SlipstreamJobsFresh Startup & VC-Backed Jobs

Endpoint Engineer, EDR (Windows)

Ent - Remote - Remote - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ent is an intent-aware workspace security platform protecting human and AI-driven work. The company was founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, and is backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. Ent is in production with Global 2000 customers across hospitality, financial services, and defense. As an Endpoint Engineer, EDR (Windows), you will design and ship the kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity on Windows and transform raw activity into high-fidelity signals about attacker intent. You will own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and interception logic that stops malicious activity before completion. Key responsibilities include: - Design, build, and ship kernel- and user-mode components that observe Windows activity and generate intent signals - Own detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic - Instrument telemetry at the OS boundary using ETW, kernel callbacks, and minifilters - Harden the agent against tamper, bypass, and evasion through self-protection, integrity validation, and safe handling of untrusted input in a privileged process - Maintain strict CPU, memory, and I/O budgets while processing thousands of events per second; profile hot paths and eliminate regressions - Build test harnesses and automated regression coverage to continuously verify efficacy claims - Drive high-severity customer escalations to root cause (crashes, hangs, performance regressions, missed detections) at the code and OS-internals level - Partner with security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement and just-in-time interventions - Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call The role operates under real constraints: the sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and must maintain strict performance and stability budgets while resisting sophisticated evasion techniques. REQUIREMENTS: Must-haves: - 10+ years designing, building, and delivering production C/C++ systems software, with substantial experience in endpoint security, OS internals, or comparable performance-critical native code - Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC - Hands-on production experience with kernel callbacks and minifilters - Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering - Practical fluency in attacker TTPs; ability to reason about attacks in raw telemetry - Strong low-level debugging skills, performance tracing, and crash-dump analysis - Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, and object lifetime management - Track record of code running on large fleets without degrading end-user experience; treat stability and performance as product features - Scripting fluency for tooling and test automation (Python or equivalent) - Clear written and verbal communication with distributed teams and customers Bonus: - Kernel-mode driver or kernel extension development shipped to production at scale - Reverse engineering, malware analysis, or exploit and vulnerability research background - Experience with anti-tamper, code integrity, driver signing, and WHQL attestation

Similar roles