About The Position

The Zero Trust OS Logon & Enterprise Applications team at Cisco Duo designs and engineers the foundational low-level authentication software that secures critical Windows and macOS enterprise endpoints across tens of thousands of global organizations. Our team's work sits directly at the frontline of Zero Trust access, ensuring seamless, resilient multi-factor authentication and passwordless logon across enterprise fleets, Active Directory environments, and cloud identity providers. We are a tight-knit, collaborative engineering squad of systems programmers and security specialists who value deep technical rigor, pragmatic problem-solving, and psychological safety. You will tackle high-stakes systems challenges—from low-level Windows Credential Providers and ADFS adapters to cutting-edge passwordless architectures—where the code you write executes at the very core of operating system security.

Requirements

  • Bachelor's degree in computer science, computer engineering, or a related technical field (or equivalent practical experience).
  • 6+ years of professional systems software engineering experience using Modern C++ (C++14/17/20) or C.
  • Experience developing native Windows desktop or server applications using Win32 APIs, multi-threading synchronization primitives, and IPC.
  • Experience administering or integrating with on-premises Active Directory (AD DS), Kerberos authentication protocols, or Windows Server environments.
  • Experience authoring PowerShell scripts or utilizing WMI/CIM for Windows system automation, configuration, and troubleshooting.

Nice To Haves

  • Direct experience developing custom Windows Credential Providers, LSA authentication packages, or Active Directory Federation Services (ADFS) MFA adapters.
  • Hands-on experience debugging user-mode crashes, race conditions, and deadlocks using WinDbg, ETW tracing, or Visual Studio diagnostic tools.
  • Experience authoring enterprise MSI installer customizations, Group Policy Administrative Templates (.admx/.adml), or GPO deployment workflows.
  • Familiarity with modern authentication protocols, FIDO2/WebAuthn, Passwordless logon architectures, or Microsoft Entra ID (Azure AD) hybrid join.
  • Demonstrated technical leadership experience authoring Architectural Decision Records (ADRs), conducting structured code reviews, and mentoring fellow engineers.

Responsibilities

  • Design and implement high-performance, memory-safe endpoint authentication components and enterprise integrations using Modern C++ (C++17/20) and native Win32 APIs to deliver resilient Zero Trust security at operating system logon.
  • Lead the technical design and hardening of custom Windows Credential Providers, ADFS MFA adapters, and WTS multi-session services to eliminate authentication latency and prevent credential bypass attacks.
  • Develop automated diagnostic utilities and robust administrative tooling using PowerShell and WMI/CIM to streamline enterprise-scale deployment and enhance sysadmin manageability.
  • Partner closely with Product Management, Security Architecture, and Design to author Architectural Decision Records (ADRs) and establish comprehensive automated test pipelines to guarantee zero-regression releases.
  • Mentor peer engineers through insightful code reviews and technical guidance to foster engineering excellence and accelerate team delivery velocity.

Benefits

  • medical, dental and vision insurance
  • a 401(k) plan with a Cisco matching contribution
  • paid parental leave
  • short and long-term disability coverage
  • basic life insurance
  • grants of Cisco restricted stock units
  • 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees
  • 1 paid day off for employee’s birthday
  • paid year-end holiday shutdown
  • 4 paid days off for personal wellness
  • 16 days of paid vacation time per full calendar year, accrued at rate of 4.92 hours per pay period for full-time employees (non-exempt)
  • flexible vacation time off program (exempt)
  • 80 hours of sick time off provided on hire date and each January 1st thereafter
  • up to 80 hours of unused sick time carried forward from one calendar year to the next
  • Additional paid time away may be requested to deal with critical or emergency issues for family members
  • Optional 10 paid days per full calendar year to volunteer
  • annual bonuses (for non-sales roles)
  • performance-based incentive pay (for sales roles)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service