About the role
We are seeking an architect-level Lead Software Engineer with deep expertise in Windows OS internals, systems programming, Windows deployment, and enterprise endpoint automation. This role focuses on low-level Windows engineering across boot and recovery, bare-metal deployment, patch orchestration, startup flows, endpoint state management, and zero-disruption updates. You will work closely with the CTO and Head of Product to translate product concepts into technical designs, lead the architecture of an endpoint decision engine, and implement WinPE-based recovery and image-free installation workflows. The role includes building content delivery infrastructure (Azure Blob, CDN, on-prem repositories), automating driver/BIOS/firmware updates, and extending Autopilot and provisioning workflows for VDI and Cloud PC scenarios. This is a fully remote, U.S. Central Time hours role for a 100% dedicated, long-term Contract (C2C) engagement. Candidates must be comfortable with the client's verification and background checks and be prepared to provide updated LinkedIn, UAN details, full employment history, and supporting documentation during the selection/BGV process.
Requirements
- 10+ years of professional software engineering experience in systems-level Windows development.
- Deep expertise in Windows Internals, including boot sequence, services, Registry, security tokens, privilege management, and kernel-adjacent/low-level development.
- Expert-level experience with C/C++ and/or C#/.NET for systems and platform development.
- Advanced PowerShell scripting and automation skills.
- Hands-on experience with WinPE, Windows OS deployment, unattended installation, and task sequencing.
- Experience building WinPE-based recovery environments and programmatic image-free Windows installation workflows.
- Experience building bare-metal OS deployment and internet-boot/recovery workflows for unbootable OS or failed storage devices.
- Proven experience developing zero-disruption Windows update mechanisms, including application detection, patch deferral/retry, and startup-sequence integration for multi-reboot orchestration where needed.