> Markdown version of [/jobs/ext/2737516-endpoint-engineer](https://www.wearedevelopers.com/jobs/ext/2737516-endpoint-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Endpoint Engineer - **Company:** 1ST CHAPTER ENT. & SECURITY SERVICES, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Automation of Tests, Code Review, Concurrent Computing, Software Debugging, Linux, File Systems, Memory Management, Python (Programming Language), Microsoft Security Essentials, Cloud Services, Reverse Engineering, Software Engineering, Multithreading, Scripting, Malware, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/endpoint-engineer-edr-linux-ent-security-9915631 ## About the Role * 10+ years designing, building, and delivering production C/C++ (or Rust) systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance-critical native code. * Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC. * Hands-on production experience with eBPF. * Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering. * Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report. * Strong low-level debugging skills, performance tracing, and crash-dump analysis. * Multi-threaded and concurrent programming under load - synchronization, lock contention, race conditions, and object lifetime management. * A track record of code running on large fleets without degrading end-user experience; you treat stability and performance as product features. * Scripting fluency for tooling and test automation (Python or equivalent). * Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers., * Kernel-mode driver or kernel extension development shipped to production at scale. * Reverse engineering, malware analysis, or exploit and vulnerability research background. * Experience with anti-tamper and code integrity. ## Description Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We're now hiring the team that will define this category., We are seeking an Endpoint Engineer to be part of the team that owns the Linux sensor at the core of Ent's EDR capability. This role builds detection and prevention on eBPF, LSM, and the audit subsystem, across the range of Linux customers actually run - workstations, servers, containers, and cloud workloads. You will own the tradeoffs between detection efficacy, false positives, and performance, and defend them with measured data., * Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Linux and turn that activity into high-fidelity intent signals. * Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes. * Make and defend explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance, backed by measured data rather than intuition. * Instrument telemetry at the OS boundary: eBPF, LSM, and audit subsystems. * Harden the agent against tamper, bypass, and evasion - self-protection, integrity validation, and safe handling of untrusted input inside a privileged process. * Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship. * Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted. * Drive high-severity customer escalations to root cause - crashes, hangs, performance regressions, missed detections - at the code and OS-internals level, and convert escalation patterns into permanent fixes. * Partner with the security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement, just-in-time interventions, and investigation timelines. * Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call. ## Related Videos - [Into the hive of eBPF!](https://www.wearedevelopers.com/videos/1199-into-the-hive-of-ebpf) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)