About The Position

About the Role We are seeking an Endpoint Engineer to be part of the team that owns Ent's data protection layer on the device: classifying sensitive data, tracing how it moves, and enforcing policy at the moment of egress — including to AI tools and agents. This role pairs classic content inspection with Ent's on-device small language model, so enforcement reflects what a person is trying to do and not only what a file contains. Precision is the product here.

Requirements

  • 5+ years shipping production systems software in C/C++, including work on an endpoint agent deployed at enterprise scale.
  • Direct experience building or operating an endpoint for insider-risk, data-security, or CASB/SASE data-protection product.
  • Strong operating system internals knowledge on at least one platform: file system filtering, process and handle interception, and the user/kernel boundary.
  • Hands-on content inspection and data classification work: pattern-based detection, fingerprinting and hashing schemes, file format parsing, and handling of archives and Office/PDF container formats.
  • Experience controlling device and network egress channels — USB and removable media, print, clipboard, HTTPS upload.
  • Multi-threaded, performance-sensitive engineering against measured latency and throughput budgets.
  • Strong debugging and profiling skills on real user machines, including application-compatibility investigations where the security agent is suspected first.
  • A precision mindset: you understand that a noisy product gets disabled, and you instrument accordingly.
  • Clear written and verbal communication with distributed teams and customer-facing stakeholders.

Nice To Haves

  • OCR, ML-based classification, or embedding and LLM-based content understanding applied to data protection.
  • Implementation experience with data lineage or provenance tracking.
  • Cross-platform development spanning Windows and macOS (Linux a plus), and browser extension development.
  • Encryption, rights management, or key handling on the endpoint.
  • Depth in regulatory compliance and audit-evidence design.
  • Insider-threat investigation workflows, or data governance for AI tools and autonomous agents.

Responsibilities

  • Build the endpoint data-protection layer of the Ent agent: classify sensitive data on the device, trace how it is created and moved, and enforce policy at the moment of egress.
  • Instrument and control the full set of exfiltration channels — removable media and USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth and AirDrop, email, web and browser upload, sync clients, and AI tools and agents including chat interfaces, IDE assistants, and CLI agents.
  • Implement on-device content inspection and classification: regular expression and pattern matching, keyword and dictionary matching, exact and indexed document matching, fingerprinting, file-type and structure identification, and OCR for image-borne content.
  • Integrate Ent's on-device small language model into classification and intent decisions so enforcement reflects what the user is trying to do, not only what a file contains.
  • Build data lineage and provenance tracking that keeps classification attached to content as it is copied, renamed, transformed, archived, compressed, or re-encoded.
  • Implement or work with team members to the interception plumbing that makes the above possible: Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, and browser extension hooks.
  • Drive precision as a first-class metric: build labeled corpora, measure false-positive and false-negative rates per detector, and tune classification quality with evidence.
  • Keep inspection cost invisible to the user — budget CPU, memory, and I/O for content scanning, and never block, delay, or corrupt legitimate user files and workflows.
  • Produce forensically useful incident evidence — who, what data, which channel, what intent — that feeds investigation timelines, insider-risk review, and compliance reporting.
  • Own customer escalations on missed egress paths, and application-compatibility conflicts, and turn recurring patterns into permanent fixes.
  • Partner with product, security research, AI, and compliance stakeholders to map endpoint controls to regulatory regimes such as GDPR, HIPAA, PCI DSS, CCPA, and export-control requirements.

Benefits

  • Distributed workplace
  • Meaningful equity
  • 90% of your medical, dental, and vision is paid by Ent
  • 75% for your dependents covered
  • Flexible PTO
  • 12 weeks of fully paid maternity leave
  • 8 weeks fully paid paternity leave
  • $100 monthly lifestyle account
  • $500 home office stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service