Endpoint Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+14 more
Job description
Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category., We are seeking an Endpoint Engineer to be part of the team that owns the endpoint agent every Ent capability ships on: collection, policy evaluation, enforcement, transport, and the lifecycle machinery around them. This role is measured on the things customers only notice when they break - installs, updates, offline behavior, and resource footprint on machines you cannot log into. Every other endpoint capability depends on getting it right., * Build and own components of Ent’s single lightweight agent across Windows, macOS, or Linux; collection, enrichment, policy evaluation, enforcement, IPC, local storage, and cloud transport.
- Deliver features end to end: design, implementation, tests, telemetry, staged rollout, and post-release monitoring.
- Own agent lifecycle engineering: packaging and installers (MSI, PKG, DEB/RPM), enrollment, configuration delivery, safe staged self-update, rollback, and clean uninstall.
- Keep the agent fast and boring - enforce CPU, memory, disk, and network budgets, catch performance regressions in CI, and treat stability as non-negotiable on machines you cannot log into.
- Implement offline and degraded-mode behavior: local queueing, backpressure, policy caching, retry semantics, and clock and connectivity edge cases.
- Apply secure engineering fundamentals inside a privileged process: least privilege, signed and verified updates, secrets handling, and safe parsing of untrusted input.
- Build diagnostics, log collection, health reporting, and support tooling so field issues can be root-caused without attaching a debugger to a customer’s laptop.
- Own test infrastructure for the agent: unit and integration tests, cross-platform CI, OS-version matrices, upgrade and downgrade paths, and soak and performance testing on real hardware.
- Integrate agent signals with backend services and the browser extension, and work with platform teams on API and schema evolution without breaking older agent versions.
- Handle escalations across the stack - failed installs, conflicts with other security agents, OS and kernel upgrades, crashes, and performance complaints.
- Contribute to code review, design review, documentation, and the on-call rotation for agent health.
Requirements
- 5+ years building production software in C/C++ or Swift, including work on native desktop or endpoint software.
- Working knowledge of operating system internals and system APIs on at least one of Windows, macOS, or Linux.
- Experience with software that runs unattended on machines you do not control: versioning, upgrades, backward compatibility, and failure recovery.
- Solid grasp of concurrency, memory management, and empirical performance measurement.
- Debugging discipline - you reproduce, instrument, and prove root cause instead of guessing at fixes.
- Comfort with build systems, cross-platform CI/CD, and test automation (CMake or Bazel, GitHub Actions or equivalent), plus scripting in Python.
- Security-conscious coding habits: input validation, privilege boundaries, and awareness of how endpoint software itself becomes attack surface.
- Clear communication and effective collaboration in a distributed, fast-moving team., * Prior endpoint security experience - EDR, DLP, EPP, MDM, or insider risk - or work on systems-monitoring agents.
- Exposure to kernel extensions and drivers, eBPF, ETW, or the macOS Endpoint Security Framework.
- Enterprise deployment realities: Intune, Jamf, SCCM, Ansible, and MDM-driven configuration management.
- Code signing, Apple notarization, or driver attestation pipelines.
Benefits & conditions
- Distributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.
- Own a piece of the journey. Every teammate gets meaningful equity on top of their salary.
- We’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.
- Take the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.
- Family matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.
- Live well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy - fitness, wellness, learning, and more.
- Set up your space. A $500 home office stipend when you join as a remote employee.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking