Role SummarySenior Lead Cyber Security Engineer responsible for designing, implementing, and managing enterprise data protection and data security controls, including SecuPi Data Activity Monitoring (DAM), Microsoft Purview Information Protection, Data Loss Prevention (DLP), CASB, and Zscaler data security capabilities. This role leads strategic initiatives focused on data visibility, monitoring, classification, protection, encryption, and secure application integration across cloud and on-premises environments.
Key Responsibilities- Lead implementation of SecuPi (DAM) controls and data-level encryption
- Lead implementation and optimization of Microsoft Purview DLP, Information Protection, Endpoint DLP, CASB, and Zscaler data protection controls.
- Define and enforce enterprise data protection policies, including data classification, labeling, monitoring, and loss prevention controls.
- Drive the adoption of Zero Trust and data-centric security principles across applications, databases, cloud platforms, and end-user environments.
- Partner with compliance, risk, and business stakeholders to align data protection controls with regulatory and governance requirements.
- Drive integration of SecuPi with enterprise applications, especially in Azure
Design and enforce data security policies and monitoring use cases
Major Duties- Design and implement enterprise data protection architectures leveraging SecuPi DAM, Microsoft Purview, and Zscaler platforms.
- Develop security use cases and monitoring strategies for sensitive data access, movement, and policy violations.
- Support integration of data security platforms with SIEM, cloud, and enterprise security ecosystems.
- Collaborate with architecture and enterprise teams
- Define scalable and secure engineering solutions
- Support full lifecycle (design to deployment and support)
- Ensure security, scalability, and performance requirements
Required Skills & Expertise
- Hands-on experience with Microsoft Purview Information Protection, Data Loss Prevention (DLP), Data Lifecycle Management, and Compliance capabilities.
- Experience implementing and managing Zscaler Data Protection, CASB, SSE, and Zero Trust security controls.
- Strong understanding of data classification, labeling, governance, privacy, and regulatory compliance requirements.
- Experience designing enterprise data-centric security architectures across cloud and hybrid environments.
- Familiarity with integrating DLP, DAM, and cloud security platforms with Microsoft Sentinel, Splunk, or comparable SIEM solutions.
- Understanding of DevSecOps and secure SDLC
- Strong Azure cloud knowledge (Functions, APIM, Event Hub, Key Vault)
Experience & Qualifications
• 9+ years in Cyber Security / Data Protection Engineering
• Bachelor’s degree or equivalent experience
• Certifications (CISSP, CISM, cloud) preferred
Leadership Scope (P3 Expectations)
• Lead enterprise DAM initiatives
• Work independently with minimal supervision
• Provide mentorship and technical leadership
• Act as escalation point for critical issues
• Influence architecture and control strategy
Nice to Have
• Event-driven architecture (Kafka, Event Hub)
• Kubernetes/cloud-native exposure
• Experience with SIEM and analytics tools
• Knowledge of governance and compliance frameworks
Summary
This role is key to advancing enterprise data-centric security by enabling real-time monitoring, encryption, and secure application integration using SecuPi/DAM platforms.
Salary Range:
Salary range is a good faith estimate of base pay. Northern Trust provides a comprehensive benefits package including retirement benefits (401k and pension), health and welfare benefits (medical, dental, vision, spending accounts and disability), paid time off, parental and caregiver leave, life & accident insurance, and other voluntary and well-being benefits. Northern Trust also provides a discretionary bonus program that may include an equity component.