Endpoint Engineer, EDR (linux)
New
E
EntCybersecurity
We also hire remotely across North AmericaFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years
- Required Skills
- PythonC++RustLinux
Requirements
- 10+ years designing, building, and delivering production C/C++ (or Rust) systems software.
- Significant experience in endpoint security, OS internals, or comparable performance-critical native code.
- Deep working knowledge of operating system internals (process and thread lifecycle, memory management, file systems, drivers, and IPC).
- Hands-on production experience with eBPF.
- Demonstrated experience building or operating EDR, EPP, XDR, or AV products.
- Practical fluency in attacker TTPs and ability to reason about attacks in raw telemetry.
- Strong low-level debugging skills, performance tracing, and crash-dump analysis.
- Experience with multi-threaded and concurrent programming under load, including synchronization and lock contention.
- Proven track record of maintaining system stability and performance across large fleets.
- Scripting fluency in Python or equivalent for tooling and test automation.
- Clear written and verbal communication skills for distributed team environments.
Responsibilities
- Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Linux.
- Own EDR-class detection and prevention capability end to end, including sensor instrumentation, event enrichment, on-box correlation, and interception logic.
- Make and defend explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance.
- Instrument telemetry at the OS boundary using eBPF, LSM, and audit subsystems.
- Harden the agent against tamper, bypass, and evasion techniques through self-protection and integrity validation.
- Maintain sensor CPU, memory, and I/O performance within strict budgets while processing high volumes of events.
- Build test harnesses and automated regression coverage to verify detection efficacy.
- Resolve high-severity customer escalations, including crashes, hangs, and performance regressions, at the code and OS-internals level.
- Collaborate with security research, AI, platform, and product teams to integrate sensor signals into broader security policies.
View Full Description & ApplyYou'll be redirected to the employer's site