> Markdown version of [/jobs/ext/2732742-endpoint-engineer](https://www.wearedevelopers.com/jobs/ext/2732742-endpoint-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Endpoint Engineer - **Company:** 1ST CHAPTER ENT. & SECURITY SERVICES, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Apple Mac Systems, Automation of Tests, C++ (Programming Language), CMake, Configuration Management, Code Review, Continuous Integration, Data Validation, Software Debugging, Linux, Memory Management, Github, Python (Programming Language), Microsoft Security Essentials, System Center Configuration Manager, Ansible, Management of Software Versions, Scripting, Performance Testing, Backend, Microsoft InTune, Integration Tests, Casper Suite, Build Tools - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/endpoint-engineer-ent-security-9915629 ## About the Role * 5+ years building production software in C/C++ or Swift, including work on native desktop or endpoint software. * Working knowledge of operating system internals and system APIs on at least one of Windows, macOS, or Linux. * Experience with software that runs unattended on machines you do not control: versioning, upgrades, backward compatibility, and failure recovery. * Solid grasp of concurrency, memory management, and empirical performance measurement. * Debugging discipline - you reproduce, instrument, and prove root cause instead of guessing at fixes. * Comfort with build systems, cross-platform CI/CD, and test automation (CMake or Bazel, GitHub Actions or equivalent), plus scripting in Python. * Security-conscious coding habits: input validation, privilege boundaries, and awareness of how endpoint software itself becomes attack surface. * Clear communication and effective collaboration in a distributed, fast-moving team., * Prior endpoint security experience - EDR, DLP, EPP, MDM, or insider risk - or work on systems-monitoring agents. * Exposure to kernel extensions and drivers, eBPF, ETW, or the macOS Endpoint Security Framework. * Enterprise deployment realities: Intune, Jamf, SCCM, Ansible, and MDM-driven configuration management. * Code signing, Apple notarization, or driver attestation pipelines. ## Description Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We're now hiring the team that will define this category., We are seeking an Endpoint Engineer to be part of the team that owns the endpoint agent every Ent capability ships on: collection, policy evaluation, enforcement, transport, and the lifecycle machinery around them. This role is measured on the things customers only notice when they break - installs, updates, offline behavior, and resource footprint on machines you cannot log into. Every other endpoint capability depends on getting it right., * Build and own components of Ent's single lightweight agent across Windows, macOS, or Linux; collection, enrichment, policy evaluation, enforcement, IPC, local storage, and cloud transport. * Deliver features end to end: design, implementation, tests, telemetry, staged rollout, and post-release monitoring. * Own agent lifecycle engineering: packaging and installers (MSI, PKG, DEB/RPM), enrollment, configuration delivery, safe staged self-update, rollback, and clean uninstall. * Keep the agent fast and boring - enforce CPU, memory, disk, and network budgets, catch performance regressions in CI, and treat stability as non-negotiable on machines you cannot log into. * Implement offline and degraded-mode behavior: local queueing, backpressure, policy caching, retry semantics, and clock and connectivity edge cases. * Apply secure engineering fundamentals inside a privileged process: least privilege, signed and verified updates, secrets handling, and safe parsing of untrusted input. * Build diagnostics, log collection, health reporting, and support tooling so field issues can be root-caused without attaching a debugger to a customer's laptop. * Own test infrastructure for the agent: unit and integration tests, cross-platform CI, OS-version matrices, upgrade and downgrade paths, and soak and performance testing on real hardware. * Integrate agent signals with backend services and the browser extension, and work with platform teams on API and schema evolution without breaking older agent versions. * Handle escalations across the stack - failed installs, conflicts with other security agents, OS and kernel upgrades, crashes, and performance complaints. * Contribute to code review, design review, documentation, and the on-call rotation for agent health. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Code to Road in < 12 hours](https://www.wearedevelopers.com/videos/1082-code-to-road-in-12-hours) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)