Develop and optimize I/O filter drivers for advanced functionality
Collaborate on system-level architecture and integration with Windows internals
Write and maintain user-mode components using Win32 API where required
Debug and troubleshoot complex driver and system issues
Требования
The ideal candidate will have strong expertise in Kernel-Mode Driver Framework (KMDF) and Windows Filtering Platform (WFP) development, primarily using C/C++
5+ years of hands-on experience in C++ development (C++11 or later)
Deep understanding of Windows internals: kernel architecture, system calls, memory management, and drivers
Strong debugging and reverse engineering skills using WinDbg, Process Monitor, Process Explorer, IDA/Ghidra
Familiarity with Windows security mechanisms: integrity levels, UAC, AppLocker, secure boot
Experience with Visual Studio, Windows Driver Kit (WDK), and related build/debug environments
Strong experience in KMDF driver development
Hands-on experience with Windows Filtering Platform (WFP)
Proficiency in C/C++ for Windows development
Familiarity with Windows internals (memory management, threading, synchronization)
Experience with I/O filter drivers (bonus)
Knowledge of user-mode programming using Win32 API
Experience building or contributing to endpoint security products (EDR, AV, EPP)
Familiarity with Windows telemetry, event logs, Sysmon, and ETW tracing
Experience with malware analysis, Windows exploit techniques, or SOC/DFIR workflows
Scripting capabilities in PowerShell or Python for automation and testing
Understanding of kernel-mode security evasion techniques and defenses
Background in code signing, driver deployment, and secure update mechanisms
Bachelor's degree in Computer Science, Software Engineering, or equivalent experience
Experience with network protocols and packet filtering
Understanding of security concepts related to driver development
Previous work on performance optimization in kernel-mode
Навыки
Proven experience in kernel-mode development (e.g., Windows Drivers, Windows Filtering Platform, minifilters, ETW)