfaces like launchd, XPC, Security.framework, and SystemConfiguration. Tooling and automation rely on Python and Bash, with shared low-level logic expanding into Rust. Deployment and testing run through physical Mac hardware, virtualized macOS pipelines, Xcode, and GitHub Actions across macOS Sonoma, Sequoia, and pre-release operating systems.

WHAT YOU’LL BE DOING

- Architect and maintain privileged system services, inter-process communication, and robust self-updating mechanisms across non-administrated endpoints

- Implement TLS interception and certificate trust chains on macOS while resolving edge cases for applications that resist or bypass standard trust mechanisms

- Resolve system proxy configuration conflicts dynamically to maintain stability alongside competing endpoint security tools, VPNs, and cloud proxies

- Build native interception capabilities for AI developer tools to monitor and apply data-loss policies to generative AI workflows

- Enforce fail-open system architecture so local failures never degrade end-user network connectivity or access to corporate assets

- Analyze real customer logs and clean-state Mac reproductions to identify root causes and ship permanent fixes for complex deployment issues

- Own product fixes when the agent conflicts with other endpoint security products rather than relying on customer-side exclusions or workarounds

- Serve as the principal technical authority for macOS engineering decisions across the broader R&D organization

WHAT WE EXPECT

MUST-HAVE

- 5+ years of systems-level software development, including 3+ years delivering production macOS software using Swift and Objective-C

- Deep expertise in macOS platform internals, including launchd, XPC, code signing, notarization, packaging, privileged operations, and debugging complex runtime behavior

- Solid grounding in networking fundamentals, including system proxies, TLS, certificate trust, and what happens to a connection between an application and the internet

- Hands-on proficiency with modern AI development tools such as Claude Code or Cursor, paired with a critical, verification-first approach to AI-generated code

- Clear technical communication skills, with experience resolving critical technical issues alongside field engineers and enterprise IT teams

- A CS degree or equivalent practical engineering background

NICE-TO-HAVE

- Hands-on experience with Security.framework, EndpointSecurity, NetworkExtension content filters or transparent proxies, trust evaluation, or browser extensions for Safari or Chrome

- Enterprise deployment experience using MDM solutions such as Jamf Pro, Intune for Mac, or Workspace ONE, including configuration profiles and tools like pkgbuild / productbuild

- Experience handling production TLS interception, trust chain management, certificate pinning, or network packet analysis

- Proficiency in Rust, Python, Model Context Protocol (MCP), or prior experience building security products such as EDR, CASB, DLP, or browser security solutions

- Windows or cross-platform endpoint experience, particularly where consistency across platforms matters

WHY THIS ROLE IS WORTH YOUR TIME

- You are building a native macOS platform rather than maintaining a ported Windows client, directly addressing the platform's unique architectural challenges

- The role gives you full technical ownership over privileged services, trust chains, proxy configuration, and network components running on endpoints you cannot access directly

- You will work in an engineering culture that enforces strict "fail open" reliability and expects teams to fix root-cause product issues rather than rely on customer-side exclusions or temporary workarounds

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Newxel's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Newxel's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Newxel's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.