SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ent is an intent-aware workspace security platform that protects human and AI-driven work by understanding not just what users and agents do, but why they do it. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier investors including Sequoia and In-Q-Tel.
As an Endpoint Engineer, you will own core components of Ent's lightweight agent that runs across Windows, macOS, and Linux. This role is critical to the platform—you'll be responsible for collection, policy evaluation, enforcement, transport, and the lifecycle machinery that every Ent capability depends on. You are measured on the things customers only notice when they break: installs, updates, offline behavior, and resource footprint on machines you cannot log into.
Key responsibilities include:
- Building and owning components of the single lightweight agent across multiple operating systems: collection, enrichment, policy evaluation, enforcement, IPC, local storage, and cloud transport.
- Delivering features end-to-end: design, implementation, tests, telemetry, staged rollout, and post-release monitoring.
- Owning agent lifecycle engineering: packaging and installers (MSI, PKG, DEB/RPM), enrollment, configuration delivery, safe staged self-update, rollback, and clean uninstall.
- Keeping the agent fast and stable by enforcing CPU, memory, disk, and network budgets, catching performance regressions in CI, and treating stability as non-negotiable.
- Implementing offline and degraded-mode behavior: local queueing, backpressure, policy caching, retry semantics, and handling clock and connectivity edge cases.
- Applying secure engineering fundamentals inside a privileged process: least privilege, signed and verified updates, secrets handling, and safe parsing of untrusted input.
- Building diagnostics, log collection, health reporting, and support tooling so field issues can be root-caused without attaching a debugger to customer laptops.
- Owning test infrastructure: unit and integration tests, cross-platform CI, OS-version matrices, upgrade and downgrade paths, and soak and performance testing on real hardware.
- Integrating agent signals with backend services and the browser extension, working with platform teams on API and schema evolution without breaking older agent versions.
- Handling escalations across the stack: failed installs, conflicts with other security agents, OS and kernel upgrades, crashes, and performance complaints.
- Contributing to code review, design review, documentation, and on-call rotation for agent health.
The company operates with a customer-first mindset, humble teamwork over showmanship, and urgency to build a durable security company in the AI era. You'll work in a distributed, fast-moving team across North America.
REQUIREMENTS:
Must-haves:
- 5+ years building production software in C/C++ or Swift, including work on native desktop or endpoint software.
- Working knowledge of operating system internals and system APIs on at least one of Windows, macOS, or Linux.
- Experience with software that runs unattended on machines you do not control: versioning, upgrades, backward compatibility, and failure recovery.
- Solid grasp of concurrency, memory management, and empirical performance measurement.
- Debugging discipline—you reproduce, instrument, and prove root cause instead of guessing at fixes.
- Comfort with build systems, cross-platform CI/CD, and test automation (CMake or Bazel, GitHub Actions or equivalent), plus scripting in Python.
- Security-conscious coding habits: input validation, privilege boundaries, and awareness of how endpoint software itself becomes attack surface.
- Clear communication and effective collaboration in a distributed, fast-moving team.
Bonus:
- Prior endpoint security experience (EDR, DLP, EPP, MDM, or insider risk) or work on systems-monitoring agents.
- Exposure to kernel extensions and drivers, eBPF, ETW, or the macOS Endpoint Security Framework.
- Enterprise deployment realities: Intune, Jamf, SCCM, Ansible, and MDM-driven configuration management.
- Code signing, Apple notarization, or driver attestation pipelines.