Job DescriptionAbout the RoleYou will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in designing, implementing, tuning, and operating DLP controls across email, endpoint, cloud, SaaS, and collaboration platforms while helping strengthen Fragomen's overall security posture.
How Will You Make a Difference at Fragomen? As a Security Engineer focused on Data Loss Prevention, you will:
- Design, implement, and tune enterprise DLP policies across Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms.
- Identify, classify, and protect sensitive information using data classification, sensitivity labels, policy conditions, and appropriate enforcement actions.
- Monitor and investigate DLP alerts involving potential data exposure, improper sharing, data exfiltration indicators, or policy violations.
- Partner with Legal, Compliance, Privacy, Risk, Records, and business stakeholders to align DLP controls with regulatory, legal, client, and operational requirements.
- Develop and maintain DLP standards, operating procedures, runbooks, exception processes, and escalation workflows.
- Evaluate and improve controls for collaboration platforms and file-sharing tools, including OneDrive, SharePoint, Box, Google Drive, Dropbox, ShareFile, NetDocuments, and similar services.
- Support CASB and SaaS governance efforts by helping identify unsanctioned data movement, risky sharing behavior, excessive permissions, and opportunities for policy enforcement.
- Conduct root cause analysis on recurring alerts, control gaps, and data handling issues to improve policy quality and reduce false positives.
- Collaborate with security operations, identity, messaging, endpoint, network, and application teams to integrate DLP telemetry into SIEM, SOAR, monitoring, and response processes.
- Prepare clear, business-appropriate communications for end users, technical teams, stakeholders, and leadership regarding DLP findings, policy changes, and recommended corrective actions.
- Provide technical guidance and mentorship to junior analysts and security team members on DLP investigations, data handling risk, and control operations.
Leverage Your Skills and Experience Required Qualifications - 5+ years of experience in cybersecurity, data protection, security operations, governance, risk, compliance, or related technology roles, or equivalent combination of education and experience.
- Working knowledge of DLP concepts, sensitive data handling, information protection, data classification, and policy-based enforcement.
- Hands-on experience supporting or operating security controls in enterprise environments, especially within Microsoft 365, email, endpoint, cloud, or SaaS platforms.
- Ability to analyze DLP alerts, user activity, sharing patterns, policy matches, and event logs to determine business impact and appropriate response.
- Working knowledge of identity and access concepts, authentication mechanisms, file permissions, collaboration tooling, and data sharing workflows.
- Strong written and verbal communication skills, including the ability to explain technical findings in clear, practical, and business-appropriate language.
- Demonstrated ability to follow structured processes while continuously improving them.
Technical Knowledge - Microsoft Purview Information Protection and DLP, including sensitivity labels, trainable classifiers, data loss prevention rules, audit logs, alerts, and policy tuning.
- Microsoft Defender for Cloud Apps, cloud app governance, CASB concepts, SaaS discovery, session controls, and cloud data exposure monitoring.
- Endpoint, email, and collaboration security controls across Windows, Microsoft 365, Exchange Online, Teams, SharePoint, and OneDrive.
- SIEM and security platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar tools used to correlate DLP and security telemetry.
- Common sensitive data types and regulatory drivers, such as PII, PCI, PHI, financial data, client confidential information, legal matter data, and regulated business records.
- Core networking and platform concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, firewalls, APIs, and cloud storage patterns.
Preferred Qualifications - Experience engineering or administering Microsoft Purview DLP, Endpoint DLP, Information Protection, Insider Risk Management, eDiscovery, Audit, or Data Lifecycle Management.
- Experience with CASB, SaaS security, cloud access governance, or file-sharing risk management across platforms such as Box, Google Drive, Dropbox, ShareFile, NetDocuments, Salesforce, ServiceNow, or similar applications.
- Experience supporting investigations involving Legal, Compliance, Privacy, Risk, Records, HR, or regulatory stakeholders.
- Experience with SOAR, ticketing, workflow automation, and process documentation for recurring security operations activities.
- Knowledge of secure collaboration practices, permission review, data retention, acceptable use, and exception governance.
- Relevant certifications, including Microsoft Security, Compliance, and Identity certifications; CISSP, SSCP, Security+, CISA, CISM; GIAC security certifications; or vendor certifications for DLP, CASB, SIEM, or endpoint platforms.