SlipstreamJobsFresh Startup & VC-Backed Jobs

Endpoint Engineer, EDR (Windows)

Ent - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Ent is an intent-aware workspace security platform protecting human and AI-driven work. Founded by the co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, the company is in production with Global 2000 customers across hospitality, financial services, and defense, backed by top-tier investors including Sequoia, Decibel, and In-Q-Tel. As an Endpoint Engineer specializing in EDR (Endpoint Detection and Response) for Windows, you will design and ship the kernel- and user-mode components that form the core of Ent's agent. Your work will observe process, file, registry, network, and identity activity on Windows systems, transforming raw telemetry into high-fidelity signals about attacker intent. You will own EDR-class detection and prevention end-to-end: instrumenting the OS boundary via ETW, kernel callbacks, and minifilters; enriching events and performing on-box correlation; and implementing interception logic that stops malicious activity before completion. The technical constraints are substantial—the sensor runs in a privileged process on large customer fleets, handling thousands of events per second while maintaining strict CPU, memory, and I/O budgets and resisting tamper, bypass, and evasion attempts. Key responsibilities include designing and shipping kernel and user-mode agent components; owning detection and prevention capability end-to-end from sensor instrumentation through interception; hardening the agent against tampering and evasion; maintaining performance budgets while processing high event volumes; building comprehensive test harnesses and automated regression coverage; driving high-severity customer escalations to root cause; and partnering with security research, AI, platform, and product teams to feed sensor signals into policy enforcement and investigation workflows. You will also review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call responsibilities. The company operates with a customer-first mindset, humble culture emphasizing teamwork over showmanship, and a sense of urgency around building durable security in the AI era. They offer distributed work across North America, meaningful equity, comprehensive health coverage (90% medical/dental/vision), flexible PTO, and 12 weeks paid parental leave.

Similar roles