SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ent is an intent-aware workspace security platform protecting human and AI-driven work. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier VCs including Sequoia and In-Q-Tel.
You will join the team owning the Linux sensor at the core of Ent's EDR (Endpoint Detection and Response) capability. This role focuses on building detection and prevention mechanisms using eBPF, LSM (Linux Security Modules), and the audit subsystem across the full range of Linux environments customers run—workstations, servers, containers, and cloud workloads.
Key responsibilities include:
- Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity, converting that activity into high-fidelity intent signals
- Own EDR-class detection and prevention end-to-end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before completion
- Make explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance, backed by measured data
- Instrument telemetry at the OS boundary using eBPF, LSM, and audit subsystems
- Harden the agent against tamper, bypass, and evasion through self-protection, integrity validation, and safe handling of untrusted input in privileged processes
- Maintain strict CPU, memory, and I/O budgets while processing thousands of events per second; profile hot paths and eliminate regressions
- Build test harnesses and automated regression coverage to continuously verify efficacy claims
- Drive high-severity customer escalations to root cause at the code and OS-internals level
- Partner with security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement
- Mentor engineers, review code, document design decisions, and share ownership of agent release quality and on-call
Required qualifications:
- 10+ years designing, building, and delivering production C/C++ or Rust systems software, with substantial experience in endpoint security, OS internals, or comparable performance-critical native code
- Deep working knowledge of OS internals: process/thread lifecycle, memory management, file systems, drivers/kernel extensions, IPC
- Hands-on production experience with eBPF
- Demonstrated experience building or operating an EDR, EPP, XDR, or AV product
- Practical fluency in attacker TTPs; ability to reason about attacks in raw telemetry
- Strong low-level debugging, performance tracing, and crash-dump analysis skills
- Multi-threaded and concurrent programming expertise under load
- Track record of code running on large fleets without degrading user experience
- Scripting fluency (Python or equivalent) for tooling and test automation
- Clear written and verbal communication with distributed teams and customers
Bonus qualifications include kernel-mode driver/kernel extension development at scale, reverse engineering, malware analysis, exploit/vulnerability research, and anti-tamper/code integrity experience.