# Senior Endpoint Engineer, EDR (macOS) at Ent

- Company: Ent
- What the company does: Ent is the intent-aware AI endpoint — reading human, AI, and app activity in real time to tell normal work from risky action and act at the moment of risk. Backed by Sequoia and Felicis.
- Company website: https://ent.ai/
- Type: Startups (AI role)
- Level: Senior
- Location: Remote
- Work setup: Remote
- Posted: 2026-09-04
- Apply by: 2026-10-19
- Apply: https://jobs.ashbyhq.com/ent-security/bbc336a1-3858-487e-a9a4-ab47be21d349
- Page: https://www.1752.vc/careers/jobs/ent-senior-endpoint-engineer-edr-macos/

## About the role

As an Endpoint Engineer, EDR (macOS), you'll design and ship the privileged daemon, per-user agents, and system extensions that observe process, file, network, device, and user-interaction activity and turn it into high-fidelity signals about what an actor is actually trying to do.

## What they're looking for

- Deep working knowledge of macOS internals: process and thread lifecycle, memory management, file systems, code signing and entitlements, launchd, IPC (XPC and Mach primitives), and the TCC permission model
- Hands-on production experience with the Endpoint Security framework and/or Network Extensions, and an understanding of the system extension lifecycle that replaced kernel extensions
- Demonstrated experience building or operating an EDR, EPP, XDR, DLP, or insider-risk product, or equivalent detection-and-response engineering
- Practical fluency in attacker TTPs, you can reason about what an attack looks like in raw telemetry, not just in a written report
- Strong low-level debugging skills: lldb, crash-dump and hang analysis, performance tracing with Instruments or equivalent
- Multi-threaded and concurrent programming under load: synchronization, lock contention, race conditions, actor isolation, and object lifetime management

Tags: R&D
