Lead Security Operations Engineer

Sorry, this job was removed at 02:08 a.m. (CST) on Wednesday, Nov 19, 2025
Be an Early Applicant
North Hills, NY
Hybrid
144K-239K Annually
Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Empowering people today to build a better future for the next generation.
The Role
The Cybersecurity Lead DLP Engineer is responsible for leading and executing data loss prevention security operations across the enterprise. This role serves as the subject matter expert for DLP technologies, policies, and incident response, ensuring the protection of sensitive and confidential data across all business units domestically and internationally. The position requires close collaboration with IT teams, compliance, legal, and business stakeholders to evaluate, improve, and maintain comprehensive DLP controls. The Lead DLP Analyst will manage DLP product deployments, investigate data exfiltration incidents, and continuously enhance the organization's data protection posture through advanced DLP monitoring techniques and security best practices.
Primary Responsibilities:
Data Loss Prevention (DLP) Operations
  • Serve as the primary subject matter expert on Data Loss Prevention technologies, strategies, and data protection concepts across the organization.
  • Lead overall responsibility for DLP security operations including policy creation, tuning, incident detection, investigation, and response to data exfiltration attempts.
  • Conduct thorough investigations of DLP alerts and incidents, including data classification violations, policy breaches, and potential insider threats involving sensitive data.
  • Monitor, analyze, and respond to DLP events from on-premise systems, cloud environments, endpoints, email gateways, web proxies, and collaboration platforms.
  • Develop and maintain data classification frameworks and work with stakeholders to implement appropriate protection controls for each classification level.
  • Continuously improve DLP detection capabilities through advanced pattern matching, machine learning models, fingerprinting, and contextual analysis techniques.

Security Monitoring and Incident Response
  • Collaborate with IT teams, compliance, legal, and business stakeholders to coordinate comprehensive DLP monitoring and response activities.
  • Monitor and analyze DLP events across email gateways, endpoints, cloud applications, network channels, and file repositories to detect policy violations and data exfiltration attempts.
  • Lead investigations of data breach incidents, insider threat cases, and data exfiltration attempts, identifying root causes and recommending remediation actions.
  • Perform advanced analysis of data exfiltration scenarios utilizing industry standard frameworks including MITRE ATT&CK data exfiltration tactics and techniques.
  • Provide timely detection, identification, and alerts of data loss events, policy violations, anomalous data movements, and potential insider threats.
  • Distinguish between benign business activities and malicious data exfiltration through contextual analysis and threat intelligence.
  • Work closely with IT teams, legal, HR, and business units to remediate security incidents while balancing security requirements with business operations.

Skills:
Data Loss Prevention (DLP)
Ability to:
  • Design, implement, and manage enterprise DLP solutions across multiple platforms including Symantec DLP, Forcepoint DLP, Microsoft Purview, Digital Guardian, or similar technologies.
  • Create and tune comprehensive DLP policies using pattern matching, regular expressions, fingerprinting, exact data matching (EDM), and machine learning classification.
  • Implement DLP controls across all data vectors including email, web, endpoint, cloud applications, file shares, removable media, and printing.
  • Establish and maintain data classification taxonomies and apply appropriate protection measures for each sensitivity level.
  • Conduct sophisticated investigations of DLP incidents including analysis of data flows, user behavior, and potential data breach scenarios.
  • Integrate DLP solutions with SIEM, CASB, email security gateways, and other security infrastructure for comprehensive visibility.
  • Balance security requirements with business productivity through effective policy tuning and false positive reduction strategies.

Security Monitoring and Operations
Ability to:
  • Work effectively with IT departments, compliance teams, legal counsel, and business stakeholders for comprehensive DLP monitoring and enforcement.
  • Perform advanced DLP event correlation, triage, and analysis to identify true positive data loss incidents versus false positives.
  • Apply contextual analysis and business knowledge to respond appropriately to data security incidents and policy violations.
  • Recognize indicators of compromise related to data exfiltration, insider threats, and unauthorized data access or transmission.
  • Lead projects to improve DLP monitoring capabilities, enhance detection accuracy, and reduce response times.
  • Demonstrate strong understanding of defense-in-depth security principles and how DLP fits within the broader security architecture.
  • Communicate complex security issues effectively to management, business stakeholders, legal teams, and technical audiences.
  • Maintain and update DLP operational guidelines, standards, procedures, and documentation.

Incident Response and Forensics
Ability to:
  • Perform incident response activities specifically focused on data breach incidents, insider threats, and data exfiltration scenarios.
  • Conduct digital forensic investigations to determine data access patterns, identify compromised systems, and trace data movements.
  • Work collaboratively with internal IT teams, external forensic providers, legal counsel, and HR during sensitive data breach investigations.
  • Ensure all data security incidents are properly documented, investigated thoroughly, and remediated according to established procedures.
  • Maintain chain of custody for digital evidence and prepare detailed incident reports for management and legal review.

Minimum Qualifications:
  • Bachelor's degree in a related discipline and 6 years' experience in a related field. The right candidate could also have a different combination, such as a master's degree and 4 years' experience; a Ph.D. and 1 year of experience; or 18 years' experience in a related field
  • Expert-level hands-on experience implementing and managing enterprise DLP solutions (Symantec/Broadcom DLP, Forcepoint, Microsoft Purview, Digital Guardian, McAfee DLP, or similar platforms)
  • Deep working experience with Data Loss Prevention, Incident Response, Insider Threat Detection, and data security operations
  • Strong experience with log analysis, DLP event investigation, and security alert triage specific to data exfiltration scenarios
  • Working knowledge of network protocols, email systems, cloud storage platforms, and endpoint technologies as they relate to DLP monitoring
  • Experience conducting security investigations and incident response for data breach, insider threat, and data exfiltration scenarios
  • Demonstrated ability to create technical documentation, operational procedures, metrics dashboards, and executive-level reports
  • Strong understanding of data privacy regulations (GDPR, CCPA, HIPAA, PCI-DSS) and compliance requirements
  • Network Administration and System Administration background with deep understanding of Windows, Linux, macOS environments
  • Advanced scripting and programming skills (Python, PowerShell, Bash) for automation and custom integrations
  • Experience with Cloud Security (AWS, Azure, GCP) and Cloud Access Security Broker (CASB) solutions
  • Hands-on experience with digital forensics tools (EnCase, FTK, X-Ways) and eDiscovery platforms
  • Experience with User and Entity Behavior Analytics (UEBA) and Insider Threat Management platforms
  • Knowledge of machine learning and AI applications in data classification and anomaly detection

USD 143,600.00 - 239,300.00 per year
Compensation:
Compensation includes a base salary of $143,600.00 - $239,300.00. The base salary may vary within the anticipated base pay range based on factors such as the ultimate location of the position and the selected candidate's knowledge, skills, and abilities. Position may be eligible for additional compensation that may include an incentive program.
Benefits:
The Company offers eligible employees the flexibility to take as much vacation with pay as they deem consistent with their duties, the company's needs, and its obligations; seven paid holidays throughout the calendar year; and up to 160 hours of paid wellness annually for their own wellness or that of family members. Employees are also eligible for additional paid time off in the form of bereavement leave, time off to vote, jury duty leave, volunteer time off, military leave, and parental leave.

What the Team is Saying

Belinda
Tonya
Chris

Similar Jobs

Cox Enterprises Logo Cox Enterprises

Account Executive

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
New York, NY, USA
50000 Employees
85K-168K Annually

Cox Enterprises Logo Cox Enterprises

Account Executive

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Rochester, NY, USA
50000 Employees
85K-168K Annually

Cox Enterprises Logo Cox Enterprises

Account Executive

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Buffalo, NY, USA
50000 Employees
85K-168K Annually

Cox Enterprises Logo Cox Enterprises

Account Executive

Automotive • Cloud • Greentech • Information Technology • Other • Software • Cybersecurity
Hybrid
Albany, NY, USA
50000 Employees
85K-168K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Atlanta, GA
50,000 Employees
Year Founded: 1898

What We Do

For well over a century, Cox Enterprises has been shaping the future with daring ideas and values-driven thinking.

Since our founding in 1898, our relentless spirit of innovation has driven us to disrupt industries and enhance the quality of life in the communities we serve. Through our major divisions — Cox Communications, Cox Automotive and Cox Farms — our people have countless opportunities to grow and make an impact in the communications and automotive industries, as well as in new ventures in agriculture, cleantech, digital media and more.

As a privately-held, family-owned business, we know that people are our most valuable asset. We offer a supportive and inclusive environment with flexible career growth, amazing benefits and work-life balance at the forefront.

Our mission, our ways of working and our commitment to people are what make our workplace culture remarkably flexible and resilient. Join us to build a better future and make your mark.

Why Work With Us

At our core, Cox is a technology company that values human relationships. We know people feel most empowered when their work has meaning, when they feel respected and have opportunities to grow. “Career satisfaction” is not enough at Cox — we’re here to help you find balance, live well and achieve your career goals even as they change over time.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Cox Enterprises Teams

Team
Product & Tech
Team
B2B & Cloud Sales
About our Teams

Cox Enterprises Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Every person has different working styles and preferences — and we aim to empower teams to work where they are most comfortable. Some roles require in-person work, but for those that can be performed remotely, we offer flexibility.

Typical time on-site: Flexible
Company Office Image
HQAtlanta, GA
Company Office Image
Austin, TX
Company Office Image
Burlington, VT
Company Office Image
Foothill Ranch, CA
Las Vegas, NV
Company Office Image
North Hills, NY
Company Office Image
Oklahoma City, OK
Company Office Image
Omaha, NE
Company Office Image
Phoenix, AZ
Company Office Image
Raleigh, NC
Company Office Image
San Diego, CA
South Jordan, UT
Learn more

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account