SlipstreamJobsFresh Startup & VC-Backed Jobs

Endpoint Engineer, EDR (macOS)

Ent - Remote - Remote - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ent is an intent-aware workspace security platform protecting human and AI-driven work. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, the company is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier VCs including Sequoia, Decibel, and In-Q-Tel. As an Endpoint Engineer, EDR (macOS), you will design and ship the privileged daemon, per-user agents, and system extensions that observe process, file, network, device, and user-interaction activity and transform it into high-fidelity signals about actor intent. You own EDR-class detection and prevention end to end: instrumentation through the Endpoint Security framework, Network Extensions, FSEvents, and IOKit; event enrichment and on-box correlation; and interception logic (ES AUTH decisions, network flow filtering) that stops malicious activity before completion. Key responsibilities include: - Design, build, and ship the macOS agent components (privileged daemon, per-user agents, system extensions) that observe activity and generate intent signals - Own full EDR detection and prevention pipeline: sensor instrumentation, event enrichment, on-box correlation and rule evaluation, and interception logic - Instrument telemetry at the OS boundary using Endpoint Security framework, Network Extensions (NEFilterDataProvider), FSEvents, IOKit, and event taps - Design and maintain multi-process architecture: launchd-managed daemon and agents, XPC protocols, code-signing-based peer authentication, and safe untrusted input handling in privileged processes - Harden the agent against tamper, bypass, and evasion using self-protection, integrity validation, and update-chain security - Maintain strict CPU, memory, and I/O budgets while processing thousands of events per second with hard real-time constraints like ES auth deadlines - Build test harnesses and automated regression coverage including VM-based end-to-end testing - Drive high-severity customer escalations to root cause and convert patterns into permanent fixes - Partner with security research, AI, platform, and product teams to feed sensor signals into on-device ML classification and intent-aware policy enforcement - Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call REQUIREMENTS: Must-haves: - 10+ years designing, building, and delivering production native systems software (Swift, C, C++, or Objective-C), with substantial experience in endpoint security, OS internals, or comparable performance-critical code; strong, current Swift including modern concurrency (actors, Sendable, structured concurrency) - Deep working knowledge of macOS internals: process and thread lifecycle, memory management, file systems, code signing and entitlements, launchd, IPC (XPC and Mach primitives), and TCC permission model - Hands-on production experience with Endpoint Security framework and/or Network Extensions, and understanding of system extension lifecycle - Demonstrated experience building or operating an EDR, EPP, XDR, DLP, or insider-risk product, or equivalent detection-and-response engineering - Practical fluency in attacker TTPs; ability to reason about attacks in raw telemetry - Strong low-level debugging skills: lldb, crash-dump and hang analysis, performance tracing with Instruments or equivalent - Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, actor isolation, and object lifetime management - Track record of code running on large fleets without degrading end-user experience; treat stability and performance as product features; understand enterprise deployment realities (MDM profiles, notarization, staged rollout, auto-update) - Scripting fluency for tooling and test automation (Python, shell, or equivalent) - Clear written and verbal communication with distributed teams and directly with customers when needed Bonus: - Reverse engineering, malware analysis, or exploit and vulnerability research background - Experience shipping on-device ML inference (Core ML, ONNX Runtime, llama.cpp-class runtimes) inside resource-constrained agents - Experience with browser extension or native-messaging integrations for telemetry capture - Cross-platform endpoint agent experience (Windows or Linux sensors) alongside macOS

Similar roles