About The Position

The Ent agent is where our product meets the operating system. As an Endpoint Engineer, EDR, you'll design and ship the kernel- and user-mode components that observe process, file, registry, network, and identity activity on Windows and turn that raw activity into high-fidelity signals about what an actor is actually trying to do. You'll own EDR-class detection and prevention end to end: instrumentation at the OS boundary through ETW, kernel callbacks, and minifilters; event enrichment and on-box correlation; and the interception logic that stops malicious activity before it completes. The constraints are real. The sensor runs inside a privileged process on large customer fleets, handles thousands of events per second, and has to stay inside strict CPU, memory, and I/O budgets while resisting tamper, bypass, and evasion. You'll work closely with security research, AI, platform, and product to feed sensor signals into policy enforcement, real-time interventions, and investigation timelines.

Requirements

  • 10+ years designing, building, and delivering production C/C++ systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance-critical native code.
  • Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
  • Hands-on production experience with kernel callbacks and minifilters.
  • Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering.
  • Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report.
  • Strong low-level debugging skills, performance tracing, and crash-dump analysis.
  • Multi-threaded and concurrent programming under load — synchronization, lock contention, race conditions, and object lifetime management.
  • A track record of code running on large fleets without degrading end-user experience; you treat stability and performance as product features.
  • Scripting fluency for tooling and test automation (Python or equivalent).
  • Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers.

Nice To Haves

  • Kernel-mode driver or kernel extension development shipped to production at scale.
  • Reverse engineering, malware analysis, or exploit and vulnerability research background.
  • Experience with anti-tamper, code integrity, driver signing and WHQL attestation.

Responsibilities

  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Windows and turn that activity into high-fidelity intent signals.
  • Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes.
  • Instrument telemetry at the OS boundary: ETW, kernel callbacks, and minifilters.
  • Harden the agent against tamper, bypass, and evasion — self-protection, integrity validation, and safe handling of untrusted input inside a privileged process.
  • Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship.
  • Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted.
  • Drive high-severity customer escalations to root cause — crashes, hangs, performance regressions, missed detections — at the code and OS-internals level, and convert escalation patterns into permanent fixes.
  • Partner with the security research, AI, platform, and product teams to feed sensor signals into intent-aware policy enforcement, just-in-time interventions, and investigation timelines.
  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on-call.

Benefits

  • Distributed workplace
  • Meaningful equity
  • 90% of your medical, dental, and vision is paid by Ent
  • 75% of your dependents' medical, dental, and vision is paid by Ent
  • Flexible PTO
  • 12 weeks of fully paid maternity leave
  • 8 weeks fully paid paternity leave
  • $100 monthly lifestyle account
  • $500 home office stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service