LO

Principal Kernel / eBPF / XDP Engineer (Runtime Evidence)

Lorasis
Posted 1 hour ago
SpainRemoteEngineering & Development
Is this job info correct?

ABOUT LORASIS


Lorasis is building the cybersecurity Trust Operating System: a governed layer designed to help organisations decide whether consequential machine actions should proceed within defined boundaries, then make what was intended, authorised, executed, and observed independently verifiable.


We are a small, deeply technical team. We do not grow through raw headcount. We grow by giving experienced people better tools while keeping judgment, accountability, and quality standards human.


THE CULTURE WE ARE BUILDING


Our model is simple: Don’t predict. Converge.


Predicting is passive. Converging means bringing engineering, security, and talent together at the point where difficult problems get solved. We do not guess the future. We build it.


We believe sustainable growth comes from genuine value and long-term customer trust, not short-term pressure that burns people out and loses customers.


Lorasis is neurodivergent founder-led. One rule is absolute: technical brilliance never excuses behaviour that undermines trust or the people around you.


We operate around three principles:


1. Autonomy over micromanagement


We hire excellent people, give them meaningful ownership, and trust them to deliver.


2. Uncompromised quality


We master our craft. When difficult obstacles appear, we collaborate and solve them together.


3. Enjoy the build


We work with high trust, side by side, as co-creators rather than followers.


AI can contribute. Humans own the decision.


We use AI to reduce busywork across research, context gathering, implementation, testing, and coordination. This creates more time for the work that requires experience: understanding risk, making difficult tradeoffs, challenging assumptions, and deciding what is safe to ship.


THE ROLE


You will own the kernel and agent evidence path behind lorasis-agent.


This includes Linux kernel, eBPF, and XDP instrumentation for evidence of execution: establishing the difference between what a system was asked to do and what actually ran. You will also connect runtime evidence with TEE, TPM, and other platform-attestation signals.


This is a hands-on Principal Individual Contributor role reporting to the Founder and CEO. It is not a cofounder or CTO position.


You will work closely with our first engineer on the AI and runtime-evidence spine of the platform. We are looking for someone capable of multiplying a very small team through deep systems expertise and practical AI-assisted engineering.


WHAT YOU WILL DO


• Own Linux kernel, eBPF, and XDP instrumentation feeding evidence of execution into lorasis-agent.


• Capture reliable runtime evidence about processes, files, network activity, and other relevant system actions.


• Integrate TEE, TPM, and trusted-computing signals into the evidence path by consuming and verifying platform quotes and measurements.


• Build systems that fail honestly, clearly exposing missing visibility, unsupported probes, degraded coverage, and verification failures.


• Design and operate complete AI-assisted development workflows from specification to code, testing, review, and pull request.


• Ensure those workflows produce real, reviewable kernel and eBPF engineering output, not isolated demonstrations or prompt theatre.


• Target RHEL, Container-Optimized OS, and GKE-class environments across our initial lab and deployment paths.


• Define clean boundaries between privileged kernel-facing components and the wider Lorasis platform.


• Lead technical design reviews, investigate difficult systems failures, and raise the quality bar for privileged code.


• Respect open-source licences, software provenance, and third-party intellectual property.


WHAT WE ARE LOOKING FOR


• Deep, hands-on Linux kernel engineering experience.


• Strong production experience with eBPF, XDP, BTF, and related kernel observability or security tooling.


• Experience packaging and operating privileged Linux components using technologies such as RPM and systemd.


• A practical understanding of probe limitations, kernel-version differences, degraded visibility, and fail-honest system design.


• Experience consuming trusted-computing or hardware-attestation signals such as Intel TDX, AMD SEV-SNP, TPM, or equivalent technologies.


• The ability to work with quotes, measurements, keys, and verifier outputs as part of an evidence path. You will not be expected to reinvent the underlying attestation platform.


• Experience building complete AI-assisted engineering workflows covering specification, implementation, testing, review, and pull requests.


• Strong architectural judgment and the ability to move between deep debugging, system design, and production delivery.


• The autonomy and communication skills required to operate effectively inside a small, senior technical team.


HUGE PLUS


• Vulnerability research, exploit analysis, malware or rootkit analysis, or kernel attack-surface research.


• Rust, systems-level C, and experience working across FFI boundaries.


• Contributions to or maintainership of kernel observability, eBPF, or security open-source projects.


• Familiarity with ecosystems such as Tracee, Jibril, BTFHub, or comparable kernel-security tooling.


• Experience mentoring systems engineers or helping shape a future kernel-security team.


HOW TO APPLY


Apply through LinkedIn with a short note describing your most relevant work across Linux kernel engineering, eBPF, XDP, trusted computing, AI-assisted development, or threat research.


Please include links to any public code, technical talks, research, articles, or other work that helps us understand how you think and build.


Candidates must respect all obligations to current and former employers.


Lorasis

Madrid, Spain · Globally remote

https://www.lorasis.io

Similar jobs