IT Security Engineer - DLP and CASB Engineering - Remote
Job Description
We are actively hiring for an IT Security Engineer - DLP and CASB Engineering - Remote
Your Role: We are seeking an experienced and highly skilled Security DLP and CASB Engineer with deep expertise in Microsoft Purview DLP, Netskope DLP/CASB, cloud security, and enterprise data protection engineering. This senior role will own the design, implementation, optimization, and ongoing management of DLP and CASB solutions across cloud and hybrid environments. The ideal candidate brings strong technical depth, architectural awareness, and the ability to collaborate across IT, Cloud, Cybersecurity, and Business teams to build scalable, modern, and proactive dataprotection capabilities.
Your Work: Security Engineering - DLP & CASB Specialist (Cloud Data Protection)
1. DLP Engineering, Architecture & Implementation
• Design, implement, and optimize enterprisewide DLP controls using Microsoft Purview DLP, Information Protection, and Netskope DLP/CASB.
• Engineer DLP policies, classifiers, exceptions, and workflows for cloud (SaaS, IaaS, PaaS), endpoint, and web channels.
• Lead integration of DLP and CASB tools with cloud platforms including AWS, Azure, and Google Cloud.
2. Cloud Security Integration
• Partner with cloud architects and application teams to embed DLP and CASB controls into cloud-native environments.
• Support secure data flows across S3, Blob, Snowflake, SQL, and SaaS applications through technical integrations and bestpractice configurations.
3. Policy Development & Tuning
• Develop and enforce advanced DLP policies aligned to security standards, regulatory requirements, and risk tolerance.
• Minimize false positives through tuning, advanced SIT/classifier creation, and rule optimization.
4. Monitoring, Analytics & Automation
• Work closely with SOC and SIEM teams (Splunk preferred) to ensure highfidelity telemetry and alerting.
• Build dashboards, analytics, and automation opportunities that improve detection and reduce manual effort.
• Identify trends and potential gaps, driving proactive mitigation strategies.
5. Incident Response & Troubleshooting
• Serve as a technical expert for complex DLP and CASB incidents.
• Perform rootcause engineering, propose long-term fixes, and partner with SOC on response playbooks.
6. Governance, Compliance & Reporting
• Provide leadership in mapping DLP controls to GDPR, CCPA, PCI, HIPAA, and other frameworks.
• Deliver executivelevel reporting and insights to leadership on DLP posture, risks, and improvements.
7. Documentation, Standards & Training
• Develop standards for data classification, masking, retention, archival, and secure data flows.
• Maintain technical documentation, SOPs, and lead stakeholder education workshops.
8. Continuous Improvement & Tool Evaluation
• Assess new DLP, CASB, and cloud security capabilities; lead POCs and vendor evaluations.
• Drive modernization efforts, platform migrations, and optimization initiatives.
• Perform advanced analysis of DLP and CASB events across Microsoft Purview, Netskope, MDCA, and related tools.
• Identify patterns, trends, mis-configurations, and gaps in controls; recommend or implement tuning and policy improvements.
• Develop and refine DLP rules, classifiers, exceptions, and highfidelity detections to reduce false positives and strengthen dataloss prevention coverage.
CrossFunctional Collaboration
• Partner closely with SOC, Cyber Defense, and Security Engineering to align on priorities, establish bestpractice playbooks, and improve DLP/incident response workflows.
• Work with IT, Cloud, and Business partners to design scalable, efficient, and compliant processes for protecting internal and external data flows.
• Educate and influence interested parties on DLP findings, risk areas, and recommended mitigations.
RiskBased Strategy & Governance
• Apply a riskbased approach to analyze, prioritize, and remediate data protection risks across the enterprise.
• Ensure alignment with regulatory requirements (GDPR, CCPA, PCI, HIPAA where applicable) and corporate security standards.
• Contribute to governance activities, including policy development, standards, and control architecture.
Continuous Improvement & Innovation
• Stay current on emerging dataprotection threats, cloudsecurity trends, and DLP/CASB industry capabilities.
• Recommend modernization opportunities in DLP technologies, automation, and process streamlining.
• Support and/or lead security awareness and training efforts related to data protection.
Required Experience, Education and Skills
• 7-10+ years in DLP engineering, cybersecurity, or cloud security roles.
• Strong handson experience with Microsoft Purview, AIP, labels, classifiers, DLP/Information Protection,
• Netskope DLP/CASB, and cloud security controls.
• Proven experience engineering DLP policies, integrating with cloud apps, and supporting enterprise-scale environments.
Deep understanding of:
• MDCA / Defender for Cloud Apps
• AWS, Azure, GCP data-protection patterns
• SIEM (Splunk), log pipelines, dashboards
• Strong troubleshooting and root-cause analysis skills.
• Excellent communication, documentation, and cross-functional collaboration abilities.
• Ability to translate technical DLP concepts for non-technical partners.
• Demonstrated leadership in driving security best practices across teams.
What would make us excited about you?
• CCSP, CISSP, CISM, Azure Security Engineer, AWS Security Specialty, Netskope or Microsoft certifications.
• Vendor certifications (Microsoft Security, Netskope, etc.) are a plus.
• Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)
• Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
• Travels as needed for role, including divisional / team meetings and other in-person meetings
• Fulfills business needs, which may include investing extra time, helping other teams, etc
Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska.
#LI-SB1
Why Choose a Career at CSAA IG?
At CSAA IG, we are a mission-driven organization proudly committed to empowering our members, our employees, and our communities to thrive.
Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at [https://careers.csaainsurance.aaa.com/us/en/benefits](https://careers.csaainsurance.aaa.com/us/en/benefits).
Career Growth: We believe in growth for everyone. Here at CSAA IG, leaders and mentors partner with employees to align interests, unlock development opportunities, and support longterm success.
Flexible Workplace: We embrace a remote-first culture through our Flexible Workplace. Most employees hold Home-Flex roles, working primarily from home, often with the flexibility to work from various locations including CSAA offices. Our flexible workplace empowers you to balance remote work with intentional inperson moments that deepen connection and collaboration.
Inclusion and Belonging: An inclusive and welcoming workplace is the cornerstone of our success. By fostering an environment where people feel valued and heard, we deepen our ability to understand and meet the unique needs of our members. This strengthens innovation and enhances our products and services, giving us a competitive edge in the market.
Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don't miss important updates from us.
CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations. If you would like to request an accommodation to participate in the job application or interview process, please contact [TalentAcquistion@csaa.com](mailto:TalentAcquistion@csaa.com)
If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.
CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
CSAA Insurance Group is an equal opportunity employer.
We are actively hiring for an IT Security Engineer - DLP and CASB Engineering - Remote
Your Role: We are seeking an experienced and highly skilled Security DLP and CASB Engineer with deep expertise in Microsoft Purview DLP, Netskope DLP/CASB, cloud security, and enterprise data protection engineering. This senior role will own the design, implementation, optimization, and ongoing management of DLP and CASB solutions across cloud and hybrid environments. The ideal candidate brings strong technical depth, architectural awareness, and the ability to collaborate across IT, Cloud, Cybersecurity, and Business teams to build scalable, modern, and proactive dataprotection capabilities.
Your Work: Security Engineering - DLP & CASB Specialist (Cloud Data Protection)
1. DLP Engineering, Architecture & Implementation
• Design, implement, and optimize enterprisewide DLP controls using Microsoft Purview DLP, Information Protection, and Netskope DLP/CASB.
• Engineer DLP policies, classifiers, exceptions, and workflows for cloud (SaaS, IaaS, PaaS), endpoint, and web channels.
• Lead integration of DLP and CASB tools with cloud platforms including AWS, Azure, and Google Cloud.
2. Cloud Security Integration
• Partner with cloud architects and application teams to embed DLP and CASB controls into cloud-native environments.
• Support secure data flows across S3, Blob, Snowflake, SQL, and SaaS applications through technical integrations and bestpractice configurations.
3. Policy Development & Tuning
• Develop and enforce advanced DLP policies aligned to security standards, regulatory requirements, and risk tolerance.
• Minimize false positives through tuning, advanced SIT/classifier creation, and rule optimization.
4. Monitoring, Analytics & Automation
• Work closely with SOC and SIEM teams (Splunk preferred) to ensure highfidelity telemetry and alerting.
• Build dashboards, analytics, and automation opportunities that improve detection and reduce manual effort.
• Identify trends and potential gaps, driving proactive mitigation strategies.
5. Incident Response & Troubleshooting
• Serve as a technical expert for complex DLP and CASB incidents.
• Perform rootcause engineering, propose long-term fixes, and partner with SOC on response playbooks.
6. Governance, Compliance & Reporting
• Provide leadership in mapping DLP controls to GDPR, CCPA, PCI, HIPAA, and other frameworks.
• Deliver executivelevel reporting and insights to leadership on DLP posture, risks, and improvements.
7. Documentation, Standards & Training
• Develop standards for data classification, masking, retention, archival, and secure data flows.
• Maintain technical documentation, SOPs, and lead stakeholder education workshops.
8. Continuous Improvement & Tool Evaluation
• Assess new DLP, CASB, and cloud security capabilities; lead POCs and vendor evaluations.
• Drive modernization efforts, platform migrations, and optimization initiatives.
• Perform advanced analysis of DLP and CASB events across Microsoft Purview, Netskope, MDCA, and related tools.
• Identify patterns, trends, mis-configurations, and gaps in controls; recommend or implement tuning and policy improvements.
• Develop and refine DLP rules, classifiers, exceptions, and highfidelity detections to reduce false positives and strengthen dataloss prevention coverage.
CrossFunctional Collaboration
• Partner closely with SOC, Cyber Defense, and Security Engineering to align on priorities, establish bestpractice playbooks, and improve DLP/incident response workflows.
• Work with IT, Cloud, and Business partners to design scalable, efficient, and compliant processes for protecting internal and external data flows.
• Educate and influence interested parties on DLP findings, risk areas, and recommended mitigations.
RiskBased Strategy & Governance
• Apply a riskbased approach to analyze, prioritize, and remediate data protection risks across the enterprise.
• Ensure alignment with regulatory requirements (GDPR, CCPA, PCI, HIPAA where applicable) and corporate security standards.
• Contribute to governance activities, including policy development, standards, and control architecture.
Continuous Improvement & Innovation
• Stay current on emerging dataprotection threats, cloudsecurity trends, and DLP/CASB industry capabilities.
• Recommend modernization opportunities in DLP technologies, automation, and process streamlining.
• Support and/or lead security awareness and training efforts related to data protection.
Required Experience, Education and Skills
• 7-10+ years in DLP engineering, cybersecurity, or cloud security roles.
• Strong handson experience with Microsoft Purview, AIP, labels, classifiers, DLP/Information Protection,
• Netskope DLP/CASB, and cloud security controls.
• Proven experience engineering DLP policies, integrating with cloud apps, and supporting enterprise-scale environments.
Deep understanding of:
• MDCA / Defender for Cloud Apps
• AWS, Azure, GCP data-protection patterns
• SIEM (Splunk), log pipelines, dashboards
• Strong troubleshooting and root-cause analysis skills.
• Excellent communication, documentation, and cross-functional collaboration abilities.
• Ability to translate technical DLP concepts for non-technical partners.
• Demonstrated leadership in driving security best practices across teams.
What would make us excited about you?
• CCSP, CISSP, CISM, Azure Security Engineer, AWS Security Specialty, Netskope or Microsoft certifications.
• Vendor certifications (Microsoft Security, Netskope, etc.) are a plus.
• Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)
• Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
• Travels as needed for role, including divisional / team meetings and other in-person meetings
• Fulfills business needs, which may include investing extra time, helping other teams, etc
Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska.
#LI-SB1
Why Choose a Career at CSAA IG?
At CSAA IG, we are a mission-driven organization proudly committed to empowering our members, our employees, and our communities to thrive.
Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at [https://careers.csaainsurance.aaa.com/us/en/benefits](https://careers.csaainsurance.aaa.com/us/en/benefits).
Career Growth: We believe in growth for everyone. Here at CSAA IG, leaders and mentors partner with employees to align interests, unlock development opportunities, and support longterm success.
Flexible Workplace: We embrace a remote-first culture through our Flexible Workplace. Most employees hold Home-Flex roles, working primarily from home, often with the flexibility to work from various locations including CSAA offices. Our flexible workplace empowers you to balance remote work with intentional inperson moments that deepen connection and collaboration.
Inclusion and Belonging: An inclusive and welcoming workplace is the cornerstone of our success. By fostering an environment where people feel valued and heard, we deepen our ability to understand and meet the unique needs of our members. This strengthens innovation and enhances our products and services, giving us a competitive edge in the market.
Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don't miss important updates from us.
CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations. If you would like to request an accommodation to participate in the job application or interview process, please contact [TalentAcquistion@csaa.com](mailto:TalentAcquistion@csaa.com)
If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.
CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).
CSAA Insurance Group is an equal opportunity employer.
About CSAA Insurance Group
Why we're forever forward -- At CSAA IG, one thing will always endure: our commitment to excellence in everything we do for our members, employees and communities. As insurance industry leaders, we know things can change in an instant. It’s why we’re here.
We’re not afraid of change. We welcome it and use it to advance the cause. For employees, our cause is to become ever more inclusive and supportive of their goals and contributions. For our AAA Members, it’s finding new ways to help them prevent, prepare for and recover from whatever comes. For our communities, it’s exploring new ways of helping them meet evolving challenges.
Whatever may happen, change becomes progress at CSAA IG.
Benefits for today and for your future -- Benefits at CSAA IG represent our commitment to protect our employees by providing for their needs today and helping them prepare for a more secure future. Our suite of benefits is designed to provide for your physical, mental, social and financial health.
Our sense of belonging keeps us together -- Belonging is the feeling of being welcomed and accepted for who you are and the qualities you bring. It’s knowing you’re heard and valued as an individual and employee.
At CSAA IG, we share a strong sense of purpose and a hunger for adventure.
Change should always be expected, but can’t always be predicted. Whatever happens, we remain true to our beliefs and clear on our purpose. We meet change head on and grow from each experience.
A promise to act -- Life is uncertain, but we are not. When our AAA Members need us, we know how to move with the speed, expertise and confidence they rely on.