Security Operations Data Loss Prevention Engineer
Pure Storage · Lehi, Utah; Santa Clara, California
About this role
**Security Operations Data Loss Prevention (DLP) Engineer** **About Everpure** Everpure (NYSE: P) has evolved from storage pioneer to a data platform, closing fiscal 2026 with **$3.7B revenue**, its first **billion-dollar quarter**, and accelerating growth into FY27. The company’s strategic agenda spans hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem. --- ## **The Role** As our **Security Operations Data Loss Prevention (DLP) Engineer**, you will own and elevate Everpure’s enterprise data protection strategy across **digital and physical** vectors. In this high-impact individual contributor role, you will establish **data governance standards** and architect **practical controls** that safeguard customer information, source code, intellectual property, and other sensitive assets—without hindering business velocity. You’ll partner with **Engineering, Legal, Privacy, DevSecOps, and GISO leadership** to define how sensitive data is discovered, classified, monitored, and protected across the enterprise. --- ## **What You’ll Do** - **Architect Enterprise DLP Strategy**: Own and mature a multi-channel DLP program end to end across **endpoint, network, SaaS, applications, cloud, and generative AI** environments. Define program metrics, evaluate build-versus-buy decisions, and report posture to GISO leadership. - **Establish Data Standards & Governance**: Author data-classification frameworks, handling requirements, and exception processes. Maintain a sensitive-data map with data owners to clarify **where regulated/proprietary data lives** and **who is accountable**. - **Protect Endpoints & Physical Channels**: Design and operate controls across **macOS, Windows, and Linux**, including **removable media, printing, clipboard, screen capture, and local cloud-sync**. Define hard-copy handling, device disposal, and media sanitization needs (including manufacturing and lab environments). - **Protect Network, Application & Cloud Data**: Define egress inspection strategies across **email, web, and network traffic**, including practical **SSL/TLS inspection boundaries** and encrypted-flow visibility. Detect and prevent sensitive-data movement through **applications, APIs, databases, file shares, CI/CD systems, and unstructured repositories** (partnering with Cloud and DevSecOps across **AWS, Azure, and GCP**). - **Protect AI Workflows & Sensitive Assets**: Establish guardrails for sensitive data flowing into/out of **public AI assistants**, embedded copilots, internal models, and agentic tools—covering prompt content, file uploads, context windows, tool integrations, source code, and build-system secrets. - **Build Detections & Automate Response**: Design and maintain high-fidelity DLP detections using **regex, EDM/IDM, document fingerprinting, custom classifiers**, and contextual conditions. Build **SIEM queries**, correlate DLP events with identity/asset/vulnerability/threat context, and integrate telemetry with **SOAR** to reduce false positives and manual effort. - **Lead Investigations & Continuous Improvement**: Investigate significant data-loss events by reconstructing what left the enterprise, which channel it used, and the impact. Serve as escalation for complex findings, brief Legal/Privacy/HR/leadership, support audit/compliance, and maintain runbooks and program documentation. - **Workplace Location**: Primarily **in-office**. Expected to work from the **Santa Clara or Lehi of
Listing freshness
CronJobs last confirmed this listing 50m ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.