{"id":1233197,"url":"https://alion.io/job/pointfive-endpoint-researcher-lead","title":"Endpoint Researcher Lead","company":{"id":1920967,"name":"PointFive","domain":"pointfive.co","url":"https://alion.io/company/pointfive-co","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":null},"role":"AI/ML","role_family":"AI/ML","seniority":"lead","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Tel Aviv, Israel"],"countries":["IL"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":118000,"max_usd":281000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":773},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"Claude Code","optional":false},{"name":"Copilot","optional":false},{"name":"Cursor","optional":false},{"name":"FinOps","optional":false},{"name":"Linux","optional":false},{"name":"llama.cpp","optional":false},{"name":"MLX ML","optional":false},{"name":"Model Context Protocol","optional":false},{"name":"Ollama","optional":false},{"name":"ONNX Runtime","optional":false},{"name":"OpenAI Codex","optional":false},{"name":"vLLM","optional":false},{"name":"Windows","optional":false},{"name":"Cloudflare","optional":true},{"name":"CUDA","optional":true},{"name":"CUDA Toolkit","optional":true},{"name":"eBPF","optional":true},{"name":"Go","optional":true},{"name":"Hyper-V","optional":true},{"name":"KV Cache","optional":true},{"name":"LocalAI","optional":true},{"name":"Quantization","optional":true},{"name":"ROCm","optional":true},{"name":"Snowflake","optional":true},{"name":"TypeScript","optional":true}],"status":"live","first_seen_at":"2026-09-23T08:15:02Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-10-01T07:18:33Z","board_verified":true,"closed_at":null,"days_open":8,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":8},"description":"About PointFive\nPointFive is the AI Efficiency OS. From the cloud to the coding agent, we're the only platform that manages AI spend everywhere it happens.\nEngineering and FinOps teams use PointFive to make their organizations more efficient and their cloud and AI more effective. We don't just show what you spend. We show what you're wasting, and we fix it autonomously. NuBank saw ROI in 10 days. Customers average 1,200%+ ROI and a 4.9 rating on G2.\nFounded by the team behind IntSights (acquired by Rapid7), PointFive recently closed a $60M Series B led by Accel, with participation from Entrée Capital and Salesforce Ventures.\nAbout the Role\nTokenShift is PointFive's newest product - an endpoint runtime for AI coding agents that gives organizations control, visibility, and efficiency across how agents execute commands and consume models.\nAs AI agents move from chat interfaces into developer machines, they increasingly need access to shells, filesystems, credentials, developer tools, and local compute. At the same time, enterprises are beginning to run models locally - on laptops, workstations, developer VMs, and managed endpoint fleets - across a wide variety of operating systems and hardware architectures.\nThis role exists to push that frontier forward.\nYou'll research how AI coding agents execute and isolate workloads, design secure sandboxing mechanisms, and build the infrastructure required to deploy and operate local models across heterogeneous endpoint environments. You'll work across macOS, Windows, Linux, WSL, developer containers, and other runtime environments, figuring out how to provide agents with powerful capabilities without giving them unrestricted access to the machine.\nIt's a rare opportunity to work at the intersection of operating systems, endpoint security, AI infrastructure, local inference, and developer tooling - in a product already running inside enterprise engineering environments.\nWhat You'll Do\nResearch AI coding agent runtimes - reverse-engineer how tools such as Claude Code, Cursor, Copilot CLI, Codex, and emerging agents execute commands, access files, spawn processes, and interact with the operating system.\n\nDesign agent sandboxing architectures that safely constrain filesystem access, networking, process execution, credentials, and other sensitive endpoint capabilities.\n\nExplore and implement OS-native isolation mechanisms across macOS, Windows, and Linux, including containers, namespaces, sandbox profiles, virtualization, restricted processes, and permission models.\n\nBuild endpoint \"harnesses\" that allow TokenShift to intercept, control, observe, and modify agent execution flows.\n\nDesign infrastructure for deploying and running local LLMs across heterogeneous endpoint fleets, accounting for operating system, CPU architecture, GPU availability, memory constraints, and hardware acceleration.\n\nEvaluate local inference runtimes and model formats such as llama.cpp, MLX, ONNX Runtime, Ollama, vLLM-compatible runtimes, and emerging alternatives.\n\nDevelop mechanisms for model discovery, installation, versioning, updates, health monitoring, and lifecycle management across large numbers of developer machines.\n\nResearch hardware-aware model selection and routing - deciding which models can run effectively on Apple Silicon, NVIDIA GPUs, Windows workstations, Linux machines, CPU-only environments, and other endpoint configurations.\n\nBuild benchmarks that measure model latency, throughput, memory consumption, startup time, resource contention, and developer experience on real endpoint hardware.\n\nInvestigate security boundaries between local models, cloud-hosted models, agents, MCP servers, shells, and enterprise resources.\n\nCollaborate with the core CLI and platform teams to take endpoint research from prototype through production.\n\nTrack the rapidly evolving AI agent, sandboxing, and local inference ecosystems and proactively identify technologies PointFive should support.\n\nWhat We're Looking For\nMust-have\nDeep understanding of operating system fundamentals: processes, permissions, filesystems, IPC, networking, signals, and process trees.\n\nStrong understanding of sandboxing and workload isolation concepts.\n\nHands-on systems experience across multiple operating systems, ideally including Linux, macOS, and Windows.\n\nExperience building or debugging software that runs directly on developer endpoints, workstations, or servers.\n\nComfort operating close to the metal - binary behavior, system calls, OS APIs, environment variables, config files, process injection/interception, and runtime behavior.\n\nInvestigative, reverse-engineering mindset - you enjoy taking apart systems you didn't build and figuring out how they actually work.\n\nAbility to move comfortably between research prototypes and production-quality systems code.\n\nNice to have\nExperience running or deploying local LLMs using frameworks such as llama.cpp, MLX, Ollama, ONNX Runtime, or similar inference runtimes.\n\nUnderstanding of model quantization, KV-cache behavior, GPU memory constraints, model loading, and inference performance.\n\nExperience with NVIDIA CUDA, Apple Metal, DirectML, ROCm, or other hardware acceleration stacks.\n\nExperience with Linux namespaces, seccomp, cgroups, AppArmor, SELinux, eBPF, or container runtimes.\n\nFamiliarity with macOS sandboxing, Endpoint Security Framework, launchd, XPC, virtualization, or Apple Silicon.\n\nFamiliarity with Windows security primitives, Job Objects, AppContainers, Windows Sandbox, Hyper-V, WSL, ETW, or Windows process APIs.\n\nHands-on familiarity with AI coding agents such as Cursor, Claude Code, Copilot CLI, and Codex.\n\nExperience with endpoint management or fleet deployment technologies such as MDM, Intune, Jamf, SCCM, or enterprise software distribution systems.\n\nExperience with containers, microVMs, or lightweight virtualization technologies.\n\nTypeScript experience.\n\nOur Tech Stack\nGo, TypeScript, Cloudflare, Snowflake, local inference runtimes, and OS-native endpoint technologies across macOS, Windows, and Linux.\nWhy PointFive\nFounders with a track record\n\nBuilt and sold IntSights to Rapid7. Backed by top-tier investors with deep conviction in this category.\nCategory-defining product\n\nWe're building the control plane for how AI agents operate across enterprise engineering environments - from model access to endpoint execution.\nHard systems problems\n\nAI agents are becoming increasingly powerful, but giving them access to developer machines introduces an entirely new class of security, isolation, performance, and infrastructure challenges. You'll work directly on those problems.\nLocal AI is becoming infrastructure\n\nAs capable models increasingly run on laptops and workstations, enterprises will need a way to deploy, manage, secure, and govern them across thousands of heterogeneous machines. You'll help define how that infrastructure works.\nEarly-stage leverage\n\nYour research will directly shape the architecture of the product and determine which capabilities PointFive can deliver next.\nFrontier of AI developer tooling\n\nAgents, local models, and endpoint runtimes are evolving extremely quickly. You'll be researching and integrating technologies before they become standard parts of the enterprise developer stack.\nEqual Opportunity Statement\nPointFive is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We welcome candidates from all backgrounds, experiences, and perspectives to apply.","description_format":"text","description_chars":7534,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Israel","iso":"IL","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cloud Cost & Multi-Cloud Management"],"lifecycle":[{"event":"open","at":"2026-09-25T15:33:06Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":7,"expected_fill_days":31,"reasons":["conf:8","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/pointfive-endpoint-researcher-lead","json_url":"https://alion.io/job/pointfive-endpoint-researcher-lead.json","meta":{"generated_at":"2026-10-01T17:02:31Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":12,"day_limit":5000,"remaining_today":4988,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}