Endpoint Engineer

1ST CHAPTER ENT. & SECURITY SERVICES, LLC
United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Artificial Intelligence Automation of Tests Code Review Concurrent Computing Software Debugging File Systems Memory Management Python (Programming Language) Microsoft Security Essentials Reverse Engineering Multithreading
+3 more
Scripting Malware Vulnerability Analysis

Job description

Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category., The Ent agent is where our product meets the operating system. As an Endpoint Engineer, EDR, you’ll design and ship the kernel- and user-mode components that observe process, file, registry, network, and identity activity on Windows and turn that raw activity into high-fidelity signals about what an actor is actually trying to do.

You’ll own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and the interception logic that stops malicious activity before it completes. The constraints are real. The sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and has to stay inside strict CPU, memory, and I/O budgets while resisting tamper, bypass, and evasion.

You’ll work closely with security research, AI, platform, and product to feed sensor signals into policy enforcement, real-time interventions, and investigation timelines.

What You’ll Achieve

  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Windows and turn that activity into high-fidelity intent signals.
  • Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes.
  • Instrument telemetry at the OS boundary: ETW, kernel callbacks, and minifilters.
  • Harden the agent against tamper, bypass, and evasion - self-protection, integrity validation, and safe handling of untrusted input inside a privileged process.
  • Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship.
  • Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted.
  • Drive high-severity customer escalations to root cause - crashes, hangs, performance regressions, missed detections - at the code and OS-internals level, and convert escalation patterns into permanent fixes.
  • Partner with the security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement, just-in-time interventions, and investigation timelines.
  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call.

Requirements

  • 10+ years designing, building, and delivering production C/C++ systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance-critical native code.
  • Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
  • Hands-on production experience with kernel callbacks and minifilters.
  • Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering.
  • Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report.
  • Strong low-level debugging skills, performance tracing, and crash-dump analysis.
  • Multi-threaded and concurrent programming under load - synchronization, lock contention, race conditions, and object lifetime management.
  • A track record of code running on large fleets without degrading end-user experience; you treat stability and performance as product features.
  • Scripting fluency for tooling and test automation (Python or equivalent).
  • Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers., * Kernel-mode driver or kernel extension development shipped to production at scale.
  • Reverse engineering, malware analysis, or exploit and vulnerability research background.
  • Experience with anti-tamper, code integrity, driver signing and WHQL attestation.

Benefits & conditions

  • Distributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.
  • Own a piece of the journey. Every teammate gets meaningful equity on top of their salary.
  • We’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.
  • Take the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.
  • Family matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.
  • Live well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy - fitness, wellness, learning, and more.
  • Set up your space. A $500 home office stipend when you join as a remote employee.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all