SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Nightfall AI is an AI-native, unified data loss prevention and insider risk management platform protecting sensitive data across SaaS apps, GenAI tools, email, endpoint devices, and more. The company serves hundreds of customers from AI innovators to top-10 banks, backed by leading VCs including Bain Capital Ventures, Venrock, and WestBridge Capital, with advisors including founders of Okta and Mandiant.
Nightfall is expanding its endpoint DLP coverage to Linux and seeks a seasoned Endpoint Engineer to lead this strategic initiative from the ground up, working alongside existing Mac and Windows endpoint teams.
In this role, you will design, build, and maintain a production-grade, AI-native DLP agent for Linux covering kernel-level event interception, userspace policy enforcement, and enterprise deployment. You will own complex features end-to-end from design through delivery, including scoping, implementation, testing, and customer-facing documentation.
Key responsibilities include:
- Design and develop data exfiltration prevention applications, kernel modules, system services, and agents on Linux
- Build and maintain mission-critical endpoint agents monitoring and enforcing DLP policies across Ubuntu, RHEL/CentOS, and other distributions
- Implement kernel-level event interception using eBPF, LSM hooks, netfilter, fanotify, or similar mechanisms
- Develop userspace components integrating with kernel subsystems to enforce policy decisions in real time
- Collaborate with Mac and Windows endpoint teams on cross-platform agent architecture and shared policy models
- Diagnose and resolve deep systems-level issues including kernel panics, race conditions, and IPC failures
- Ensure agent reliability, upgrade safety, and minimal performance footprint
- Write and maintain internal architecture documentation, public APIs, and enterprise deployment guides
Required qualifications:
- 10+ years of systems/endpoint engineering experience
- Expert-level C/C++ for Linux systems development; Go familiarity is a strong plus
- Demonstrable production experience building agents or system-level software on Linux
- Deep hands-on experience with Linux kernel subsystems relevant to security: eBPF (BPF CO-RE, libbpf, BCC), Linux Security Modules (SELinux, AppArmor), fanotify, inotify, netlink, procfs
- Familiarity with Linux namespaces, cgroups, and container runtimes in enterprise deployments
- Experience with kernel-level debugging tools: ftrace, perf, crash, SystemTap, GDB with KGDB
- Ability to use reverse engineering and binary analysis for kernel-space debugging
- Familiarity with enterprise Linux deployment and MDM tools
- Ability to decompose complex problems and own them end-to-end across teams
Nice-to-have experience includes prior DLP/EDR/endpoint security product development on Linux, open-source Linux kernel or eBPF contributions, FUSE or overlayfs file activity interception, Linux audit subsystem integration, XDR/EDR platform development, and X11/Wayland display server internals knowledge.