Senior Data Loss Prevention (DLP) Architect & Engineer

Brown Brothers HarrimanJersey City, NJ
$110,000 - $160,000

About The Position

We are seeking an experienced Senior Data Loss Prevention (DLP) Architect & Engineer to join our Cybersecurity organization. This dual-function role combines strong hands-on engineering execution with architectural design responsibilities. The successful candidate will play a key role in implementing, operating, and continuously improving our enterprise DLP program spanning network, endpoint, and cloud in a highly regulated financial services environment. As a key technical contributor, the candidate will support the build-out of automated event monitoring and response pipelines that integrate with our broader security operations ecosystem. The role also requires close collaboration with Legal, Risk, Compliance, and Engineering teams to protect sensitive financial and customer data and support compliance with SEC, FINRA, PCIDSS, SOX, GDPR and other regulatory requirements.

Requirements

  • 8+ years of progressive experience in information security, with a minimum of 5 years focused on Data Loss Prevention architecture, engineering, and operational leadership in large enterprise environments.
  • Demonstrated experience in designing, implementing, and optimizing both network DLP (web, email, cloud) and endpoint DLP (agent-based, EDR integrated) across large enterprise environments.
  • Zscaler DLP - Required; demonstrated expertise in design, implementation, policy development, tuning, troubleshooting, and ongoing operations.
  • Excellent written and verbal communication skills with the ability to translate technical and business risk into actionable recommendations to executive-level audiences and produce high-quality documentation.
  • Bachelor's degree in Computer Science, Information Security, Information Technology, or a related technical discipline required.
  • Master's degree in Cybersecurity, Information Assurance, or equivalent preferred.
  • Relevant industry certifications are highly desirable, including but not limited to CISSP, CISM, CCSP, GIAC, Security+, or vendor-specific DLP certifications.

Nice To Haves

  • Candidates with deep expertise in multiple DLP platforms and a proven track record of leading enterprise DLP programs will be strongly preferred.
  • Proofpoint DLP - Strongly Preferred; experience with data protection controls, policy configuration, incident management, and integrations.
  • Microsoft Purview Information Protection & DLP – Preferred; experience implementing and managing endpoint, cloud, and Microsoft 365 DLP capabilities, including data classification and sensitivity labeling.
  • Splunk (ES / SIEM) - Experience with developing security use cases, dashboards, correlation searches, alerting, and reporting.
  • Microsoft Sentinel - Experience with integrating DLP telemetry, developing analytics rules, searches, alerting, reporting, and automating response workflows.
  • Microsoft Defender XDR - Experience with leveraging endpoint, email, and cloud security signals to enhance data protection, insider risk detection, and incident response capabilities.

Responsibilities

  • Contribute to the design and continuous improvement of the enterprise DLP architecture across network, endpoint, email, and cloud channels.
  • Apply architecture standards and integration blueprints for DLP tooling within the BBH's broader security ecosystem.
  • Participate in DLP technology roadmap planning; evaluate emerging tools and capabilities and provide technical recommendations to the leadership.
  • Assist in leading proof-of-concept (PoC) evaluations and vendor assessments.
  • Deploy, configure, tune, and document DLP solutions across network egress points (web proxy, email gateway, API channels) and endpoint agents at enterprise scale.
  • Support the development of DLP policies aligned with data classification frameworks and labeling taxonomies across all data channels.
  • Build and maintain DLP policy rulesets, data dictionaries, and custom detectors for sensitive data types including PII, NPI, MNPI, and trading data.
  • Conduct regular policy effectiveness reviews and false-positive tuning sessions.
  • Engineer end-to-end event monitoring pipelines, integrating DLP alert telemetry into SIEM platforms for correlation, enrichment, and dashboarding.
  • Develop automation workflows and playbooks to accelerate DLP incident triage, notification, and response.
  • Lead the planning, execution, and implementation of DLP related changes, ensuring adherence to change management processes while documenting design decisions, configuration updates, testing results, deployment procedures, and rollback plans.
  • Serve as a technical escalation point for complex DLP incidents, conducting root cause analysis and driving remediation in coordination with the VP of DLP.
  • Contribute to the development of DLP KPIs and metrics, support production of operational dashboards and reporting inputs for quarterly risk reviews.
  • Partner with Legal, Compliance, and Privacy teams to translate regulatory obligations into DLP technical controls and audit evidence packages.
  • Provide guidance and mentorship to junior DLP analysts and engineers on tooling, investigation techniques, and policy management.
  • Support internal and external audits (SOX, PCI-DSS, regulatory examinations) by providing documentation, evidence, and technical walkthroughs.

Benefits

  • base salary
  • annual target bonus
  • discretionary bonuses
  • profit-sharing
  • long-term savings
  • healthcare
  • income protection
  • professional development opportunities
  • time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service