368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$73k – $145k per year (Estimated)
Location
Remote (Palo Alto, United States)
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Nightfall is the agentic, all-in-one data loss prevention (DLP) & AI data security platform that prevents data leaks, gets visibility into data flows, and stops data exfiltration across SaaS, gen AI apps, endpoints, and more.

About Nightfall:

Nightfall is the AI-native, unified data loss prevention and insider risk management platform that protects sensitive data across SaaS apps, GenAI tools, email, endpoint devices, and more. Hundreds of customers, spanning AI innovators to top 10 banks, trust Nightfall to detect and stop data exfiltration at scale. Nightfall enables organizations to innovate freely without the risks of losing intellectual property or exposing customer data. Our agentic platform helps security teams regain their time by putting data loss prevention on autopilot. With automatic remediation, security violations can be resolved automatically before they become incidents, and end-users can be automatically trained and coached in the moment to self-heal violations that they introduce.

Nightfall is backed by leading VC firms including Bain Capital Ventures (Enrique Salem - former CEO of Symantec), Venrock (early investors in Cloudflare), WestBridge Capital, Pear VC (early investors in Dropbox and Doordash), and a cadre of cybersecurity leaders including Frederic Kerrest (founder of Okta), Maynard Webb (former COO of eBay), Ryan Carlson (President of Chainguard), Kevin Mandia (founder of Mandiant), and many others.

About the role:

As a DLP Analyst at Nightfall, you'll be at the forefront of protecting our customers' most sensitive data. You'll become an expert on Nightfall's DLP platform, working directly with security teams to operationalize data loss prevention across their organizations. This is a hands-on role that combines technical depth, investigative skills, and customer obsession to help enterprises detect, investigate, and prevent data exfiltration incidents while maintaining employee productivity.

You'll work closely with customers' security operations teams to monitor data movement, investigate alerts, tune detection policies, and provide strategic guidance on insider threat mitigation. This role requires someone who can balance technical precision with business judgment - understanding when an alert represents a genuine security incident versus legitimate business activity.

Key Responsibilities

Alert Monitoring & Incident Response

  • Monitor and analyze DLP alerts across endpoint, browsers, SaaS, and AI applications to identify potential data exfiltration events, policy violations, and insider threats

  • Conduct real-time triage of security alerts, distinguishing between true positives and false positives using behavioral context, data lineage analysis and sensitive findings

  • Perform detailed forensic investigations into data loss incidents, analyzing user activity, data movement patterns, and exfiltration vectors (email, web uploads, removable storage, print, source code exfiltration, desktop apps, GenAI apps etc.)

  • Understand and follow incident response processes and escalation procedures, coordinating with customer incident response teams on high-severity cases

  • Document investigation findings, evidence trails, and remediation recommendations with clear, actionable reports

Policy Development & Optimization

  • Configure and maintain DLP policies based on customer data classification schemes, compliance requirements (GDPR, HIPAA, PCI-DSS, SOX), and business objectives

  • Continuously tune detection rules and sensitivity thresholds to reduce false positives while maintaining high detection accuracy

  • Identify patterns in alert data to recommend new use cases, detection methods, and policy improvements

  • Work with customers to develop custom detection policies for industry-specific sensitive data types and unique organizational requirements

  • Establish baselines for normal user behavior by role, department, and geography to improve anomaly detection

Customer Collaboration & Advisory

  • Serve as a trusted technical advisor and subject matter expert on data protection, DLP best practices, and insider threat management

  • Conduct regular operational reviews with customers to share insights on data risk trends, policy effectiveness, and program maturity

  • Educate customer security teams on using Nightfall's platform effectively, including investigation workflows, reporting capabilities, onboarding and deployment best practices

  • Understand customer business context to deliver relevant, actionable security guidance - not just alerts, but answers to "why this matters" and "what to do next"

Platform Administration & Technical Support

  • Administer Nightfall's DLP solution including agent deployment, policy configuration, integration setup, and performance monitoring

  • Troubleshoot technical issues with endpoint agents, browser extensions, SaaS integrations

  • Work with Nightfall engineering teams to report bugs, provide product feedback, and contribute to feature development based on customer needs

  • Stay current on Nightfall platform updates, new capabilities, and best practices to maximize value for customers

  • Coordinate with internal teams (Sales Engineering, Customer Success, Product) to ensure successful customer outcomes

Threat Intelligence & Research

  • Stay informed about emerging insider threat trends, data exfiltration techniques, and adversary tactics, techniques, and procedures (TTPs)

  • Analyze external DLP market developments and competitive intelligence to inform customer guidance

  • Contribute to Nightfall's insider risk intelligence by documenting novel attack patterns, evasion techniques, and detection methods

Reporting & Metrics

  • Compile and deliver executive-level reports with clear metrics, data visualizations, and risk assessments

  • Track key performance indicators: detection accuracy, false positive rates, mean time to detect/respond, policy coverage, data at risk

  • Provide business impact analysis showing how DLP program prevents data loss, supports compliance, and enables secure business operations

  • Develop recommendations for continuous program improvement based on operational data and industry benchmarks

What You Need

Required Experience & Skills

  • 3-5 years of experience in information security, with at least 2 years focused on data loss prevention (DLP), insider threat, or data protection technologies

  • Hands-on experience with DLP tools (e.g., Forcepoint, Symantec, McAfee, Digital Guardian, Microsoft Purview, or other enterprise DLP solutions)

  • Proven DLP administration skills: configuring policies, tuning detection rules, managing agents, generating reports, and performing incident investigations

  • Strong understanding of data classification methodologies, sensitive data types (PII, PHI, PCI, IP, credentials), and regex/pattern matching for content inspection

  • Experience with incident response processes, forensic investigation techniques, and security event escalation workflows

  • Knowledge of compliance frameworks and regulations: GDPR, HIPAA, PCI-DSS, SOX, and their data protection requirements

Technical Proficiency

  • Strong analytical skills - ability to analyze complex, multivariate security problems and use systematic approaches to reach resolution

  • Experience with SIEM platforms, SOAR tools, or log analysis software (Splunk, ELK, Tines etc)

  • Familiarity with User and Entity Behavior Analytics (UEBA) and behavioral risk indicators

  • Understanding of endpoint security, including macOS, Windows, and browser platforms

  • Knowledge of SaaS security, CASB solutions, and cloud application architectures (Office 365, Google Workspace, Slack, GitHub, Salesforce, etc.)

  • Basic scripting skills (Python, PowerShell, Bash) for automation and data analysis

Bonus Points

  • Prior experience with Nightfall, Cyberhaven, Code42, DTEX, Proofpoint, or similar DLP/insider risk platforms

  • Background in Security Operations Center (SOC) operations, threat hunting, or blue team activities

  • Knowledge of machine learning/AI-based detection systems and how they improve upon traditional pattern-matching approaches

  • Understanding of API security, OAuth flows, and integration architectures for SaaS platforms

  • Contributions to security community: blog posts, speaking engagements, open-source projects, or threat research

Environment

Nightfall AI takes pride in being an equal-opportunity employer. We value a diverse and global talent pool and the collaboration that results from having a diverse and inclusive team. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status. Our hiring decisions are based exclusively on merit, qualifications, and business needs.

Compensation

Employee compensation will be determined based on interview performance, level of experience, specialization of skills, and market rate. During the offer discussion, your recruiter will review the finalized base salary, bonus (for applicable roles), benefits & perks, and stock options as they’ll be reflected in the offer letter.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Palo Alto
$26k – $65k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • PhD • Budapest
Python
SQL
AI/ML
Anomaly Detection
Cybersecurity
GDPR
Management
Power Automate
Apply
$30k – $75k per year (Estimated) • In office • Full-Time • 10+ years exp • Mumbai
AI/ML
AI Agents
DevOps
AWS
Azure
Bicep
CI/CD
CloudFormation
Docker
GCP
IAM
Kubernetes
Terraform
Cybersecurity
CIS Benchmarks
Crowdstrike
GDPR
HIPAA
ISO 27001
Lacework
Microsoft Entra ID
NIST CSF
PCI DSS
Prisma Cloud
SOC 2
Wiz
Cryptography
Vault
Apply
$30k – $75k per year (Estimated) • In office • Full-Time • 12+ years exp • Gurgaon
AI/ML
AI Agents
DevOps
AWS
Azure
Bicep
CI/CD
CloudFormation
Docker
GCP
IAM
Kubernetes
Terraform
Cybersecurity
CIS Benchmarks
Crowdstrike
GDPR
HIPAA
ISO 27001
Lacework
NIST CSF
PCI DSS
Prisma Cloud
SOC 2
Wiz
Cryptography
Vault
Apply
$100k – $160k per year • In office • Full-Time • 6+ years exp • London
Python
SQL
Databases
Amazon Redshift
AI/ML
AI Agents
Anomaly Detection
Claude
Claude Code
Cursor
dbt
OpenAI Codex
Windsurf
DevOps
AWS
GitHub
GitHub Actions
Analytics
ETL/ELT
Apply
$80k – $140k per year • In office • Full-Time • 6+ years exp • London
Python
Databases
MySQL
PostgreSQL
DevOps
AWS
Azure
Azure AKS
CI/CD
Docker
GitHub
GitHub Actions
Kubernetes
Terraform
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
$31k – $78k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C++
Go
Java
Node JS
Python
SQL
JavaScript
Databases
Apache Kafka
Cassandra
PostgreSQL
Redis
Snowflake
AI/ML
Flink
Hadoop
LLM
Context Engineering
AI Agents
Frontend
React.js
DevOps
AWS
Cloudflare
Docker
Envoy
Kubernetes
Terraform
ZooKeeper
Cybersecurity
Okta
Apply
$31k – $78k per year (Estimated) • In office • 6+ years exp • Bengaluru
C++
Go
Java
Python
Rust
Databases
Apache Kafka
Redis
AI/ML
AI Agents
Flink
NLP
RAG
Semantic Search
Context Engineering
Semantic Search
Apply
$47k – $102k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C++
Go
Java
Python
SQL
Databases
Apache Kafka
Cassandra
Databricks
PostgreSQL
Snowflake
AI/ML
Flink
AI Agents
DevOps
Cloudflare
Cybersecurity
Okta
Apply
$31k – $78k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
C++
Java
Python
C++
PyTorch C++
Databases
Apache Kafka
PostgreSQL
Redis
AI/ML
Fine-tuning
NLP
PyTorch
Edge AI
AI Agents
DevOps
AWS
Cloudflare
GCP
Cybersecurity
Okta
Apply
$30k – $72k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Bengaluru
C++
AI/ML
AI Agents
DevOps
CentOS Stream
Cloudflare
containerd
Docker
eBPF
Ubuntu
Cybersecurity
Crowdstrike
Okta
SentinelOne
Apply
Senior ML Engineer 2 hours ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
$110k – $240k per year (Estimated) • In office • Bachelor's Degree • Palo Alto
Java
Python
Scala
AI/ML
AI Agents
Fine-tuning
LLM Guardrails
DevOps
AWS
Azure
GCP
Git
GitHub
Marketing
Salesforce
Apply
$160k – $210k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp • San Francisco • Chicago • Boston • New York • Palo Alto
AI/ML
AI Agents
Apply
$160k – $210k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp • San Francisco • Chicago • Boston • New York • Palo Alto
AI/ML
AI Agents
Apply
Chief of Staff 11 hours ago
$120k – $150k per year • Equity 0.4–0.7% • In office • Full-Time • 3+ years exp • Palo Alto
AI/ML
AI Agents
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.