The Ent agent is where our product meets the operating system. As an Endpoint Engineer, EDR, you'll design and ship the kernel- and user-mode components that observe process, file, registry, network, and identity activity on Windows and turn that raw activity into high-fidelity signals about what an actor is actually trying to do. You'll own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and the interception logic that stops malicious activity before it completes. The constraints are real. The sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and has to stay inside strict CPU, memory, and I/O budgets while resisting tamper, bypass, and evasion. You'll work closely with security research, AI, platform, and product to feed sensor signals into policy enforcement, real-time interventions, and investigation timelines.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed