SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ent is an intent-aware workspace security platform protecting human and AI-driven work. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, the company is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier investors including Sequoia, Decibel, and In-Q-Tel.
As an Endpoint Engineer specializing in EDR for macOS, you will design and ship the privileged daemon, per-user agents, and system extensions that observe process, file, network, device, and user-interaction activity to generate high-fidelity signals about actor intent. You own EDR-class detection and prevention end-to-end: instrumentation through Endpoint Security framework, Network Extensions, FSEvents, and IOKit; event enrichment and on-box correlation; and interception logic (ES AUTH decisions, network flow filtering) that stops malicious activity before completion.
Key responsibilities include designing the multi-process macOS agent architecture (launchd-managed daemon and agents, XPC protocols, code-signing-based peer authentication); hardening against tamper, bypass, and evasion using self-protection and integrity validation; maintaining strict CPU, memory, and I/O budgets while processing thousands of events per second with hard real-time constraints; building test harnesses and automated regression coverage including VM-based end-to-end testing; driving high-severity customer escalations to root cause and permanent fixes; and partnering with security research, AI, platform, and product teams to feed sensor signals into on-device ML classification and intent-aware policy enforcement.
You will review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call responsibilities. The role requires deep expertise in macOS internals, production native systems software, Endpoint Security framework and Network Extensions, EDR/EPP/XDR product experience, attacker TTPs, low-level debugging, multi-threaded programming, and a track record of shipping stable, performant code at scale.