Endpoint Engineer, EDR – Linux

Posted 5 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Endpoint Engineer building Linux EDR sensors for Ent’s workspace security platform. Developing eBPF-based detection, prevention, and telemetry across endpoints, servers, containers, and cloud workloads.

Responsibilities

  • Own the Linux sensor at the core of Ent's EDR capability
  • Design, build, and ship kernel- and user-mode components of the Ent agent
  • Observe process, file, registry, network, and identity activity on Linux and convert it into high-fidelity intent signals
  • Own EDR-class detection and prevention end to end, including sensor instrumentation, event enrichment, on-box correlation, and interception logic
  • Make and defend tradeoffs among detection efficacy, false-positive rate, and endpoint performance using measured data
  • Instrument telemetry at the OS boundary using eBPF, LSM, and audit subsystems
  • Harden the agent against tamper, bypass, and evasion
  • Maintain strict CPU, memory, and I/O budgets while processing thousands of events per second
  • Profile hot paths and eliminate performance regressions
  • Build test harnesses and automated regression coverage
  • Drive high-severity customer escalations to root cause and convert patterns into permanent fixes
  • Partner with security research, AI, platform, and product teams on policy enforcement, interventions, and investigation timelines
  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call

Requirements

  • 10+ years designing, building, and delivering production C/C++ or Rust systems software
  • Substantial experience in endpoint security, OS internals, or comparable performance-critical native code
  • Deep knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC
  • Hands-on production experience with eBPF
  • Experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering
  • Practical fluency in attacker TTPs
  • Strong low-level debugging, performance tracing, and crash-dump analysis skills
  • Experience with multithreaded and concurrent programming under load, including synchronization, lock contention, race conditions, and object lifetime management
  • Track record of deploying code across large fleets without degrading end-user experience
  • Scripting fluency for tooling and test automation, such as Python or equivalent
  • Clear written and verbal communication with distributed teams and customers
  • Kernel-mode driver or kernel extension development shipped to production at scale (bonus)
  • Reverse engineering, malware analysis, or exploit and vulnerability research background (bonus)
  • Experience with anti-tamper and code integrity (bonus)

Benefits

  • Meaningful equity on top of salary
  • 90% of medical, dental, and vision premiums paid by Ent
  • 75% coverage for dependents
  • Flexible PTO
  • 12 weeks of fully paid maternity leave (birth, adoption, or foster)
  • 8 weeks of fully paid paternity leave
  • $100 monthly lifestyle account for fitness, wellness, learning, and more
  • $500 home office stipend for remote employees
  • Distributed workplace and remote work across North America

Job type

Full Time

Experience level

SeniorLead

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

LinuxPythonRustC++

Location requirements

RemoteNorth America

Report this job

Found something wrong with the page? Please let us know by submitting a report below.