REMOTE Windows Endpoint Engineer / Agent Developer
Job Description
Company: Candor Security (Seed, founded 2025, 1–10 employees) — https://candor.security/
This is a REMOTE Role hiring in the US, LATAM and India
Compensation: $6,000–$15,000 / month (contract). Regional comps: India $6k–$8k/mo, LATAM $7k–$9k/mo, US $10k–$15k/mo. Experience: 5+ years. Visa sponsorship: none.
About the RoleCandor is bringing its data-loss-prevention engine down to the endpoint. The AI detection engine is being built in-house; this role owns the Windows endpoint agent end-to-end — defining the agent's internal structure, reverse-engineering the relevant Windows system APIs, and emitting the telemetry the platform needs (browser data uploads, endpoint data movement, web searches, file renaming, and other suspicious-activity indicators) streamed back to the backend. Teach-and-build role with substantial architectural latitude; a mistake at this layer can trigger blue screens across a customer fleet, so hands-on experience is essential.
What You'll Own- Design, build, and ship the Windows endpoint agent end-to-end, from system-level telemetry capture to backend streaming
- Reverse-engineer and integrate the Windows system APIs required to observe data movement safely without destabilizing the OS
- Emit the defined telemetry set (browser data uploads, endpoint data movement, web searches, file renaming, and other indicators)
- Own customer deployment: MDM policy design, staged rollout, and safe agent update mechanisms
- Set and evolve the agent architecture and level up a technical founding team
- Proven experience building and shipping production Windows endpoint agents end-to-end
- Deep familiarity with Windows system internals and collecting telemetry safely without instability/BSODs
- Proficiency in Rust (or willingness to build in Rust); strong C++ acceptable with a clear rationale
- Hands-on deploying endpoint agents at customer scale — MDM policy design, staged rollout, update delivery
- High autonomy and strong communication; able to lead architecture and teach a technical founder
- Prior DLP or insider-risk experience (Palo Alto Networks, CrowdStrike, SentinelOne, Cyberhaven, Microsoft Defender)
- Agents across both Windows and macOS
- Early-stage startup experience
- Browser extension or cross-platform telemetry experience
