×
Register Here to Apply for Jobs or Post Jobs. X

Data Protection Engineer; Trellix), Zero Trust Program; TS​/SCI Security Clearance

Job in Tampa, Hillsborough County, Florida, 33601, USA
Listing for: Kentro
Full Time position
Listed on 2026-01-01
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Position: Data Protection Engineer (Trellix), Zero Trust Program (TS/SCI) with Security Clearance
Description Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities. By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development.

Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones. Kentro is hiring a specialized Data Protection Engineer (Trellix) to join the SIPR and Top-Secret Network Execution Teams for a major Zero Trust transformation at U.S. Special Operations Command (USSOCOM). While other roles focus on cloud-native security, this position is dedicated to securing the "tactical edge" and on-premises endpoints within the Command's classified environments.

As the Senior Trellix Engineer, you will be the technical authority for the design, deployment, and management of the Trellix (formerly McAfee) Data Loss Prevention (DLP) suite. You will be responsible for configuring and tuning the Trellix ePolicy Orchestrator (ePO) to enforce rigorous device control and data protection policies on workstations operating in disconnected and air-gapped environments. Your work will directly prevent the unauthorized exfiltration of classified intelligence via USB drives, printing, and clipboard transfer, ensuring that the Command's most sensitive networks remain secure against insider threats and accidental data loss.

Responsibilities:
* Trellix DLP Architecture:
Lead the design and configuration of Trellix DLP Endpoint policies within the ePolicy Orchestrator (ePO) on SIPR and Top-Secret networks to monitor and block unauthorized data transfer vectors (USB, Web, Print, Clipboard).

* Policy & Rule Tuning:
Create and refine complex data classification rules and regex patterns to identify specific USSOCOM sensitive data types, actively tuning policies to reduce false positives and transition from "Audit" to "Block" mode.

* Air-Gapped Operations:
Manage the unique lifecycle of the ePO environment on the Top-Secret network, including the manual "sneaker-net" transfer of policy updates, agent patches, and threat intelligence definitions.

* Integration:
Configure ICAP integration between Trellix and other security components (such as Kiteworks or Web Proxies) to extend DLP inspection to network traffic and file transfers.

* Incident Triage:
Serve as the Tier 3 escalation point for DLP incidents, analyzing blocked actions and working with the SOC/SIEM team to ensure alerts are properly ingested into Splunk.

Location:

Onsite in Tampa, FL Requirements
* Senior Level: Master of Science (MS) degree in Computer Science, Cybersecurity, Information Technology, or a related field.

* Senior Level: 10+ years of related technical experience.

* Trellix/McAfee Expertise:
Extensive (5+ years) hands-on experience architecting and administering Trellix (McAfee) ePolicy Orchestrator (ePO) and Data Loss Prevention (DLP) Endpoint products.

* Device Control:
Deep understanding of Device Control policies for managing removable storage, peripheral devices, and printing in a secure environment.

* Regex & Classification:
Proficiency in creating custom data identifiers using Regular Expressions (Regex) and dictionaries to detect sensitive information.

* Troubleshooting:
Proven ability to troubleshoot complex agent-based issues on Windows endpoints, including conflict resolution with other security software.

Preferred Experience & Skills ("Nice-to-Haves")
* Experience working in Air-Gapped or isolated network environments (e.g., JWICS, SAPs).

* Knowledge of Trellix Endpoint Security (ENS) and Threat Intelligence Exchange (TIE/DXL).

* Familiarity with Kiteworks or Boldon James for data classification integration.

* Experience with Splunk for log analysis and dashboarding.

Certifications:

* Required:

CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.

* Preferred:
Trellix Certified Specialist - Data Loss Prevention (DLP) or equivalent McAfee certification.
Clearance:
* Active Top-Secret…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary