Senior Information Security Engineer- DLP/Insider Threat
Core
Protects sensitive healthcare data (PHI, PII, IP) and mitigates insider threats through Data Loss Prevention (DLP) and insider risk operations.
Role type
Senior Information Security Engineer (DLP/Insider Threat)
Builds
DLP, UEBA, and insider risk controls across endpoint, email, SaaS, cloud, and identity platforms.
Domain
Healthcare Information Security / Data Protection
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
DLP configuration and tuning, UEBA analysis, insider risk investigation, endpoint security management, cloud security posture management, SIEM log analysis, alert triage, policy management, data exfiltration detection, secrets detection, tool troubleshooting (Cyberhaven, Proofpoint, CrowdStrike, Splunk), HIPAA compliance knowledge.
Preferred skills
GCIH, CDPSE, CIPP/US, AIGP, CCSK, Microsoft SC-401, insider risk training.
Technologies
Cyberhaven, Proofpoint, CrowdStrike, Splunk, Microsoft Purview, ServiceNow, Jira, GitGuardian, Orca.
Responsibilities
Configure and tune DLP, UEBA, and insider risk controls; triage alerts regarding sensitive data movement and unusual user behavior; investigate data exposure and recommend control improvements; maintain playbooks, SOPs, and dashboards; partner with Incident Response and other security teams; perform 24x7 on-call support.
Seniority
Senior, hands-on IC