Principal, Cyber Sec Eng - DLP / Data Protection

Northern Trust

Chicago (IL)

On-site

USD 137,000 - 234,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401k plan
Pension benefits
Discretionary bonus

Job summary

Northern Trust is seeking a Principal Cyber Security Engineer to lead Data Protection Engineering, including DLP, encryption, and external data transfer controls. The role focuses on establishing technical strategy, governance, and secure cross-team collaboration.

You will drive automation for exception handling, oversee Zscaler policy redesign, and guide the Symantec-to-Purview migration, ensuring a controlled exit from legacy systems while maintaining enterprise risk posture.

Qualifications

  • Extensive experience in Cyber Security, Data Protection Engineering, or a closely related discipline.
  • Experience in a highly regulated enterprise environment.
  • Experience supporting control alignment with FFIEC, PCI-DSS, and SOX expectations is preferred.
  • Experience leading large-scale DLP platform migrations, policy redesigns, or legacy technology exit strategies is preferred.

Responsibilities

  • Own the technical vision and control strategy for DLP and encryption data protection, not just feature implementation.
  • Lead secure enablement and control oversight for DLP engineering and external data transfer controls, including data center bypass capabilities.
  • Drive automation of exception handling and establish repeatable governance workflows.
  • Lead the redesign and optimization of Zscaler data protection and security policies.
  • Provide technical direction for Database Activity Monitoring (DAM) initiatives.
  • Lead the migration from Symantec DLP to Microsoft Purview and define a controlled, supportable Symantec exit strategy.
  • Define durable and repeatable security patterns that can be adopted by engineering, technology, and business teams.
  • Partner with Security, Compliance, Privacy, Microsoft 365, and Risk stakeholders to align controls with enterprise requirements.

Skills

Zscaler DLP
Purview DLP
Data protection
Data classification
Encryption
Azure security
DLP migration
Stakeholder mgmt

Tools

Azure Information Protection
Microsoft Information Protection
Defender for Cloud Apps
Active Directory
Microsoft Entra ID

Job description

About Northern Trust

As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions. Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide. With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.

Role Summary

Principal Cyber Security Engineer responsible for leading the secure enablement, technical direction, control guidance, and execution oversight for Data Protection Engineering. The role has primary accountability for Data Loss Prevention (DLP), encryption-related data protection, and external data transfer controls, including ongoing data center bypass work. This position also provides technical leadership for exception handling automation, Zscaler policy redesign, Database Activity Monitoring (DAM), and the migration from Symantec DLP to Microsoft Purview, including the Symantec exit strategy.

Key Responsibilities
  • Own the technical vision and control strategy for DLP and encryption data protection, not just feature implementation.
  • Lead secure enablement and control oversight for DLP engineering and external data transfer controls, including data center bypass capabilities.
  • Drive automation of exception handling and establish repeatable governance workflows.
  • Lead the redesign and optimization of Zscaler data protection and security policies.
  • Provide technical direction for Database Activity Monitoring (DAM) initiatives.
  • Lead the migration from Symantec DLP to Microsoft Purview and define a controlled, supportable Symantec exit strategy.
  • Define durable and repeatable security patterns that can be adopted by engineering, technology, and business teams.
  • Partner with Security, Compliance, Privacy, Microsoft 365, and Risk stakeholders to align controls with enterprise requirements.
Major Duties
  • Design, implement, and operate enterprise DLP-related controls spanning information protection, labeling, endpoint, cloud, identity, and governance capabilities.
  • Develop and maintain the enterprise information protection and labeling strategy.
  • Engineer and operate DLP and Endpoint DLP controls, including AI-specific data protection scenarios.
  • Implement and enhance Insider Risk Management and Communication Compliance controls.
  • Advance Data Lifecycle Management capabilities, including retention enforcement.
  • Support Data Security Posture Management (DSPM), including exposure detection and oversharing remediation.
  • Configure, deploy, troubleshoot, and operate controls across Active Directory and Microsoft Entra ID environments.
  • Support production changes through disciplined change management, testing, approved deployment windows, and post-change validation.
  • Anticipate data protection and emerging AI risks and translate them into preventive and detective controls.
  • Serve as the escalation point and design authority for complex or ambiguous AI and data protection security decisions.
Required Skills & Expertise
  • Strong hands-on experience with Zscaler and Microsoft Purview DLP.
  • Deep knowledge of Data Loss Prevention, data classification, information protection, encryption, and enterprise data protection principles.
  • Experience with enterprise DLP platforms and Azure security capabilities, including Azure Information Protection (AIP), Microsoft Information Protection (MIP), and Microsoft Defender for Cloud Apps (formerly MCAS).
  • Strong understanding of network security concepts, including proxies, firewalls, traffic analysis, and external data transfer paths.
  • Experience designing, deploying, troubleshooting, and operating security controls in complex enterprise environments.
  • Strong troubleshooting, analytical, written communication, and stakeholder management skills.
  • Ability to operate independently, lead through influence, and make sound technical decisions in complex or ambiguous situations.
  • Experience working in a highly regulated enterprise environment.
  • Experience supporting control alignment with FFIEC, PCI-DSS, and SOX expectations is preferred.
  • Experience leading large-scale DLP platform migrations, policy redesigns, or legacy technology exit strategies is preferred.
Experience & Qualifications
  • Extensive experience in Cyber Security, Data Protection Engineering, or a closely related discipline.
  • Experience working in a highly regulated enterprise environment.
  • Experience supporting control alignment with FFIEC, PCI-DSS, and SOX expectations is preferred.
  • Experience leading large-scale DLP platform migrations, policy redesigns, or legacy technology exit strategies is preferred.
Leadership Scope (P4 Expectations)
  • Operate as a senior individual contributor with wide autonomy and minimal oversight.
  • Own technical strategy and influence architecture, controls, and execution priorities.
  • Provide direct influence across Security, Compliance, Privacy, Microsoft 365, and Risk.
  • Create scalable, reusable engineering patterns and operational guardrails.
  • Anticipate risk before incidents occur and translate emerging threats into preventive controls.
  • Act as the escalation point and design authority for critical or ambiguous decisions.
Nice to Have
  • Experience with AI-specific DLP use cases, DSPM, Insider Risk Management, Communication Compliance, and retention enforcement.
  • Experience with Database Activity Monitoring and data-centric security controls.
  • Experience integrating DLP, DAM, cloud security, and monitoring platforms across hybrid enterprise environments.
  • Knowledge of governance, privacy, compliance, and risk management frameworks.
Summary

This role is key to advancing enterprise data protection by establishing the technical direction for DLP and related controls, modernizing the DLP technology landscape, improving the consistency of engineering patterns, and enabling timely, risk-informed decisions across complex security initiatives.

Salary Range

Salary Range: $137,400 - 233,600 USD Salary range is a good faith estimate of base pay.

Benefits
  • retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits.
  • Northern Trust also provides a discretionary bonus program that may include an equity component.
Work Authorization

Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).

Reasonable Accommodation

Northern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com, or alternatively you can discuss your individual requirements with the recruiter you are working with.

Terms and Conditions

Candidate Privacy Notice California Applicant Privacy Notice Pay Transparency Nondiscrimination Provision (U.S) Transparency in Coverage Disclosure – North America Northern Trust is committed to working with and providing reasonable accommodations to individuals with disabilities. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the employment process, please email our HR Service Center or call 1-800-807-0302 (North America), +630-276-5353 (Asia Pacific), 1800-425-0333 (India), +44(0)207 982 4357 (Europe, Middle East and Africa) and let us know the nature of your request and your contact information.

APAC/INDIA EEO STATEMENT

It is the policy and practice of Northern Trust to provide equal employment opportunities to all employees and applicants. Northern Trust does not discriminate on the basis of race, colour, religion or belief, nationality, ethnic or national origin, sex, marital status, sexual orientation, disability or age. All employment decisions will be made in a non-discriminatory manner in accordance with our obligations under the law and codes of practice. This includes human resources’ decisions relating to recruitment, terms and conditions of employment, transfers, promotions and access to learning and development.

Canada EEO STATEMENT

Northern Trust is an Equal Opportunity Employer. Hiring and other employment decisions at Northern Trust are made without regard to race, colour, religion, sex, ancestry, national origin, ethnic origin, age, disability, citizenship, veteran status, sexual orientation, record of offences, marital status, family status, or any other characteristic protected by federal, provincial, or local law, regulation, or ordinance.

EMEA EEO STATEMENT

It is the policy and practice of Northern Trust to provide equal employment opportunities to all employees and applicants. Northern Trust does not discriminate on the basis of race, colour, religion or belief, nationality, ethnic or national origin, sex, marital status, sexual orientation, disability or age. All employment decisions will be made in a non-discriminatory manner in accordance with our obligations under the law and codes of practice. This includes human resources’ decisions relating to recruitment, terms and conditions of employment, transfers, promotions and access to learning and development.

USA EEO STATEMENT

It is the policy of The Northern Trust Company to afford equal opportunity in all phases of employment without regard to an individual's age, race, color, religion, creed, gender, national origin, citizenship status, marital status, pregnancy, sexual orientation, gender identity, gender expression, genetic tests and information, physical or mental disability, protected veteran status or any other legally protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal, Cyber Sec Eng - DLP / Data Protection
Principal, Cyber Sec Eng - DLP / Data Protection

Quest Oracle Community • Chicago (IL), Northern (KY)

Hybrid
USD 137,000 - 234,000
401k and pension
Medical/dental/vision benefits
Paid time off
+4
Principal, Cyber Sec Eng - DLP / Data Protection
Principal, Cyber Sec Eng - DLP / Data Protection

Northern Trust Corp. • Chicago (IL)

On-site
USD 140,000 - 234,000
401(k) plan
Pension
Medical, dental, vision
+1
Senior Lead, Security Engineering and Operations
Senior Lead, Security Engineering and Operations

Northern Trust • Chicago (IL)

On-site
USD 115,000 - 195,000
Senior Lead, Technology Risk and Control
Senior Lead, Technology Risk and Control

Northern Trust • Chicago (IL)

On-site
USD 96,000 - 162,000
Discretionary bonus
Equity component
Lead, Arch Solutions
Lead, Arch Solutions

Northern Trust Corp • Chicago (IL), Northern (KY)

On-site
USD 115,000 - 195,000
retirement benefits (401k and pension)
health and welfare benefits (medical,
paid time off
+3
Lead - Technology Risk and Control Self Assessment
Lead - Technology Risk and Control Self Assessment

Northern Trust • Chicago (IL)

On-site
USD 83,000 - 141,000
Discretionary bonus
Health benefits
Retirement plan
+3
Principal, Solution Architect
Principal, Solution Architect

Northern Trust Corp • Chicago (IL), Northern (KY)

Hybrid
USD 137,000 - 234,000
401k and pension
Medical, dental, vision
Paid time off
+3
Associate Specialist - Finance Data Analytics
Associate Specialist - Finance Data Analytics

Northern Trust • Chicago (IL)

On-site
USD 96,000 - 162,000
Hybrid work model
Comprehensive benefits
Sr Principal Software Engineer, AI Security Platform
Sr Principal Software Engineer, AI Security Platform

Northern Trust • Chicago (IL)

On-site
USD 165,000 - 288,000
401k plan
Pension
Health benefits
+9
Specialist, Data Analytics
Specialist, Data Analytics

Northern Trust Corp • Chicago (IL), Northern (KY)

On-site
USD 137,000 - 240,000
Discretionary bonus program
401k and pension
Health and welfare benefits