Senior DLP Security Engineer

Atlanta, Georgia

The Senior DLP Security Engineer will serve as the organization’s subject matter expert (SME) on Data Loss Prevention (DLP), spearheading the development and execution of a comprehensive DLP strategy. This role is essential in ensuring data protection through policy creation, implementation of preventive and detective controls, user behavior monitoring, and collaboration across various teams. The individual will also leverage SecurityDevOps practices and scripting to automate DLP processes and enhance security controls.

Additional Responsibilities

  • DLP Program Development: Lead the design and implementation of a cohesive DLP strategy, including data classification, policy creation, standards, and operational best practices to safeguard sensitive information.
  • Data Classification and Labeling: Develop and manage data classification schemes and collaborate with data owners to ensure data is accurately labeled according to sensitivity and regulatory requirements.
  • Data Discovery and Inventory Management: Use data discovery tools to locate and catalog sensitive data across on-premises and cloud environments, maintaining a dynamic inventory of sensitive data repositories.
  • Policy and Rule Configuration: Design, implement, and fine-tune DLP policies and detection rules to minimize false positives and optimize incident management.
  • User Behavior Analytics (UBA): Integrate user behavior analytics with DLP tools to detect abnormal data access or potential insider threats, developing models to monitor deviations in sensitive data handling.
  • Data Exfiltration Monitoring and Response: Create controls to monitor and detect data exfiltration attempts via multiple channels, working with Incident Response teams to contain and remediate potential data breaches.
  • Cloud and SaaS Data Protection: Develop DLP strategies specifically for cloud services and SaaS applications to extend data visibility and control in cloud environments.
  • Endpoint and Network DLP: Deploy and manage endpoint and network DLP solutions to ensure data protection on user devices and throughout network channels, such as email and web.
  • Data Masking and Tokenization: Implement data masking, encryption, and tokenization techniques to protect sensitive data in non-production environments, ensuring compliance without disrupting business functions.
  • Incident Analysis and Root Cause Identification: Analyze DLP incidents to determine root causes and implement preventive measures, collaborating with relevant teams to mitigate future incidents.
  • Metrics and Reporting: Define DLP metrics and KPIs to evaluate the program’s effectiveness, regularly reporting findings and trends to leadership to support data security initiatives.
  • Compliance Alignment and Auditing: Ensure DLP policies and controls align with industry regulations (e.g., GDPR, CCPA, HIPAA) and participate in compliance audits to assess and enhance the DLP program.
  • Third-party and Supply Chain Data Protection: Extend DLP controls to cover third-party and supply chain interactions, working with vendor management and legal teams to ensure sensitive data remains protected when shared externally.
  • Automation & Scripting: Leverage scripting languages (e.g., Python, PowerShell) to automate DLP processes, enhance security monitoring, and support the integration of DLP controls within existing systems.
  • Security Integration: Utilize SecurityDevOps practices to facilitate the deployment and maintenance of DLP and other security controls within CI/CD pipelines and automated workflows.
  • Collaboration with DevOps Teams: Partner with DevOps and engineering teams to ensure DLP requirements are embedded within development and deployment processes.
  • Security Controls Optimization: Identify and implement automation opportunities to improve the DLP program’s efficiency in detecting and responding to security incidents.

Experience

  • DLP Expertise: Strong understanding of DLP technologies, data classification, exfiltration monitoring, and endpoint/network DLP, particularly with Microsoft Purview and Varonis.
  • Policy Development: Experience in creating and managing data protection policies and governance processes, with the ability to adapt to regulatory requirements.
  • SecurityDevOps Knowledge: Familiarity with SecurityDevOps principles, CI/CD, and automation within DLP and security processes.
  • Scripting Proficiency: Proficient in scripting languages (e.g., Python, PowerShell) to support DLP automation.
  • Security Architecture: Ability to create reference security architectures and frameworks that incorporate DLP, SecurityDevOps, and automation.
  • Communication and Training: Excellent communication skills to present DLP and security concepts and conduct training on data handling and security requirements.
  • Cross-functional Collaboration: Proven ability to build relationships and secure buy-in across multiple teams to advance data protection initiatives.

Preferred Experience

  • Security Certifications: Recognized certifications (e.g., CISSP, CCSP, CISM, GSEC) focused on data protection, SecurityDevOps, or cloud security.
  • DLP & Security Engineering Experience: 7+ years’ experience as a Security Engineer with 2+ years of demonstrated experience working with DLP technologies; one year of demonstrated experience with SecurityDevOps.
  • Project Leadership: Experience leading DLP or security automation projects from design through deployment, with an emphasis on collaboration and cross-functional engagement.

Location Requirements
Atlanta, GA or Gainesville, FL

Pay range is commensurate with education, experience, specialized skills or certifications, etc.

Gas South Pay Range

$116,484 - $130,188 USD

Our Purpose and Culture

At Gas South, we approach each day knowing we have an opportunity to make a difference in people’s lives. That means helping our customers save money with everyday low rates and treating them with dignity, honesty and respect. It means supporting our employees in their personal and professional lives, and it means we want to make sure our success directly benefits the communities we serve by giving back 5% of profits to support children in need. Through partnerships with non-profits like United Way, Salvation Army, Junior Achievement, Bert’s Big Adventure and many others, we’re proud to help make a difference.  At Gas South our employees bring their boldest ideas and most authentic selves to work, no matter their title, position or background.  We understand that our people are our most valuable assets. So, we treat them that way, with competitive benefits, flexible schedule options, and a fun, casual atmosphere.

Gas South affirms that it is an Equal Opportunity Employer whose actions and practices are consistent with fair employment.  In this regard, Gas South will not discriminate against any employee or applicant with regard to race, color, religion, sex, age, national origin, disability, pregnancy, childbirth or related medical conditions, genetic information, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.  This policy applies to all terms and conditions of employment including recruiting, hiring, placement, training, promotion, lay-offs, transfers, leave of absence, compensation and termination.

Gas South is committed to fostering a diverse workforce and is an affirmative action employer.

Benefits for full-time employees include:

  • Full medical, dental, and vision coverage
  • Employer-paid life and disability coverage
  • Annual employer contributions of up to 12.5% to your 401k
  • Remote work options available based on business needs
  • Annual performance incentive is a % of annual benchmark based on position level
  • Paid four-week sabbatical every five years
  • Opportunities to volunteer in the community
  • Education assistance up to $5250 per year

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Gas South’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.