
Principal, Cyber Sec Eng - DLP / Data Protection
Northern Trust1 day ago
Base Salary
$137k - $234k/yr
Responsibilities
- Own the technical vision, control strategy, and secure enablement of enterprise DLP, encryption-related data protection, and external data-transfer controls.
- Lead DLP engineering, data-center bypass capabilities, exception-handling automation, governance workflows, and repeatable security patterns.
- Redesign and optimize Zscaler data-protection and security policies and provide technical direction for Database Activity Monitoring initiatives.
- Lead the migration from Symantec DLP to Microsoft Purview and define a controlled Symantec exit strategy.
- Design, implement, troubleshoot, and operate controls for information protection, labeling, endpoint DLP, cloud, identity, governance, Insider Risk Management, Communication Compliance, retention, and DSPM.
- Configure and operate security controls across Active Directory and Microsoft Entra ID environments.
- Translate emerging data-protection and AI risks into preventive and detective controls and serve as escalation point and design authority for complex security decisions.
- Partner with Security, Compliance, Privacy, Microsoft 365, and Risk stakeholders while supporting disciplined production changes, testing, deployment, and post-change validation.
Requirements
- Extensive experience in cybersecurity, data protection engineering, or a closely related discipline.
- Strong hands-on experience with Zscaler and Microsoft Purview DLP.
- Deep knowledge of Data Loss Prevention, data classification, information protection, encryption, and enterprise data protection principles.
- Experience with enterprise DLP platforms and Azure security capabilities, including Azure Information Protection, Microsoft Information Protection, and Microsoft Defender for Cloud Apps.
- Strong understanding of network security concepts including proxies, firewalls, traffic analysis, and external data-transfer paths.
- Experience designing, deploying, troubleshooting, and operating security controls in complex enterprise environments.
- Experience working in highly regulated enterprise environments.
- Strong troubleshooting, analytical, written communication, stakeholder management, independent decision-making, and influence skills.
- Preferred experience with FFIEC, PCI-DSS, and SOX control alignment; large-scale DLP migrations; policy redesigns; legacy technology exit strategies; AI-specific DLP use cases; DSPM; Insider Risk Management; Communication Compliance; retention enforcement; Database Activity Monitoring; and hybrid security-platform integrations.
- Ability to operate as a senior individual contributor with broad autonomy, own technical strategy, influence architecture and controls, and act as a design authority for critical or ambiguous decisions.
Benefits
- Comprehensive benefits include 401(k) and pension retirement benefits, medical, dental, vision, spending accounts, disability coverage, paid time off, parental and caregiver leave, life and accident insurance, and voluntary and well-being benefits.
- A discretionary bonus program may include an equity component.
- The company describes a flexible and collaborative work culture with internal mobility, accessible senior leaders, and an inclusive workplace.
About Northern Trust
Northern Trust is a financial services company that provides asset servicing (custody and fund administration), asset management, wealth management, and banking/treasury services to institutions, corporations, and affluent families. Its business model centers on fees for assets under custody/administration and management, plus banking services. Founded in 1889 and headquartered in Chicago, it is publicly traded on Nasdaq (NTRS) and serves clients across the Americas, EMEA, and APAC.