SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ent is an intent-aware workspace security platform protecting human and AI-driven work. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier investors including Sequoia, Decibel, and In-Q-Tel.
You will be part of the team owning the Linux sensor at the core of Ent's EDR (Endpoint Detection and Response) capability. This role focuses on building detection and prevention mechanisms using eBPF, LSM (Linux Security Modules), and the audit subsystem across the full range of Linux environments customers run—workstations, servers, containers, and cloud workloads.
Key responsibilities include:
- Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity, converting that activity into high-fidelity intent signals.
- Own EDR-class detection and prevention capability end-to-end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before completion.
- Make and defend explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance, backed by measured data.
- Instrument telemetry at the OS boundary using eBPF, LSM, and audit subsystems.
- Harden the agent against tamper, bypass, and evasion through self-protection, integrity validation, and safe handling of untrusted input in privileged processes.
- Hold sensor CPU, memory, and I/O within strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before shipping.
- Build test harnesses and automated regression coverage so every efficacy claim is continuously verified.
- Drive high-severity customer escalations to root cause—crashes, hangs, performance regressions, missed detections—at the code and OS-internals level, converting escalation patterns into permanent fixes.
- Partner with security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement and investigation timelines.
- Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call responsibilities.
REQUIREMENTS:
Must-haves:
- 10+ years designing, building, and delivering production C/C++ or Rust systems software, with a substantial portion in endpoint security, OS internals, or comparable performance-critical native code.
- Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
- Hands-on production experience with eBPF.
- Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering.
- Practical fluency in attacker TTPs; ability to reason about what an attack looks like in raw telemetry.
- Strong low-level debugging skills, performance tracing, and crash-dump analysis.
- Multi-threaded and concurrent programming under load—synchronization, lock contention, race conditions, and object lifetime management.
- Track record of code running on large fleets without degrading end-user experience; treating stability and performance as product features.
- Scripting fluency for tooling and test automation (Python or equivalent).
- Clear written and verbal communication with distributed teams and directly with customers when escalations demand it.
Bonus:
- Kernel-mode driver or kernel extension development shipped to production at scale.
- Reverse engineering, malware analysis, or exploit and vulnerability research background.
- Experience with anti-tamper and code integrity.