Principal Support Engineer - Endpoint
Quick Summary
About the Role
~1 min readReach Security tells organizations what their existing security tools should be doing with the products they already own — and proves it. As a Principal Support Engineer, Endpoint, you are Reach's senior domain authority on everything endpoint.
This is not an endpoint break/fix role. You won't spend your days administering endpoints, packaging agents, or chasing agent crashes. You've already done that work — for years — and that is exactly what qualifies you. Those years in the trenches are what let you look at a customer's endpoint configuration, their controls, and Reach's findings and say, with authority, what matters, what doesn't, and why.
In this role you put that hard-won judgment to work advising the field, guiding customers through their hardest problems, sharpening Reach's recommendations, and troubleshooting how Reach integrates with the endpoint products already in a customer's environment. It is a high-agency individual-contributor role for a proven expert who is energized by unfamiliar problems rather than thrown by them.
You'll serve three audiences at once, and the strongest people in this seat move fluidly between them:
The experience below is the foundation we're hiring for. You've done this work hands-on, at depth, earlier in your career — and in this role you'll leverage that judgment as a subject-matter expert rather than performing it day to day. We're screening for the expertise that experience produced, not for a desire to keep doing endpoint administration.
6+ years of deep, hands-on experience with Windows and macOS endpoint agents and endpoint security in enterprise environments — enough to have developed genuine expertise, not passing familiarity.
Time in a senior individual-contributor role such as L3 Support Engineer, Endpoint Engineer, Windows/macOS Engineer, or Security Support Engineer.
Demonstrated command of endpoint agent behavior across Windows and macOS — installation, upgrades, persistence, OS compatibility, performance, and stability — and the judgment to know what “good” looks like.
Kernel-level understanding of Windows, including ETW, WFP, memory management, process/thread behavior, and driver interactions.
macOS internals experience, including the Endpoint Security framework, System Extensions, FSEvents, MDM interactions, notarization, code signing, and process lifecycle.
A track record of analyzing endpoint telemetry, logs, and diagnostics to reach root cause in complex system interactions.
Experience resolving interoperability issues between endpoint agents and security tools (EDR, DLP, MDM, or similar).
Working knowledge of Linux system administration, sufficient to reason about supporting services that interact with endpoint deployments.
Experience with enterprise-scale environments and large endpoint fleets.
The advisory instinct that defines this role: the ability to look at a set of findings and controls and tell a customer, clearly, which few things matter and why.
Strong written and verbal communication — you can make a complex endpoint issue clear to a customer, an SE, and an engineer, each in their own language.
Strong time management and a real sense of urgency in customer-impacting situations.
BS or MS in Computer Science, Engineering, or a related technical discipline — or equivalent practical experience.
Reach spans the whole security stack, and the best domain experts are curious well past their specialty. You don't need to be an expert in all of these, but comfort in several will make you far stronger here: identity and IDP troubleshooting (SSO, SAML/OIDC, layered and conditional access, MDM-to-IdP interactions); a working grasp of threats and vulnerabilities and how they manifest at the endpoint; and familiarity with email security controls. We'll gladly help you deepen the areas you're newer to.
Nice to Have
~1 min readExperience supporting endpoint security, insider risk, or behavioral-analytics platforms.
Experience reproducing customer issues in labs that mirror production endpoint configurations.
Exposure to cloud or hybrid enterprise environments (AWS, Azure, GCP).
Linux internals: kernel/user-space boundaries, eBPF, LSM (SELinux/AppArmor), cgroups and namespaces, netfilter, systemd, proc/sysfs, inotify/fanotify, auditd/seccomp, ELF/ptrace.
Hands-on experience with third-party endpoint security products such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, or similar.
You're the person peers escalate to — and still the first to say “I haven't seen that before, let me dig in.” You think in systems, you're relentless about root cause, and you're generous with what you learn. You're as comfortable teaching the field how to defend a finding as you are reading a kernel trace. Curiosity, adaptability, and low ego matter to us as much as depth: the security stack keeps changing, and we're looking for someone who's genuinely excited by that.
Competitive salary, and equity package
Comprehensive benefits package including:
Medical, dental, and vision insurance, including plan options with company-paid employee coverage
FSA, HSA, and 401(k) plans
Company paid life insurance and disability coverage, along with buy up options
Voluntary benefits including pet insurance, identify theft coverage, and legal services
Unlimited PTO and sick time
Location & Eligibility
Listing Details
- Posted
- August 25, 2026
- First seen
- September 25, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 4
- Repost count
- 0
- Trust Level
- 28%
- Scored at
- September 30, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.