Description
Key Responsibilities
- Design, implement and continuously tune DLP detection capabilities and policies across Microsoft Purview, Zscaler, Proofpoint to maximize true positives and minimize operational friction
- Develop custom detection logic and integrations for internally developed systems
- Perform regular testing and validation of existing DLP controls to identify coverage gaps and bypass techniques
- Engineer automation workflows to assist DLP analysts, reducing manual review time and automating the triage of low-fidelity events
- Act as highest-level technical escalation point for complex data leakage incidents and associated investigations
- Collaborate directly with data owners, legal and compliance teams to translate business and regulatory requirements into technical enforcement rules
- Evaluate and integrate additional DLP tools, and participate in proof-of-concept trials.
Required Technical Skills
- DLP & Security Operations: Proven experience handling data loss incidents, insider threat investigations, or general security incident response.
You need to know what a valuable alert looks like to build one
- Core Stack Expertise: Deep, hands-on administrative experience with tools like Microsoft Purview, Zscaler, ServiceNow and Proofpoint
- Automation & Scripting: Strong proficiency in tools like Python or PowerShell. You must be able to interact with REST APIs to pull logs, enrich alerts, and trigger automated response actions
- Detection Engineering: Proficiency with regular expressions, exact data matching, indexed document matching and custom dictionary creation
- System Architecture: Solid understanding of enterprise network routing, proxies, cloud access, and mail transport rules
What Sets You Apart
- Experience integrating DLP tooling with SOAR platforms (e.g., Splunk SOAR, Cortex XSOAR, Tines) to build end-to-end automated review pipelines
- Background in software engineering or DevSecOps, with an understanding of CI/CD pipelines and versi