Senior DLP Red Team Engineer
Charlotte, VT - USA
Job Summary
Red Team Analyst Data Loss Prevention (Enterprise Information Protection)
Summary:
The Red Team Analyst Data Loss Prevention will serve as an offensive security specialist within the Enterprise Information Protection (EIP) program responsible for testing validating and stress testing DLP controls against real world insider threat and data exfiltration scenarios.
This role focuses on thinking like a malicious insider employee contractor or compromised identity to simulate and execute data loss techniques across endpoints email cloud collaboration platforms and unstructured data repositories. Findings will directly inform control improvements detection tuning policy enforcement and insider risk modeling across EIP and Insider Risk programs.
Responsibilities:
1) Design and execute red team style data exfiltration scenarios aligned to insider threat negligent user and compromised account risk.
2) Simulate data loss techniques across endpoint email cloud storage collaboration tools web upload printing and removable media.
3) Test DLP controls for bypass techniques misconfigurations policy gaps and detection blind spots.
4) Emulate high risk behaviors tied to role based access privileged users leavers and third party identities.
5) Validate effectiveness of DLP policies sensitivity labels endpoint controls and alerting logic.
6) Partner with EIP engineering teams to tune detection rules thresholds and policy guardrails.
7) Execute testing tied to new DLP capabilities roadmap initiatives and tool deployments (e.g. endpoint DLP unstructured data controls).
8) Produce clear defensible reports outlining attack paths control weaknesses risk severity and remediation guidance.
9) Present findings to EIP leadership Insider Risk governance forums and control owners.
10) Track remediation activities and validate improvements through re testing.
Skills:
1) 5 years of experience in red team offensive security purple team or adversary simulation roles.
2) Proven experience testing or bypassing Data Loss Prevention (DLP) or data protection controls.
3) Strong understanding of insider threat behaviors data exfiltration techniques and endpoint attack vectors.
4) Hands on experience with endpoint email cloud and collaboration security controls.
5) Ability to translate technical findings into business and risk relevant insights.
6) Direct experience working with Varonis Microsoft Purview (DLP Information Protection Insider Risk) and Proofpoint environments (TRAP TAP CASB).
7) Experience testing unstructured data environments and user driven data movement.
8) Knowledge of threat modeling frameworks applied to human centric and insider risk.
9) Background in regulated industries (financial services healthcare or technology).
| Skill | Your experience in years |
| Red Team & Data Exfiltration Simulation |
|
| DLP Control Testing & Bypass Techniques |
|
| Insider Threat & Human-Centric Risk Analysis |
|
| Security Tooling Expertise (Varonis Purview Proofpoint) |
|
| Reporting Risk Translation & Stakeholder Communication |
|
Brandon Consulting Associates Inc. is an EQUAL OPPORTUNITY EMPLOYER and has been in business for 29years.