SlipstreamJobsFresh Startup & VC-Backed Jobs

Endpoint Engineer, Data Security

Ent - Remote - Remote - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ent is an intent-aware workspace security platform protecting human and AI-driven work. The company, founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, is backed by top-tier investors including Sequoia and In-Q-Tel, and is in production with Global 2000 customers across hospitality, financial services, and defense. As an Endpoint Engineer in Data Security, you will own the endpoint data-protection layer of Ent's agent. Your core responsibilities include: - Build and maintain the data classification, tracing, and egress-enforcement system on the device, leveraging both classic content inspection and Ent's on-device small language model to reflect user intent, not just file contents. - Instrument and control all exfiltration channels: removable media, USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth, AirDrop, email, web uploads, sync clients, and AI tools (chat interfaces, IDE assistants, CLI agents). - Implement on-device content inspection: regex and pattern matching, keyword and dictionary matching, exact and indexed document matching, fingerprinting, file-type identification, and OCR for image content. - Integrate on-device small language models into classification and intent decisions. - Build data lineage and provenance tracking that preserves classification as content is copied, renamed, transformed, archived, compressed, or re-encoded. - Implement interception plumbing across platforms: Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, and browser extension hooks. - Drive precision as a first-class metric: build labeled corpora, measure false-positive and false-negative rates, and tune classification quality with evidence. - Optimize for performance: budget CPU, memory, and I/O so content scanning is invisible to users and never blocks, delays, or corrupts legitimate workflows. - Produce forensically useful incident evidence (who, what data, which channel, what intent) for investigation timelines, insider-risk review, and compliance reporting. - Own customer escalations on missed egress paths and application-compatibility conflicts; turn recurring patterns into permanent fixes. - Partner with product, security research, AI, and compliance teams to map endpoint controls to regulatory regimes (GDPR, HIPAA, PCI DSS, CCPA, export-control requirements). The role is distributed; while Ent has an SF office, remote hiring is available across North America. Compensation includes meaningful equity, 90% company-paid medical/dental/vision (75% for dependents), flexible PTO, 12 weeks paid maternity leave and 8 weeks paid paternity leave, a $100 monthly lifestyle account, and a $500 home office stipend for remote employees. REQUIREMENTS Must-haves: - 5+ years shipping production systems software in C/C++, including work on an endpoint agent deployed at enterprise scale. - Direct experience building or operating an endpoint for insider-risk, data-security, or CASB/SASE data-protection product. - Strong operating system internals knowledge on at least one platform: file system filtering, process and handle interception, and the user/kernel boundary. - Hands-on content inspection and data classification work: pattern-based detection, fingerprinting and hashing schemes, file format parsing, and handling of archives and Office/PDF container formats. - Experience controlling device and network egress channels (USB, removable media, print, clipboard, HTTPS upload). - Multi-threaded, performance-sensitive engineering against measured latency and throughput budgets. - Strong debugging and profiling skills on real user machines, including application-compatibility investigations. - A precision mindset: understanding that noisy products get disabled, and instrumenting accordingly. - Clear written and verbal communication with distributed teams and customer-facing stakeholders. Bonus: - OCR, ML-based classification, or embedding and LLM-based content understanding applied to data protection. - Implementation experience with data lineage or provenance tracking. - Cross-platform development spanning Windows and macOS (Linux a plus), and browser extension development. - Encryption, rights management, or key handling on the endpoint. - Depth in regulatory compliance and audit-evidence design. - Insider-threat investigation workflows, or data governance for AI tools and autonomous agents.

Similar roles