Keeper Security

Senior Linux Engineer, Privileged Access

Keeper Security
Apply
3 hours ago
Remote, United StatesSenior

Responsibilities

  • Design, develop, and maintain Linux endpoint privilege management capabilities across Rust, C, and .NET components.
  • Build kernel-facing agent functionality using fanotify, the proc filesystem, namespaces, capabilities, and process identity interfaces.
  • Develop and maintain native PAM modules and Linux privilege-elevation workflows.
  • Build long-running privileged Linux services using Rust, Tokio, MQTT, TLS, and asynchronous programming patterns.
  • Develop Linux orchestration and session-management capabilities in .NET 8, including process authentication, access controls, ephemeral accounts, and session monitoring.
  • Diagnose Linux execution and security issues involving blocked processes, authentication races, permissions, SELinux, AppArmor, and system services.
  • Design privilege-enforcement mechanisms based on least privilege, process trust, and protection against TOCTOU and authorization race conditions.
  • Build and maintain systemd services, RPM and DEB packages, installation workflows, service hardening, and operational diagnostics.
  • Collaborate with PAM, endpoint, QA, and platform engineers on architecture, testing, cross-platform functionality, and production troubleshooting.
  • Use AI-assisted development tools such as Claude, ChatGPT, and GitHub Copilot for research, debugging, development, testing, and documentation.

Requirements

  • 7+ years of professional software or systems engineering experience with significant hands-on Linux systems programming experience.
  • Deep understanding of Linux processes, security concepts, the proc filesystem, user and group IDs, capabilities, namespaces, and process execution.
  • Strong C programming experience, including native Linux development, memory management, GCC, Make-based workflows, and defensive error handling.
  • Experience developing or integrating with Linux PAM and PAM configuration.
  • Strong Rust experience with ownership, concurrency, asynchronous development, and long-running service or daemon design.
  • Experience with Tokio or similar asynchronous Rust frameworks.
  • Working proficiency with C# and .NET in Linux environments.
  • Experience developing security-sensitive software involving authentication, authorization, privilege elevation, process trust, or least-privilege controls.
  • Understanding of Linux service management and operations, including systemd, journalctl, SELinux and/or AppArmor, and RPM/DEB packaging.
  • Experience troubleshooting low-level Linux behavior using logs, process inspection, tracing, and reproducible test tools.
  • Ability to read Linux kernel and subsystem documentation and translate system behavior into secure production implementations.
  • Ability and willingness to use AI-assisted tools for systems programming, debugging, technical analysis, testing, and documentation.
  • Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent practical experience.
  • Preferred: experience with MQTT or other event-driven messaging technologies.
  • Preferred: experience with Linux desktop session technologies such as X11, Wayland, GDM, and D-Bus.
  • Preferred: familiarity with TLS, PKI, code signing, and certificate-based process or plugin authentication.
  • Preferred: experience supporting RHEL and Ubuntu and understanding SELinux/AppArmor differences.
  • Preferred: experience with endpoint privilege management, privileged access management, or endpoint security products.
  • Preferred: familiarity with Avalonia or another cross-platform Linux desktop UI framework.
  • Preferred: experience building Linux software for x86 and ARM architectures, including packaging and signing pipelines.
  • Preferred: familiarity with endpoint security architectures on Windows or macOS and authorization models including allow, deny, approval, and just-in-time elevation workflows.

Benefits

  • 100% remote position, with hybrid scheduling available for candidates in the Chicago, Illinois or El Dorado Hills, California metro areas.
  • Medical, dental, and vision insurance, including domestic partnerships.
  • Employer-paid life insurance and supplemental life insurance options.
  • Voluntary short- and long-term disability insurance.
  • Roth or traditional 401(k).
  • Generous paid time off, including paid bereavement and jury duty leave.
  • Above-market annual bonuses.

Tech Stack

CC#LinuxmacOSMake.NETRustWindows
Keeper Security

About Keeper Security

501-1,000 employees

Keeper Security is transforming cybersecurity for millions of individuals and thousands of organizations globally. Built to protect against today’s threats and tomorrow’s challenges, our unified, cloud-native cybersecurity platform is trusted by Fortune 100 companies to protect every user, on every device, in every location. Keeper is a pioneer of zero-knowledge and zero-trust security built for any IT environment. Our core offering, KeeperPAM®, is an AI-enabled, cloud-native platform that protects all users, devices and infrastructure from cyber attacks. Recognized in the Gartner Magic Quadrant for Privileged Access Management (PAM), Keeper continues to lead in cybersecurity innovation, securing passwords and passkeys, infrastructure secrets, remote connections and endpoints with role-based enforcement policies, least privilege and just-in-time access. As threats evolve and environments scale, Keeper is redefining modern cybersecurity to deliver the visibility, control and intelligence organizations need to operate confidently and securely. Our security and compliance standards include: - The longest-standing SOC 2 and ISO 27001 certifications in the industry - FedRAMP and GovRAMP Authorization - FIPS 140-3 validation - SOC 3, PCI DSS and ISO 27001, 27017 and 27018 certification Learn more at keepersecurity.com.