Senior Security Engineer, Data Loss Prevention

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Engineer protecting Fragomen’s immigration law firm data through enterprise DLP controls. Investigating exposure risks and integrating Microsoft 365, cloud, SaaS, endpoint, and SIEM security capabilities.

Responsibilities:

  • Design, implement, and tune enterprise DLP policies across Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms
  • Identify, classify, and protect sensitive information using data classification, sensitivity labels, policy conditions, and enforcement actions
  • Monitor and investigate DLP alerts involving potential data exposure, improper sharing, data exfiltration indicators, or policy violations
  • Partner with Legal, Compliance, Privacy, Risk, Records, and business stakeholders to align DLP controls with requirements
  • Develop and maintain DLP standards, operating procedures, runbooks, exception processes, and escalation workflows
  • Evaluate and improve controls for collaboration and file-sharing platforms
  • Support CASB and SaaS governance efforts by identifying unsanctioned data movement, risky sharing, excessive permissions, and policy enforcement opportunities
  • Conduct root cause analysis on recurring alerts, control gaps, and data handling issues
  • Integrate DLP telemetry into SIEM, SOAR, monitoring, and response processes with security, identity, messaging, endpoint, network, and application teams
  • Prepare communications regarding DLP findings, policy changes, and corrective actions
  • Provide technical guidance and mentorship to junior analysts and security team members

Requirements:

  • 5+ years of experience in cybersecurity, data protection, security operations, governance, risk, compliance, or related technology roles, or equivalent combination of education and experience
  • Working knowledge of DLP concepts, sensitive data handling, information protection, data classification, and policy-based enforcement
  • Hands-on experience supporting or operating enterprise security controls, especially in Microsoft 365, email, endpoint, cloud, or SaaS platforms
  • Ability to analyze DLP alerts, user activity, sharing patterns, policy matches, and event logs
  • Working knowledge of identity and access concepts, authentication mechanisms, file permissions, collaboration tooling, and data-sharing workflows
  • Strong written and verbal communication skills
  • Ability to explain technical findings in clear, practical, business-appropriate language
  • Ability to follow structured processes while continuously improving them
  • Knowledge of Microsoft Purview Information Protection and DLP, including sensitivity labels, trainable classifiers, DLP rules, audit logs, alerts, and policy tuning
  • Knowledge of Microsoft Defender for Cloud Apps, CASB concepts, SaaS discovery, session controls, and cloud data exposure monitoring
  • Knowledge of endpoint, email, and collaboration security controls across Windows, Microsoft 365, Exchange Online, Teams, SharePoint, and OneDrive
  • Knowledge of SIEM and security platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar tools
  • Knowledge of sensitive data types and regulatory drivers including PII, PCI, PHI, financial data, client confidential information, legal matter data, and regulated business records
  • Knowledge of TCP/IP, DNS, HTTP/S, VPNs, proxies, firewalls, APIs, and cloud storage patterns
  • Preferred experience with Microsoft Purview DLP, Endpoint DLP, Information Protection, Insider Risk Management, eDiscovery, Audit, or Data Lifecycle Management
  • Preferred experience with CASB, SaaS security, cloud access governance, or file-sharing risk management
  • Preferred experience supporting investigations involving Legal, Compliance, Privacy, Risk, Records, HR, or regulatory stakeholders
  • Preferred experience with SOAR, ticketing, workflow automation, and process documentation
  • Relevant certifications are preferred, including Microsoft certifications, CISSP, SSCP, Security+, CISA, CISM, GIAC, or vendor certifications
  • Legal authorization to work in the offered position’s location
  • Successful completion of the Firm’s pre-employment screening process and background check, where permitted

Benefits:

  • Hybrid & Remote work arrangements
  • Fragomen Academy
  • Leadership Academy
  • Practical Management Academy
  • Regional Development Conferences
  • Three managerial check-ins per year through the Feedback Works process
  • Programs supporting health and wellness
  • Programs addressing work-life balance
  • Benefits covering a wide range of well-being needs
  • Diversity, inclusion, and equal opportunity commitment
  • Community support and giving-back initiatives
  • Sustainability initiatives