{"schemaVersion":"jobsearcher.job.v1","id":"b9e9f99f68673684d6de5925","url":"https://jobsearcher.com/jobs/b9e9f99f68673684d6de5925","canonicalUrl":"https://jobsearcher.com/jobs/b9e9f99f68673684d6de5925","title":"Endpoint Engineer, Data Security","description":"Endpoint Engineer, Data Security\n\nAbout Ent\n\nEnt is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category.\n\nHow We Work\n\nCustomer first. The product and the business are built around problems we’ve watched real security teams struggle with — not the other way around. Every roadmap conversation starts with what a CISO told us last week.\n\nHumble. No drama. We hire people who share the mission and trust each other to deliver. Teamwork over showmanship. Accountability over politics. The work speaks louder than the person doing it.\n\nUrgency. The window to build a durable security company in the AI era is open right now and it will not stay open. The shot clock has started. We move at the speed of the people we want to protect.\n\nAbout the Role\n\nWe are seeking an Endpoint Engineer to be part of the team that owns Ent's data protection layer on the device: classifying sensitive data, tracing how it moves, and enforcing policy at the moment of egress — including to AI tools and agents. This role pairs classic content inspection with Ent's on-device small language model, so enforcement reflects what a person is trying to do and not only what a file contains. Precision is the product here.\n\nWhat You’ll Achieve\n\nBuild the endpoint data-protection layer of the Ent agent: classify sensitive data on the device, trace how it is created and moved, and enforce policy at the moment of egress.\n\nInstrument and control the full set of exfiltration channels — removable media and USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth and AirDrop, email, web and browser upload, sync clients, and AI tools and agents including chat interfaces, IDE assistants, and CLI agents.\n\nImplement on-device content inspection and classification: regular expression and pattern matching, keyword and dictionary matching, exact and indexed document matching, fingerprinting, file-type and structure identification, and OCR for image-borne content.\n\nIntegrate Ent's on-device small language model into classification and intent decisions so enforcement reflects what the user is trying to do, not only what a file contains.\n\nBuild data lineage and provenance tracking that keeps classification attached to content as it is copied, renamed, transformed, archived, compressed, or re-encoded.\n\nImplement or work with team members to the interception plumbing that makes the above possible: Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, and browser extension hooks.\n\nDrive precision as a first-class metric: build labeled corpora, measure false-positive and false-negative rates per detector, and tune classification quality with evidence.\n\nKeep inspection cost invisible to the user — budget CPU, memory, and I/O for content scanning, and never block, delay, or corrupt legitimate user files and workflows.\n\nProduce forensically useful incident evidence — who, what data, which channel, what intent — that feeds investigation timelines, insider-risk review, and compliance reporting.\n\nOwn customer escalations on missed egress paths, and application-compatibility conflicts, and turn recurring patterns into permanent fixes.\n\nPartner with product, security research, AI, and compliance stakeholders to map endpoint controls to regulatory regimes such as GDPR, HIPAA, PCI DSS, CCPA, and export-control requirements.\n\nWhat You’ll Bring\nMust-haves\n\n5+ years shipping production systems software in C/C++, including work on an endpoint agent deployed at enterprise scale.\n\nDirect experience building or operating an endpoint for insider-risk, data-security, or CASB/SASE data-protection product.\n\nStrong operating system internals knowledge on at least one platform: file system filtering, process and handle interception, and the user/kernel boundary.\n\nHands-on content inspection and data classification work: pattern-based detection, fingerprinting and hashing schemes, file format parsing, and handling of archives and Office/PDF container formats.\n\nExperience controlling device and network egress channels — USB and removable media, print, clipboard, HTTPS upload.\n\nMulti-threaded, performance-sensitive engineering against measured latency and throughput budgets.\n\nStrong debugging and profiling skills on real user machines, including application-compatibility investigations where the security agent is suspected first.\n\nA precision mindset: you understand that a noisy product gets disabled, and you instrument accordingly.\n\nClear written and verbal communication with distributed teams and customer-facing stakeholders.\n\nBonus\n\nOCR, ML-based classification, or embedding and LLM-based content understanding applied to data protection.\n\nImplementation experience with data lineage or provenance tracking.\n\nCross-platform development spanning Windows and macOS (Linux a plus), and browser extension development.\n\nEncryption, rights management, or key handling on the endpoint.\n\nDepth in regulatory compliance and audit-evidence design.\n\nInsider-threat investigation workflows, or data governance for AI tools and autonomous agents.\n\nOur Benefits\n\nDistributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.\n\nOwn a piece of the journey. Every teammate gets meaningful equity on top of their salary.\n\nWe’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.\n\nTake the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.\n\nFamily matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.\n\nLive well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy — fitness, wellness, learning, and more.\n\nSet up your space. A $500 home office stipend when you join as a remote employee.\n\nDiversity & Accommodations\n\nWe’re committed to building a diverse, inclusive, and equitable workplace where people of all backgrounds, identities, experiences, and abilities are welcomed, valued, and supported. We recognize there is no single path to success and value nontraditional career journeys and diverse perspectives as key to building stronger, more innovative teams.\n\nWe strive to ensure an inclusive experience at every stage of hiring and are happy to provide reasonable accommodations. If you require accommodations or accessible formats at any point during our process, please let your recruiter know. As an equal opportunity employer, our hiring process is designed to put you at ease and help you do your best work. If there’s anything we can do to improve your experience, we’re always open to feedback.","company":"Ent","rawCompany":"ent","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-09-06T08:22:28.613Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Endpoint Engineer, Data Security","description":"Endpoint Engineer, Data Security\n\nAbout Ent\n\nEnt is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co-founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In-Q-Tel. We’re now hiring the team that will define this category.\n\nHow We Work\n\nCustomer first. The product and the business are built around problems we’ve watched real security teams struggle with — not the other way around. Every roadmap conversation starts with what a CISO told us last week.\n\nHumble. No drama. We hire people who share the mission and trust each other to deliver. Teamwork over showmanship. Accountability over politics. The work speaks louder than the person doing it.\n\nUrgency. The window to build a durable security company in the AI era is open right now and it will not stay open. The shot clock has started. We move at the speed of the people we want to protect.\n\nAbout the Role\n\nWe are seeking an Endpoint Engineer to be part of the team that owns Ent's data protection layer on the device: classifying sensitive data, tracing how it moves, and enforcing policy at the moment of egress — including to AI tools and agents. This role pairs classic content inspection with Ent's on-device small language model, so enforcement reflects what a person is trying to do and not only what a file contains. Precision is the product here.\n\nWhat You’ll Achieve\n\nBuild the endpoint data-protection layer of the Ent agent: classify sensitive data on the device, trace how it is created and moved, and enforce policy at the moment of egress.\n\nInstrument and control the full set of exfiltration channels — removable media and USB, printing, clipboard, drag-and-drop, screen capture, network shares, Bluetooth and AirDrop, email, web and browser upload, sync clients, and AI tools and agents including chat interfaces, IDE assistants, and CLI agents.\n\nImplement on-device content inspection and classification: regular expression and pattern matching, keyword and dictionary matching, exact and indexed document matching, fingerprinting, file-type and structure identification, and OCR for image-borne content.\n\nIntegrate Ent's on-device small language model into classification and intent decisions so enforcement reflects what the user is trying to do, not only what a file contains.\n\nBuild data lineage and provenance tracking that keeps classification attached to content as it is copied, renamed, transformed, archived, compressed, or re-encoded.\n\nImplement or work with team members to the interception plumbing that makes the above possible: Windows minifilters and ETW, macOS Endpoint Security Framework and Network Extensions, Linux fanotify and eBPF, and browser extension hooks.\n\nDrive precision as a first-class metric: build labeled corpora, measure false-positive and false-negative rates per detector, and tune classification quality with evidence.\n\nKeep inspection cost invisible to the user — budget CPU, memory, and I/O for content scanning, and never block, delay, or corrupt legitimate user files and workflows.\n\nProduce forensically useful incident evidence — who, what data, which channel, what intent — that feeds investigation timelines, insider-risk review, and compliance reporting.\n\nOwn customer escalations on missed egress paths, and application-compatibility conflicts, and turn recurring patterns into permanent fixes.\n\nPartner with product, security research, AI, and compliance stakeholders to map endpoint controls to regulatory regimes such as GDPR, HIPAA, PCI DSS, CCPA, and export-control requirements.\n\nWhat You’ll Bring\nMust-haves\n\n5+ years shipping production systems software in C/C++, including work on an endpoint agent deployed at enterprise scale.\n\nDirect experience building or operating an endpoint for insider-risk, data-security, or CASB/SASE data-protection product.\n\nStrong operating system internals knowledge on at least one platform: file system filtering, process and handle interception, and the user/kernel boundary.\n\nHands-on content inspection and data classification work: pattern-based detection, fingerprinting and hashing schemes, file format parsing, and handling of archives and Office/PDF container formats.\n\nExperience controlling device and network egress channels — USB and removable media, print, clipboard, HTTPS upload.\n\nMulti-threaded, performance-sensitive engineering against measured latency and throughput budgets.\n\nStrong debugging and profiling skills on real user machines, including application-compatibility investigations where the security agent is suspected first.\n\nA precision mindset: you understand that a noisy product gets disabled, and you instrument accordingly.\n\nClear written and verbal communication with distributed teams and customer-facing stakeholders.\n\nBonus\n\nOCR, ML-based classification, or embedding and LLM-based content understanding applied to data protection.\n\nImplementation experience with data lineage or provenance tracking.\n\nCross-platform development spanning Windows and macOS (Linux a plus), and browser extension development.\n\nEncryption, rights management, or key handling on the endpoint.\n\nDepth in regulatory compliance and audit-evidence design.\n\nInsider-threat investigation workflows, or data governance for AI tools and autonomous agents.\n\nOur Benefits\n\nDistributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.\n\nOwn a piece of the journey. Every teammate gets meaningful equity on top of their salary.\n\nWe’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.\n\nTake the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.\n\nFamily matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.\n\nLive well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy — fitness, wellness, learning, and more.\n\nSet up your space. A $500 home office stipend when you join as a remote employee.\n\nDiversity & Accommodations\n\nWe’re committed to building a diverse, inclusive, and equitable workplace where people of all backgrounds, identities, experiences, and abilities are welcomed, valued, and supported. We recognize there is no single path to success and value nontraditional career journeys and diverse perspectives as key to building stronger, more innovative teams.\n\nWe strive to ensure an inclusive experience at every stage of hiring and are happy to provide reasonable accommodations. If you require accommodations or accessible formats at any point during our process, please let your recruiter know. As an equal opportunity employer, our hiring process is designed to put you at ease and help you do your best work. If there’s anything we can do to improve your experience, we’re always open to feedback.","datePosted":"2026-09-06T08:22:28.613Z","dateModified":"2026-09-06T08:22:28.613Z","hiringOrganization":{"@type":"Organization","name":"Ent","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"b9e9f99f68673684d6de5925"},"url":"https://jobsearcher.com/jobs/b9e9f99f68673684d6de5925"}}