
Endpoint Engineer, EDR – Windows
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in North America.
• Design, develop, and deliver both kernel- and user-mode components of the Ent agent for Windows.
• Monitor process, file, registry, network, and identity activities, converting them into high-fidelity intent signals.
• Take full ownership of EDR-class detection and prevention processes, including sensor instrumentation, event enrichment, on-box correlation, and interception logic.
• Implement telemetry at the OS boundary using ETW, kernel callbacks, and minifilters.
• Strengthen the agent against tampering, bypassing, and evasion through self-protection and integrity validation measures.
• Ensure that sensor CPU, memory, and I/O usage remain within strict limits while managing the processing of thousands of events per second.
• Analyze hot paths and eliminate performance regressions prior to release.
• Develop test harnesses and automated regression coverage.
• Lead high-severity customer escalations to determine root causes, including crashes, hangs, performance regressions, and missed detections.
• Transform escalation trends into permanent solutions.
• Collaborate with security research, AI, platform, and product teams on policy enforcement, interventions, and investigation timelines.
• Review code, mentor engineers, document design decisions, and collectively ensure the quality of agent releases and on-call responsibilities.
• Over 10 years of experience in designing, building, and deploying production C/C++ systems software, with a significant focus on endpoint security, OS internals, or similar performance-critical native code.
• Profound knowledge of operating system internals, including process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.
• Practical experience with kernel callbacks and minifilters in a production environment.
• Background in building or operating an EDR, EPP, XDR, or AV product, or equivalent detection-and-response engineering.
• Practical understanding of attacker TTPs and raw telemetry analysis.
• Strong skills in low-level debugging, performance tracing, and crash-dump analysis.
• Experience with multithreaded and concurrent programming under load, covering synchronization, lock contention, race conditions, and object lifetime management.
• Proven ability to run code on large fleets without compromising end-user experience.
• Proficient in scripting for tooling and test automation, utilizing Python or equivalent languages.
• Excellent written and verbal communication skills with distributed teams and customers.
• Experience in kernel-mode driver or kernel extension development delivered to production at scale.
• Background in reverse engineering, malware analysis, or exploit and vulnerability research.
• Knowledge of anti-tamper measures, code integrity, driver signing, and WHQL attestation.
• Every team member receives meaningful equity in addition to their salary.
• Ent covers 90% of medical, dental, and vision insurance costs.
• Dependents receive 75% coverage.
• Flexible Paid Time Off (PTO).
• 12 weeks of fully paid maternity leave (for birth, adoption, or foster care).
• 8 weeks of fully paid paternity leave.
• A $100 monthly lifestyle account for fitness, wellness, learning, and more.
• A $500 home office stipend for remote employees upon joining.
• A distributed workplace with remote work opportunities across North America.
Green Energy Venture AG
Abacus Group
EXP
Get handpicked remote jobs straight to your inbox weekly.