1

Dlp Engineer Jobs (NOW HIRING)

This role combines security operations with platform engineering: the analyst will investigate and respond to data loss prevention (DLP), insider risk, and endpoint security events while continuously ...

DLP Engineer, Purview

San Antonio, TX · On-site

$53.50 - $71.25/hr

... engineering * 2+ years of hands-on experience with Microsoft Purview (DLP, Information Protection, Sensitivity Labels) * Strong knowledge of data classification, labeling strategies, and information ...

DLP Network Engineer

Plano, TX

$100K - $136K/yr

DLP Engineer Location : Plano, TX Duration 12+ Months (Good Chance of Extension) Description : * Proven experience regarding architecture and design of technical solutions, preferably DLP related.

Phoenix Cyberis looking for a DLP Engineerto join our client delivery team. This position is onsite ... engineering services, operations services, sustainment services and managed security services to ...

Senior Security Engineer

Plano, TX · On-site

$109K - $150K/yr

Client is seeking a Senior Security Engineer to support a broader enterprise data security program ... The role will work alongside the client's internal security, DLP, and operations teams to triage ...

Als Consultant DLP Engineer (m/w/d) unterstutzt du unsere Kunden bei der technischen Implementierung und dem Betrieb von Data Leakage Prevention Losungen und tragst so zum Schutz von Daten vor ...

Host and Network based Data Loss Prevention (DLP) software * Email encryption software * Anti ... A Bachelor's Degree in Computer Science or Engineering or equivalent experience * Coding/Scripting ...

Host and Network based Data Loss Prevention (DLP) software * Email encryption software * Anti ... A Bachelor's Degree in Computer Science or Engineering or equivalent experience * Coding/Scripting ...

next page

Showing results 1-20

Dlp Engineer information

See salary details

$30.5K

$68.6K

$115.5K

How much do dlp engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for dlp engineer in the United States is $68,617.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,000.00 and $74,500.00 per year, depending on experience, location, and employer.

What is a DLP engineer?

A DLP Engineer is an information security professional who specializes in Data Loss Prevention (DLP) technologies and strategies. They design, implement, and manage systems to prevent unauthorized access, sharing, or leakage of sensitive data within an organization. Their responsibilities include configuring DLP software, monitoring data flows, responding to incidents, and ensuring compliance with data protection regulations. DLP Engineers work closely with IT and security teams to protect intellectual property and confidential information. They also provide guidance on best practices for data security across the company.

What are the key skills and qualifications needed to thrive as a DLP engineer?

To thrive as a DLP Engineer, you need a solid background in information security, network protocols, and data protection strategies, often supported by a degree in computer science or cybersecurity. Familiarity with Data Loss Prevention (DLP) tools like Symantec DLP, Forcepoint, or Microsoft Information Protection, as well as relevant certifications such as CISSP or CISM, is typically required. Strong analytical thinking, problem-solving abilities, and effective communication skills help in identifying vulnerabilities and collaborating with stakeholders. These skills are crucial for safeguarding sensitive information, ensuring compliance, and mitigating data breaches within an organization.

What are the most common challenges faced by DLP engineers when implementing data loss prevention solutions in large organizations?

DLP Engineers often encounter challenges such as balancing robust data protection with business productivity, managing false positives, and ensuring compliance with evolving regulations. Integrating DLP solutions with existing IT infrastructure can be complex, requiring strong collaboration with IT, security, and business units. Additionally, ongoing user education and policy refinement are essential to adapt to changing data flows and minimize operational disruptions.

What is the difference between Dlp Engineer vs Data Security Analyst?

AspectDlp EngineerData Security Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Data Privacy Solutions Engineer (CDPSE)CISSP, Certified Information Security Manager (CISM)
Work EnvironmentFocuses on implementing and managing Data Loss Prevention tools and policies within IT/security teamsAnalyzes security risks, monitors data breaches, and develops security strategies
Industry UsageUsed in organizations with data protection needs, especially in finance, healthcare, and techCommon across industries for overall data security and compliance

The Dlp Engineer primarily focuses on deploying and maintaining Data Loss Prevention solutions to prevent data leaks, while the Data Security Analyst monitors security threats and analyzes data breach incidents. Both roles require security certifications and work within similar environments, but their core responsibilities differ in implementation versus analysis.

More about Dlp Engineer jobs

What cities are hiring for Dlp Engineer jobs?

Cities with the most Dlp Engineer job openings:

What are the most commonly searched types of Dlp Engineer jobs?

The most popular types of Dlp Engineer jobs are:

What states have the most Dlp Engineer jobs?

States with the most job openings for Dlp Engineer jobs include:

What are popular job titles related to Dlp Engineer jobs?

For Dlp Engineer jobs, the most frequently searched job titles are:

Infographic showing various Dlp Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 92% Full Time, 3% Part Time, and 4% Contract. Highlights an 85% Physical, 4% Hybrid, and 11% Remote job distribution, with an average salary of $68,617 per year, or $33 per hour.

DLP Engineer

Memphis, TN • On-site

Other

Posted 9 days ago


Key responsibilities

  • Monitor, triage, investigate, and respond to DLP, insider risk, and endpoint security alerts and incidents.

  • Determine incident scope, document findings, and coordinate containment, escalation, and remediation.

  • Administer and tune Microsoft Purview DLP policies, rules, and related controls.


Job description

Data Security & Insider Risk Analyst

Suggested alternate title: Data Security Analyst – DLP & Insider Risk

Position Summary

We are seeking a hands‑on Data Security & Insider Risk Analyst to protect sensitive information across Microsoft 365, endpoints, and other enterprise platforms. This role combines security operations with platform engineering: the analyst will investigate and respond to data loss prevention (DLP), insider risk, and endpoint security events while continuously tuning Microsoft Purview policies, detections, and workflows to improve accuracy and reduce risk. The ideal candidate is analytical, curious, and comfortable translating security data into clear findings and practical control improvements.

Key Responsibilities
  • Monitor, triage, investigate, and respond to DLP, insider risk, and endpoint security alerts and incidents.
  • Determine incident scope, business context, data sensitivity, user activity, and potential impact; document findings and coordinate appropriate containment, escalation, and remediation.
  • Administer and tune Microsoft Purview DLP policies, rules, sensitive information types, classifiers, alert thresholds, exceptions, and user notifications.
  • Support DLP controls across Exchange, SharePoint, OneDrive, Teams, endpoints, browsers, removable media, printing, clipboard activity, and cloud applications, as applicable.
  • Review false positives, false negatives, user overrides, and recurring alert patterns; recommend and implement policy improvements.
  • Support Microsoft Purview Insider Risk Management use cases, indicators, policies, alerts, cases, and privacy‑aware investigation workflows.
  • Partner with identity, corporate security, human resources, incident response teams, and line‑of‑business teams during investigations, containment, remediation, and control changes.
  • Use Microsoft Purview, Microsoft Defender, SentinelOne EDR, Splunk SIEM, audit, identity, and endpoint telemetry to build investigation timelines, correlate activity, and validate findings.
  • Create dashboards, metrics, and trend analyses that communicate incident volume, policy effectiveness, data movement, root causes, and control gaps.
  • Develop and maintain procedures, investigation playbooks, tuning standards, exception records, and knowledge articles.
  • Participate in testing, change management, and phased deployment of new or updated data protection controls.
  • Identify opportunities for automation, enrichment, and workflow integration that improve response speed and consistency.
Required Qualifications
  • Experience in information security, data protection, security operations, incident response, threat analysis, compliance operations, criminology, law enforcement, corporate security, fraud investigation, or a related discipline. Candidates with transferable investigative experience are encouraged to apply.
  • Working knowledge of DLP concepts, data classification, sensitive data handling, insider risk, and common data exfiltration paths.
  • Ability to investigate alerts using evidence from users, devices, applications, email, collaboration platforms, and audit logs.
  • Experience configuring or tuning security policies, detections, rules, or alerting logic in an enterprise environment.
  • Strong analytical and problem‑solving skills, including the ability to distinguish legitimate business activity from potential misuse.
  • Clear written and verbal communication skills, with the judgment to handle sensitive investigations professionally and confidentially.
  • Ability to manage multiple investigations and tuning efforts while maintaining accurate case documentation.
Preferred Qualifications
  • Hands‑on experience with Microsoft Purview Data Loss Prevention, Endpoint DLP, Insider Risk Management, Information Protection, Data Explorer, Activity Explorer, or related capabilities.
  • Hands‑on experience with Zscaler Data Loss Prevention (DLP), including policy configuration, content inspection, alert investigation, false‑positive tuning, or data exfiltration controls across web, cloud applications and email.
  • Experience investigating Microsoft Purview alerts and incidents through Microsoft Defender or an integrated SIEM/SOAR workflow.
  • Experience using any endpoint detection and response (EDR) platform to investigate endpoint activity, correlate alerts, or support containment and remediation. Experience with comparable EDR tools is readily transferable to SentinelOne, which is used in this role.
  • Data analytics or reporting experience using Power BI, Tableau, SQL, Kusto Query Language (KQL), Excel, or similar tools.
  • Experience using any security information and event management (SIEM) platform for searching, correlation, dashboards, reporting, or investigation support. Experience with comparable SIEM tools is readily transferable to Splunk, which is used in this role.
  • Understanding of Microsoft 365 services, Microsoft Entra ID, endpoint management, audit logging, and cloud security concepts.
  • Experience in a regulated industry or with privacy, records management, legal, HR, or compliance stakeholders.
  • Relevant certifications, such as Microsoft Information Protection and Compliance Administrator (SC‑400), Microsoft Security Operations Analyst (SC‑200), Security+, or equivalent practical experience.
  • Professional experience in criminology, law enforcement, corporate security, fraud, investigations, or a similar field that demonstrates sound investigative judgment, evidence handling, interviewing, case management, or pattern analysis.
What Success Looks Like
  • DLP and insider risk alerts are investigated promptly, consistently, and with clear supporting evidence.
  • Policies become more effective over time, with fewer unnecessary alerts and better coverage of meaningful risk.
  • Incident trends and control gaps are translated into measurable recommendations for security and business partners.
  • Investigation procedures, tuning decisions, and exceptions are documented and repeatable.
  • Data security, endpoint security, and business stakeholders collaborate effectively on remediation and risk reduction.
Ideal Candidate Profile

You enjoy both sides of data security operations: working an alert through investigation and resolution, then using what you learned to improve the control that generated it. You can analyze technical evidence, understand business context, communicate findings without unnecessary jargon, and make thoughtful tuning decisions that balance protection with user productivity.

#J-18808-Ljbffr