Job Summary:
ThreatLocker® is a leader in endpoint protection technologies, providing enterprise-level cybersecurity tools. We are seeking a Windows Kernel Driver Engineer to build and maintain critical kernel-mode components for threat detection and prevention on Windows systems.
Responsibilities:
• Design and develop kernel-mode filter drivers (file system minifilter, registry filter, network filter, etc.) to support security monitoring and enforcement.
• Investigate and reverse-engineer Windows internals to implement low-level security features and bypass-resistant protections.
• Collaborate with the threat research, detection, and user-mode engineering teams to develop scalable and stealthy security solutions.
• Perform in-depth kernel debugging, crash dump analysis, and performance tuning using WinDbg, ETW, and related tools.
• Develop robust, secure, and maintainable driver code that meets Microsoft's signing and certification standards.
• Monitor Windows platform changes to ensure compatibility and stability across OS versions.
Qualifications:
Required:
• 5+ years of hands-on experience writing Windows kernel-mode drivers, particularly filter drivers.
• Expert knowledge of Windows system internals (memory management, I/O subsystem, object manager, etc.).
• Proficiency in C/C++, Windows Driver Kit (WDK), and kernel debugging tools.
• Experience in the cybersecurity domain, especially endpoint protection, EDR, anti-malware, or kernel-level monitoring.
• Solid understanding of code injection techniques, hooking, kernel-mode exploits, and mitigation strategies.
• Strong problem-solving skills and a security-first engineering mindset.
Preferred:
• Experience with malware analysis, reverse engineering, or rootkit detection.
• Familiarity with Windows kernel threat models and secure coding practices.
• Exposure to Microsoft kernel-mode signing, WHQL, and driver submission processes.
• Contributions to the infosec community (research, publications, open-source projects, talks)
Company:
ThreatLocker is a cybersecurity company that specializes in endpoint security and application whitelisting solutions. Founded in 2017, the company is headquartered in Orlando, USA, with a team of 501-1000 employees. The company is currently Late Stage.