Principal, Cyber Sec Eng - DLP / Data Protection

Northern Trust Corp.

Chicago (IL)

On-site

USD 140,000 - 234,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401(k) plan
Pension
Medical, dental, vision
Discretionary bonus with equity

Job summary

Northern Trust Corp. in Chicago is seeking a Principal Cyber Security Engineer to lead Data Protection Engineering, focusing on DLP, encryption, and external data transfer controls, including a Symantec exit strategy.

You will own the technical vision for DLP, drive policy redesign with Zscaler, and provide direction for DAM initiatives while collaborating with Security, Compliance, Privacy, and Risk teams to align controls with enterprise requirements.

Qualifications

  • Strong hands-on experience with Zscaler and Microsoft Purview DLP.
  • Deep knowledge of Data Loss Prevention, data classification, information protection, encryption, and enterprise data protection principles.
  • Experience with enterprise DLP platforms and Azure security capabilities, including Azure Information Protection (AIP), Microsoft Information Protection (MIP), and Microsoft Defender for Cloud Apps.

Responsibilities

  • Design, implement, and operate enterprise DLP-related controls spanning information protection, labeling, endpoint, cloud, identity, and governance capabilities.
  • Develop and maintain the enterprise information protection and labeling strategy.
  • Engineer and operate DLP and Endpoint DLP controls, including AI-specific data protection scenarios.
  • Implement and enhance Insider Risk Management and Communication Compliance controls.
  • Advance Data Lifecycle Management capabilities, including retention enforcement.
  • Support Data Security Posture Management (DSPM), including exposure detection and oversharing remediation.

Skills

Zscaler DLP
Microsoft Purview DLP
Data Loss Prevention
Azure security
Information protection
DLP platforms
Network security

Tools

Microsoft Purview
Azure Information Protection
MCAS (Defender for Cloud Apps)

Job description

About Northern TrustAs a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions.Since 1889, we have aligned our efforts with our three guiding Principles That Endure: Service, Expertise, and Integrity. Together, they reflect the three cornerstones of business conduct which we strive to instill in our employees, whom we call partners, and to provide to our clients and the communities we serve worldwide.With more than 135 years of financial experience and over 24,000 partners, we serve the world’s most sophisticated clients using leading technology and exceptional service.Role SummaryPrincipal Cyber Security Engineer responsible for leading the secure enablement, technical direction, control guidance, and execution oversight for Data Protection Engineering. The role has primary accountability for Data Loss Prevention (DLP), encryption-related data protection, and external data transfer controls, including ongoing data center bypass work. This position also provides technical leadership for exception handling automation, Zscaler policy redesign, Database Activity Monitoring (DAM), and the migration from Symantec DLP to Microsoft Purview, including the Symantec exit strategy.Key ResponsibilitiesOwn the technical vision and control strategy for DLP and encryption data protection, not just feature implementation.Lead secure enablement and control oversight for DLP engineering and external data transfer controls, including data center bypass capabilities.Drive automation of exception handling and establish repeatable governance workflows.Lead the redesign and optimization of Zscaler data protection and security policies.Provide technical direction for Database Activity Monitoring (DAM) initiatives.Lead the migration from Symantec DLP to Microsoft Purview and define a controlled, supportable Symantec exit strategy.Define durable and repeatable security patterns that can be adopted by engineering, technology, and business teams.Partner with Security, Compliance, Privacy, Microsoft 365, and Risk stakeholders to align controls with enterprise requirements.Major DutiesDesign, implement, and operate enterprise DLP-related controls spanning information protection, labeling, endpoint, cloud, identity, and governance capabilities.Develop and maintain the enterprise information protection and labeling strategy.Engineer and operate DLP and Endpoint DLP controls, including AI-specific data protection scenarios.Implement and enhance Insider Risk Management and Communication Compliance controls.Advance Data Lifecycle Management capabilities, including retention enforcement.Support Data Security Posture Management (DSPM), including exposure detection and oversharing remediation.Configure, deploy, troubleshoot, and operate controls across Active Directory and Microsoft Entra ID environments.Support production changes through disciplined change management, testing, approved deployment windows, and post-change validation.Anticipate data protection and emerging AI risks and translate them into preventive and detective controls.Serve as the escalation point and design authority for complex or ambiguous AI and data protection security decisions.Required Skills & ExpertiseStrong hands-on experience with Zscaler and Microsoft Purview DLP.Deep knowledge of Data Loss Prevention, data classification, information protection, encryption, and enterprise data protection principles.Experience with enterprise DLP platforms and Azure security capabilities, including Azure Information Protection (AIP), Microsoft Information Protection (MIP), and Microsoft Defender for Cloud Apps (formerly MCAS).Strong understanding of network security concepts, including proxies, firewalls, traffic analysis, and external data transfer paths.Experience designing, deploying, troubleshooting, and operating security controls in complex enterprise environments.Strong troubleshooting, analytical, written communication, and stakeholder management skills.Ability to operate independently, lead through influence, and make sound technical decisions in complex or ambiguous situations.Experience & QualificationsExtensive experience in Cyber Security, Data Protection Engineering, or a closely related discipline.Experience working in a highly regulated enterprise environment.Experience supporting control alignment with FFIEC, PCI-DSS, and SOX expectations is preferred.Experience leading large-scale DLP platform migrations, policy redesigns, or legacy technology exit strategies is preferred.Leadership Scope (P4 Expectations)Operate as a senior individual contributor with wide autonomy and minimal oversight.Own technical strategy and influence architecture, controls, and execution priorities.Provide direct influence across Security, Compliance, Privacy, Microsoft 365, and Risk.Create scalable, reusable engineering patterns and operational guardrails.Anticipate risk before incidents occur and translate emerging threats into preventive controls.Act as the escalation point and design authority for critical or ambiguous decisions.Nice to HaveExperience with AI-specific DLP use cases, DSPM, Insider Risk Management, Communication Compliance, and retention enforcement.Experience with Database Activity Monitoring and data-centric security controls.Experience integrating DLP, DAM, cloud security, and monitoring platforms across hybrid enterprise environments.Knowledge of governance, privacy, compliance, and risk management frameworks.SummaryThis role is key to advancing enterprise data protection by establishing the technical direction for DLP and related controls, modernizing the DLP technology landscape, improving the consistency of engineering patterns, and enabling timely, risk-informed decisions across complex security initiatives.Salary Range:$137,400 - 233,600 USDSalary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.Work AuthorizationApplicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).Working with UsAs a Northern Trust partner, you will be part of a flexible and collaborative work culture, which has a strong history of financial strength and stability. Movement within the organization is encouraged, senior leaders are accessible, and you can take pride in working for a company committed to an inclusive workplace and assisting the communities we serve.Philanthropy is deeply rooted in Northern Trust’s history and is an essential element of our culture. Employees around the world give their time and talent to work for the greater good of their communities.Reasonable AccommodationNorthern Trust is committed to working with and providing adjustments to individuals with health conditions and disabilities. If you need a reasonable accommodation for any part of the employment process, please email our HR Service Center at MyHRHelp@ntrs.com, or alternatively you can discuss your individual requirements with the recruiter you are working with.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal, Cyber Sec Eng - DLP / Data Protection
Principal, Cyber Sec Eng - DLP / Data Protection

Quest Oracle Community • Chicago (IL), Northern (KY)

Hybrid
USD 137,000 - 234,000
401k and pension
Medical/dental/vision benefits
Paid time off
+4
Sr Lead, Cyber Sec Eng
Sr Lead, Cyber Sec Eng

Northern Trust Corp. • Chicago (IL)

On-site
USD 140,000 - 190,000
401(k) and pension benefits
Medical, dental, vision coverage
Paid time off
+1
Lead, Cyber Sec Eng
Lead, Cyber Sec Eng

Northern Trust Corp • Chicago (IL), Northern (KY)

On-site
USD 130,000 - 190,000
Principal, Cyber Sec Eng - DLP / Data Protection
Principal, Cyber Sec Eng - DLP / Data Protection

Northern Trust • Chicago (IL)

On-site
USD 137,000 - 234,000
401k plan
Pension benefits
Discretionary bonus
Lead, Cyber Sec Eng
Lead, Cyber Sec Eng

Northern Trust • Chicago (IL)

On-site
USD 120,000 - 180,000
Lead Cyber Sec Eng – Business Analyst
Lead Cyber Sec Eng – Business Analyst

Northern Trust Corp • Chicago (IL)

On-site
USD 100,000 - 169,000
401k and pension
Health and welfare benefits
Paid time off
+1
Sr Lead, Cyber Sec Eng
Sr Lead, Cyber Sec Eng

Northern Trust Corp • Chicago (IL)

On-site
USD 150,000 - 210,000
Senior Lead, Security Engineering and Operations
Senior Lead, Security Engineering and Operations

Northern Trust Corp. • Chicago (IL)

On-site
USD 115,000 - 195,000
Comprehensive benefits package
Retirement benefits (401k)
Paid time off
+2
Principal, Technology and Cyber Risk Management
Principal, Technology and Cyber Risk Management

Northern Trust Corp. • Tempe (AZ)

On-site
USD 109,000 - 185,000
Discretionary bonus program
401(k) and pension options
Principal Security Engineer – AI & Copilot Data Protection
Principal Security Engineer – AI & Copilot Data Protection

Northern Trust Corp • Chicago (IL)

On-site
USD 150,000 - 210,000
Comprehensive benefits package
401k and pension
Discretionary bonus program