DLP Engineer
First Horizon Bank · Memphis, TN · 2 days ago
Information TechnologyFull-time
Key Responsibilities
- Monitor, triage, investigate, and respond to DLP, insider risk, and endpoint security alerts and incidents.
- Determine incident scope, business context, data sensitivity, user activity, and potential impact; document findings and coordinate appropriate containment, escalation, and remediation.
- Administer and tune Microsoft Purview DLP policies, rules, sensitive information types, classifiers, alert thresholds, exceptions, and user notifications.
- Support DLP controls across Exchange, SharePoint, OneDrive, Teams, endpoints, browsers, removable media, printing, clipboard activity, and cloud applications, as applicable.
- Review false positives, false negatives, user overrides, and recurring alert patterns; recommend and implement policy improvements.
- Support Microsoft Purview Insider Risk Management use cases, indicators, policies, alerts, cases, and privacy-aware investigation workflows.
- Partner with identity, corporate security, human resources, incident response teams, and line-of-business teams during investigations, containment, remediation, and control changes.
- Use Microsoft Purview, Microsoft Defender, SentinelOne EDR, Splunk SIEM, audit, identity, and endpoint telemetry to build investigation timelines, correlate activity, and validate findings.
- Create dashboards, metrics, and trend analyses that communicate incident volume, policy effectiveness, data movement, root causes, and control gaps.
- Develop and maintain procedures, investigation playbooks, tuning standards, exception records, and knowledge articles.
- Participate in testing, change management, and phased deployment of new or updated data protection controls.
- Identify opportunities for automation, enrichment, and workflow integration that improve response speed and consistency.
Required Qualifications
- Experience in information security, data protection, security operations, incident response, threat analysis, compliance operations, criminology, law enforcement, corporate security, fraud investigation, or a related discipline.
- Candidates with transferable investigative experience are encouraged to apply.
- Working knowledge of DLP concepts, data classification, sensitive data handling, insider risk, and common data exfiltration paths.
- Ability to investigate alerts using evidence from users, devices, applications, email, collaboration platforms, and audit logs.
- Experience configuring or tuning security policies, detections, rules, or alerting logic in an enterprise environment.
- Strong analytical and problem-solving skills, including the ability to distinguish legitimate business activity from potential misuse.
- Clear written and verbal communication skills, with the judgment to handle sensitive investigations professionally and confidentially.
- Ability to manage multiple investigations and tuning efforts while maintaining accurate case documentation.
Preferred Qualifications
- Hands-on experience with Microsoft Purview Data Loss Prevention, Endpoint DLP, Insider Risk Management, Information Protection, Data Explorer, Activity Explorer, or related capabilities.
- Hands-on experience with Zscaler Data Loss Prevention (DLP), including policy configuration, content inspection, alert investigation, false-positive tuning, or data exfiltration controls across web, cloud applications and email.
- Experience investigating Microsoft Purview alerts and incidents through Microsoft Defender or an integrated SIEM/SOAR workflow.
- Experience using any endpoint detection and response (EDR) platform to investigate endpoint activity, correlate alerts, or support containment and remediation.
- Experience with comparable EDR tools is readily transferable to SentinelOne, which is used in this role.
- Data analytics or reporting experience using Power BI, Tableau, SQL, Kusto Query Language (KQL), Excel, or similar tools.
- Experience using any security information and event management (SIEM) platform for searching, correlation, dashboards, reporting, or investigation support.
- Experience with comparable SIEM tools is readily transferable to Splunk, which is used in this role.
- Understanding of Microsoft 365 services, Microsoft Entra ID, endpoint management, audit logging, and cloud security concepts.
- Experience in a regulated industry or with privacy, records management, legal, HR, or compliance stakeholders.
- Relevant certifications, such as Microsoft Information Protection and Compliance Administrator (SC-400), Microsoft Security Operations Analyst (SC-200), Security+, or equivalent practical experience.
- Professional experience in criminology, law enforcement, corporate security, fraud, investigations, or a similar field that demonstrates sound investigative judgment, evidence handling, interviewing, case management, or pattern analysis.