×
Register Here to Apply for Jobs or Post Jobs. X

DLP Engineer

Job in Memphis, Shelby County, Tennessee, 37544, USA
Listing for: First Horizon Bank
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 120000 USD Yearly USD 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Job Description

Data Security & Insider Risk Analyst

Suggested alternate title:
Data Security Analyst – DLP & Insider Risk Position Summary

We are seeking a hands-on Data Security & Insider Risk Analyst to protect sensitive information across Microsoft 365, endpoints, and other enterprise platforms. This role combines security operations with platform engineering: the analyst will investigate and respond to data loss prevention (DLP), insider risk, and endpoint security events while continuously tuning Microsoft Purview policies, detections, and workflows to improve accuracy and reduce risk.

The ideal candidate is analytical, curious, and comfortable translating security data into clear findings and practical control improvements.

Key Responsibilities
  • Monitor, triage, investigate, and respond to DLP, insider risk, and endpoint security alerts and incidents.
  • Determine incident scope, business context, data sensitivity, user activity, and potential impact; document findings and coordinate appropriate containment, escalation, and remediation.
  • Administer and tune Microsoft Purview DLP policies, rules, sensitive information types, classifiers, alert thresholds, exceptions, and user notifications.
  • Support DLP controls across Exchange, SharePoint, One Drive, Teams, endpoints, browsers, removable media, printing, clipboard activity, and cloud applications, as applicable.
  • Review false positives, false negatives, user overrides, and recurring alert patterns; recommend and implement policy improvements.
  • Support Microsoft Purview Insider Risk Management use cases, indicators, policies, alerts, cases, and privacy-aware investigation workflows.
  • Partner with identity, corporate security, human resources, incident response teams, and line-of-business teams during investigations, containment, remediation, and control changes.
  • Use Microsoft Purview, Microsoft Defender, Sentinel One EDR, Splunk SIEM, audit, identity, and endpoint telemetry to build investigation timelines, correlate activity, and validate findings.
  • Create dashboards, metrics, and trend analyses that communicate incident volume, policy effectiveness, data movement, root causes, and control gaps.
  • Develop and maintain procedures, investigation playbooks, tuning standards, exception records, and knowledge articles.
  • Participate in testing, change management, and phased deployment of new or updated data protection controls.
  • Identify opportunities for automation, enrichment, and workflow integration that improve response speed and consistency.
Required Qualifications
  • Experience in information security, data protection, security operations, incident response, threat analysis, compliance operations, criminology, law enforcement, corporate security, fraud investigation, or a related discipline. Candidates with transferable investigative experience are encouraged to apply.
  • Working knowledge of DLP concepts, data classification, sensitive data handling, insider risk, and common data exfiltration paths.
  • Ability to investigate alerts using evidence from users, devices, applications, email, collaboration platforms, and audit logs.
  • Experience configuring or tuning security policies, detections, rules, or alerting logic in an enterprise environment.
  • Strong analytical and problem-solving skills, including the ability to distinguish legitimate business activity from potential misuse.
  • Clear written and verbal communication skills, with the judgment to handle sensitive investigations professionally and confidentially.
  • Ability to manage multiple investigations and tuning efforts while maintaining accurate case documentation.
Preferred Qualifications
  • Hands-on experience with Microsoft Purview Data Loss Prevention, Endpoint DLP, Insider Risk Management, Information Protection, Data Explorer, Activity Explorer, or related capabilities.
  • Hands-on experience with Zscaler Data Loss Prevention (DLP), including policy configuration, content inspection, alert investigation, false-positive tuning, or data exfiltration controls across web, cloud applications and email.
  • Experience investigating Microsoft Purview alerts and incidents through Microsoft Defender or an integrated SIEM/SOAR workflow.
  • Exper…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary