Fragomen

Senior Security Engineer, Data Loss Prevention

Fragomen$110K — $130K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity, data protection, risk, or compliance roles.
  • Knowledge of data loss prevention (DLP) concepts and sensitive data handling.
  • Hands-on experience with security controls in enterprise environments, especially Microsoft 365.
  • Ability to analyze DLP alerts and sharing patterns for business impact.
  • Familiarity with identity and access management, authentication mechanisms, and data sharing workflows.
  • Strong communication skills to articulate technical findings in business language.

Responsibilities

  • Design and implement DLP policies across various platforms including Microsoft 365 and cloud services.
  • Identify, classify, and protect sensitive information via data classification and policy conditions.
  • Monitor DLP alerts for data exposure and policy violations.
  • Partner with various stakeholders to align DLP controls with regulatory and operational needs.
  • Develop DLP standards, procedures, and escalation workflows.
  • Evaluate existing controls for collaboration and file-sharing tools.
  • Conduct root cause analysis on data handling issues to enhance policy effectiveness.

Benefits

  • Join a team that prioritizes security as a key differentiator in technology offerings.
  • Contribute to the development of industry-leading data protection capabilities.
  • Collaborate across multiple teams to shape enterprise security policy.
  • Engage in continuous improvement of security processes and controls.
Full Job Description
Job Description

About the Role

Cyber Security Engineer with strong experience in Data Loss Prevention (DLP), sensitive data governance, SaaS and cloud data protection, and security control engineering to join our Information Security & Cyber Security team.

Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and protecting sensitive client, employee, and firm data is critical to its success. We are seeking a professional who is passionate about reducing data exposure risk, engineering practical DLP controls, and partnering across Legal, Compliance, Privacy, Risk, IT, and business teams to mature enterprise data protection capabilities.

You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in designing, implementing, tuning, and operating DLP controls across email, endpoint, cloud, SaaS, and collaboration platforms while helping strengthen Fragomen's overall security posture.

How Will You Make a Difference at Fragomen?

As a Security Engineer focused on Data Loss Prevention, you will:

  • Design, implement, and tune enterprise DLP policies across Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms.


  • Identify, classify, and protect sensitive information using data classification, sensitivity labels, policy conditions, and appropriate enforcement actions.


  • Monitor and investigate DLP alerts involving potential data exposure, improper sharing, data exfiltration indicators, or policy violations.


  • Partner with Legal, Compliance, Privacy, Risk, Records, and business stakeholders to align DLP controls with regulatory, legal, client, and operational requirements.


  • Develop and maintain DLP standards, operating procedures, runbooks, exception processes, and escalation workflows.


  • Evaluate and improve controls for collaboration platforms and file-sharing tools, including OneDrive, SharePoint, Box, Google Drive, Dropbox, ShareFile, NetDocuments, and similar services.


  • Support CASB and SaaS governance efforts by helping identify unsanctioned data movement, risky sharing behavior, excessive permissions, and opportunities for policy enforcement.


  • Conduct root cause analysis on recurring alerts, control gaps, and data handling issues to improve policy quality and reduce false positives.


  • Collaborate with security operations, identity, messaging, endpoint, network, and application teams to integrate DLP telemetry into SIEM, SOAR, monitoring, and response processes.


  • Prepare clear, business-appropriate communications for end users, technical teams, stakeholders, and leadership regarding DLP findings, policy changes, and recommended corrective actions.


  • Provide technical guidance and mentorship to junior analysts and security team members on DLP investigations, data handling risk, and control operations.


Leverage Your Skills and Experience

Required Qualifications

  • 5+ years of experience in cybersecurity, data protection, security operations, governance, risk, compliance, or related technology roles, or equivalent combination of education and experience.


  • Working knowledge of DLP concepts, sensitive data handling, information protection, data classification, and policy-based enforcement.


  • Hands-on experience supporting or operating security controls in enterprise environments, especially within Microsoft 365, email, endpoint, cloud, or SaaS platforms.


  • Ability to analyze DLP alerts, user activity, sharing patterns, policy matches, and event logs to determine business impact and appropriate response.


  • Working knowledge of identity and access concepts, authentication mechanisms, file permissions, collaboration tooling, and data sharing workflows.


  • Strong written and verbal communication skills, including the ability to explain technical findings in clear, practical, and business-appropriate language.


  • Demonstrated ability to follow structured processes while continuously improving them.


Technical Knowledge

  • Microsoft Purview Information Protection and DLP, including sensitivity labels, trainable classifiers, data loss prevention rules, audit logs, alerts, and policy tuning.


  • Microsoft Defender for Cloud Apps, cloud app governance, CASB concepts, SaaS discovery, session controls, and cloud data exposure monitoring.


  • Endpoint, email, and collaboration security controls across Windows, Microsoft 365, Exchange Online, Teams, SharePoint, and OneDrive.


  • SIEM and security platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar tools used to correlate DLP and security telemetry.


  • Common sensitive data types and regulatory drivers, such as PII, PCI, PHI, financial data, client confidential information, legal matter data, and regulated business records.


  • Core networking and platform concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, firewalls, APIs, and cloud storage patterns.


Preferred Qualifications

  • Experience engineering or administering Microsoft Purview DLP, Endpoint DLP, Information Protection, Insider Risk Management, eDiscovery, Audit, or Data Lifecycle Management.


  • Experience with CASB, SaaS security, cloud access governance, or file-sharing risk management across platforms such as Box, Google Drive, Dropbox, ShareFile, NetDocuments, Salesforce, ServiceNow, or similar applications.


  • Experience supporting investigations involving Legal, Compliance, Privacy, Risk, Records, HR, or regulatory stakeholders.


  • Experience with SOAR, ticketing, workflow automation, and process documentation for recurring security operations activities.


  • Knowledge of secure collaboration practices, permission review, data retention, acceptable use, and exception governance.


  • Relevant certifications, including Microsoft Security, Compliance, and Identity certifications; CISSP, SSCP, Security+, CISA, CISM; GIAC security certifications; or vendor certifications for DLP, CASB, SIEM, or endpoint platforms.


About Fragomen

Fragomen is a global immigration law firm that provides immigration services to clients in over 170 countries. The firm has over 50 offices worldwide and employs over 5,000 people. Fragomen provides a range of immigration services, including assistance with work visas, permanent residence, and citizenship applications. The firm also provides compliance and advisory services to help clients navigate the complex and ever-changing immigration landscape. Fragomen's clients include multinational corporations, small businesses, and individuals.
Learn more about Fragomen
Size
5,000 employees
Industry

Similar Jobs

More Jobs at Fragomen

More Information Technology Jobs

Find similar Senior Security Engineer, Data Loss Prevention jobs: