SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ent is an intent-aware workspace security platform protecting human and AI-driven work. The company was founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, and is backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. Ent is in production with Global 2000 customers across hospitality, financial services, and defense.
As an Endpoint Engineer, EDR (Windows), you will design and ship the kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity on Windows and transform raw activity into high-fidelity signals about attacker intent. You will own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and interception logic that stops malicious activity before completion.
Key responsibilities include:
- Design, build, and ship kernel- and user-mode components that observe Windows activity and generate intent signals
- Own detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic
- Instrument telemetry at the OS boundary using ETW, kernel callbacks, and minifilters
- Harden the agent against tamper, bypass, and evasion through self-protection, integrity validation, and safe handling of untrusted input in a privileged process
- Maintain strict CPU, memory, and I/O budgets while processing thousands of events per second; profile hot paths and eliminate regressions
- Build test harnesses and automated regression coverage to continuously verify efficacy claims
- Drive high-severity customer escalations to root cause (crashes, hangs, performance regressions, missed detections) at the code and OS-internals level
- Partner with security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement and just-in-time interventions
- Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call
The role operates under real constraints: the sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and must maintain strict performance and stability budgets while resisting sophisticated evasion techniques.
REQUIREMENTS:
Must-haves:
- 10+ years designing, building, and delivering production C/C++ systems software, with substantial experience in endpoint security, OS internals, or comparable performance-critical native code
- Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC
- Hands-on production experience with kernel callbacks and minifilters
- Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering
- Practical fluency in attacker TTPs; ability to reason about attacks in raw telemetry
- Strong low-level debugging skills, performance tracing, and crash-dump analysis
- Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, and object lifetime management
- Track record of code running on large fleets without degrading end-user experience; treat stability and performance as product features
- Scripting fluency for tooling and test automation (Python or equivalent)
- Clear written and verbal communication with distributed teams and customers
Bonus:
- Kernel-mode driver or kernel extension development shipped to production at scale
- Reverse engineering, malware analysis, or exploit and vulnerability research background
- Experience with anti-tamper, code integrity, driver signing, and WHQL attestation