Overview:We are seeking an experienced Senior Data Loss Prevention (DLP) Architect & Engineer to join our Cybersecurity organization. This dual-function role combines strong hands-on engineering execution with architectural design responsibilities. The successful candidate will play a key role in implementing, operating, and continuously improving our enterprise DLP program spanning network, endpoint, and cloud in a highly regulated financial services environment.
As a key technical contributor, the candidate will support the build-out of automated event monitoring and response pipelines that integrate with our broader security operations ecosystem. The role also requires close collaboration with Legal, Risk, Compliance, and Engineering teams to protect sensitive financial and customer data and support compliance with SEC, FINRA, PCIDSS, SOX, GDPR and other regulatory requirements.
Main areas of responsibilities:Architecture & Strategy:
- Contribute to the design and continuous improvement of the enterprise DLP architecture across network, endpoint, email, and cloud channels.
- Apply architecture standards and integration blueprints for DLP tooling within the BBH's broader security ecosystem.
- Participate in DLP technology roadmap planning; evaluate emerging tools and capabilities and provide technical recommendations to the leadership.
- Assist in leading proof-of-concept (PoC) evaluations and vendor assessments.
Engineering & Implementation:
- Deploy, configure, tune, and document DLP solutions across network egress points (web proxy, email gateway, API channels) and endpoint agents at enterprise scale.
- Support the development of DLP policies aligned with data classification frameworks and labeling taxonomies across all data channels.
- Build and maintain DLP policy rulesets, data dictionaries, and custom detectors for sensitive data types including PII, NPI, MNPI, and trading data.
- Conduct regular policy effectiveness reviews and false-positive tuning sessions.
- Engineer end-to-end event monitoring pipelines, integrating DLP alert telemetry into SIEM platforms for correlation, enrichment, and dashboarding.
- Develop automation workflows and playbooks to accelerate DLP incident triage, notification, and response.
- Lead the planning, execution, and implementation of DLP related changes, ensuring adherence to change management processes while documenting design decisions, configuration updates, testing results, deployment procedures, and rollback plans.
Operations & Governance:
- Serve as a technical escalation point for complex DLP incidents, conducting root cause analysis and driving remediation in coordination with the VP of DLP.
- Contribute to the development of DLP KPIs and metrics, support production of operational dashboards and reporting inputs for quarterly risk reviews.
- Partner with Legal, Compliance, and Privacy teams to translate regulatory obligations into DLP technical controls and audit evidence packages.
- Provide guidance and mentorship to junior DLP analysts and engineers on tooling, investigation techniques, and policy management.
- Support internal and external audits (SOX, PCI-DSS, regulatory examinations) by providing documentation, evidence, and technical walkthroughs.
Requirements:
- 8+ years of progressive experience in information security, with a minimum of 5 years focused on Data Loss Prevention architecture, engineering, and operational leadership in large enterprise environments.
- Demonstrated experience in designing, implementing, and optimizing both network DLP (web, email, cloud) and endpoint DLP (agent-based, EDR integrated) across large enterprise environments.
- Zscaler DLP - Required; demonstrated expertise in design, implementation, policy development, tuning, troubleshooting, and ongoing operations.
- Excellent written and verbal communication skills with the ability to translate technical and business risk into actionable recommendations to executive-level audiences and produce high-quality documentation.
- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related technical discipline required.
- Master's degree in Cybersecurity, Information Assurance, or equivalent preferred.
- Relevant industry certifications are highly desirable, including but not limited to CISSP, CISM, CCSP, GIAC, Security+, or vendor-specific DLP certifications.
Nice to have attributes:- Candidates with deep expertise in multiple DLP platforms and a proven track record of leading enterprise DLP programs will be strongly preferred.
- Proofpoint DLP - Strongly Preferred; experience with data protection controls, policy configuration, incident management, and integrations.
- Microsoft Purview Information Protection & DLP - Preferred; experience implementing and managing endpoint, cloud, and Microsoft 365 DLP capabilities, including data classification and sensitivity labeling.
- Preference will be given to candidates with experience/skills in one or more of the following:
- Splunk (ES / SIEM) - Experience with developing security use cases, dashboards, correlation searches, alerting, and reporting.
- Microsoft Sentinel - Experience with integrating DLP telemetry, developing analytics rules, searches, alerting, reporting, and automating response workflows.
- Microsoft Defender XDR - Experience with leveraging endpoint, email, and cloud security signals to enhance data protection, insider risk detection, and incident response capabilities.
Salary RangeNJ: $110,000-$160,000 base salary + annual target bonus
BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck-providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.
We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn't followed a traditional path, includes alternative experiences, or doesn't meet every qualification or skill listed in the job description, please do go ahead and apply.