
Endpoint Engineer, Data Security
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in North America.
• Develop Ent's endpoint data-protection framework to identify sensitive data, monitor its trajectory, and enforce policies at egress.
• Manage and regulate exfiltration channels such as USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth/AirDrop, email, browser uploads, sync clients, and AI tools or agents.
• Execute on-device content inspection and classification utilizing patterns, keywords, dictionaries, document matching, fingerprinting, file and structure identification, and OCR.
• Incorporate Ent's on-device small language model into classification and intent assessments.
• Establish data lineage and provenance tracking throughout copying, renaming, transformation, archiving, compression, and re-encoding processes.
• Implement interception mechanisms using Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, as well as browser extension hooks.
• Create labeled corpora, assess detector false-positive and false-negative rates, and enhance classification accuracy.
• Allocate CPU, memory, and I/O resources for content scanning without hindering, delaying, or compromising legitimate workflows.
• Generate forensic incident evidence detailing who, what data, channel, and intent involved.
• Manage customer escalations related to overlooked egress paths and application compatibility issues, transforming recurring patterns into lasting solutions.
• Collaborate with product, security research, AI, and compliance stakeholders to align endpoint controls with GDPR, HIPAA, PCI DSS, CCPA, and export-control mandates.
• Over 5 years of experience in deploying production systems software in C/C++.
• Familiarity with an endpoint agent used at an enterprise scale.
• Direct experience in developing or managing an endpoint insider-risk, data-security, or CASB/SASE data-protection product.
• Strong understanding of operating system internals on at least one platform.
• Experience with file system filtering, process and handle interception, and the user/kernel interface.
• Practical experience in content inspection and data classification.
• Knowledge of pattern-based detection, fingerprinting and hashing techniques, file format parsing, archives, and Office/PDF container formats.
• Experience in controlling USB/removable media, print, clipboard, and HTTPS upload egress channels.
• Expertise in multi-threaded, performance-sensitive engineering adhering to measured latency and throughput budgets.
• Strong debugging and profiling capabilities on actual user machines.
• Experience in identifying application compatibility conflicts involving security agents.
• Precision-oriented approach with instrumentation for managing false-positive and false-negative rates.
• Excellent written and verbal communication skills with distributed teams and customer-facing stakeholders.
• Bonus: Experience with OCR, ML-based classification, embeddings, or LLM-based content understanding for data protection.
• Bonus: Knowledge of data lineage or provenance tracking.
• Bonus: Cross-platform development experience across Windows and macOS; Linux and browser extension development.
• Bonus: Familiarity with encryption, rights management, or endpoint key handling.
• Bonus: Experience with regulatory compliance and audit-evidence design.
• Bonus: Knowledge of insider-threat investigation workflows or AI-agent data governance.
• Meaningful equity in addition to salary.
• 90% coverage of medical, dental, and vision expenses paid by Ent.
• 75% coverage for dependents.
• Flexible paid time off (PTO).
• 12 weeks of fully paid maternity leave (for birth, adoption, or foster care).
• 8 weeks of fully paid paternity leave.
• $100 monthly lifestyle account for fitness, wellness, learning, and more.
• $500 home office stipend for remote workers.
SysMap Solutions
Get handpicked remote jobs straight to your inbox weekly.