We are seeking a Senior Information Security Engineer to help transform the Intellectual Property (IP) protection program through advanced, AI-driven data loss prevention (DLP) and data labeling capabilities. This role goes beyond traditional rule-based DLPfocusing on contextual understanding of data, users, and behavior, large-scale discovery of sensitive IP, and adaptive, automated controls powered by machine learning and generative AI technologies
Key responsibilities
DLP Architecture & Operations
– Design and deploy DLP capabilities that understand data sensitivity, business context, user intent, and behavioral risk, rather than relying solely on patterns or keywords.
– Build detection rules for source code, hardware design files, algorithms, product roadmaps, and other IP artifacts (e.g., complex regex, fingerprints, EDM/IDM, ML-based classifiers).
– Tune and optimize policies to reduce false positives/negatives; implement tiered response workflows and auto-remediation actions.
– Establish monitoring for egress vectors (USB/removable media, print, email, SaaS, personal webmail, messaging, generative AI tools, cloud sync).
– Develop detections for anomalous IP access/exfil patterns (e.g., code repo mirroring, bulk downloads, atypical off-hours activity).
– Identify early indicators of IP misuse or exfiltration through behavioral analytics rather than reactive alerting.
– Define guardrails for the secure use of generative AI tools, ensuring proprietary data and IP are protected from unintended disclosure
– Author and maintain IP protection standards, DLP/runbooks, and exception processes.
– Define and track KPIs/KRIs (e.g., DLP alert quality, mean time to triage/close, exfil attempts prevented, classification coverage).
Data Classification & Labeling
– Implement scalable AI-assisted data discovery across endpoints, cloud services, SaaS platforms, and code repositories to identify previously unknown or unclassified IP.
– Implement and scale enterprise data classification and labeling for IP-heavy content.
– Drive adoption via policy-based auto-labeling, built-in nudges, and sensitivity label inheritance through workflows and repositories.
– Implement conditional access, DRM, and rights management for sensitive content shared internally and externally.
Qualifications and Experience
– Robust understanding of AI concepts, machine learning pipelines, and automation tools.
– Hands-on experience or coursework in Copilot Studio, UiPath, and SharePoint.
– Knowledge with cloud AI platforms: Azure AI Foundry, AWS Bedrock, etc.
– Experience in leveraging, creating, and driving AI in DLP solutions
– Minimum 4 years of experience in information security with hands-on DLP and/or data classification/labeling at scale.
– Proven experience designing and tuning DLP policies for endpoints, email, web, and SaaS
– Practical knowledge of IP data types (source code, firmware, design files, algorithms, roadmaps) and how they move across an enterprise.
– Strong operational understanding of using custom keywords and dictionaries
– Strong knowledge of networking and operating systems
– Knowledge of cloud service providers, including Azure, AWS, and GCP
– Hands-on expertise SIEM/SOAR platforms.
– Scripting/automation proficiency (PowerShell, Python, or Splunk SPL).
– Excellent written and verbal communication skills
Education:
– B.Tech degree in Computer Science, Computer Engineering, other technical disciplines, or equivalent work experience.
– Candidates with a masters degree in technology or science and relevant professional certifications are preferred. We are seeking a Senior Information Security Engineer to help transform the Intellectual Property (IP) protection program through advanced, AI-driven data loss prevention (DLP) and data labeling capabilities. This role goes beyond traditional rule-based DLPfocusing on contextual understanding of data, users, and behavior, large-scale discovery of sensitive IP, and adaptive, automated controls powered by machine learning and generative AI technologies
Key responsibilities
DLP Architecture & Operations
– Design and deploy DLP capabilities that understand data sensitivity, business context, user intent, and behavioral risk, rather than relying solely on patterns or keywords.
– Build detection rules for source code, hardware design files, algorithms, product roadmaps, and other IP artifacts (e.g., complex regex, fingerprints, EDM/IDM, ML-based classifiers).
– Tune and optimize policies to reduce false positives/negatives; implement tiered response workflows and auto-remediation actions.
– Establish monitoring for egress vectors (USB/removable media, print, email, SaaS, personal webmail, messaging, generative AI tools, cloud sync).
– Develop detections for anomalous IP access/exfil patterns (e.g., code repo mirroring, bulk downloads, atypical off-hours activity).
– Identify early indicators of IP misuse or exfiltration through behavioral analytics rather than reactive a
