Skip to content

Open nowPosted 29 days ago

Senior Windows Endpoint Developer — Workforce AI Security (NXJ-197)

Newxel10 open roles

Where
Europe
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Windows Endpoint Developer — Workforce AI Security (NXJ-197)Newxel · Europe
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Newxel's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Newxel postings stay open a median of 13 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 29 days ago

Newxel median: 13 days open

The posting

THE ROLE

The Windows agent runs on hundreds of thousands of enterprise machines, enforcing data-loss policies and providing visibility over employee AI usage. The hard part isn’t standard application logic — it’s building deep systems-level software, privileged services, and network interception mechanisms that execute reliably across highly heterogeneous enterprise environments without breaking host operations. The role owns the Windows agent end-to-end, serving as the technical authority for the platform while engineering silent installation and updates, certificate trust and TLS interception, system proxy configuration, and seamless coexistence with third-party security software.

ABOUT THE PRODUCT

The platform provides enterprise-wide visibility and governance over employee interactions with generative AI tools and developer environments. Operating at global enterprise scale, it monitors endpoint AI usage, enforces real-time DLP policies, and inspects network traffic directly on managed devices. The Windows agent must operate reliably across highly varied corporate environments, alongside existing antivirus, EDR, VPN, proxy, and device-management software, without disrupting users or corporate connectivity.

Technology Stack:

The core endpoint architecture is built primarily in C# with Python and PowerShell powering tooling and automation. The Windows platform includes privileged Windows services, registry, COM, WMI, UAC and elevation, WinHTTP and WinInet, certificate stores, system proxy configuration, and browser integrations for Edge and Chrome. Network-level interception and inspection may involve Windows Filtering Platform and related system components. Shared cross-platform logic increasingly relies on Python and Rust.

Deployment and field execution are managed through enterprise tooling such as Intune, Configuration Manager, Group Policy, and Tanium. The engineering toolkit includes Visual Studio, MSI and InstallShield, WiX, signtool, WinDbg, Process Monitor, Process Explorer, Wireshark, Git, and GitHub Actions.

WHAT YOU’LL BE DOING

- Own the Windows agent end-to-end, leading architecture for privileged services, inter-process communication, installation, and unattended auto-update pipelines

- Architect certificate trust and TLS interception on Windows, including correct handling of machine and user certificate stores, trust chains, and applications that resist interception

- Design resilient state-reconciliation logic for system proxy configuration, including coexistence with VPN clients, cloud proxies, and other software competing for proxy state

- Build deep integrations into AI developer tools such as Claude Desktop, Cursor, and VS Code to inspect and govern local AI activity

- Ensure reliable coexistence with antivirus, EDR, VPN, proxy, and other endpoint security products, fixing compatibility issues in the product rather than relying on customer-side exclusions

- Drive field root-cause engineering, using logs, diagnostics, and evidence from real customer environments to turn recurring deployment and runtime failures into permanent product fixes

- Own the Windows installation and update experience, including silent installation, upgrades, rollback scenarios, and enterprise deployment edge cases

- Act as the definitive Windows technical owner, establishing engineering standards, conducting code reviews, and contributing to the technical direction of the agent

- Help ensure the product follows a fail-open philosophy, with every error path designed to degrade gracefully rather than interrupt customer connectivity or access to corporate resources

WHAT WE EXPECT

MUST-HAVE

- 8+ years of systems-level development experience preferred, including strong production experience building Windows software or endpoint products. 5+ years may be considered for candidates with a strong security background

- Deep, practical expertise in Windows internals and architecture — this is critical. The role requires someone who understands Windows at the system level, not just someone who has built applications for Windows

- AI applications on Windows and macOS. You use AI coding agents and assistants daily (Claude Code, Cursor, Copilot, Gemini CLI) and are an expert in their skills, MCP servers and plugins. You've worked with how these tools talk to their backends, including streaming and WebSockets.

- Agent extension points. You've built or integrated MCP servers and clients, and you're an expert in the protocol: stdio vs HTTP transports, tool calls and OAuth 2.1. You've also built agent hooks, skills and plugins.

- Networking and protocols. You've built and debugged network-facing software over HTTP/1.1, HTTP/2, QUIC, WebSockets and CONNECT tunneling. You can explain why Chrome skips a proxy, or stays on a direct connection after the proxy restarts, and you can fix it.

- TLS and PKI. You've built TLS inspection or interception components and are an expert in certificate chains, intermediates, AKI, and OS and browser trust stores. You've shipped alongside, or interoperated with, other TLS inspection products such as Zscaler, Palo Alto or Symantec.

- Windows internals. You've built Windows software that relies on the registry (including SYSTEM vs HKCU), processes and services, and Task Scheduler. You're an expert in how these behave on managed endpoints.

- Multithreaded development in C# or Python. You've written concurrent code (threads, async, locking) that runs reliably on customer machines.

- Security engineering. You've designed security software with a clear view of fail-open vs fail-closed behavior. You've found and closed DLP bypasses such as odd encodings and partial scanning, and you write secure code by default.

- Client-side development. You've built and shipped background services and agents that run on thousands of managed endpoints.

- Field debugging. You've taken customer log bundles and found the root cause. This is a big part of the job.

NICE-TO-HAVE

- Rust. You've written Rust. We use it for the MCP security proxy and the hooks client.

- Proxy configuration. You've configured PAC/WPAD, chained to an upstream proxy, and deployed through MDM (Kandji, Chrome managed policies).

- Installer packaging. You've built installers with MSI/WiX, NSIS or Inno, and macOS .pkg.

- Other languages. You've written Python, Swift/ObjC, and TypeScript.

- Traffic analysis. You've reverse-engineered web app traffic from HAR files or a proxy

HOW THE TEAM WORKS

- Fail open, always. Nothing shipped may prevent a customer from browsing the internet or reaching corporate resources. Every error path should degrade gracefully

- Fix the product, not the customer. When the agent conflicts with another vendor’s software, the engineering team owns the fix rather than asking the customer to add an exclusion

- Read the logs before theorizing. Diagnosis starts with evidence from the actual machine, not assumptions

- Tests are how the team ships confidently into environments it cannot log into. Reproducibility, diagnostics, and automated testing are essential to the development process

TEAM & GROWTH

- You would join a small Windows-focused team with significant room to grow.

- The current core team has two Windows developers and one macOS developer, with a plan to hire several additional Windows engineers.

- The role itself is expected to remain focused on Windows development for at least the next 6–12 months, with the opportunity to have significant ownership as the team grows.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Newxel's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Newxel's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Newxel's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.