DLP Engineer

Posted Yesterday
Be an Early Applicant
Memphis, TN, USA
In-Office
Entry level
Financial Services
The Role
Investigates and responds to DLP, insider risk, and endpoint security alerts across Microsoft 365 and enterprise platforms. Administers and tunes Microsoft Purview policies, detections, classifiers, thresholds, and workflows; analyzes false positives and data exfiltration patterns; develops dashboards and investigation playbooks; and partners with security, HR, identity, incident response, and business teams on containment and remediation. The role also supports automation, change management, control testing, and continuous improvement of data protection capabilities.
Summary Generated by Built In

Data Security & Insider Risk Analyst

Suggested alternate title: Data Security Analyst – DLP & Insider Risk

Position Summary

We are seeking a hands-on Data Security & Insider Risk Analyst to protect sensitive information across Microsoft 365, endpoints, and other enterprise platforms. This role combines security operations with platform engineering: the analyst will investigate and respond to data loss prevention (DLP), insider risk, and endpoint security events while continuously tuning Microsoft Purview policies, detections, and workflows to improve accuracy and reduce risk. The ideal candidate is analytical, curious, and comfortable translating security data into clear findings and practical control improvements.

Key Responsibilities

·       Monitor, triage, investigate, and respond to DLP, insider risk, and endpoint security alerts and incidents.

·       Determine incident scope, business context, data sensitivity, user activity, and potential impact; document findings and coordinate appropriate containment, escalation, and remediation.

·       Administer and tune Microsoft Purview DLP policies, rules, sensitive information types, classifiers, alert thresholds, exceptions, and user notifications.

·       Support DLP controls across Exchange, SharePoint, OneDrive, Teams, endpoints, browsers, removable media, printing, clipboard activity, and cloud applications, as applicable.

·       Review false positives, false negatives, user overrides, and recurring alert patterns; recommend and implement policy improvements.

·       Support Microsoft Purview Insider Risk Management use cases, indicators, policies, alerts, cases, and privacy-aware investigation workflows.

·       Partner with identity, corporate security, human resources, incident response teams, and line-of-business teams during investigations, containment, remediation, and control changes.

·       Use Microsoft Purview, Microsoft Defender, SentinelOne EDR, Splunk SIEM, audit, identity, and endpoint telemetry to build investigation timelines, correlate activity, and validate findings.

·       Create dashboards, metrics, and trend analyses that communicate incident volume, policy effectiveness, data movement, root causes, and control gaps.

·       Develop and maintain procedures, investigation playbooks, tuning standards, exception records, and knowledge articles.

·       Participate in testing, change management, and phased deployment of new or updated data protection controls.

·       Identify opportunities for automation, enrichment, and workflow integration that improve response speed and consistency.

Required Qualifications

·       Experience in information security, data protection, security operations, incident response, threat analysis, compliance operations, criminology, law enforcement, corporate security, fraud investigation, or a related discipline. Candidates with transferable investigative experience are encouraged to apply.

·       Working knowledge of DLP concepts, data classification, sensitive data handling, insider risk, and common data exfiltration paths.

·       Ability to investigate alerts using evidence from users, devices, applications, email, collaboration platforms, and audit logs.

·       Experience configuring or tuning security policies, detections, rules, or alerting logic in an enterprise environment.

·       Strong analytical and problem-solving skills, including the ability to distinguish legitimate business activity from potential misuse.

·       Clear written and verbal communication skills, with the judgment to handle sensitive investigations professionally and confidentially.

·       Ability to manage multiple investigations and tuning efforts while maintaining accurate case documentation.

Preferred Qualifications

·       Hands-on experience with Microsoft Purview Data Loss Prevention, Endpoint DLP, Insider Risk Management, Information Protection, Data Explorer, Activity Explorer, or related capabilities.

·       Hands-on experience with Zscaler Data Loss Prevention (DLP), including policy configuration, content inspection, alert investigation, false-positive tuning, or data exfiltration controls across web, cloud applications and email.

·       Experience investigating Microsoft Purview alerts and incidents through Microsoft Defender or an integrated SIEM/SOAR workflow.

·       Experience using any endpoint detection and response (EDR) platform to investigate endpoint activity, correlate alerts, or support containment and remediation. Experience with comparable EDR tools is readily transferable to SentinelOne, which is used in this role.

·       Data analytics or reporting experience using Power BI, Tableau, SQL, Kusto Query Language (KQL), Excel, or similar tools.

·       Experience using any security information and event management (SIEM) platform for searching, correlation, dashboards, reporting, or investigation support. Experience with comparable SIEM tools is readily transferable to Splunk, which is used in this role.

·       Understanding of Microsoft 365 services, Microsoft Entra ID, endpoint management, audit logging, and cloud security concepts.

·       Experience in a regulated industry or with privacy, records management, legal, HR, or compliance stakeholders.

·       Relevant certifications, such as Microsoft Information Protection and Compliance Administrator (SC-400), Microsoft Security Operations Analyst (SC-200), Security+, or equivalent practical experience.

·       Professional experience in criminology, law enforcement, corporate security, fraud, investigations, or a similar field that demonstrates sound investigative judgment, evidence handling, interviewing, case management, or pattern analysis.

What Success Looks Like

·       DLP and insider risk alerts are investigated promptly, consistently, and with clear supporting evidence.

·       Policies become more effective over time, with fewer unnecessary alerts and better coverage of meaningful risk.

·       Incident trends and control gaps are translated into measurable recommendations for security and business partners.

·       Investigation procedures, tuning decisions, and exceptions are documented and repeatable.

·       Data security, endpoint security, and business stakeholders collaborate effectively on remediation and risk reduction.

Ideal Candidate Profile

You enjoy both sides of data security operations: working an alert through investigation and resolution, then using what you learned to improve the control that generated it. You can analyze technical evidence, understand business context, communicate findings without unnecessary jargon, and make thoughtful tuning decisions that balance protection with user productivity.

 

Skills Required

  • Experience in information security, data protection, security operations, incident response, threat analysis, compliance operations, criminology, law enforcement, corporate security, fraud investigation, or a related discipline
  • Working knowledge of DLP concepts, data classification, sensitive data handling, insider risk, and common data exfiltration paths
  • Ability to investigate alerts using evidence from users, devices, applications, email, collaboration platforms, and audit logs
  • Experience configuring or tuning security policies, detections, rules, or alerting logic in an enterprise environment
  • Strong analytical and problem-solving skills
  • Clear written and verbal communication skills, including professional and confidential handling of sensitive investigations
  • Ability to manage multiple investigations and tuning efforts while maintaining accurate case documentation
  • Hands-on experience with Microsoft Purview Data Loss Prevention, Endpoint DLP, Insider Risk Management, Information Protection, Data Explorer, Activity Explorer, or related capabilities
  • Hands-on experience with Zscaler Data Loss Prevention
  • Experience investigating Microsoft Purview alerts and incidents through Microsoft Defender or an integrated SIEM/SOAR workflow
  • Experience with an endpoint detection and response platform
  • Data analytics or reporting experience using Power BI, Tableau, SQL, Kusto Query Language, Excel, or similar tools
  • Experience using a security information and event management platform
  • Understanding of Microsoft 365 services, Microsoft Entra ID, endpoint management, audit logging, and cloud security concepts
  • Experience in a regulated industry or with privacy, records management, legal, HR, or compliance stakeholders
  • Relevant certifications such as Microsoft Information Protection and Compliance Administrator SC-400, Microsoft Security Operations Analyst SC-200, Security+, or equivalent practical experience
  • Professional experience in criminology, law enforcement, corporate security, fraud, investigations, or a similar field involving evidence handling, interviewing, case management, or pattern analysis

First Horizon Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about First Horizon Bank and has not been reviewed or approved by First Horizon Bank.

  • Retirement Support Retirement offerings include a 401(k) plan with company matching contributions up to 6% of pre-tax income, alongside FSA/HSA options and a defined benefit pension plan. Stock purchase and equity programs (including options and RSUs) also add to longer-term wealth-building opportunities for eligible employees.
  • Parental & Family Support Parental leave is available for childbirth, adoption, foster parenting, or surrogacy, and adoption reimbursement is included in the package. These family-building benefits broaden support beyond traditional maternity/paternity leave structures.
  • Wellbeing & Lifestyle Benefits Wellbeing support includes an internal wellness program, an employee assistance program, and access to a digital wellness platform. Group life insurance and disability coverage (including no-cost options) strengthen financial protection and day-to-day support.

First Horizon Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Memphis, TN
6,494 Employees
Year Founded: 1864

What We Do

When we opened our doors in 1864 on North Court Street in Memphis, we had a simple mission: to provide the best service to our customers, one opportunity at a time. In the 150 years that followed, our communities transformed and expanded. We’ve seen our business and banking in general grow and adapt to the changing needs of customers through the years. But one thing that will always remain constant is our commitment to financial integrity and to helping our customers take good care of their money.

Similar Jobs

Citizens Logo Citizens

Security Engineer

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees
175K-250K Annually
In-Office or Remote
2 Locations
31000 Employees

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
64 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
66 Locations
370000 Employees
77K-202K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account