SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ent is an intent-aware workspace security platform protecting human and AI-driven work. The company, founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, is backed by top-tier investors including Sequoia and In-Q-Tel, and is in production with Global 2000 customers across hospitality, financial services, and defense.
As an Endpoint Engineer in Data Security, you will own the endpoint data-protection layer of Ent's agent. Your core responsibilities include:
- Build and maintain the data classification, tracing, and egress-enforcement system on the device, leveraging both classic content inspection and Ent's on-device small language model to reflect user intent, not just file contents.
- Instrument and control all exfiltration channels: removable media, USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth, AirDrop, email, web uploads, sync clients, and AI tools (chat interfaces, IDE assistants, CLI agents).
- Implement on-device content inspection: regex and pattern matching, keyword and dictionary matching, exact and indexed document matching, fingerprinting, file-type identification, and OCR for image content.
- Integrate on-device small language models into classification and intent decisions.
- Build data lineage and provenance tracking that preserves classification as content is copied, renamed, transformed, archived, compressed, or re-encoded.
- Implement interception plumbing across platforms: Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, and browser extension hooks.
- Drive precision as a first-class metric: build labeled corpora, measure false-positive and false-negative rates, and tune classification quality with evidence.
- Optimize for performance: budget CPU, memory, and I/O so content scanning is invisible to users and never blocks, delays, or corrupts legitimate workflows.
- Produce forensically useful incident evidence (who, what data, which channel, what intent) for investigation timelines, insider-risk review, and compliance reporting.
- Own customer escalations on missed egress paths and application-compatibility conflicts; turn recurring patterns into permanent fixes.
- Partner with product, security research, AI, and compliance teams to map endpoint controls to regulatory regimes (GDPR, HIPAA, PCI DSS, CCPA, export-control requirements).
The role is distributed; while Ent has an SF office, remote hiring is available across North America. Compensation includes meaningful equity, 90% company-paid medical/dental/vision (75% for dependents), flexible PTO, 12 weeks paid maternity leave and 8 weeks paid paternity leave, a $100 monthly lifestyle account, and a $500 home office stipend for remote employees.
REQUIREMENTS
Must-haves:
- 5+ years shipping production systems software in C/C++, including work on an endpoint agent deployed at enterprise scale.
- Direct experience building or operating an endpoint for insider-risk, data-security, or CASB/SASE data-protection product.
- Strong operating system internals knowledge on at least one platform: file system filtering, process and handle interception, and the user/kernel boundary.
- Hands-on content inspection and data classification work: pattern-based detection, fingerprinting and hashing schemes, file format parsing, and handling of archives and Office/PDF container formats.
- Experience controlling device and network egress channels (USB, removable media, print, clipboard, HTTPS upload).
- Multi-threaded, performance-sensitive engineering against measured latency and throughput budgets.
- Strong debugging and profiling skills on real user machines, including application-compatibility investigations.
- A precision mindset: understanding that noisy products get disabled, and instrumenting accordingly.
- Clear written and verbal communication with distributed teams and customer-facing stakeholders.
Bonus:
- OCR, ML-based classification, or embedding and LLM-based content understanding applied to data protection.
- Implementation experience with data lineage or provenance tracking.
- Cross-platform development spanning Windows and macOS (Linux a plus), and browser extension development.
- Encryption, rights management, or key handling on the endpoint.
- Depth in regulatory compliance and audit-evidence design.
- Insider-threat investigation workflows, or data governance for AI tools and autonomous agents.