10 Aug
|
Amazure Technologies
|
Pune
10 Aug
Amazure Technologies
Pune
Description for L2 Forcepoint DLP Engineer and Senior DLP Engineer L3
Senior DLP Engineer L3
Location : Pune
Mode : On site
Experience : 6+ years
Relevant Exp. : 5+ years
Job Summary
We are looking for a Senior DLP Engineer (L3) to lead enterprise DLP architecture, design, implementation, and optimization initiatives. The candidate will provide technical leadership, design security strategies, and manage complex enterprise deployments across on-premises and cloud environments.
Roles & Responsibilities
- Design, architect, and implement enterprise-wide Data Loss Prevention (DLP) solutions to safeguard sensitive organizational data across on-premises and cloud environments.
- Lead the deployment, migration, and optimization of DLP platforms, including Forcepoint DLP , Symantec Endpoint DLP , and Zscaler DLP .
- Develop and enforce advanced DLP policies for Endpoint, Network, Email, Web, and Cloud channels to ensure comprehensive data protection.
- Implement and manage advanced detection technologies such as Exact Data Match (EDM), Indexed Document Matching (IDM), Optical Character Recognition (OCR), document fingerprinting, and advanced content classifiers.
- Conduct DLP architecture reviews, platform health assessments, and performance optimization to maintain secure and resilient environments.
- Integrate DLP solutions with enterprise security technologies, including SIEM, SOAR, CASB, Microsoft Purview, and Identity & Access Management (IAM) platforms.
- Lead the investigation and resolution of critical data security incidents, ensuring timely response and effective containment.
- Perform root cause analysis (RCA) for security incidents and recommend strategic improvements to strengthen the organization's data protection posture.
- Develop and implement automation scripts using PowerShell or Python to streamline DLP administration, monitoring, and reporting.
- Plan and execute platform upgrades, migrations, disaster recovery (DR) testing, and high-availability (HA) implementations to ensure business continuity.
- Provide technical leadership, mentoring, and guidance to L1 and L2 security engineers while driving operational excellence.
- Collaborate with internal stakeholders, auditors, and customers to support security audits, regulatory compliance initiatives, and client engagements.
- Create and maintain technical documentation, standard operating procedures (SOPs), and architecture documentation for DLP solutions.
- Recommend best practices and continuous improvements to enhance enterprise data protection, governance, and compliance frameworks.
Required Skills
- 6+ years of enterprise DLP experience
- Expert-level knowledge of Forcepoint DLP
- Strong experience with Symantec Endpoint DLP
- Strong experience in Zscaler DLP (ZIA)
- Enterprise DLP architecture and implementation
- Endpoint, Network, Email, Cloud, and Web DLP
- Advanced policy design and tuning
- Data classification frameworks
- SIEM/SOAR integration
- Active Directory and Azure AD
- PowerShell and Python automation
- Cloud security (Azure, AWS, Microsoft 365)
- Excellent stakeholder management and leadership skills
Preferred Skills
- Microsoft Purview Information Protection & DLP
- CASB (Defender for Cloud Apps, Netskope, etc.)
- DSPM concepts
- CISSP, CCSP, SC-100, SC-400, or equivalent security certifications
- Experience with regulatory frameworks such as GDPR, HIPAA, PCI DSS, and ISO 27001
L2 Forcepoint DLP Engineer
Location : Pune
Mode : On site
Experience: 3–6 years in DLP/Security Operations (1–3 years Forcepoint DLP)
Shift: Business hours with on-call support for critical incidents
Key Responsibilities
1. L2 Support & Advanced Troubleshooting
- Provide Level 2 support for Forcepoint DLP-related incidents escalated from L1.
- Perform root cause analysis (RCA) for complex incidents: agent failures, policy misconfigurations, false positives/negatives.
- Troubleshoot :-
-Endpoint agent communication failures, performance degradation. -TLS/SSL inspection issues, reverse proxy conflicts.
-Email DLP (Exchange Online, SMTP gateway) issues.
-Web DLP (HTTP/HTTPS uploads, cloud storage) issues.
-DSPM connector failures, data discovery errors, classification mismatches.
- Resolve application compatibility conflicts across Windows/Mac endpoints.
- Coordinate with Forcepoint Support for bugs, patches, and hotfixes.
1. DLP Policy Management & Tuning
- Create, implement, and optimize Forcepoint DLP policies based on security requirements.
- Tune detection methods:
- Exact Data Matching (EDM) for structured data
- File Fingerprinting (structured & unstructured) up to 100M files
- OCR, Dictionaries, Natural Language Processing (NLP) scripts
- Content inspection rules, insider threat workflows
- Reduce false positives while maintaining high detection accuracy
- -Validate policy efficacy regularly and adjust rules based on business feedback
- Manage Endpoint Classification policies:
- MIP label import/application (Azure Information Protection).
- Custom labels, sensitivity tags, third-party classification integration.
1. Incident Response & Remediation
- Lead response to data leakage incidents and security breaches.
- Investigate detection, mitigation, and evidence generation for unauthorized access events.
- Perform single-click remediation: block, encrypt, quarantine, coach users.
- Document incident timelines, actions taken, and lessons learned.
- Prepare incident reports for management and compliance audits.
1. Platform Maintenance & Upgrades
- Perform routine system health checks, patch updates, and version upgrades.
- Execute maintenance windows with minimal service disruption.
- Restore DLP infrastructure from backups when required.
- Manage enforcer configurations, agent deployments,
and policy synchronization.
- Monitor system performance (CPU, memory, disk) and optimize as needed.
1. DSPM Operations & Data Classification
- Administer Forcepoint DSPM for data discovery across:
-Cloud: AWS S3, Azure Blob, Google Cloud Storage, Microsoft 365 (OneDrive, SharePoint) -On-prem: File servers, databases, network shares
- Configure DSPM connectors, API integrations, and authentication
- Review DSPM classification results and validate AI Mesh technology outputs
- Remediate risks to sensitive data: access governance, encryption, policy enforcement
- Integrate DSPM with DLP for unified data protection (classification tags used by both)
1. Integration & Automation
- Integrate Forcepoint DLP/DSPM with enterprise technologies:
-SIEM: Splunk, QRadar (log forwarding, correlation rules) -ITSM: ServiceNow (incident, change, problem management)
-Active Directory/Azure AD (user sync, groups, RBAC)
-APIs for automation workflows and custom reporting
- Develop scripts (PowerShell/Python) for automation:
-Policy deployment validation -Agent health checks
-Incident data extraction
-Report generation
1. Collaboration & Knowledge Sharing
- Work with Threat Intelligence, Network Security, Endpoint Security teams.
- Provide guidance and mentorship to L1 Engineer.
- Conduct knowledge sharing sessions on DLP/DSPM best practices.
- Maintain accurate documentation of configurations, policies, RCA, and incident responses.
1. Compliance & Audit Support
- Align DLP/DSPM policies with regulations: GDPR, CCPA, HIPAA, PCI-DSS, ISO 27001
- Support audit readiness: evidence generation, compliance validation, policy reviews
- Participate in security assessments, gap analysis, and remediation planning
Education B.E./B.Tech in IT/Computer Science or MCA
- Experience with DSPM or cloud data security (AWS/Azure/GCP) preferred
Technical Skills
- Deep knowledge of Forcepoint DLP (Endpoint, Network, Email, Web, Cloud)
- Forcepoint DSPM (data discovery, AI classification, cloud connectors)
- Endpoint Classification: MIP/Azure Information Protection, custom labels
- DLP Detection Methods: EDM, Fingerprinting, OCR, NLP (300+ scripts), Regex, Dictionary
- Active Directory/Azure AD integration, RBAC, user context in incidents
- Troubleshooting: TLS/SSL, reverse proxies, SMTP, UDP/TCP, XML validation
- Scripting: PowerShell, Python, batch scripting for automation
Tools
- Forcepoint Security Manager (FSM) / ONE Data Security portal
- SIEM (Splunk/QRadar) for log analysis and correlation
- ServiceNow/Jira for ITSM workflows
- APIs for automation (REST API)
- VPN, remote access tools, packet capture (Wireshark)
Soft Skills
- Solid analytical and problem-solving skills
- Excellent communication (verbal & written) for client interaction
- SLA-driven, proactive, detail-oriented
- Mentoring ability (guide L1 Engineer)
Certifications (Preferred)
- Forcepoint DLP Certification (highly preferred)
- Security+ / CEH / CISSP / PCNSE
- AWS/Azure Security certifications (for DSPM)
📌 DLP Engineer (Pune)
🏢 Amazure Technologies
📍 Pune