Senior Security Engineer, Data Loss Prevention

600 Mobility Tech Solutions LLC

United States

Hybrid

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fragomen is seeking a Cyber Security Engineer specializing in Data Loss Prevention to design and operate DLP controls across Microsoft 365, endpoints, SaaS, and cloud platforms. You will classify sensitive data, tune policies, monitor alerts, and collaborate with Legal, Privacy, Risk, and IT teams to align controls with regulatory requirements.

You will help strengthen Fragomen's security posture by implementing standardized procedures, promoting data protection best practices, and mentoring

Qualifications

  • 5+ years in cybersecurity, data protection, security operations, governance, risk, or related tech roles.
  • Familiarity with DLP concepts, sensitive data handling, and policy-based enforcement.
  • Hands-on experience implementing security controls in enterprise environments (Microsoft 365, email, endpoint, cloud or SaaS).
  • Ability to analyze DLP alerts, user activity, sharing patterns, and logs to gauge business impact.
  • Strong communication to explain findings and collaborate with cross-functional teams.

Responsibilities

  • Design, implement, and tune enterprise DLP policies across Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms.
  • Classify and protect sensitive information using data classification, sensitivity labels, and policy actions.
  • Monitor and investigate DLP alerts for data exposure, improper sharing, or policy violations.
  • Collaborate with Legal, Compliance, Privacy, Risk, Records, and stakeholders to align controls with requirements.
  • Develop and maintain DLP standards, runbooks, and escalation workflows.
  • Evaluate controls for collaboration platforms and file-sharing tools (OneDrive, SharePoint, Box, Google Drive, Dropbox, ShareFile, NetDocuments, etc.).
  • Support CASB and SaaS governance to identify unsanctioned data movement and risky sharing.
  • Perform root cause analysis to reduce false positives and improve policy quality.
  • Integrate DLP telemetry into SIEM/SOAR and incident response with security operations teams.
  • Provide clear communications to end users and leadership on findings and corrective actions.
  • Mentor junior analysts on DLP investigations and data handling risk.

Skills

DLP
Data governance
Security engineering
Microsoft 365
SaaS security
Cloud security
Communication
Policy enforcement

Tools

Microsoft Purview DLP
Microsoft Defender for Cloud Apps
Splunk
Microsoft Sentinel
QRadar
ArcSight

Job description

Job Description About the Role Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Data Loss Prevention (DLP), sensitive data governance, SaaS and cloud data protection, and security control engineering to join our Information Security & Cyber Security team. Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and protecting sensitive client, employee, and firm data is critical to its success. We are seeking a professional who is passionate about reducing data exposure risk, engineering practical DLP controls, and partnering across Legal, Compliance, Privacy, Risk, IT, and business teams to mature enterprise data protection capabilities. You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in designing, implementing, tuning, and operating DLP controls across email, endpoint, cloud, SaaS, and collaboration platforms while helping strengthen Fragomen's overall security posture.

How Will You Make a Difference at Fragomen?

As a Security Engineer focused on Data Loss Prevention, you will:

  • Design, implement, and tune enterprise DLP policies across Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms.
  • Identify, classify, and protect sensitive information using data classification, sensitivity labels, policy conditions, and appropriate enforcement actions.
  • Monitor and investigate DLP alerts involving potential data exposure, improper sharing, data exfiltration indicators, or policy violations.
  • Partner with Legal, Compliance, Privacy, Risk, Records, and business stakeholders to align DLP controls with regulatory, legal, client, and operational requirements.
  • Develop and maintain DLP standards, operating procedures, runbooks, exception processes, and escalation workflows.
  • Evaluate and improve controls for collaboration platforms and file-sharing tools, including OneDrive, SharePoint, Box, Google Drive, Dropbox, ShareFile, NetDocuments, and similar services.
  • Support CASB and SaaS governance efforts by helping identify unsanctioned data movement, risky sharing behavior, excessive permissions, and opportunities for policy enforcement.
  • Conduct root cause analysis on recurring alerts, control gaps, and data handling issues to improve policy quality and reduce false positives.
  • Collaborate with security operations, identity, messaging, endpoint, network, and application teams to integrate DLP telemetry into SIEM, SOAR, monitoring, and response processes.
  • Prepare clear, business‑appropriate communications for end users, technical teams, stakeholders, and leadership regarding DLP findings, policy changes, and recommended corrective actions.
  • Provide technical guidance and mentorship to junior analysts and security team members on DLP investigations, data handling risk, and control operations.
Leverage Your Skills and Experience

Required Qualifications

  • 5+ years of experience in cybersecurity, data protection, security operations, governance, risk, compliance, or related technology roles, or equivalent combination of education and experience.
  • Working knowledge of DLP concepts, sensitive data handling, information protection, data classification, and policy-based enforcement.
  • Hands‑on experience supporting or operating security controls in enterprise environments, especially within Microsoft 365, email, endpoint, cloud, or SaaS platforms.
  • Ability to analyze DLP alerts, user activity, sharing patterns, policy matches, and event logs to determine business impact and appropriate response.
  • Working knowledge of identity and access concepts, authentication mechanisms, file permissions, collaboration tooling, and data sharing workflows.
  • Strong written and verbal communication skills, including the ability to explain technical findings in clear, practical, and business‑appropriate language.
  • Demonstrated ability to follow structured processes while continuously improving them.

Technical Knowledge

  • Microsoft Purview Information Protection and DLP, including sensitivity labels, trainable classifiers, data loss prevention rules, audit logs, alerts, and policy tuning.
  • Microsoft Defender for Cloud Apps, cloud app governance, CASB concepts, SaaS discovery, session controls, and cloud data exposure monitoring.
  • Endpoint, email, and collaboration security controls across Windows, Microsoft 365, Exchange Online, Teams, SharePoint, and OneDrive.
  • SIEM and security platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar tools used to correlate DLP and security telemetry.
  • Common sensitive data types and regulatory drivers, such as PII, PCI, PHI, financial data, client confidential information, legal matter data, and regulated business records.
  • Core networking and platform concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, firewalls, APIs, and cloud storage patterns.

Preferred Qualifications

  • Experience engineering or administering Microsoft Purview DLP, Endpoint DLP, Information Protection, Insider Risk Management, eDiscovery, Audit, or Data Lifecycle Management.
  • Experience with CASB, SaaS security, cloud access governance, or file‑sharing risk management across platforms such as Box, Google Drive, Dropbox, ShareFile, NetDocuments, Salesforce, ServiceNow, or similar applications.
  • Experience supporting investigations involving Legal, Compliance, Privacy, Risk, Records, HR, or regulatory stakeholders.
  • Experience with SOAR, ticketing, workflow automation, and process documentation for recurring security operations activities.
  • Knowledge of secure collaboration practices, permission review, data retention, acceptable use, and exception governance.
  • Relevant certifications, including Microsoft Security, Compliance, and Identity certifications; CISSP, SSCP, Security+, CISA, CISM; GIAC security certifications; or vendor certifications for DLP, CASB, SIEM, or endpoint platforms.

All offers and/or employment contracts are contingent upon the successful completion of the Firm's pre‑employment screening process. This process may include verifying the candidate's identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI‑assisted tools for administrative screening purposes only - never for decision‑making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.

About Fragomen

Fragomen is the leading global immigration law firm with more than 6,000 professionals in nearly 70 offices across the Americas, EMEA and Asia Pacific, delivering services in over 170 countries. Ranked on both the Am Law 100 and Am Law Global 100, the firm is widely recognized for its leadership in immigration law and commitment to fostering a culture where diverse attorneys thrive and all individuals have equal opportunities to succeed. Fragomen helps corporations and individuals navigate the complexities of global mobility and provides end‑to‑end support across the immigration lifecycle, from strategic planning and policy design to compliance, government investigations, litigation and more. The firm combines legal acumen and advanced digital capabilities to simplify global mobility and deliver smarter, faster and more adaptive solutions via a suite of technology brands—including Nomadic, its business travel platform that enables real‑time compliance, WorkRight, its multi‑jurisdictional employment verification software and Simple Citizen, a digital solution designed to streamline the pathway to US citizenship. With a global presence, multidisciplinary approach and investment in technology, Fragomen is uniquely positioned to address today’s immigration challenges and shape the future of workforce mobility.

Fragomen is committed to promoting diversity, inclusion and equal opportunity for all employees and applicants, regardless of race, ethnicity, heritage, gender, age, religion, disability, sexual orientation, gender identity or intersex status. At Fragomen, we do meaningful and impactful work for our clients and put a focus on our Responsible Business Practices: #LifeAtFragomen: We drive innovation and change. We respect colleagues, embrace diversity, and empower others. #FragomenForward: At Fragomen, pursuing an equal, diverse, and inclusive workforce goes beyond a policy. It’s part of our DNA—and always has been. Year after year, we are recognized as leaders in diversity in our industry. Giving Back. We have a deep history of giving back to the communities where we live and work—and we continue that mission today. Serving the less fortunate by providing advice and community support where it is most needed allows us to help immigrants secure a better future for themselves and their families. Corporate Social Responsibility. We believe there is more to success in business than generating profit—we want to do well by doing good. We are committed to considering the impact that our business decisions have on our people, our planet, the communities in which we work and our clients. Sustainability. Fragomen is focused on sustainability in our business operations and practices—and we know there is much work to be done, with countless opportunities available to minimize our impact on the environment Well‑being. We are committed to implementing firmwide initiatives that support the health and wellness of our people, including programs to address work‑life balance and benefits that cover a wide range of well‑being needs of all employees. Our #FragomenWorks program provides the ability to be successful at home or in the office, via Hybrid & Remote work arrangements. Our Feedback Works process includes three managerial check‑ins per year to help you progress in your career. Unique learning programs like: Fragomen Academy, Leadership Academy, Practical Management Academy, and Regional Development Conferences.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Business Immigration Coordinator
Business Immigration Coordinator

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Phoenix (AZ)

On-site
USD 42,000 - 64,000
22 PTO days + Federal holidays
Medical, Dental, and Vision plans + FS
401K plan
Business Immigration Supervisor
Business Immigration Supervisor

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Dallas (TX)

On-site
USD 90,000 - 130,000
22 PTO days + Federal holidays
Medical, Dental, Vision + FSA & HSA
401K plan with company matching
Senior Business Immigration Analyst
Senior Business Immigration Analyst

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Salt Lake City (UT)

On-site
USD 80,000 - 110,000
22 PTO days + Federal holidays
Medical, Dental, and Vision plans
401K plan with company matching
Immigration Program Manager
Immigration Program Manager

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Los Angeles (CA)

Hybrid
USD 109,000 - 130,000
PTO & holidays
Medical/Dental/Vision
401K with company matching
Senior Business Immigration Analyst (Paralegal)
Senior Business Immigration Analyst (Paralegal)

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • San Francisco (CA)

On-site
USD 63,000 - 75,000
PTO days
Medical/Dental/Vision plans
FSA & HSA Plans
+1
Senior Business Immigration Analyst (Paralegal)
Senior Business Immigration Analyst (Paralegal)

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Boston (MA)

Hybrid
USD 63,000 - 75,000
22 PTO days + Federal holidays
Medical, Dental, Vision + FSA & HSA
401K plan with company matching
Business Immigration Associate (3-4 years)
Business Immigration Associate (3-4 years)

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Houston (TX)

On-site
USD 110,000 - 170,000
27 PTO days + Federal holidays
Medical, Dental, and Vision plans + FS
401K plan, with company matching
Business Immigration Analyst
Business Immigration Analyst

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Los Angeles (CA)

Hybrid
USD 52,000 - 60,000
22 PTO days + Federal holidays
Medical, Dental, and Vision plans
FSA & HSA Plans
+1
Senior Business Immigration Analyst (Paralegal)
Senior Business Immigration Analyst (Paralegal)

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Atlanta (GA)

On-site
USD 65,000 - 90,000
22 PTO days + Federal holidays
Medical, Dental, Vision plans + FSA &H
401K plan with company matching
Business Immigration Consultant (Experienced Paralegal)
Business Immigration Consultant (Experienced Paralegal)

100 Fragomen, Del Rey, Bernsen & Loewy, LLP • Houston (TX)

Hybrid
USD 75,000 - 115,000
22 PTO days
Health plans + FSA/HSA
401K with company match