Endpoint Engineer, EDR – Windows
Posted 46mins ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Endpoint Engineer building Windows kernel and user-mode EDR sensors for Ent’s workspace security platform. Improving detection, prevention, performance, and tamper resistance across customer fleets.
Responsibilities:
- Design, build, and ship kernel- and user-mode components of the Ent agent for Windows
- Observe process, file, registry, network, and identity activity and convert it into high-fidelity intent signals
- Own EDR-class detection and prevention end to end, including sensor instrumentation, event enrichment, on-box correlation, and interception logic
- Instrument telemetry at the OS boundary using ETW, kernel callbacks, and minifilters
- Harden the agent against tamper, bypass, and evasion through self-protection and integrity validation
- Keep sensor CPU, memory, and I/O within strict budgets while processing thousands of events per second
- Profile hot paths and eliminate performance regressions before release
- Build test harnesses and automated regression coverage
- Drive high-severity customer escalations to root cause, including crashes, hangs, performance regressions, and missed detections
- Convert escalation patterns into permanent fixes
- Partner with security research, AI, platform, and product teams on policy enforcement, interventions, and investigation timelines
- Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call
Requirements:
- 10+ years designing, building, and delivering production C/C++ systems software, with a substantial portion in endpoint security, OS internals, or comparable performance-critical native code
- Deep working knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC
- Hands-on production experience with kernel callbacks and minifilters
- Experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering
- Practical fluency in attacker TTPs and raw telemetry analysis
- Strong low-level debugging, performance tracing, and crash-dump analysis skills
- Experience with multithreaded and concurrent programming under load, including synchronization, lock contention, race conditions, and object lifetime management
- Track record of code running on large fleets without degrading end-user experience
- Scripting fluency for tooling and test automation, using Python or equivalent
- Clear written and verbal communication with distributed teams and customers
- Kernel-mode driver or kernel extension development shipped to production at scale
- Reverse engineering, malware analysis, or exploit and vulnerability research background
- Experience with anti-tamper, code integrity, driver signing, and WHQL attestation
Benefits:
- Every teammate gets meaningful equity on top of their salary
- 90% of medical, dental, and vision is paid by Ent
- 75% coverage for dependents
- Flexible PTO
- 12 weeks of fully paid maternity leave (birth, adoption, or foster)
- 8 weeks of fully paid paternity leave
- $100 monthly lifestyle account for fitness, wellness, learning, and more
- $500 home office stipend when joining as a remote employee
- Distributed workplace and remote work across North America















