Windows Kernel Security Engineering — Educational
Budget / Salary₹600–1,500
TypeFreelance project
LocationRemote
Posted2 hours ago
**Job Title:** Windows Kernel Security Engineer — Educational Governance Runtime
**About the Project**
We are a technology book publisher working on a hands-on book about Windows security engineering. As part of the book's companion code, we are building a working Windows kernel-level security enforcement and audit system that demonstrates real production-grade governance concepts in a testable environment.
The system operates at the kernel level — intercepting OS events, enforcing policy decisions, and generating a tamper-evident audit trail. The core policy engine is supplied by us as a sealed compiled library. Your role is to build the enforcement plumbing around it: the kernel driver, the audit infrastructure, the monitoring tooling, and the final deployment package. You integrate our library — you do not implement policy logic.
The programme covers seven milestones spanning Authenticode manifest tooling, a KMDF enforcement driver using ObRegisterCallbacks and a minifilter, an ETW audit provider with hash-chained post-quantum signatures, COM/DCOM interception with a WFP network callout, a VBS/VSM VTL1 trustlet, a behavioural monitor Windows Service, and a pentest-ready Windows Server deployment package with a consolidated CLI monitoring tool and MSI installer.
**What We Are Looking For**
You have hands-on Windows kernel driver development experience — not just familiarity, but shipped code. You know KMDF and the WDK. You run Driver Verifier from the start of development, not only before release. You have written ObRegisterCallbacks hooks, minifilters, and WFP callout drivers. ETW kernel provider development and COM/DCOM interception are within your range. Experience with VTL1 IUM trustlet development or Secure Call / VMCALL interfaces is a strong advantage and required for one milestone — please describe any prior experience in your bid.
A firmware or embedded systems background is a genuine plus. The discipline of writing reliable C/C++ under hardware-adjacent constraints transfers directly to the demands of this project.
**How to Bid**
Do not ask for our budget. Instead, read the specification carefully and tell us how you estimate the effort per milestone and why. Your per-milestone breakdown and your answer to this question are what we evaluate alongside your price: *For the enforcement driver milestone, what Driver Verifier profile do you use and at what point in development do you enable it?* Also tell us whether you work solo or have team members who can work milestones in parallel, and what the realistic calendar duration would be.
Bids that skip the estimation and ask only for a budget number will not be considered.
**NDA**
A Non-Disclosure and Invention Assignment Agreement must be signed before any technical details are shared.
**About the Project**
We are a technology book publisher working on a hands-on book about Windows security engineering. As part of the book's companion code, we are building a working Windows kernel-level security enforcement and audit system that demonstrates real production-grade governance concepts in a testable environment.
The system operates at the kernel level — intercepting OS events, enforcing policy decisions, and generating a tamper-evident audit trail. The core policy engine is supplied by us as a sealed compiled library. Your role is to build the enforcement plumbing around it: the kernel driver, the audit infrastructure, the monitoring tooling, and the final deployment package. You integrate our library — you do not implement policy logic.
The programme covers seven milestones spanning Authenticode manifest tooling, a KMDF enforcement driver using ObRegisterCallbacks and a minifilter, an ETW audit provider with hash-chained post-quantum signatures, COM/DCOM interception with a WFP network callout, a VBS/VSM VTL1 trustlet, a behavioural monitor Windows Service, and a pentest-ready Windows Server deployment package with a consolidated CLI monitoring tool and MSI installer.
**What We Are Looking For**
You have hands-on Windows kernel driver development experience — not just familiarity, but shipped code. You know KMDF and the WDK. You run Driver Verifier from the start of development, not only before release. You have written ObRegisterCallbacks hooks, minifilters, and WFP callout drivers. ETW kernel provider development and COM/DCOM interception are within your range. Experience with VTL1 IUM trustlet development or Secure Call / VMCALL interfaces is a strong advantage and required for one milestone — please describe any prior experience in your bid.
A firmware or embedded systems background is a genuine plus. The discipline of writing reliable C/C++ under hardware-adjacent constraints transfers directly to the demands of this project.
**How to Bid**
Do not ask for our budget. Instead, read the specification carefully and tell us how you estimate the effort per milestone and why. Your per-milestone breakdown and your answer to this question are what we evaluate alongside your price: *For the enforcement driver milestone, what Driver Verifier profile do you use and at what point in development do you enable it?* Also tell us whether you work solo or have team members who can work milestones in parallel, and what the realistic calendar duration would be.
Bids that skip the estimation and ask only for a budget number will not be considered.
**NDA**
A Non-Disclosure and Invention Assignment Agreement must be signed before any technical details are shared.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.