1

Ebpf Linux Jobs in Kentucky (NOW HIRING)

$200 - $250/hr

This role builds detection and prevention on eBPF, LSM, and the audit subsystem, across the range of Linux customers actually run -- workstations, servers, containers, and cloud workloads. You will ...

New

$200 - $250/hr

... Linux Kernel and driver components, focusing on system architecture and optimization. * Drive the adoption and integration of kernel bypass technologies such as XDP/EBPF, AF_XDP, and DPDK. * Deep ...

New

$200 - $250/hr

Strong familiarity with Linux kernel development or Linux components like overlayfs, cgroups, and eBPF. * A strong infrastructure background with experience in multiple clouds or racking physical ...

$200 - $250/hr

Build secure-by-default infrastructure using Linux security mechanisms (AppArmor, SELinux, seccomp, cgroups), Kubernetes, and eBPF to enforce runtime policies and gain deep visibility into systems ...

$200 - $250/hr

Build secure, reliable networking capabilities using technologies such as IPsec, MASQUE, eBPF, and Linux kernel networking primitives while keeping the system small, predictable, and secure.

$150 - $200/hr

Linux operating systems, networking, filesystems, containers, performance tooling (perf, flamegraphs, nvprof/rocprof, basic eBPF). * Clear communication: ability to turn complex systems into ...

New

$200 - $250/hr

Proficiency in C or C++ with concurrent or timing-sensitive software in Linux, real-time Linux, or ... Experience with high-performance packet-processing technologies such as DPDK, VPP, eBPF, or ...

$100 - $125/hr

Linux experience, including eBPF, systemd, kernel module development, or D-Bus. * Experience building cross platform C++ agents that run on Windows, macOS, and Linux. * Familiarity with CIS Benchmark ...

$150 - $200/hr

Proficiency in Linux and familiarity with how platform engineering teams build and operate ... Experience with runtime threat detection tools such as Falco or eBPF -based security tooling

$200 - $250/hr

... Grafana, eBPF, or equivalent). * Experience with Linux/Unix environments and practical system administration for test and production-like systems. * Experience automating test or deployment ...

$200 - $250/hr

Tracing and profiling using tools such as ftrace, perf, eBPF, BPFtrace, LTTng, systemtap ... Strong experience with systems programming (such as with Linux, BSD, etc), including meaningful ...

$250/hr

Experience with Technologies like eBPF and XDP for Observability & DDoS mitigation * Collect and ... Linux OS Proficiency with Kernel Internals * Experience with running large environments consisting ...

$200 - $250/hr

Hands-on experience with Linux, containers, Kubernetes or another cluster scheduler, infrastructure ... or eBPF networking, or topology-aware placement. * Experience with Terraform, workflow ...

$150 - $200/hr

Experience with low-latency userspace packet processing; familiarity with Linux kernel networking primitives such as netfilter, nftables, eBPF, tc, and network namespaces is also valuable

$250/hr

Deep Linux performance skill: perf, eBPF, flamegraphs, hardware counters, packet captures, and tracing, plus the judgment to know which one answers the question in front of you. * Networking depth:

New

$250/hr

Deep Linux performance skill: perf, eBPF, flamegraphs, hardware counters, packet captures, and tracing, plus the judgment to know which one answers the question in front of you. Networking depth: UDP ...

New

Ebpf Linux information

What is an eBPF Linux engineer?

An eBPF Linux engineer is a software professional who specializes in working with eBPF (extended Berkeley Packet Filter) technology on the Linux operating system. eBPF allows for the execution of sandboxed programs in the Linux kernel, enabling advanced networking, security, and observability features without modifying kernel source code. Engineers in this role typically develop, optimize, and troubleshoot eBPF programs for use cases such as network monitoring, performance analysis, and security enforcement. They need a strong understanding of Linux internals, networking, and programming in C and sometimes Rust or Go. eBPF Linux engineers are increasingly in demand due to the growing use of cloud-native and containerized environments.

What are the key skills and qualifications needed to thrive as an eBPF Linux engineer?

To thrive as an eBPF Linux Engineer, you need strong skills in Linux systems programming, networking fundamentals, and proficiency with C or Go, often supported by a computer science degree or equivalent experience. Familiarity with eBPF tools (like bpftrace, libbpf, or bpftool), kernel debugging, and knowledge of containerization platforms are typically required. Analytical thinking, problem-solving, and effective collaboration set top professionals apart in this field. These competencies are crucial for developing efficient, secure, and scalable system observability or networking solutions within complex Linux environments.

What are some common challenges faced when developing with eBPF on Linux systems?

Developing with eBPF on Linux often involves navigating kernel version compatibility, as eBPF features evolve rapidly and may not be available on older kernels. Debugging eBPF programs can also be challenging due to strict verifier constraints and limited debugging tools. Additionally, integrating eBPF with existing monitoring or networking solutions requires a solid understanding of both kernel space and user space interactions. Collaborating with platform engineers and security teams is common, as eBPF programs frequently impact system performance and security.

What is the difference between Ebpf Linux vs Linux Kernel Developer?

AspectEbpf LinuxLinux Kernel Developer
Required credentialsKnowledge of eBPF, Linux internals, C programmingDeep understanding of Linux kernel, C, and kernel modules
Work environmentDeveloping and deploying eBPF programs within Linux systemsWriting, maintaining, and optimizing Linux kernel code
Employer and industry usageTech companies, cloud providers, security firms using eBPF for monitoring and securityOperating system vendors, enterprise IT, open-source projects

Ebpf Linux specialists focus on developing eBPF programs to enhance Linux system capabilities, while Linux Kernel Developers work on core kernel code. Both roles require strong C skills and Linux knowledge but differ in scope and focus.

What are popular job titles related to Ebpf Linux jobs in Kentucky?

For Ebpf Linux jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Ebpf Linux jobs in Kentucky look for?

The top searched job categories for Ebpf Linux jobs in Kentucky are:

Infographic showing various Ebpf Linux job openings in Kentucky as of August 2026, with employment types broken down into 85% Full Time, 6% Part Time, and 9% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution.

Endpoint Engineer, EDR (linux)

Ent

On-site

$200 - $250/hr

Other

Medical, Dental, Vision, PTO

Posted yesterday

New


Job description

Endpoint Engineer, EDR (linux) About Ent

Ent is the intent-aware workspace security platform for securing human and AI-driven work. Built to protect productivity, the new attack surface, Ent understands not just what users and agents do but why, and intervenes at the moment of risk before incidents occur. Where existing tools see events, Ent sees intent, so security teams can step in at the moment of risk instead of investigating days later. Founded by Lou Manousos and Brandon Dixon, co‑founders of RiskIQ (acquired by Microsoft) and the team behind Microsoft Security Copilot, Ent is in production with Global 2000 customers across hospitality, financial services, and defense, and backed by Decibel, Sequoia, Crosspoint Capital, Craft Ventures, Shield Capital, Felicis, and In‑Q‑Tel. We’re now hiring the team that will define this category.

How We Work

Customer first. The product and the business are built around problems we’ve watched real security teams struggle with — not the other way around. Every roadmap conversation starts with what a CISO told us last week.

Humble. No drama. We hire people who share the mission and trust each other to deliver. Teamwork over showmanship. Accountability over politics. The work speaks louder than the person doing it.

Urgency. The window to build a durable security company in the AI era is open right now and it will not stay open. The shot clock has started. We move at the speed of the people we want to protect.

About the Role

We are seeking an Endpoint Engineer to be part of the team that owns the Linux sensor at the core of Ent's EDR capability. This role builds detection and prevention on eBPF, LSM, and the audit subsystem, across the range of Linux customers actually run — workstations, servers, containers, and cloud workloads. You will own the tradeoffs between detection efficacy, false positives, and performance, and defend them with measured data.

What You’ll Achieve
  • Design, build, and ship kernel- and user-mode components of the Ent agent that observe process, file, registry, network, and identity activity for Linux and turn that activity into high-fidelity intent signals.

  • Own EDR-class detection and prevention capability end to end: sensor instrumentation, event enrichment, on-box correlation, and interception logic that stops malicious activity before it completes.

  • Make and defend explicit tradeoffs between detection efficacy, false-positive rate, and endpoint performance, backed by measured data rather than intuition.

  • Instrument telemetry at the OS boundary: eBPF, LSM, and audit subsystems.

  • Harden the agent against tamper, bypass, and evasion — self-protection, integrity validation, and safe handling of untrusted input inside a privileged process.

  • Hold sensor CPU, memory, and I/O inside strict budgets while processing thousands of events per second; profile hot paths and eliminate regressions before they ship.

  • Build test harnesses, automated regression coverage so every efficacy claim is continuously verified, not asserted.

  • Drive high-severity customer escalations to root cause — crashes, hangs, performance regressions, missed detections — at the code and OS-internals level, and convert escalation patterns into permanent fixes.

  • Partner with the security research, AI, platform, and product teams to feed sensor signals into intent‑aware policy enforcement, just‑in‑time interventions, and investigation timelines.

  • Review code, mentor engineers, document design decisions, and share ownership of agent release quality and on‑call.

What You’ll Bring Must-haves
  • 10+ years designing, building, and delivering production C/C++ (or Rust) systems software, a substantial portion of it in endpoint security, OS internals, or comparable performance‑critical native code.

  • Deep working knowledge of operating system internals: process and thread lifecycle, memory management, file systems, drivers or kernel extensions, and IPC.

  • Hands‑on production experience with eBPF.

  • Demonstrated experience building or operating an EDR, EPP, XDR, or AV product, or equivalent detection‑and‑response engineering.

  • Practical fluency in attacker TTPs; you can reason about what an attack looks like in raw telemetry, not just in a written report.

  • Strong low‑level debugging skills, performance tracing, and crash‑dump analysis.

  • Multi‑threaded and concurrent programming under load — synchronization, lock contention, race conditions, and object lifetime management.

  • A track record of code running on large fleets without degrading end‑user experience; you treat stability and performance as product features.

  • Scripting fluency for tooling and test automation (Python or equivalent).

  • Clear written and verbal communication with distributed teams and, when escalations demand it, directly with customers.

Bonus
  • Kernel‑mode driver or kernel extension development shipped to production at scale.

  • Reverse engineering, malware analysis, or exploit and vulnerability research background.

  • Experience with anti‑tamper and code integrity.

Our Benefits
  • Distributed workplace. While we have positions we hire for in our SF office, we also hire remotely across North America.

  • Own a piece of the journey. Every teammate gets meaningful equity on top of their salary.

  • We’ve got you covered. 90% of your medical, dental, and vision is paid by Ent. We also cover 75% for your dependents.

  • Take the time you need. Our flexible PTO lets you recharge, travel, or just take a breather.

  • Family matters. 12 weeks of fully paid maternity leave (birth, adoption, or foster) and 8 weeks fully paid paternity leave.

  • Live well. A $100 monthly lifestyle account to spend on what keeps you healthy and happy — fitness, wellness, learning, and more.

  • Set up your space. A $500 home office stipend when you join as a remote employee.

Diversity & Accommodations

We’re committed to building a diverse, inclusive, and equitable workplace where people of all backgrounds, identities, experiences, and abilities are welcomed, valued, and supported; we recognize there is no single path to success and value nontraditional career journeys and diverse perspectives as key to building stronger, more innovative teams.

We strive to ensure an inclusive experience at every stage of hiring and are happy to provide reasonable accommodations. If you require accommodations or accessible formats at any point during our process, please let your recruiter know. As an equal opportunity employer, our hiring process is designed to put you at ease and help you do your best work. If there’s anything we can do to improve your experience, we’re always open to feedback.

#J-18808-Ljbffr