Job Description :
We are seeking a highly experienced and hands-on DLP Lead to spearhead our organization's data loss prevention strategy and implementation. The ideal candidate will be responsible for designing, deploying, and maintaining DLP solutions to safeguard sensitive business and customer information across digital channels.
Key Responsibilities :
- Lead the design, implementation, and continuous improvement of Data Loss Prevention (DLP) policies, procedures, and controls.
- Manage and configure DLP solutions such as Symantec, Microsoft Purview DLP, Forcepoint, McAfee, etc.
- Monitor, analyze, and respond to DLP incidents, and perform root cause analysis of potential data breaches or leaks.
- Collaborate with Legal, Compliance, IT, and Security teams to ensure alignment with data governance and privacy regulations (e.g., GDPR, HIPAA, RBI Guidelines).
- Drive user awareness campaigns, documentation, and training on DLP best practices.
- Regularly review and enhance DLP rulesets to address evolving threats and changing business needs.
- Conduct periodic audits, compliance checks, and reporting for executive and regulatory stakeholders.
- Work with vendors and partners on DLP technology upgrades, support, and issue resolution.
Required Qualifications :
7-12 years of experience in Cybersecurity / Information Security, with 3+ years focused on DLP implementation and operations.Hands-on experience with enterprise DLP platforms (Microsoft 365 DLP, Symantec DLP, Forcepoint, McAfee, etc.).Strong understanding of data classification, encryption, endpoint protection, network security, and cloud DLP strategies.Familiarity with regulatory compliance requirements : GDPR, ISO 27001, PCI DSS, SOX, etc.Ability to identify and remediate data protection vulnerabilities in on-prem and cloud environments (e.g., AWS, Azure, GCP).Excellent analytical, communication, and incident-handling skills.Preferred Qualifications :
Certifications such as CISSP, CISM, CEH, or Certified Data Privacy Solutions Engineer (CDPSE).Experience in SIEM integration and threat intelligence systems.Familiarity with CASB tools and Information Rights Management (IRM).(ref : hirist.tech)