SECTION I · THE BRIEF
Brief #26757Updated 12 DEC 2025ORLANDO, FLGreenhouseSOFTWARE COMPANIES
Employbl Company Profile

Senior Kernel Software Developer

ThreatLocker combines Application Whitelisting with Ringfencing and Storage Control in ways that make security simple. By combining these three techniques, untrusted applications will not run or weaponize against you.

Location
Orlando, FL
Company size
200–1,000
Posted
8mo ago
Via
Greenhouse
Section II · Premium ProfileMembers only
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

7-day free trial · $25/mo · cancel anytime

ThreatLocker Inc logo

Senior Kernel Software Developer · ThreatLocker Inc

View company profile
Job title
Senior Kernel Software Developer
Job location
Orlando, FL
Job description

COMPANY OVERVIEW

ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools to improve the security of servers and endpoints. The ThreatLocker® platform with Application Allowlisting, Ringfencing™, Storage Control, Elevation Control, Endpoint Network Control, Configuration Management, and Operational Alert solutions are leading the cybersecurity market toward a more secure approach of blocking the exploits of application vulnerabilities.

POSITION OVERVIEW

We are seeking a Windows Kernel Driver Engineer with extensive experience in filter driver development and Windows system internals to join our cybersecurity product team. In this role, you will build and maintain critical kernel-mode components that power next-generation threat detection, prevention, and response capabilities on Windows systems. The role will be based in Orlando, FL and is an in-office position.

JOB SCOPE

The Kernel Developer will be responsible for, but not limited to:

  • Design and develop kernel-mode filter drivers (file system minifilter, registry filter, network filter, etc.) to support security monitoring and enforcement.
  • Investigate and reverse-engineer Windows internals to implement low-level security features and bypass-resistant protections.
  • Collaborate with the threat research, detection, and user-mode engineering teams to develop scalable and stealthy security solutions.
  • Perform in-depth kernel debugging, crash dump analysis, and performance tuning using WinDbg, ETW, and related tools.
  • Develop robust, secure, and maintainable driver code that meets Microsoft's signing and certification standards.
  • Monitor Windows platform changes to ensure compatibility and stability across OS versions.

REQUIRED QUALIFICATIONS

  • 5+ years of hands-on experience writing Windows kernel-mode drivers, particularly filter drivers.
  • Expert knowledge of Windows system internals (memory management, I/O subsystem, object manager, etc.).
  • Proficiency in C/C++, Windows Driver Kit (WDK), and kernel debugging tools.
  • Experience in the cybersecurity domain, especially endpoint protection, EDR, anti-malware, or kernel-level monitoring.
  • Solid understanding of code injection techniques, hooking, kernel-mode exploits, and mitigation strategies.
  • Strong problem-solving skills and a security-first engineering mindset.

PREFERRED QUALIFICATIONS

  • Experience with malware analysis, reverse engineering, or rootkit detection.
  • Familiarity with Windows kernel threat models and secure coding practices.
  • Exposure to Microsoft kernel-mode signing, WHQL, and driver submission processes
  • Contributions to the infosec community (research, publications, open-source projects, talks)

WORKING CONDITIONS

The duties described below are representative of those encountered while performing the essential functions of this position. If necessary, reasonable accommodation may be requested and will be evaluated for its relationship to the essential functions that must be performed.

  • Job will generally be performed in an office environment but may require travel to visit company offices and/or property locations.
  • While performing duties of this job, would occasionally require to stand, walk, sit, reach with hands and arms, climb or balance, stoop or kneel, talk and hear, and use fingers and hands to feel objects and tools.
  • Must occasionally lift and/or move up to 25 pounds.
  • Specific vision abilities required include close vision, distance vision, depth perceptions, and the ability to adjust focus.

A background check and drug/substance screening are required after a conditional offer. Employment will proceed only upon receiving clear results from both.

ThreatLocker also conducts randomized drug and substance testing approximately every 60 days, in line with the same screening standards.

 

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Where this role is based

Orlando, FL

Loading map…

ThreatLocker Inc headquarters

Orlando, FL

Company size

2001,000 employees

Founded

2017

Total raised

$489,443,508

View company profile ↗

Funding rounds

  • Series F$190M
  • Series E$60M
  • Series D$115M
  • Series C$100M
  • Series B$20M
  • Series A$4.4M
  • Seed$4.4M