
Senior Linux Engineer, Privileged Access
Keeper Security2 months ago
Remote, United StatesSenior
Responsibilities
- Design, develop, and maintain Linux endpoint privilege management capabilities across Rust, C, and .NET components.
- Build kernel-facing agent functionality using fanotify, the proc filesystem, namespaces, capabilities, and process identity interfaces.
- Develop and maintain native PAM modules and Linux privilege-elevation workflows.
- Build long-running privileged Linux services using Rust, Tokio, MQTT, TLS, and asynchronous programming patterns.
- Develop Linux orchestration and session-management capabilities in .NET 8, including process authentication, access controls, ephemeral accounts, and session monitoring.
- Diagnose Linux execution and security issues involving blocked processes, authentication races, permissions, SELinux, AppArmor, and system services.
- Design privilege-enforcement mechanisms based on least privilege, process trust, and protection against TOCTOU and authorization race conditions.
- Build and maintain systemd services, RPM and DEB packages, installation workflows, service hardening, and operational diagnostics.
- Collaborate with PAM, endpoint, QA, and platform engineers on architecture, testing, cross-platform functionality, and production troubleshooting.
- Use AI-assisted development tools such as Claude, ChatGPT, and GitHub Copilot for research, debugging, development, testing, and documentation.
Requirements
- 7+ years of professional software or systems engineering experience with significant hands-on Linux systems programming experience.
- Deep understanding of Linux processes, security concepts, the proc filesystem, user and group IDs, capabilities, namespaces, and process execution.
- Strong C programming experience, including native Linux development, memory management, GCC, Make-based workflows, and defensive error handling.
- Experience developing or integrating with Linux PAM and PAM configuration.
- Strong Rust experience with ownership, concurrency, asynchronous development, and long-running service or daemon design.
- Experience with Tokio or similar asynchronous Rust frameworks.
- Working proficiency with C# and .NET in Linux environments.
- Experience developing security-sensitive software involving authentication, authorization, privilege elevation, process trust, or least-privilege controls.
- Understanding of Linux service management and operations, including systemd, journalctl, SELinux and/or AppArmor, and RPM/DEB packaging.
- Experience troubleshooting low-level Linux behavior using logs, process inspection, tracing, and reproducible test tools.
- Ability to read Linux kernel and subsystem documentation and translate system behavior into secure production implementations.
- Ability and willingness to use AI-assisted tools for systems programming, debugging, technical analysis, testing, and documentation.
- Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
- Preferred: experience with MQTT or other event-driven messaging technologies.
- Preferred: experience with Linux desktop session technologies such as X11, Wayland, GDM, and D-Bus.
- Preferred: familiarity with TLS, PKI, code signing, and certificate-based process or plugin authentication.
- Preferred: experience supporting RHEL and Ubuntu and understanding SELinux/AppArmor differences.
- Preferred: experience with endpoint privilege management, privileged access management, or endpoint security products.
- Preferred: familiarity with Avalonia or another cross-platform Linux desktop UI framework.
- Preferred: experience building Linux software for x86 and ARM architectures, including packaging and signing pipelines.
- Preferred: familiarity with endpoint security architectures on Windows or macOS and authorization models including allow, deny, approval, and just-in-time elevation workflows.
Benefits
- 100% remote position, with hybrid scheduling available for candidates in the Chicago, Illinois or El Dorado Hills, California metro areas.
- Medical, dental, and vision insurance, including domestic partnerships.
- Employer-paid life insurance and supplemental life insurance options.
- Voluntary short- and long-term disability insurance.
- Roth or traditional 401(k).
- Generous paid time off, including paid bereavement and jury duty leave.
- Above-market annual bonuses.
About Keeper Security
Keeper Security builds a cloud-based, zero-knowledge platform for password management, secrets management, privileged access management and secure remote connections for individuals and organizations. The privately held company, founded in 2011 and headquartered in Chicago, sells its KeeperPAM suite as subscription software, is published in 23 languages and sold in over 150 countries, and supports integrations with common identity providers and enterprise tech stacks.