
Posted 6 days ago
No clicks
**Bengaluru VP Security Engineering** Lead engineering efforts to tighten data loss prevention (DLP) across Microsoft Purview, Zscaler, and Proofpoint. Key responsibilities include: - Design and tune DLP detection capabilities to maximize accuracy and minimize operational friction. - Develop custom logic and integrations for internal systems. - Regularly validate and tune DLP controls to identify gaps and bypass techniques. - Build automation workflows to assist DLP analysts and reduce manual review time. - Collaborate with data owners, legal, and compliance teams to translate requirements into technical enforcement rules. - Integrate additional DLP tools and participate in proof-of-concept trials. **Required:** - Proven experience in data loss incidents handling, insider threat investigations, or security incident response. - Deep, hands-on experience with tools like Microsoft Purview, Zscaler, ServiceNow, and Proofpoint. - Proficiency in Python/PowerShell, with experience interacting with REST APIs. - Strong detection engineering skills, including regular expression and data matching proficiency. - Solid understanding of enterprise network routing and mail transport rules. **Preferred:** - Experience integrating DLP tools with SOAR platforms. - Background in software engineering or DevSecOps, with CI/CD pipeline experience. - Applied AI/ML in Detection Engineering and agentic workflow automation experience. Join our dynamic engineering teams, transforming finance and exploring a world of opportunity at the speed of markets. Learn more about our benefits: [Goldman Sachs Benefits](https://www.goldmansachs.com/careers/benefits-wellness-compensation.html)
- Compensation
- Not specified
- City
- Bengaluru
- Country
- India
Currency: Not specified
Full Job Description
Key Responsibilities
- Design, implement and continuously tune DLP detection capabilities and policies across Microsoft Purview, Zscaler, Proofpoint to maximize true positives and minimize operational friction
- Develop custom detection logic and integrations for internally developed systems
- Perform regular testing and validation of existing DLP controls to identify coverage gaps and bypass techniques
- Engineer automation workflows to assist DLP analysts, reducing manual review time and automating the triage of low-fidelity events
- Act as highest-level technical escalation point for complex data leakage incidents and associated investigations
- Collaborate directly with data owners, legal and compliance teams to translate business and regulatory requirements into technical enforcement rules
- Evaluate and integrate additional DLP tools, and participate in proof-of-concept trials.
Required Technical Skills
- DLP & Security Operations: Proven experience handling data loss incidents, insider threat investigations, or general security incident response. You need to know what a good alert looks like to build one
- Core Stack Expertise: Deep, hands-on administrative experience with tools like Microsoft Purview, Zscaler, ServiceNow and Proofpoint
- Automation & Scripting: Strong proficiency in tools like Python or PowerShell. You must be able to interact with REST APIs to pull logs, enrich alerts, and trigger automated response actions
- Detection Engineering: Proficiency with regular expressions, exact data matching, indexed document matching and custom dictionary creation
- System Architecture: Solid understanding of enterprise network routing, proxies, cloud access, and mail transport rules
What Sets You Apart
- Experience integrating DLP tooling with SOAR platforms (e.g., Splunk SOAR, Cortex XSOAR, Tines) to build end-to-end automated review pipelines
- Background in software engineering or DevSecOps, with an understanding of CI/CD pipelines and version control for managing detection as code
- A builder mindset: you prefer to solve problems with code rather than relying solely on out-of-the-box vendor configurations
- Applied AI/ML in Detection Engineering experience moving beyond static rules by training, tuning and deploying ML classifiers for context-aware data discovery. Familiarity with Microsoft Purviews Trainable Classifiers or using custom Natural Language Processing models to identify sensitive data types that traditional regex approach misses
- Agentic workflow automation: experience building next-generation, LLM-driven agentic workflows. You have moved beyond basic SOAR playbooks and built autonomous systems where AI agents gather contextual telemetry, interact directly with employees (e.g, via MS Teams bots, email, task management systems) to verify business intent, and pre-triage alerts before they are manually reviewed




