Operate and engineer client Data Loss Prevention controls under the direction of the DLP Specialist. The role performs platform administration, incident triage, policy implementation, testing, health monitoring, troubleshooting and evidence management across Forcepoint DLP, Microsoft Purview and connected data protection technologies.
Primary Responsibilities : -
- Monitor DLP alert queues and triage incidents across endpoint, email, network, Microsoft 365 and cloud/SaaS channels.
- Validate incident context, policy match, data sensitivity, user activity and business justification; escape high-risk cases promptly.
- Implement approved DLP policy changes, classifiers, thresholds, actions, exceptions and user notifications under change control.
- Execute test cases for monitor, coach, justify, quarantine and block actions before production deployment.
- Administer Forcepoint DLP components, endpoint agents, discovery tasks, connectors, policy deployments and system health checks.
- Support Microsoft Purview DLP, Endpoint DLP, sensitivity label integration and Activity/Content Explorer investigations.
- Investigate agent/connector failures, policy deployment issues, false positives, workflow errors and performance problems.
- Maintain allowlists, dictionaries, keyword lists, fingerprints, EDM datasets and detection patterns as approved.
- Create and update incidents, service requests, changes and problem records in the ITSM platform; meet agreed SLAs.
- Capture complete evidence, actions, approvals, communications, timestamps and closure rationale for audit readiness.
- Prepare operational reports covering alert volumes, policy hits, false positives, open cases, endpoint coverage and service health.
- Support DLP policy tuning, business-unit pilots, user communication and remediation validation.
- Follow least privilege, dual-control, data minimization and confidentiality requirements when handling sensitive data.
Skills / Certifications: -
- Forcepoint DLP Administrator training
- SC-400 or equivalent Microsoft Purview training
- CompTIA Security+ or equivalent
- ITIL Foundation (advantage)
- Soft skills: Excellent written and verbal communication, Analytical thinking and problem solving.
- Attention to detail and quality, Accountability and ownership,
- Teamwork and stakeholder collaboration.
- Ability to prioritize and meet deadlines.
- Ability to work at client sites and provide after-hours support when required
Minimum Work Experience & Education: -
- 7+ years of information security or security operations experience, including at least 2 years of hands-on DLP administration or incident operations.
- Bachelor’s degree in computer science, Cybersecurity, Information Technology, Information Systems, Engineering or equivalent.
- Postgraduate qualification in information/cyber security is an advantage.