Requirements
The role requires 7+ years of information security or security operations experience, with at least 2 years of hands-on DLP administration or incident operations. A Bachelor's degree in computer science, Cybersecurity, Information Technology, Information Systems, Engineering or equivalent is mandatory. Postgraduate qualification in information/cyber security is an advantage. Must possess Forcepoint DLP Administrator training, SC-400 or equivalent Microsoft Purview training, and CompTIA Security+ or equivalent certification. Strong soft skills including excellent communication, analytical thinking, problem-solving, attention to detail, accountability, teamwork, and ability to prioritize are essential. Ability to work at client sites and provide after-hours support is also required.
Description
Job Purpose : -Operate and engineer client Data Loss Prevention controls under the direction of the DLP Specialist. The role performs platform administration, incident triage, policy implementation, testing, health monitoring, troubleshooting and evidence management across Forcepoint DLP, Microsoft Purview and connected data protection technologies.Primary Responsibilities : -Monitor DLP alert queues and triage incidents across endpoint, email, network, Microsoft 365 and cloud/SaaS channels.Validate incident context, policy match, data sensitivity, user activity and business justification; escalate high-risk cases promptly.Implement approved DLP policy changes, classifiers, thresholds, actions, exceptions and user notifications under change control.Execute test cases for monitor, coach, justify, quarantine and block actions before production deployment.Administer Forcepoint DLP components, endpoint agents, discovery tasks, connectors, policy deployments and system health checks.Support Microsoft Purview DLP, Endpoint DLP, sensitivity label integration and Activity/Content Explorer investigations.Investigate agent/connector failures, policy deployment issues, false positives, workflow errors and performance problems.Maintain allowlists, dictionaries, keyword lists, fingerprints, EDM datasets and detection patterns as approved.Create and update incidents, service requests, changes and problem records in the ITSM platform; meet agreed SLAs.Capture complete evidence, actions, approvals, communications, timestamps and closure rationale for audit readiness.Prepare operational reports covering alert volumes, policy hits, false positives, open cases, endpoint coverage and service health.Support DLP policy tuning, business-unit pilots, user communication and remediation validation.Follow least privilege, dual-control, data minimization and confidentiality requirements when handling sensitive data.Skills / Certifications: -Forcepoint DLP Administrator trainingSC-400 or equivalent Microsoft Purview trainingCompTIA Security+ or equivalentITIL Foundation (advantage)Soft skills: Excellent written and verbal communication, Analytical thinking and problem solving.Attention to detail and quality, Accountability and ownership, Teamwork and stakeholder collaboration.Ability to prioritize and meet deadlines.Ability to work at client sites and provide after-hours support when requiredMinimum Work Experience & Education: -7+ years of information security or security operations experience, including at least 2 years of hands-on DLP administration or incident operations.Bachelor's degree in computer science, Cybersecurity, Information Technology, Information Systems, Engineering or equivalent.Postgraduate qualification in information/cyber security is an advantage.