Senior Software Engineer, Endpoint Sensor
About Mimecast
The work people build is worth protecting, and it's harder to protect than it used to be. AI agents now move at machine speed with human-level access, and a small slip-up can become a very public one. We disrupt cybercriminal activity before that happens. We think fast, go big, and always demand more of ourselves. We work hard, deliver, and repeat. We grow with real determination and put success well within reach. We push each other to be better and expect to be pushed back, in a community built on respect, where everyone is counted. Work Protected.
Overview
Incydr Product Development is looking for a Senior Software Engineer to join the Endpoint Data Protection team. Reporting to the Senior Manager - Engineering, you’ll help protect organizations from data loss and insider risk across millions of endpoints as we invest in the next generation of that protection: defending data wherever it moves, however it moves.
This is a foundational role working on our endpoint sensor technology that runs continuously and reliably on millions of corporate machines across Windows, macOS, and Linux. You'll work at the lowest levels of the operating system, building kernel drivers and Endpoint Security extensions that power how Incydr detects and stops data loss and insider risk. You'll own features end to end, from early research and proof of concept through production at scale.
Mimecast is an AI-First engineering organization. Our teams actively leverage AI-powered development tools across all facets of engineering, and we're looking for someone genuinely curious about working this way—including bringing that curiosity to securing the AI-driven workflows this role increasingly has to defend against.
What You'll Do:
Design and develop core capabilities for our Windows, macOS, and Linux agents throughout the complete software development and release lifecycle.
Work at the OS boundary, building performant, reliable kernel-mode components and Endpoint Security and Network extensions that handle complex system interactions.
Build detection paths and real-time inline enforcement, moving beyond telemetry and alerting to deny/block decisions without compromising endpoint performance.
Own features end to end, from early research and proof of concept through production at scale, and integrate agent capabilities with backend and product workflows.
Build always-on components with strong observability, performance, and stability in production.
Bring an adversarial, security-first mindset to everything you build, designing components that resist evasion and treat all input as untrusted.
Collaborate with product and cloud service teams to turn discoveries into capabilities that support real-world security investigations.
What You'll Bring:
Deep experience building production software, including substantial work in low-level systems or endpoint development and code that runs continuously and reliably across large-scale endpoint or systems deployments.
Low-level endpoint development expertise on at least one platform: Windows kernel mode, including minifilters, drivers, WFP, and C++; or macOS Endpoint Security and Network Extension frameworks using Swift or C++.
Strong C++ fundamentals, with sound judgment about memory, concurrency, and performance trade-offs and fluency with the debugging and profiling tools this work demands.
Experience designing extensible software architectures, including library boundaries and interface contracts, with the discipline to maintain and evolve long-lived code.
A security mindset that accounts for both evasion and adversarial behavior and how authorized users move data. This is insider risk, not just external attackers.
Experience building real-time inline enforcement and deny/block paths—not just detection and telemetry—under the strict performance and stability constraints of always-on endpoint software.
Performance discipline: you build always-on software that earns its place on the endpoint and never degrades the user's experience, applying profiling, caching, and memory-management techniques.
Comfort working daily with AI coding assistants and agents, with an interest in helping secure the AI-driven workflows customers are adopting.
Cross-platform development experience across Windows, macOS, and Linux.
Network-layer monitoring experience, including user-space traffic capture, TLS-aware analysis, macOS Network Extensions, or the Windows Filtering Platform.
Exposure to data security, DLP, or content-classification concepts—or genuine eagerness to grow into the data-centric problem space, including file-activity telemetry, content hints, and egress enrichment.
Experience shipping enterprise endpoint software, including silent installation, automatic updates, multi-tenant configuration, and the operational reality of heterogeneous corporate fleets.
Production experience with Rust, or demonstrated ability and interest in working in a Rust codebase.
A background in behavioral analytics or adjacent detection domains.
The base salary range for this position is $148,000-$222,000 plus benefits. This range represents the minimum and maximum new hire compensation for this role. The position may also be eligible for incentive plans and additional benefits, in accordance with company policy and local regulations. Our salary ranges are determined by role, level, and location with individual compensation also dependent on factors such as qualifications, experience, and skills. Final offers will reflect these considerations and may vary accordingly.
Belonging at Mimecast
Cybersecurity is a community effort. That’s why we’re committed to building an inclusive, diverse community that celebrates and welcomes everyone – unless they’re a cybercriminal, of course.
We’re proud to be an Equal Opportunity and Affirmative Action Employer, and we’d encourage you to join us whatever your background. We particularly welcome applicants from traditionally underrepresented groups.
We consider everyone equally: your race, age, religion, sexual orientation, gender identity, ability, marital status, nationality, or any other protected characteristic won’t affect your application.
If you require any adjustments or accommodations due to a disability, or any other reason that may help you in your interview process, please let us know by emailing [email protected].
Due to certain obligations to our customers, an offer of employment will be subject to your successful completion of applicable background checks, conducted in accordance with local law.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.
Skills Required
- Substantial experience building production software, including low-level systems or endpoint development deployed reliably at scale
- Low-level endpoint development experience on Windows kernel mode or macOS Endpoint Security and Network Extension frameworks
- Strong C++ fundamentals, including memory management, concurrency, performance, debugging, and profiling
- Experience designing extensible software architectures with durable library boundaries and interface contracts
- Security-focused experience addressing evasion, adversarial behavior, and insider-risk data movement
- Experience building real-time inline enforcement and deny/block paths in always-on endpoint software
- Experience optimizing always-on software through profiling, caching, and memory-management techniques
- Comfort working daily with AI coding assistants and agents
- Cross-platform development experience across Windows, macOS, and Linux
- Network-layer monitoring experience, including traffic capture, TLS-aware analysis, macOS Network Extensions, or Windows Filtering Platform
- Exposure to data security, data loss prevention, or content-classification concepts, or willingness to develop expertise in the area
- Experience shipping enterprise endpoint software with silent installation, automatic updates, multi-tenant configuration, and heterogeneous fleet support
- Production experience with Rust or demonstrated ability and interest in working in a Rust codebase
- Background in behavioral analytics or adjacent detection domains
Mimecast Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Mimecast and has not been reviewed or approved by Mimecast.
-
Fair & Transparent Compensation — Pay is characterized as solid and competitive relative to similar companies, with a wide range of role-based salary outcomes. Compensation satisfaction is reinforced by frequent references to pay feeling fair for the work in multiple contexts.
-
Healthcare Strength — Health insurance is repeatedly described as a strong part of the package, often paired with other core benefits. The overall benefits bundle is framed as comprehensive and supportive of employee and family health needs.
-
Wellbeing & Lifestyle Benefits — Workplace perks such as flexible hours, hybrid/remote options, free meals, and on-site fitness amenities are consistently presented as meaningful additions to total rewards. These perks appear to materially improve day-to-day employee experience beyond base pay.
Mimecast Insights
What We Do
Relentless protection. Resilient world. Mimecast (NASDAQ: MIME) was born in 2003 with a focus on delivering relentless protection. Each day, we take on cyber disruption for our tens of thousands of customers around the globe; always putting them first, and never giving up on tackling their biggest security challenges together. We are the company that built an intentional and scalable design ideology that solves the number one cyberattack vector – email. We continuously invest to thoughtfully integrate brand protection, security awareness training, web security, compliance and other essential capabilities. Mimecast is here to help protect large and small organizations from malicious activity, human error and technology failure; and to lead the movement toward building a more resilient world. Learn more about us at www.mimecast.com.








