1

Senior Dlp Engineer Jobs in Reston, VA (NOW HIRING)

Senior Engineer I, IT Systems

Bethesda, MD ยท On-site

$111K - $152K/yr

Senior Engineer I (ITSys) Reports to: Senior Director, Cloud Ops POSITION SUMMARY: The Senior ... Experience troubleshooting and optimizing the security tools (Endpoint Security, DLP, HIPS, etc.

Showing results 41-60

Senior Dlp Engineer information

See Reston, VA salary details

$76.5K

$142.7K

$194K

How much do senior dlp engineer jobs pay per year?

As of Sep 2, 2026, the average yearly pay for senior dlp engineer in Reston, VA is $142,665.00, according to ZipRecruiter salary data. Most workers in this role earn between $119,100.00 and $163,300.00 per year, depending on experience, location, and employer.

What is a senior DLP engineer?

Senior DLP (Data Loss Prevention) Engineers are cybersecurity professionals responsible for designing, implementing, and managing systems that protect sensitive data from unauthorized access, leakage, or loss. They work with DLP tools and policies to monitor data movement across networks, endpoints, and cloud environments. In addition to technical configuration, they often lead incident response efforts related to data breaches and provide guidance on best practices for data security. Their role also includes collaborating with other IT and compliance teams to ensure regulatory requirements are met and data security strategies are up to date.

What are the key skills and qualifications needed to thrive as a senior DLP engineer?

To thrive as a Senior DLP Engineer, you need deep expertise in information security, data loss prevention strategies, and a solid understanding of network and endpoint security, usually supported by a relevant degree and industry certifications like CISSP or CISM. Proficiency with DLP platforms such as Symantec or Forcepoint, SIEM tools, and scripting languages is typically required. Strong analytical thinking, problem-solving abilities, and effective communication help you collaborate across teams and respond to incidents efficiently. These skills and qualifications are critical for protecting sensitive data, ensuring regulatory compliance, and mitigating security risks within organizations.

What are some typical challenges a senior DLP engineer faces when implementing data loss prevention solutions across a large organization?

A Senior DLP Engineer often encounters challenges such as balancing security policies with user productivity, ensuring consistent DLP enforcement across various endpoints and cloud environments, and adapting to evolving data privacy regulations. Coordinating with multiple departments to understand data flows and classifying sensitive information accurately is also a key part of the role. Additionally, troubleshooting false positives and keeping up with emerging threats requires continuous learning and effective communication with IT and compliance teams.

What is the difference between Senior Dlp Engineer vs Data Security Engineer?

AspectSenior Dlp EngineerData Security Engineer
CredentialsCertifications like CISSP, CISA, or DLP-specific trainingCertifications such as CISSP, CISA, or Security+
Work EnvironmentFocus on Data Loss Prevention tools and policies within security teamsBroader security infrastructure, including data, network, and application security
Industry UsageCommon in organizations with strict data compliance needsWidespread across industries focusing on overall security architecture

The Senior Dlp Engineer specializes in Data Loss Prevention technologies and policies, primarily focusing on protecting sensitive data. In contrast, a Data Security Engineer has a broader role, encompassing various security measures beyond DLP. Both roles require similar certifications and are integral to organizational security strategies, but their scope and focus differ.

What are popular job titles related to Senior Dlp Engineer jobs in Reston, VA?

For Senior Dlp Engineer jobs in Reston, VA, the most frequently searched job titles are:

What job categories do people searching Senior Dlp Engineer jobs in Reston, VA look for?

The top searched job categories for Senior Dlp Engineer jobs in Reston, VA are:

What cities near Reston, VA are hiring for Senior Dlp Engineer jobs?

Cities near Reston, VA with the most Senior Dlp Engineer job openings:

Infographic showing various Senior Dlp Engineer job openings in Reston, VA as of August 2026, with employment types broken down into 72% Full Time, and 28% Contract. Highlights an 87% In-person, and 13% Remote job distribution, with an average salary of $142,665 per year, or $68.6 per hour.

Staff Cybersecurity Engineer, Detection & Response

ON.energy

Reston, VA โ€ข On-site

Full-time

This job post hasย expired today.ย Applications are no longer accepted.


Job description

ON.energy is hiring a Sr. Cybersecurity Engineer to run detection and response across the corporate security stack: the SIEM, the Defender suite, SaaS applications, and the data moving through them. A growing energy business generates significant signal across these four surfaces, and most of it currently goes unread. This is a SecOps role focused on detection ownership, response speed, and incident resolution. The underlying platforms that generate the telemetry are built and governed by other functions. This role owns turning that signal into alerts that matter and incidents that get closed.ย 

Key Responsibilities

Detection Engineering & Incident Responseย 

  • SIEM (Microsoft Sentinel): Deploy and own Sentinel in the Defender portal, data connectors across Entra, Defender XDR, M365, AWS, and SaaS sources, plus the retention and tiering decisions that keep ingestion cost defensible.ย 
  • Detection Engineering: Write and tune analytics rules and custom detections in KQL, mapped to MITRE ATT&CK. Run the tuning board; every rule requires a documented reason to exist, and noisy rules get fixed or killed.ย 
  • Incident Response: Own the IR lifecycle end to end for anything surfaced through Sentinel: triage, containment, eradication, and written post-incident review. Maintain playbooks for top scenarios (BEC, ransomware, credential compromise, third-party breach, DLP/insider risk escalation), run tabletops with IT, Legal, and Operations leadership, and lead the corporate side of any incident that crosses into OT.ย 

Endpoint, Email, App & Data Securityย 

  • Endpoint & Email (Defender): Own triage and response for Defender for Endpoint and Defender for Office 365 alerts: investigate, contain, and close the loop back into Sentinel detections. Does not own EDR policy architecture, ASR baselines, or the Intune device compliance program; that build sits with Endpoint/IT Engineering. Consumes their telemetry and detects against it.ย 
  • App Security (Defender for Cloud Apps): Own detection logic for risky OAuth grants, shadow IT, and anomalous app behavior, fed into Sentinel as first-class detections. Does not run the SaaS app approval and governance program itself; that's a GRC/IT governance function this role feeds, not owns.ย 
  • Data Security (Purview): Own detection and response for DLP and insider risk alerts flowing into Sentinel: investigate matches, determine real exposure, and drive the incident through to close. Does not design label taxonomy or author insider risk policy; that's a data governance function partnered with Legal and HR. Responds to what it produces.ย 

Governance, Risk & Complianceย 

  • Control Frameworks & Audit Support: Supply technical evidence and control-operation proof for SOC 2, ISO 27001, and NIST CSF 2.0 audits, and answer technical questions in customer security questionnaires, as directed by GRC. Does not own the audit relationship, the control framework, or the risk register; that sits with GRC. Proves the controls operated actually work.ย 

Cloud Securityย 

  • Consume AWS GuardDuty findings into Sentinel and write detections against them. AWS security architecture and IAM least-privilege design belong to DevOps; this role owns the telemetry pipeline into the SIEM, not that surface.ย 
Requirements
  • 5+ years of hands-on security operations and detection engineering experience, with real depth in at least two of: endpoint, email, SaaS, or data security telemetry, and hands-on ownership of incident response.ย 

Technical Stack Proficiency:ย 

  • Microsoft Sentinel: Hands-on deployment, data connectors, and detections written in KQL. Comfortable tuning for signal quality and managing ingestion cost.ย 
  • Defender suite: Working knowledge of Defender for Endpoint, Office 365, and Cloud Apps from a triage/response and detection-tuning angle, not policy architecture.ย 
  • Purview: Experience investigating DLP and insider risk alerts and translating them into incident response, not building the DLP program.ย 
  • Entra ID: Comfortable reading sign-in logs and Identity Protection risk signals for detection purposes, at a light touch. Deep Conditional Access/PIM architecture experience is not required.ย 
  • Automation: KQL, PowerShell, Graph API, or Python; sufficient to automate triage rather than perform it manually.ย 

Required Background:

  • Detection & Response Ownership: Demonstrated accountability for detection engineering and incident response outcomes across more than one telemetry source, beyond working a queue inside someone else's program.ย 
  • Incident Response: Experience leading real incidents through post-incident review, including briefing non-technical leadership.ย 
  • Compliance Support: Experience supplying technical evidence for a control framework audit (SOC 2, ISO 27001, NIST CSF, or similar) as the technical operator, without necessarily owning the audit relationship.ย 

Core Traits:ย 

  • Hands-on: Prefers writing the KQL that proves an alert is real over describing how to write it.ย 
  • Signal-disciplined: Every rule shipped has a documented reason to exist and gets tuned or killed when it stops earning its alert volume.ย 
  • Evidence-disciplined: Documents while building, shaped by experience on the wrong side of an audit sample where the control worked but the proof did not exist.ย 
  • Clear about lanes: Able to redirect an out-of-scope request to the correct owner without stalling the incident.ย 

Preferred:ย 

  • Experience running SecOps in a hybrid Microsoft-and-AWS environment.ย 
  • Background in energy, utilities, industrial, or another operationally critical sector, with enough IT/OT context to partner with an OT security engineer.ย 
  • Certifications: SC-200 (Security Operations Analyst), CISSP, GCIH, GCIA, or GCDA.ย