> Markdown version of [/jobs/ext/2733051-endpoint-engineer-edr-macos](https://www.wearedevelopers.com/jobs/ext/2733051-endpoint-engineer-edr-macos). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Endpoint Engineer, EDR (macOS) - **Company:** 1ST CHAPTER ENT. & SECURITY SERVICES, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Automation of Tests, C++ (Programming Language), Code Review, Concurrent Computing, Software Debugging, Linux, File Systems, Memory Management, Python (Programming Language), Microsoft Security Essentials, E2e Testing, Reverse Engineering, Multithreading, Scripting, Malware, ONNX (Open Neural Network Exchange) Format, Objective C++, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/endpoint-engineer-edr-macos-ent-security-9915632 ## About the Role * 10+ years designing, building, and delivering production native systems software (Swift, C, C++, or Objective-C), a substantial portion of it in endpoint security, OS internals, or comparable performance-critical code with strong, current Swift, including modern concurrency (actors, Sendable, structured concurrency). * Deep working knowledge of macOS internals: process and thread lifecycle, memory management, file systems, code signing and entitlements, launchd, IPC (XPC and Mach primitives), and the TCC permission model. * Hands-on production experience with the Endpoint Security framework and/or Network Extensions, and an understanding of the system extension lifecycle that replaced kernel extensions. * Demonstrated experience building or operating an EDR, EPP, XDR, DLP, or insider-risk product, or equivalent detection-and-response engineering. * Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report. * Strong low-level debugging skills: lldb, crash-dump and hang analysis, performance tracing with Instruments or equivalent. * Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, actor isolation, and object lifetime management. * A track record of code running on large fleets without degrading end-user experience; you treat stability and performance as product features, and you understand enterprise deployment realities (MDM profiles, notarization, staged rollout, auto-update). * Scripting fluency for tooling and test automation (Python, shell, or equivalent). * Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers., * Reverse engineering, malware analysis, or exploit and vulnerability research background. * Experience shipping on-device ML inference (Core ML, ONNX Runtime, llama.cpp-class runtimes) inside a resource-constrained agent. * Experience with browser extension or native-messaging integrations for telemetry capture. * Cross-platform endpoint agent experience (Windows or Linux sensors) alongside macOS. ## Description Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We're now hiring the team that will define this category., As an Endpoint Engineer, EDR (macOS), you'll design and ship the privileged daemon, per-user agents, and system extensions that observe process, file, network, device, and user-interaction activity and turn it into high-fidelity signals about what an actor is actually trying to do. You'll own EDR-class detection and prevention end to end: instrumentation through the Endpoint Security framework, Network Extensions, FSEvents, and IOKit; event enrichment and on-box correlation; and the interception logic - ES AUTH decisions, network flow filtering - that stops malicious activity before it completes. The constraints are real. The sensor spans multiple processes joined by XPC, runs privileged on large customer fleets, handles thousands of events per second against hard deadlines, and has to resist tamper and evasion without degrading the machine. You'll work closely with security research, AI, platform, and product to feed sensor signals into on-device classification, policy enforcement, and investigation timelines. What You'll Achieve * Design, build, and ship the privileged daemon, per-user agents, and system extensions that make up the macOS agent: observing process, file, network, device, and user-interaction activity and turning it into intent signals. * Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation and rule evaluation, and interception logic (Endpoint Security AUTH decisions, network flow filtering) that stops malicious or policy-violating activity before it completes. * Instrument telemetry at the OS boundary: Endpoint Security framework, Network Extensions (NEFilterDataProvider), FSEvents, IOKit, and event taps and capture data-movement signals. * Design and maintain the multi-process architecture that ties it together: launchd-managed daemon and agents, XPC protocols between components, code-signing-based peer authentication, and safe handling of untrusted input inside a privileged process. * Harden the agent against tamper, bypass, and evasion using self-protection, integrity validation, and update-chain security. * Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second including hard real-time constraints like ES auth deadlines, profile hot paths, and eliminate regressions before they ship. * Build test harnesses and automated regression coverage, including VM-based end-to-end testing that exercises real OS mechanisms. * Drive high-severity customer escalations to root cause crashes, hangs, performance regressions, missed detections, permission and deployment failures at the code and OS-internals level, and convert escalation patterns into permanent fixes. * Partner with the security research, AI, platform, and product teams to feed sensor signals into on-device ML classification, intent-aware policy enforcement, just-in-time interventions, and investigation timelines. * Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call. ## Related Videos - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 176: Expensive Agents, Taking Over VSCode and Safer Vibe Coding](https://www.wearedevelopers.com/magazine/603-dev-digest-176-expensive-agents-taking-over-vscode-and-safer-vibe-coding) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)