Endpoint Engineer, EDR – Windows

Posted last week

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Endpoint Engineer building Windows kernel and user-mode EDR sensors for Ent’s workspace security platform. Improving detection, prevention, performance, and tamper resistance across customer fleets.

Responsibilities

  • Design, build, and ship kernel- and user-mode components of the Ent agent for Windows
  • Observe process, file, registry, network, and identity activity and convert it into high-fidelity intent signals
  • Own EDR-class detection and prevention end to end, including sensor instrumentation, event enrichment, on-box correlation, and interception logic
  • Instrument telemetry at the OS boundary using ETW, kernel callbacks, and minifilters
  • Harden the agent against tamper, bypass, and evasion through self-protection and integrity validation
  • Keep sensor CPU, memory, and I/O within strict budgets while processing thousands of events per second
  • Profile hot paths and eliminate performance regressions before release
  • Build test harnesses and automated regression coverage
  • Drive high-severity customer escalations to root cause, including crashes, hangs, performance regressions, and missed detections
  • Convert escalation patterns into permanent fixes
  • Partner with security research, AI, platform, and product teams on policy enforcement, interventions, and investigation timelines
  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call

Requirements

  • 10+ years designing, building, and delivering production C/C++ systems software, with a substantial portion in endpoint security, OS internals, or comparable performance-critical native code
  • Deep working knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC
  • Hands-on production experience with kernel callbacks and minifilters
  • Experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering
  • Practical fluency in attacker TTPs and raw telemetry analysis
  • Strong low-level debugging, performance tracing, and crash-dump analysis skills
  • Experience with multithreaded and concurrent programming under load, including synchronization, lock contention, race conditions, and object lifetime management
  • Track record of code running on large fleets without degrading end-user experience
  • Scripting fluency for tooling and test automation, using Python or equivalent
  • Clear written and verbal communication with distributed teams and customers
  • Kernel-mode driver or kernel extension development shipped to production at scale
  • Reverse engineering, malware analysis, or exploit and vulnerability research background
  • Experience with anti-tamper, code integrity, driver signing, and WHQL attestation

Benefits

  • Every teammate gets meaningful equity on top of their salary
  • 90% of medical, dental, and vision is paid by Ent
  • 75% coverage for dependents
  • Flexible PTO
  • 12 weeks of fully paid maternity leave (birth, adoption, or foster)
  • 8 weeks of fully paid paternity leave
  • $100 monthly lifestyle account for fitness, wellness, learning, and more
  • $500 home office stipend when joining as a remote employee
  • Distributed workplace and remote work across North America

Job title

Job type

Full Time

Experience level

SeniorLead

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

PythonC++

Location requirements

RemoteNorth America

Report this job

Found something wrong with the page? Please let us know by submitting a report below.