368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$114k – $211k per year (Estimated)
Location
Remote (United States)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Fragomen (Fragomen, Del Rey, Bernsen & Loewy, LLP) is a global corporate immigration law firm and professional services organization headquartered in Matawan, New Jersey. Founded in 1951 by William F. Fragomen, the firm has grown into the world's largest law practice exclusively dedicated to immigration law, operating over 50 offices across the Americas, EMEA, and Asia-Pacific regions. Fragomen provides comprehensive global mobility, visa, work permit, compliance, and immigration consulting services for multinational corporations, government entities, and private clients.

Job Description

About the Role

Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Data Loss Prevention (DLP), sensitive data governance, SaaS and cloud data protection, and security control engineering to join our Information Security & Cyber Security team.

Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and protecting sensitive client, employee, and firm data is critical to its success. We are seeking a professional who is passionate about reducing data exposure risk, engineering practical DLP controls, and partnering across Legal, Compliance, Privacy, Risk, IT, and business teams to mature enterprise data protection capabilities.

You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in designing, implementing, tuning, and operating DLP controls across email, endpoint, cloud, SaaS, and collaboration platforms while helping strengthen Fragomen’s overall security posture.

How Will You Make a Difference at Fragomen?

As a Security Engineer focused on Data Loss Prevention, you will:

  • Design, implement, and tune enterprise DLP policiesacross Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms.

  • Identify, classify, and protect sensitive informationusing data classification, sensitivity labels, policy conditions, and appropriate enforcement actions.

  • Monitor and investigate DLP alerts involving potential data exposure, improper sharing, data exfiltration indicators, or policy violations.

  • Partner with Legal, Compliance, Privacy, Risk, Records, and business stakeholders to align DLP controls with regulatory, legal, client, and operational requirements.

  • Develop and maintain DLP standards, operating procedures, runbooks, exception processes, and escalation workflows.

  • Evaluate and improve controls for collaboration platforms and file-sharing tools, including OneDrive, SharePoint, Box, Google Drive, Dropbox, ShareFile, NetDocuments, and similar services.

  • Support CASB and SaaS governance efforts by helping identify unsanctioned data movement, risky sharing behavior, excessive permissions, and opportunities for policy enforcement.

  • Conduct root cause analysis on recurring alerts, control gaps, and data handling issues to improve policy quality and reduce false positives.

  • Collaborate with security operations, identity, messaging, endpoint, network, and application teams to integrate DLP telemetry into SIEM, SOAR, monitoring, and response processes.

  • Prepare clear, business-appropriate communications for end users, technical teams, stakeholders, and leadership regarding DLP findings, policy changes, and recommended corrective actions.

  • Provide technical guidance and mentorship to junior analysts and security team members on DLP investigations, data handling risk, and control operations.

Leverage Your Skills and Experience

Required Qualifications

  • 5+ years of experience in cybersecurity, data protection, security operations, governance, risk, compliance, or related technology roles, or equivalent combination of education and experience.

  • Working knowledge of DLP concepts, sensitive data handling, information protection, data classification, and policy-based enforcement.

  • Hands-on experience supporting or operating security controls in enterprise environments, especially within Microsoft 365, email, endpoint, cloud, or SaaS platforms.

  • Ability to analyze DLP alerts, user activity, sharing patterns, policy matches, and event logs to determine business impact and appropriate response.

  • Working knowledge of identity and access concepts, authentication mechanisms, file permissions, collaboration tooling, and data sharing workflows.

  • Strong written and verbal communication skills, including the ability to explain technical findings in clear, practical, and business-appropriate language.

  • Demonstrated ability to follow structured processes while continuously improving them.

Technical Knowledge

  • Microsoft Purview Information Protection and DLP, including sensitivity labels, trainable classifiers, data loss prevention rules, audit logs, alerts, and policy tuning.

  • Microsoft Defender for Cloud Apps, cloud app governance, CASB concepts, SaaS discovery, session controls, and cloud data exposure monitoring.

  • Endpoint, email, and collaboration security controls across Windows, Microsoft 365, Exchange Online, Teams, SharePoint, and OneDrive.

  • SIEM and security platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar tools used to correlate DLP and security telemetry.

  • Common sensitive data types and regulatory drivers, such as PII, PCI, PHI, financial data, client confidential information, legal matter data, and regulated business records.

  • Core networking and platform concepts including TCP/IP, DNS, HTTP/S, VPNs, proxies, firewalls, APIs, and cloud storage patterns.

Preferred Qualifications

  • Experience engineering or administering Microsoft Purview DLP, Endpoint DLP, Information Protection, Insider Risk Management, eDiscovery, Audit, or Data Lifecycle Management.

  • Experience with CASB, SaaS security, cloud access governance, or file-sharing risk management across platforms such as Box, Google Drive, Dropbox, ShareFile, NetDocuments, Salesforce, ServiceNow, or similar applications.

  • Experience supporting investigations involving Legal, Compliance, Privacy, Risk, Records, HR, or regulatory stakeholders.

  • Experience with SOAR, ticketing, workflow automation, and process documentation for recurring security operations activities.

  • Knowledge of secure collaboration practices, permission review, data retention, acceptable use, and exception governance.

  • Relevant certifications, including Microsoft Security, Compliance, and Identity certifications; CISSP, SSCP, Security+, CISA, CISM; GIAC security certifications; or vendor certifications for DLP, CASB, SIEM, or endpoint platforms.

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position’s location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI-assisted tools for administrative screening purposes only - never for decision-making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
United States
$143k – $184k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Cooper
DevOps
Azure
IAM
Cybersecurity
FedRAMP
Microsoft Defender
Nessus
NIST 800-53
Apply
$18k – $39k per year (Estimated) • In office • Full-Time • 3+ years exp • Bhubaneswar
DevOps
Splunk
Apply
$50k – $68k per year • In office • Full-Time • 3+ years exp • United States
SQL
DevOps
Splunk
VMWare
Windows Server
Apply
$83k – $166k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Singapore
Python
DevOps
Splunk
Cybersecurity
PCI DSS
Apply
$133k – $284k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Singapore
DevOps
Incident Management
SLI/SLO/SLA
Splunk
Management
Confluence
ServiceNow
Apply
Product Owner 8 days ago
$133k – $239k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • United States
AI/ML
Claude
Claude Code
Apply
$80k – $149k per year (Estimated) • In office • Full-Time • 2+ years exp • Associate's Degree • Montreal
Apply
I9 Help Desk Manager 3 months ago
$80k – $158k per year (Estimated) • Remote • Full-Time • 7+ years exp • Bachelor's Degree • United States
Management
ServiceNow
Apply
$116k – $214k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • United States
Python
C#
C#
.NET
Cybersecurity
Threat Modeling
Apply
WorkRight Analyst 6 months ago
Remote/Hybrid • Full-Time
Apply
$78k – $130k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Cary • San Jose
Analytics
Power BI
Apply
$91k – $182k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • United States
Design
SolidWorks
Apply
$45k – $60k per year • Remote • Full-Time • 2+ years exp • PhD • United States
Cybersecurity
HIPAA
Apply
$117k – $258k per year (Estimated) • Equity • Remote • Full-Time • United States
C++
Java
Python
Cybersecurity
Crowdstrike
Apply
$90k – $184k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp • United States
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Cobalt Strike
Crowdstrike
Metasploit
MITRE ATT&CK
Nessus
Nmap
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.