Security Operations Data Loss Prevention Engineer

Everpure

Lehi, Santa Clara (UT, CA)

On-site

USD 205,000 - 308,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible time off
Wellness resources
Company-sponsored team events

Job summary

Everpure is seeking a Security Operations Data Loss Prevention Engineer to own enterprise DLP strategy across endpoints, networks, cloud, and AI environments. You will establish data governance, protect sensitive assets, and lead investigations while partnering with Engineering, Legal, Privacy, DevSecOps, and GISO leadership.

The role emphasizes detecting and preventing data exfiltration, building high-fidelity detections, and driving continuous improvement.

Qualifications

  • Enterprise DLP ownership across architecture, deployment, policy design, tuning, and operations.
  • Hands-on experience with enterprise DLP technologies (Purview, Zscaler, Netskope, etc.).
  • Experience with data discovery, classification, and cloud protection controls.
  • Ability to design, tune, and maintain high-fidelity DLP detections and SIEM/SOAR integration.
  • Knowledge of data protection frameworks (NIST CSF, ISO 27001, SOC 2, GDPR, CCPA, PCI DSS, HIPAA).
  • Strong communication to translate risks into business outcomes and balance controls with user experience.

Responsibilities

  • Architect enterprise DLP strategy end-to-end across endpoints, network, SaaS, apps, cloud, and AI environments.
  • Establish data standards, governance, and a sensitive-data map with data owners.
  • Protect endpoints (macOS, Windows, Linux) and physical channels; define device disposal and media sanitization needs.
  • Protect network, applications, and cloud data; define egress inspection and encrypted-flow visibility.
  • Guard AI workflows and sensitive assets; address prompt content and build-system secrets.
  • Build detections and automate response; develop SIEM queries and SOAR integrations.
  • Lead investigations into data-loss events; brief Legal, Privacy, HR, and leadership; maintain runbooks and diagrams.
  • Work from Santa Clara or Lehi office in compliance with Everpure policies.

Skills

Enterprise DLP ownership
Technical DLP expertise
Detection engineering
Data discovery & cloud protection
Automation & investigation
Security & privacy frameworks
Communication & judgment

Tools

Microsoft Purview
Zscaler
Netskope
Forcepoint
Broadcom/Symantec
Trellix
CrowdStrike Data Protection

Job description

Security Operations Data Loss Prevention Engineer

Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem.

This type of work—work that changes the world is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.

THE ROLE

As our Security Operations Data Loss Prevention (DLP) Engineer, you will own and elevate Everpure’s enterprise data protection strategy across every digital and physical vector.

In this high-impact individual contributor role, you will establish data governance standards and architect practical controls that safeguard customer information, source code, intellectual property, and other sensitive assets without hindering business velocity. You will partner with Engineering, Legal, Privacy, DevSecOps, and GISO leadership to define how sensitive data is discovered, classified, monitored, and protected across the enterprise.

WHAT YOU'LL DO
  • Architect Enterprise DLP Strategy: Own and mature the multi-channel DLP program end to end across endpoint, network, SaaS, application, cloud, and generative AI environments. Define program metrics, track outcomes, evaluate build-versus-buy decisions, and report data-protection posture to GISO leadership.
  • Establish Data Standards & Governance: Author data-classification frameworks, handling requirements, and exception processes. Maintain a sensitive-data map with data owners so the organization understands where regulated and proprietary data lives, how it is classified, and who is accountable for it.
  • Protect Endpoints & Physical Channels: Design and operate controls across macOS, Windows, and Linux, including removable media, printing, clipboard, screen capture, and local cloud-sync channels. Define requirements for hard-copy handling, device disposal, and media sanitization, including the specific needs of manufacturing and lab environments.
  • Protect Network, Application & Cloud Data: Define egress inspection strategies across email, web, and general network traffic, including practical SSL/TLS inspection boundaries and encrypted-flow visibility. Detect and prevent sensitive-data movement through applications, APIs, databases, file shares, CI/CD systems, and unstructured repositories while partnering with Cloud and DevSecOps teams across AWS, Azure, and GCP.
  • Protect AI Workflows & Sensitive Assets: Establish practical guardrails for sensitive data flowing into and out of public AI assistants, embedded copilots, internal models, and agentic tools. Address prompt content, file uploads, context windows, tool integrations, source code, and build-system secrets while enabling safe AI adoption.
  • Build Detections & Automate Response: Design, tune, and maintain high-fidelity DLP detections using regex, exact data match (EDM), indexed document matching (IDM), document fingerprinting, custom classifiers, and contextual conditions. Develop SIEM queries, correlate DLP events with identity, asset, vulnerability, and threat context, and integrate telemetry with SOAR platforms to reduce false positives and manual response effort.
  • Lead Investigations & Continuous Improvement: Direct investigations into significant data-loss events by reconstructing what left the enterprise, through which channel, and with what impact. Serve as the escalation point for complex findings, brief Legal, Privacy, HR, and leadership clearly, support audit and compliance engagements, and maintain runbooks, architectural diagrams, and program documentation.
  • Workplace Location: We are primarily an in-office environment and therefore, you will be expected to work from the Santa Clara or Lehi office in compliance with Everpure’s policies, unless you are on PTO, or work travel, or other approved leave.
WHAT YOU BRING
  • Enterprise DLP Ownership: Demonstrated experience owning or materially contributing to an enterprise DLP or data-protection program across architecture, deployment, policy design, tuning, operations, and continuous improvement.
  • Technical DLP Expertise: Hands-on experience with enterprise DLP technologies such as Microsoft Purview, Zscaler, Netskope, Forcepoint, Broadcom/Symantec, Trellix, CrowdStrike Data Protection, or equivalent platforms.
  • Detection Engineering: Strong experience with regex, EDM/IDM, document fingerprinting, data classification, custom classifiers, and detection tuning, including reducing false positives while maintaining effective coverage.
  • Data Discovery & Cloud Protection: Experience with data discovery, classification, CASB/SaaS security, cloud data protection, and controls for sensitive data across enterprise and cloud environments.
  • Automation & Investigation: Experience using Python, PowerShell, REST APIs, SIEM, and/or SOAR platforms to automate response, analyze telemetry, and improve operational outcomes.
  • Security & Privacy Frameworks: Working knowledge of data-protection and security frameworks such as NIST CSF, ISO 27001, SOC 2, GDPR, CCPA, PCI DSS, and HIPAA.
  • Communication & Judgment: Ability to translate complex data-protection risks into clear decisions and business outcomes for technical teams, cross-functional partners, executives, auditors, and other stakeholders. You know how to balance effective controls with user experience and business needs.
PREFERRED / PLUS SKILLS
  • Experience with AI/GenAI data protection, DSPM, insider risk, privacy engineering, or source-code and secrets protection.
  • Experience securing data in AWS, Azure, or GCP, or integrating data-protection controls into CI/CD, DevSecOps, containers, or Kubernetes.
  • Background in application security, cloud security, or privacy engineering.
  • Experience communicating data-protection strategy and posture to executives, auditors, regulators, or enterprise customers.
  • Relevant security, privacy, or cloud certifications such as CISSP, CISM, CIPP, GIAC, SC-400, or equivalent.

#LI-ONSITE

Salary ranges are determined based on role, level and location. For positions open to candidates in multiple geographical locations, the base salary range is reflective of the labor market across the applicable locations.

This role may be eligible for incentive pay and/or equity.

There is no application deadline and we accept applications on an ongoing basis until the job is filled.

The annual base salary range is:

$205,000 - $308,000 USD

WHAT YOU CAN EXPECT FROM US:

  • Innovation: We celebrate those who think critically, like a challenge, and aspire to be trailblazers.
  • Growth: We give you the space and support to grow along with us and to contribute to something meaningful. We have been named Fortune's Best Workplaces in Technology Fortune's Best Workplaces in the Bay Area, and certified as a Great Place to Work
  • Team: We build each other up and set aside ego for the greater good.

And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events. Check out http://benefits.everpuredata.com/ for more information.

ACCOMMODATIONS AND ACCESSIBILITY:

Candidates with disabilities may request accommodations for all aspects of our hiring process. For more on this, contact us at TA-Ops@purestorage.com if you’re invited to an interview.

OUR COMMITMENT TO A STRONG AND INCLUSIVE TEAM:

We’re forging a future where everyone finds their rightful place and where every voice matters. Where uniqueness isn’t just accepted but embraced. That’s why we are committed to fostering the growth and development of every person, cultivating a sense of community through our Employee Resource Groups and advocating for inclusive leadership.

Everpure is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other characteristic legally protected by the laws of the jurisdiction in which you are being considered for hire.

Join us and bring your best.

Bring your bold.

Pure and simple.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Security Operations - Detection Engineering & Incident Response
Senior Manager, Security Operations - Detection Engineering & Incident Response

Everpure • Santa Clara (CA)

On-site
USD 225,000 - 281,000
Equity
Flexible PTO
Career development
Associate Security Engineer
Associate Security Engineer

Everpure • Santa Clara (CA)

On-site
USD 115,000 - 173,000
Flexible time off
Wellness resources
Team events
Director, Strategy and Business Operations
Director, Strategy and Business Operations

Everpure • Santa Clara (CA)

On-site
USD 247,000 - 317,000
Associate Security Engineer
Associate Security Engineer

Everpure • Lehi (UT)

On-site
USD 82,000 - 123,000
Enterprise Architect
Enterprise Architect

Talentify • Santa Clara (CA)

On-site
USD 154,000 - 231,000
Flexible time off
Wellness resources
Team events
Software Engineer
Software Engineer

Talentify • Santa Clara (CA)

On-site
USD 149,000 - 359,000
Incentive pay
Equity
AI Software Engineer, Security
AI Software Engineer, Security

Pure Storage, Inc. • Santa Clara (CA)

On-site
USD 149,000 - 224,000
AI Software Engineer, Security
AI Software Engineer, Security

Everpure • Santa Clara (CA)

On-site
USD 149,000 - 224,000
Flexible time off
Wellness resources
Team events
+1
Software Engineering Manager
Software Engineering Manager

Everpure • Santa Clara (CA)

On-site
USD 193,000 - 317,000
Senior Full Stack Software Engineer, Digital Experience
Senior Full Stack Software Engineer, Digital Experience

Everpure • Bellevue (WA)

On-site
USD 180,000 - 270,000
Flexible time off
Wellness resources
Company-sponsored team events