Senior Linux Engineer, Privileged Access
About the role
About the Job
Keeper Security is hiring a Senior Linux Systems Engineer to join our Privileged Access Management team and help build secure endpoint privilege management capabilities for Linux environments. This is a 100% remote position, with an opportunity to work a hybrid schedule for candidates based in the Chicago, IL or El Dorado Hills, CA metro areas.
About the Role
As a Senior Linux Systems Engineer on the PAM team, you will design and build security-sensitive components that control privileged execution and elevation on Linux endpoints. This is a systems engineering role focused on endpoint privilege management, process authorization, Linux security boundaries and long-running privileged services. You will work across a Rust-based Linux agent, native C PAM modules and .NET services running on Linux. The role requires strong knowledge of Linux internals and the ability to reason carefully about process identity, permissions, authentication, kernel-facing APIs and secure failure behavior. This is not a traditional application development role; the work operates close to the Linux operating system and directly influences how privileged processes are authorized and executed.
Responsibilities
- Design, develop and maintain Linux endpoint privilege management capabilities across Rust, C and .NET components
- Build and enhance kernel-facing agent functionality using Linux interfaces such as fanotify, the proc filesystem, namespaces, capabilities and process identity
- Develop and maintain native PAM modules and Linux privilege-elevation workflows
- Build long-running privileged Linux services using Rust, Tokio, MQTT, TLS and asynchronous programming patterns
- Develop Linux-specific orchestration and session-management capabilities in .NET 8, including process authentication, access controls, ephemeral accounts and session monitoring
- Diagnose complex Linux execution and security issues involving blocked processes, authentication races, permissions, SELinux, AppArmor and system service behavior
- Design secure privilege-enforcement mechanisms based on least privilege, process trust and protection against time-of-check/time-of-use (TOCTOU) and authorization race conditions
- Build and maintain systemd services, RPM and DEB packages, installation workflows, service hardening and operational diagnostics
- Collaborate with PAM, endpoint, QA and platform engineers on architecture, testing, cross-platform functionality and production troubleshooting