
Endpoint Engineer, EDR β Linux
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in North America.
β’ Take ownership of the Linux sensor that underpins Ent's EDR capabilities.
β’ Design, develop, and deploy both kernel and user-mode components of the Ent agent.
β’ Monitor process, file, registry, network, and identity activities on Linux, transforming them into high-fidelity intent signals.
β’ Manage end-to-end EDR-class detection and prevention, including sensor instrumentation, event enrichment, on-box correlation, and interception logic.
β’ Make informed trade-offs between detection efficacy, false-positive rates, and endpoint performance based on empirical data.
β’ Implement telemetry at the OS boundary utilizing eBPF, LSM, and audit subsystems.
β’ Strengthen the agent against tampering, bypassing, and evasion attempts.
β’ Adhere to strict CPU, memory, and I/O budgets while processing thousands of events per second.
β’ Analyze performance hotspots and eliminate regressions.
β’ Create test harnesses and establish automated regression testing coverage.
β’ Lead high-severity customer escalations to identify root causes and transform patterns into lasting solutions.
β’ Collaborate with security research, AI, platform, and product teams on policy enforcement, interventions, and investigation timelines.
β’ Review code, mentor engineering staff, document design decisions, and share responsibility for the quality of agent releases and on-call duties.
β’ Over 10 years of experience in designing, building, and delivering production C/C++ or Rust systems software.
β’ Significant experience in endpoint security, OS internals, or similarly performance-critical native code.
β’ In-depth understanding of operating system internals, including process and thread lifecycles, memory management, file systems, drivers or kernel extensions, and IPC.
β’ Practical experience with eBPF in production environments.
β’ Background in building or operating EDR, EPP, XDR, or AV products, or equivalent detection-and-response engineering.
β’ Proficient understanding of attacker TTPs.
β’ Strong skills in low-level debugging, performance tracing, and crash-dump analysis.
β’ Experience with multithreaded and concurrent programming under load, including synchronization, lock contention, race conditions, and object lifecycle management.
β’ Proven track record of deploying code across large fleets without negatively impacting end-user experience.
β’ Fluency in scripting for tooling and test automation, such as Python or comparable languages.
β’ Excellent written and verbal communication skills, particularly with distributed teams and customers.
β’ Experience in kernel-mode driver or kernel extension development that has been shipped to production at scale (bonus).
β’ Background in reverse engineering, malware analysis, or exploit and vulnerability research (bonus).
β’ Familiarity with anti-tamper and code integrity measures (bonus).
β’ Meaningful equity in addition to salary.
β’ 90% of medical, dental, and vision premiums covered by Ent.
β’ 75% coverage for dependents.
β’ Flexible paid time off (PTO).
β’ 12 weeks of fully paid maternity leave (for birth, adoption, or foster care).
β’ 8 weeks of fully paid paternity leave.
β’ $100 monthly lifestyle account for fitness, wellness, learning, and more.
β’ $500 home office stipend for remote employees.
β’ A distributed workplace allowing for remote work across North America.
Motive
Oportun
Mercury Insurance
Get handpicked remote jobs straight to your inbox weekly.