×
Register Here to Apply for Jobs or Post Jobs. X

Endpoint Engineer, EDR; Windows

Job in New York, New York County, New York, 10261, USA
Listing for: ENT
Full Time position
Listed on 2026-10-02
Job specializations:
  • Software Development
    Software Engineer
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Endpoint Engineer, EDR (Windows)
Location: New York

Endpoint Engineer, EDR (Windows)
About Ent

Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later.

Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We're now hiring the team that will define this category.

How We Work

Customer first.

Humble.

Urgency.

About the Role

The Ent agent is where our product meets the operating system. As an Endpoint Engineer, EDR, you'll design and ship the kernel- and user-mode components that observe process, file, registry, network, and identity activity on Windows and turn that raw activity into high-fidelity signals about what an actor is actually trying to do.

You'll own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and the interception logic that stops malicious activity before it completes. The constraints are real. The sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and has to stay inside strict CPU, memory, and I/O budgets while resisting tamper, bypass, and evasion.

You'll work closely with security research, AI, platform, and product to feed sensor signals into policy enforcement, real-time interventions, and investigation timelines.

What You’ll Achieve
  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Windows and turn that activity into high-fidelity intent signals.

  • Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes.

  • Instrument telemetry at the OS boundary: ETW, kernel callbacks, and minifilters.

  • Harden the agent against tamper, bypass, and evasion — self-protection, integrity validation, and safe handling of untrusted input inside a privileged process.

  • Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship.

  • Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted.

  • Drive high-severity customer escalations to root cause — crashes, hangs, performance regressions, missed detections — at the code and OS-internals level, and convert escalation patterns into permanent fixes.

  • Partner with the security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement, just-in-time interventions, and investigation timelines.

  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call.

What You’ll Bring
Must-haves
  • 10+ years designing, building, and delivering production C/C++ systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance-critical native code.

  • Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.

  • Hands-on…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary