DLP/Data Security Engineer

ADT

Boca Raton (FL)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

ADT is seeking a DLP / Data Security Engineer to engineer, administer, and continuously improve enterprise controls protecting sensitive information across Microsoft 365, Google, email, endpoints, browsers, networks, and SaaS apps. You will translate business and regulatory requirements into practical policies, detections, and response workflows while balancing strong protection with usability.

The ideal candidate combines hands-on platform administration with policy-tuning, automation, and

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.

Responsibilities

  • Administer and maintain Microsoft Purview DLP policies across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and other supported locations.

Skills

Data classification
Sensitive information detection
Policy logic
Data labeling
Data encryption
Access control
Data lifecycle protections
IAM
Conditional access
Managed devices
Browser management
TLS inspection
APIs
Cloud logging
PowerShell
Python
REST APIs
KQL/XQL
BigQuery

Education

Bachelor's degree in Cybersecurity/CS/IT
Hands-on enterprise DLP/security controls
Certifications in security (preferred)

Tools

PowerShell
Python
REST APIs
KQL/XQL
BigQuery
SIEM/SOAR

Job description

Summary:

The DLP / Data Security Engineer is responsible for engineering, administering, and continuously improving enterprise controls that protect sensitive information across Microsoft 365, Google, email, endpoints, browsers, networks, and SaaS applications. This role serves as a technical owner for data loss prevention and related data security capabilities, translating business, privacy, legal, and regulatory requirements into practical policies, detections, enforcement actions, monitoring, exception processes, and response workflows.

The ideal candidate combines hands-on platform administration with strong troubleshooting, policy-tuning, automation, and communication skills. Success requires balancing strong protection with business usability, reducing false positives, measuring control effectiveness, and partnering across Security Engineering, Security Operations, IT, Legal, Privacy, Compliance, and application teams.

Duties and Responsibilities:

Microsoft Purview DLP and Information Protection

  • Administer and maintain Microsoft Purview Data Loss Prevention policies across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and other supported locations.

  • Configure and tune sensitive information types, classifiers, sensitivity labels, policy rules, user notifications, overrides, alerting, incident workflows, and scoped exceptions.

  • Design policies that reduce unauthorized external sharing while preserving approved business workflows and maintaining clear, auditable exception paths.

  • Investigate DLP alerts and user-reported issues, identify false positives and control gaps, and implement measured tuning based on risk and evidence.

  • Maintain policy naming standards, administrative access, change records, testing procedures, operational documentation, metrics, and effectiveness reviews.

Google and Generative AI Data Security

  • Administer Google Sensitive Data Protection and related Gemini Enterprise data security controls, including prompt, response, file, and connector protection where supported.

  • Configure and tune protection for sensitive data, prompt injection, jailbreak attempts, and other approved AI security use cases.

  • Validate DLP behavior through repeatable testing, troubleshoot inconsistent or overly broad detections, and document known limitations and user guidance.

  • Coordinate logging and telemetry integration for Gemini and data protection events with BigQuery, SIEM, case management, and incident response workflows.

  • Support governance of sanctioned and unsanctioned generative AI use, including discovery, policy enforcement, user warnings, blocking, and risk-based exceptions.

Network, SaaS, and CASB Data Protection

  • Administer and expand network-level DLP, inline data inspection, and SaaS DLP or CASB controls across web traffic, cloud applications, APIs, collaboration platforms, and file-sharing services.

  • Configure and tune data-in-motion and data-at-rest policies for sanctioned SaaS applications, external collaboration, cloud storage, uploads, downloads, copy-and-paste activity, and other exfiltration paths.

  • Partner with Network Security and Cloud Security teams to align DLP enforcement with TLS inspection, secure web gateway, SASE, firewall, identity, and application control architectures.

  • Evaluate overlapping capabilities across Purview, Google, Palo Alto, Slack, and other data security platforms to improve coverage and avoid conflicting or duplicate controls.

  • Contribute to proof-of-value testing, product evaluations, architecture decisions, rollout plans, and operational readiness for new data security capabilities.

Email Security

  • Administer email security controls that protect users and data from phishing, malicious content, impersonation, business email compromise, data leakage, and unauthorized forwarding or sharing.

  • Tune policies, detections, allow lists, block lists, quarantine actions, user-reporting workflows, and exceptions while minimizing unnecessary disruption.

  • Investigate email security incidents and collaborate with Security Operations on containment, remediation, threat hunting, and control improvements.

  • Produce metrics and reporting on email threats, policy actions, coverage, false positives, user reporting, and outstanding risk.

Chrome Enterprise Browser Security

  • Administer Chrome Enterprise browser security and data protection configuration, including managed policies, organizational unit scoping, trusted integrations, and controlled testing.

  • Configure and evaluate browser-based controls for generative AI activity, file uploads and downloads, copy-and-paste restrictions, warnings, blocking, watermarking, and evidence capture where supported.

  • Coordinate browser policy rollout with endpoint, identity, workstation engineering, and business stakeholders, using staged pilots and documented rollback plans.

  • Monitor browser telemetry and policy effectiveness and integrate relevant security events into enterprise monitoring and response processes.

Operations, Governance, and Response

  • Develop and maintain DLP response playbooks, operational runbooks, support procedures, architecture diagrams, policy inventories, exception documentation, and end-user guidance.

  • Create dashboards and reports for technical teams and leadership, including policy actions, prevented events, alert trends, false-positive rates, coverage gaps, and remediation progress.

  • Partner with Legal, Privacy, Compliance, Human Resources, Internal Audit, and business owners on investigations, evidence requests, policy decisions, and regulatory or contractual requirements.

  • Participate in incident response involving suspected data exposure, insider risk, unauthorized sharing, credential leakage, or control bypass attempts.

  • Automate repeatable administrative, reporting, triage, and policy-validation activities using APIs, scripting, SIEM/SOAR workflows, and cloud-native tooling.

  • Stay current on data security, DLP, AI security, browser security, SaaS security, and email security threats and capabilities, and recommend pragmatic improvements.

Education and Experience:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent practical experience.

  • Hands-on experience administering enterprise DLP, information protection, email security, CASB, SaaS security, endpoint, browser, or network security controls.

  • Experience with Microsoft Purview DLP and Microsoft 365 workloads strongly preferred.

  • Experience with Google Cloud Sensitive Data Protection, Gemini Enterprise security controls, Chrome Enterprise, or comparable technologies preferred.

  • Experience with email security platforms, secure web gateways, SASE, firewalls, SaaS security platforms, and SIEM/SOAR integration preferred.

  • Experience supporting regulated or sensitive data environments and working with privacy, compliance, legal, or audit stakeholders.

  • Relevant certifications such as CISSP, CCSP, Microsoft Security, Compliance, and Identity credentials, Google Cloud security credentials, or GIAC certifications are preferred.

Skills and Knowledge:
  • Strong understanding of data classification, sensitive information detection, context-based policy logic, exact data match concepts, labeling, encryption, access control, and data lifecycle protections.

  • Ability to design layered controls across Microsoft 365, Google, email, endpoints, browsers, networks, and SaaS applications.

  • Practical experience tuning detections to balance coverage, confidence, false positives, business impact, and enforceability.

  • Working knowledge of identity and access management, conditional access, managed devices, browser management, TLS inspection, APIs, and cloud logging.

  • Ability to analyze alerts and logs, identify root cause, document evidence, and translate technical findings into clear recommendations.

  • Experience with PowerShell, Python, REST APIs, KQL/XQL, BigQuery, regular expressions, or similar query and automation technologies is a plus.

  • Strong documentation, stakeholder communication, and project coordination skills.

  • Ability to work independently, manage competing priorities, and collaborate effectively in a fast-paced security engineering environment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DLP Engineer
DLP Engineer

First-Horizon-Bank • Memphis (TN)

On-site
USD 90,000 - 120,000
Senior Data Security Engineer
Senior Data Security Engineer

I.T. Solutions, Inc. • United States

On-site
USD 160,000 - 220,000
Data Security Specialist
Data Security Specialist

DBI Staffing • New York (NY)

On-site
USD 130,000 - 180,000
Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
DLP/Data Security Engineer (Job ID 3022226)
DLP/Data Security Engineer (Job ID 3022226)

ADT Security Services • Boca Raton (FL), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000
DLP SME
DLP SME

Peyton Resource Group • Washington

On-site
USD 140,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Unisys • Rockville (MD)

On-site
USD 120,000 - 170,000
Senior Information Protection & AI Governance Engineer
Senior Information Protection & AI Governance Engineer

Think Consulting • Atlanta (GA)

On-site
USD 140,000 - 190,000
Data Security Engineer
Data Security Engineer

Unisys • United States

On-site
USD 130,000 - 180,000