Overview
Skills
Job Details
DLP Engineer
Remote (must travel the first week to get a badge and orientation to DC)
Full time role
This is for a Data Loss Prevention Engineer. This particular task is responsible for DLP and Vulnerability Management.
Interview process dual interview with Task Lead and DLP Lead
Start date 14-21 days after offer
What to know All candidates out of the DC metro area will have to travel to Maryland to receive badging and GFE
Technical experience - DLP (Symantec/Broadcom) experience
Keys to success organized professionals who are alert and reply in a timely manner, understand the pressures of changing priorities
This is what a Data Loss Prevention Engineer does. It s a Security position
A Data Loss Prevention (DLP) Engineer supporting government contracts needs to focus on securing sensitive data within government systems and networks. This involves implementing and maintaining DLP solutions, ensuring compliance with relevant regulations, and providing ongoing support and monitoring.
Data Loss Prevention Engineer to provide support to government contracts.
Responsibilities:
- Implement enterprise-wide Symantec Data Loss Prevention (DLP) solutions
- Migrate DLP capabilities to Office 365 from third party channel DLP solutions
- Integrate DLP solutions with cloud access security brokers (CASB).
- Implement data protection controls in Amazon Web Services (AWS) and Google Compute Platform (Google Cloud Platform).
- Manage a team of engineers in the deployment, integration, and configuration of Symantec DLP solution to protect sensitive data for high value assets and major infrastructure investments.
- Conduct data protections reviews for high value assets and major infrastructure investments to include system inventory, exiting security controls, vulnerability assessment scanning inventory, database security, and application security testing inventory.
- Collaborate with forensics staff on IT security events resulting in law enforcement indictments.
- Develop and deliver essential data profiles for public facing systems across the enterprise resulting in an improved enterprise risk posture and more efficient incident response capabilities.
- Collaborate with forensics staff on IT security event resulting in law enforcement indictments.
- Participate in the Privacy Incident Response Team (PIRT) and Federal Privacy Council.
- Enhance and tune standards-based rulesets (HIPAA, PCI-DSS, SSN, CNSSI) and apply them to DLP Tools and SOAR playbooks.
- Support the design and implementation of automated response to DLP incidents
- Assist in the develop of security controls framework and assessment of current directives, standards and patterns.
- Investigate, design, and architect DLP controls as they are identified, developing backlog and gap for analysis.
- Evaluate emerging technologies & risks that will define a security architectural framework with threat modeling methodology.
Qualifications:
- Five or more years of work experience with at least one of those specialized in cyber security
- Bachelor s Degree (additional years of experience in cyber security reduce this educational requirement)
- A minimum of five (5) years technical experience effectively providing network and/or systems administration, information assurance security, testing and evaluation.
- Proficient with Security Orchestration, Automation and Response (SOAR) and Security Information and Event Management (SIEM) tools like Swimlane, Splunk, IBM Resilient
- Strong knowledge and understanding of Data Loss Prevention and/or Cybersecurity.
- Experience with Cybersecurity/DLP tools like Varonis, Netskope, McAfee, Office 365, Splunk, QRadar
- Strong understanding of government privacy standards and related controls like NIST, CSF, PCI-DSS, CMM.
- Strong understanding of Privacy Overlays, protecting PII/PHI/PCI and other sensitive data
- Experience running/participating in meetings with remote team members through collaboration technology
- Experience building cybersecurity programs for government agencies. Have some experience with the following agile and collaboration technologies: Jira, Confluence, and SharePoint
- Strong Client Interaction and Problem-solving skills
- Ability to obtain Security Clearance of Public Trust once hired
Desired Elements
- Certifications in information security (such as GCIA, GCIH, CEH, CISSP, SSCP, Sec+, AWS Security, etc.)
- Experience in a cyber security operational environment
- Security clearance
- Knowledge and experience using an incident response framework
- Programming or scripting experience
- Knowledge of Federal contract vehicles
- Presentation skills
- Experience with government contracting firms supporting the Federal government.