SlipstreamJobsFresh Startup & VC-Backed Jobs

Endpoint Engineer, Data Security

Ent - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ent is an intent-aware workspace security platform protecting human and AI-driven work. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, the company is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier VCs including Sequoia and In-Q-Tel. As an Endpoint Engineer in Data Security, you will own Ent's data protection layer on the device, responsible for classifying sensitive data, tracing its movement, and enforcing policy at the moment of egress—including to AI tools and agents. This role combines classic content inspection with Ent's on-device small language model to ensure enforcement reflects user intent, not just file contents. Key responsibilities include: - Building the endpoint data-protection layer: classify sensitive data on-device, trace creation and movement, enforce policy at egress - Instrumenting and controlling exfiltration channels: removable media, USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth, AirDrop, email, web uploads, sync clients, and AI tools - Implementing on-device content inspection: regex/pattern matching, keyword matching, document fingerprinting, file-type identification, and OCR - Integrating on-device small language models into classification and intent decisions - Building data lineage and provenance tracking that preserves classification through copies, renames, transformations, and re-encoding - Implementing interception plumbing: Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, browser extension hooks - Driving precision as a first-class metric: building labeled corpora, measuring false-positive/negative rates, tuning classification quality - Optimizing inspection cost: budgeting CPU, memory, and I/O without blocking or delaying legitimate workflows - Producing forensically useful incident evidence for investigation and compliance reporting - Owning customer escalations on missed egress paths and application-compatibility conflicts - Partnering with product, security research, AI, and compliance teams on regulatory mapping (GDPR, HIPAA, PCI DSS, CCPA, export controls) Required qualifications: - 5+ years shipping production systems software in C/C++, including endpoint agent deployment at enterprise scale - Direct experience building or operating an endpoint for insider-risk, data-security, or CASB/SASE data-protection products - Strong OS internals knowledge on at least one platform: file system filtering, process/handle interception, user/kernel boundary - Hands-on content inspection and data classification: pattern detection, fingerprinting, file format parsing, archive/Office/PDF handling - Experience controlling device and network egress channels: USB, removable media, print, clipboard, HTTPS upload - Multi-threaded, performance-sensitive engineering with measured latency and throughput budgets - Strong debugging and profiling skills on real user machines - Precision mindset and clear communication with distributed teams and customers Bonus skills: OCR, ML-based classification, LLM-based content understanding, data lineage/provenance tracking, cross-platform development (Windows, macOS, Linux), browser extension development, encryption/rights management, regulatory compliance expertise, insider-threat investigation knowledge.

Similar roles