819,019open jobs
52,716companies
133,023added this week
Browse all
Salary
≈ $102k – $219k per year (Estimated)
Location
Remote (North America)
Seniority
Senior · 10+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Sep 4, 2026.

Overview
Company
Impact
Profile match

Ent

Intent-aware security for the enterprise. Ent reads human, AI, and application activity in real time and steps in at the moment of risk — protecting work as it happens.

Senior Endpoint Engineer, EDR (Windows)

About Ent

Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category.

How We Work

Customer first. The product and the business are built around problems we’ve watched real security teams struggle with - not the other way around. Every roadmap conversation starts with what a CISO told us last week.

Humble. No drama. We hire people who share the mission and trust each other to deliver. Teamwork over showmanship. Accountability over politics. The work speaks louder than the person doing it.

Urgency. The window to build a durable security company in the AI era is open right now and it will not stay open. The shot clock has started. We move at the speed of the people we want to protect.

About the Role

The Ent agent is where our product meets the operating system. As an Endpoint Engineer, EDR, you'll design and ship the kernel- and user-mode components that observe process, file, registry, network, and identity activity on Windows and turn that raw activity into high-fidelity signals about what an actor is actually trying to do.

You'll own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and the interception logic that stops malicious activity before it completes. The constraints are real. The sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and has to stay inside strict CPU, memory, and I/O budgets while resisting tamper, bypass, and evasion.

You'll work closely with security research, AI, platform, and product to feed sensor signals into policy enforcement, real-time interventions, and investigation timelines.

What You’ll Achieve

  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Windows and turn that activity into high-fidelity intent signals.

  • Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes.

  • Instrument telemetry at the OS boundary: ETW, kernel callbacks, and minifilters.

  • Harden the agent against tamper, bypass, and evasion - self-protection, integrity validation, and safe handling of untrusted input inside a privileged process.

  • Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship.

  • Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted.

  • Drive high-severity customer escalations to root cause - crashes, hangs, performance regressions, missed detections - at the code and OS-internals level, and convert escalation patterns into permanent fixes.

  • Partner with the security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement, just-in-time interventions, and investigation timelines.

  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call.

What You’ll Bring

Must-haves

  • 10+ years designing, building, and delivering production C/C++ systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance-critical native code.

  • Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.

  • Hands-on production experience with kernel callbacks and minifilters.

  • Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering.

  • Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report.

  • Strong low-level debugging skills, performance tracing, and crash-dump analysis.

  • Multi-threaded and concurrent programming under load - synchronization, lock contention, race conditions, and object lifetime management.

  • A track record of code running on large fleets without degrading end-user experience; you treat stability and performance as product features.

  • Scripting fluency for tooling and test automation (Python or equivalent).

  • Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers.

Bonus

  • Kernel-mode driver or kernel extension development shipped to production at scale.

  • Reverse engineering, malware analysis, or exploit and vulnerability research background.

  • Experience with anti-tamper, code integrity, driver signing and WHQL attestation.

Our Benefits

  • Distributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.

  • Own a piece of the journey. Every teammate gets meaningful equity on top of their salary.

  • We’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.

  • Take the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.

  • Family matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.

  • Live well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy - fitness, wellness, learning, and more.

  • Set up your space. A $500 home office stipend when you join as a remote employee.

Diversity & Accommodations

We’re committed to building a diverse, inclusive, and equitable workplace where people of all backgrounds, identities, experiences, and abilities are welcomed, valued, and supported. We recognize there is no single path to success and value nontraditional career journeys and diverse perspectives as key to building stronger, more innovative teams.

We strive to ensure an inclusive experience at every stage of hiring and are happy to provide reasonable accommodations. If you require accommodations or accessible formats at any point during our process, please let your recruiter know. As an equal opportunity employer, our hiring process is designed to put you at ease and help you do your best work. If there’s anything we can do to improve your experience, we’re always open to feedback.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
819,019 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Support
Similar stack
Same company
In your city
$46k – $74k per year • In office • Full-Time • Colorado Springs
DevOps
Red Hat
AWS
Linux
Windows
Apply
$42k – $66k per year • In office • Full-Time • Fargo
DevOps
Red Hat
AWS
Linux
Windows
Apply
≈ $65k – $139k per year (Estimated) • In office • Full-Time • 8+ years exp • Plano
JavaScript
Node JS
Node JS
Commander.js
DevOps
Splunk
Datadog
Dynatrace
PagerDuty
Incident Management
SLI/SLO/SLA
Management
ServiceNow
ITIL
Apply
≈ $54k – $105k per year (Estimated) • Remote (likely United States) • 2+ years exp • Associate's Degree
Management
Microsoft Office
Apply
≈ $83k – $176k per year (Estimated) • In office • Bachelor's Degree • Austin
Chips/EDA
Ansys HFSS
Ansys SIwave
Apply
≈ $61k – $132k per year (Estimated) • Remote (United States) • Full-Time • 4+ years exp • United States
Python
JavaScript
TypeScript
AI/ML
Copilot
LangGraph
AutoGen
LangChain
Claude
ChatGPT
Model Context Protocol
Prompt Engineering
AI Agents
CrewAI
RAG
OpenAI
Anthropic
DevOps
GCP
Azure
CI/CD
AWS
Management
Agile
QA
Selenium
Cypress
Playwright
Pytest
Robot Framework
Apply
$78k – $100k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • United States
Python
JavaScript
PowerShell
AI/ML
Embeddings
AI Agents
LLM
Human-in-the-Loop
Structured Outputs
LLM Guardrails
DevOps
GCP
Azure
AWS
Management
ITIL
ITSM
Apply
$140k – $170k per year • Equity • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Madison • Lincoln • Centennial
Python
JavaScript
Java
TypeScript
C#
Node JS
Java
Spring Boot
Frontend
Angular
React.js
Mobile
Firebase
DevOps
GCP
Azure
CI/CD
AWS
GitHub
Cybersecurity
OWASP Top 10
Apply
$29k – $65k per year • In office • Full-Time • Tokyo
Python
DevOps
Docker
Linux
Apply
≈ $38k – $102k per year (Estimated) • In office • Full-Time • Tokyo
Python
DevOps
Docker
Linux
Apply
≈ $91k – $176k per year (Estimated) • Remote (North America) • Full-Time • 5+ years exp
Python
C++
C++
CMake
AI/ML
Copilot
DevOps
Ansible
GitHub Actions
CI/CD
Configuration Management
Bazel
eBPF
Linux
Windows
Cybersecurity
Least Privilege
DLP
Apply
≈ $80k – $154k per year (Estimated) • Remote (North America) • Full-Time • 5+ years exp
C++
AI/ML
Copilot
LLM
OCR
DevOps
eBPF
Linux
Windows
Cybersecurity
PCI DSS
GDPR
HIPAA
Apply
≈ $106k – $228k per year (Estimated) • Equity • Remote (North America) • Full-Time • 10+ years exp
Python
C++
Objective-C
AI/ML
Copilot
llama.cpp
Edge AI
ONNX Runtime
Mobile
Core ML
DevOps
Linux
Windows
Cybersecurity
DLP
Apply
CISO 3 days ago
≈ $170k – $292k per year (Estimated) • Remote (North America) • Full-Time
Go
Go
Ent
AI/ML
Copilot
AI Agents
DevOps
GCP
Azure
AWS
Windows
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Threat Modeling
Microsoft Entra ID
Management
Google Workspace
Apply
≈ $59k – $122k per year (Estimated) • Hybrid • Full-Time • 2+ years exp • San Francisco
AI/ML
Copilot
Management
Slack
Apply
See all jobs
This is one of many
819,019 more open roles from verified company boards, updated every day.