Endpoint Engineer, EDR (linux)

New
E
EntCybersecurity
We also hire remotely across North AmericaFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
10+ years
Required Skills
PythonC++RustLinux

Requirements

  • 10+ years designing, building, and delivering production C/C++ (or Rust) systems software.
  • Significant experience in endpoint security, OS internals, or comparable performance-critical native code.
  • Deep working knowledge of operating system internals (process and thread lifecycle, memory management, file systems, drivers, and IPC).
  • Hands-on production experience with eBPF.
  • Demonstrated experience building or operating EDR, EPP, XDR, or AV products.
  • Practical fluency in attacker TTPs and ability to reason about attacks in raw telemetry.
  • Strong low-level debugging skills, performance tracing, and crash-dump analysis.
  • Experience with multi-threaded and concurrent programming under load, including synchronization and lock contention.
  • Proven track record of maintaining system stability and performance across large fleets.
  • Scripting fluency in Python or equivalent for tooling and test automation.
  • Clear written and verbal communication skills for distributed team environments.

Responsibilities

  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Linux.
  • Own EDR-class detection and prevention capability end to end, including sensor instrumentation, event enrichment, on-box correlation, and interception logic.
  • Make and defend explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance.
  • Instrument telemetry at the OS boundary using eBPF, LSM, and audit subsystems.
  • Harden the agent against tamper, bypass, and evasion techniques through self-protection and integrity validation.
  • Maintain sensor CPU, memory, and I/O performance within strict budgets while processing high volumes of events.
  • Build test harnesses and automated regression coverage to verify detection efficacy.
  • Resolve high-severity customer escalations, including crashes, hangs, and performance regressions, at the code and OS-internals level.
  • Collaborate with security research, AI, platform, and product teams to integrate sensor signals into broader security policies.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now