Concentric AI
Website:
concentric.ai
Job details:
About the Role
We are building a cross-platform endpoint agent platform for enterprise data security. You will join the Endpoint Agent Services team, which owns the user-space management agent that runs continuously on every managed device. This agent is responsible for authentication, policy sync, telemetry, self-update, health monitoring, local coordination, and user notifications across macOS and Windows fleets.
This role is focused on the user-space endpoint agent/service, not kernel drivers or interception layers. The agent coordinates with native enforcement components and cloud services, but the candidate does not need to build macOS Network Extensions, Windows WFP/MiniFilter drivers, or packet/file-system interception components. We are prioritizing engineers who have built reliable endpoint agents, desktop services, device-management clients, security clients, VPN/ZTNA/SASE clients, MDM/UEM agents, or observability agents that operate safely at fleet scale.
What You'll Do
- Design and build the core endpoint agent service, running as a privileged background daemon/service on macOS and Windows
- Implement device and user authentication flows (e.g., mTLS, OAuth/OIDC device flows, certificate-based identity) between the endpoint and cloud services
- Build the policy client: fetching, caching, versioning, and safely applying policies from the backend, with rollback and offline-resilience support
- Own telemetry pipelines: structured event collection, batching, local buffering, and reliable upload with backpressure handling
- Build the self-update mechanism for the endpoint agent, including staged rollout, signature verification, rollback-on-failure, and safe recovery from partial updates
- Implement health-check and watchdog logic — detecting crashed or hung components, restarting services when safe, and reporting endpoint health upstream
- Design local IPC/RPC interfaces that allow the user-space agent to coordinate cleanly with native macOS and Windows components
- Build the notification/UI surface layer (system tray, native notification APIs) for policy prompts, block notices, and user consent flows
- Coordinate with native enforcement components and cloud services to manage device identity, local trust anchors, proxy credentials, and policy-driven behavior
- Collaborate closely with macOS, Windows, backend, proxy, and security teams to define stable cross-component contracts
- Contribute to architecture decisions around resilience, tamper-resistance, minimal privilege, and performance (CPU/memory footprint on constrained enterprise laptops)
- Participate in incident response and root-cause analysis for production fleet issues
- Mentor engineers, review designs/code, and (at Staff level) drive technical strategy across the service team
Required Qualifications
- 6+ years (Senior) / 9+ years (Staff) of professional software engineering experience
- Strong experience building endpoint agents, desktop services, device-management clients, security clients, VPN/ZTNA/SASE clients, MDM/UEM agents, or observability agents — you understand fleet heterogeneity, service lifecycle management, tamper resistance, low-resource operation, and the operational realities of running software on end-user machines
- Proven experience building long-running user-space background services/daemons on macOS and/or Windows, including launchd/LaunchDaemon/LaunchAgent, Windows Services, service lifecycle management, and safe recovery patterns, in any systems language such as Go, C++, Rust, C#, or Swift
- Experience with secure authentication/identity patterns: OAuth2/OIDC, mTLS client auth, token refresh/rotation, secure credential storage (Keychain/DPAPI/Credential Manager)
- Experience designing systems for reliability under adverse conditions: intermittent connectivity, partial failures, crash recovery, safe rollback
- Solid grasp of concurrency and resource lifecycle management in your primary language — this runs on end-user machines, so leaks and runaway CPU/memory are unacceptable
- Experience shipping and operating auto-update systems with cryptographic signature verification
- Familiarity with observability: structured logging, metrics, tracing, and building telemetry pipelines with local buffering/backpressure
- Security mindset: comfortable reasoning about attack surface, tamper resistance, privilege separation, and secure-by-default design — this is security-adjacent software running with elevated privileges
- Strong cross-team collaboration skills — this role sits at the intersection of endpoint platform, native OS, backend, proxy, and security teams, so clear API/contract design and communication matter as much as code
Click on Apply to know more.