Job Closed
This listing is no longer active.
Forever Forward
IT Security Engineer - DLP and CASB Engineering - Remote
Location
United States
Posted
78 days ago
Salary
$122K - $164K / year
Seniority
Mid Level
Job Description
IT Security Engineer - DLP and CASB Engineering - Remote
CSAA Insurance Group, a AAA Insurer
External candidates: In order for your application to be correctly processed please sign-in before you apply Internal candidates: Please go to Workday and click "Find Jobs" link under Career Thank you for considering opportunities with us! Job Title IT Security Engineer - DLP and CASB Engineering - Remote Requisition Number R7642 IT Security Engineer - DLP and CASB Engineering - Remote (Open) Location Arizona - Home Teleworkers Additional Locations Alabama - Home Teleworkers, Alabama - Home Teleworkers, Arkansas - Home Teleworkers, California - Home Teleworkers, Colorado - Home Teleworkers, Connecticut - Home Teleworkers, Delaware - Home Teleworker, District of Columbia - Home Teleworkers, Florida - Home Teleworkers, Georgia - Home Teleworkers, Idaho - Home Teleworkers, Illinois - Home Teleworkers, Indiana - Home Teleworkers, Iowa - Home Teleworkers, Kansas - Home Teleworker, Kentucky - Home Teleworkers, Louisiana - Home Teleworkers, Maine Home Teleworkers, Maryland - Home Teleworkers, Massachusetts - Home Teleworkers, Michigan - Home Teleworkers, Minnesota - Home Teleworkers, Mississippi - Home Teleworker, Missouri - Home Teleworker, Montana - Home Teleworkers {+ 21 more} Job Information CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the leading personal lines property and casualty insurance groups in the United States. Here, every employee shapes our mission. We build innovative, human-centered solutions that help AAA members prevent, prepare for, and recover from life's uncertainties. You will join a collaborative, inclusive culture where your strengths have room to grow and your ideas can drive real impact. Step into a role where you can contribute to our shared success through meaningful work. We are actively hiring for an IT Security Engineer - DLP and CASB Engineering - Remote Your Role: We are seeking an experienced and highly skilled Security DLP and CASB Engineer with deep expertise in Microsoft Purview DLP, Netskope DLP/CASB, cloud security, and enterprise data protection engineering. This senior role will own the design, implementation, optimization, and ongoing management of DLP and CASB solutions across cloud and hybrid environments. The ideal candidate brings strong technical depth, architectural awareness, and the ability to collaborate across IT, Cloud, Cybersecurity, and Business teams to build scalable, modern, and proactive data‑protection capabilities. Your Work: Security Engineering – DLP & CASB Specialist (Cloud Data Protection) DLP Engineering, Architecture & Implementation - Design, implement, and optimize enterprise‑wide DLP controls using Microsoft Purview DLP, Information Protection, and Netskope DLP/CASB. - Engineer DLP policies, classifiers, exceptions, and workflows for cloud (SaaS, IaaS, PaaS), endpoint, and web channels. - Lead integration of DLP and CASB tools with cloud platforms including AWS, Azure, and Google Cloud. 2. Cloud Security Integration - Partner with cloud architects and application teams to embed DLP and CASB controls into cloud-native environments. - Support secure data flows across S3, Blob, Snowflake, SQL, and SaaS applications through technical integrations and best‑practice configurations. 3. Policy Development & Tuning - Develop and enforce advanced DLP policies aligned to security standards, regulatory requirements, and risk tolerance. - Minimize false positives through tuning, advanced SIT/classifier creation, and rule optimization. 4. Monitoring, Analytics & Automation - Work closely with SOC and SIEM teams (Splunk preferred) to ensure high‑fidelity telemetry and alerting. - Build dashboards, analytics, and automation opportunities that improve detection and reduce manual effort. - Identify trends and potential gaps, driving proactive mitigation strategies. 5. Incident Response & Troubleshooting - Serve as a technical expert for complex DLP and CASB incidents. - Perform root‑cause engineering, propose long-term fixes, and partner with SOC on response playbooks. 6. Governance, Compliance & Reporting - Provide leadership in mapping DLP controls to GDPR, CCPA, PCI, HIPAA, and other frameworks. - Deliver executive‑level reporting and insights to leadership on DLP posture, risks, and improvements. 7. Documentation, Standards & Training - Develop standards for data classification, masking, retention, archival, and secure data flows. - Maintain technical documentation, SOPs, and lead stakeholder education workshops. 8. Continuous Improvement & Tool Evaluation - Assess new DLP, CASB, and cloud security capabilities; lead POCs and vendor evaluations. - Drive modernization efforts, platform migrations, and optimization initiatives. - Perform advanced analysis of DLP and CASB events across Microsoft Purview, Netskope, MDCA, and related tools. - Identify patterns, trends, mis-configurations, and gaps in controls; recommend or implement tuning and policy improvements. - Develop and refine DLP rules, classifiers, exceptions, and high‑fidelity detections to reduce false positives and strengthen data‑loss prevention coverage. Cross‑Functional Collaboration - Partner closely with SOC, Cyber Defense, and Security Engineering to align on priorities, establish best‑practice playbooks, and improve DLP/incident response workflows. - Work with IT, Cloud, and Business partners to design scalable, efficient, and compliant processes for protecting internal and external data flows. - Educate and influence interested parties on DLP findings, risk areas, and recommended mitigations. Risk‑Based Strategy & Governance - Apply a risk‑based approach to analyze, prioritize, and remediate data protection risks across the enterprise. - Ensure alignment with regulatory requirements (GDPR, CCPA, PCI, HIPAA where applicable) and corporate security standards. - Contribute to governance activities, including policy development, standards, and control architecture. Continuous Improvement & Innovation - Stay current on emerging data‑protection threats, cloud‑security trends, and DLP/CASB industry capabilities. - Recommend modernization opportunities in DLP technologies, automation, and process streamlining. - Support and/or lead security awareness and training efforts related to data protection. Required Experience, Education and Skills - 7–10+ years in DLP engineering, cybersecurity, or cloud security roles. - Strong hands‑on experience with Microsoft Purview, AIP, labels, classifiers, DLP/Information Protection, - Netskope DLP/CASB, and cloud security controls. - Proven experience engineering DLP policies, integrating with cloud apps, and supporting enterprise-scale environments. Deep understanding of: - MDCA / Defender for Cloud Apps - AWS, Azure, GCP data-protection patterns - SIEM (Splunk), log pipelines, dashboards - Strong troubleshooting and root-cause analysis skills. - Excellent communication, documentation, and cross-functional collaboration abilities. - Ability to translate technical DLP concepts for non-technical partners. - Demonstrated leadership in driving security best practices across teams. What would make us excited about you? - CCSP, CISSP, CISM, Azure Security Engineer, AWS Security Specialty, Netskope or Microsoft certifications. - Vendor certifications (Microsoft Security, Netskope, etc.) are a plus. - Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.) - Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.) - Travels as needed for role, including divisional / team meetings and other in-person meetings - Fulfills business needs, which may include investing extra time, helping other teams, etc Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska. #LI-SB1 Why Choose a Career at CSAA IG? At CSAA IG, we are a mission-driven organization proudly committed to empowering our members, our employees, and our communities to thrive. Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at https://careers.csaainsurance.aaa.com/us/en/benefits. Career Growth: We believe in growth for everyone. Here at CSAA IG, leaders and mentors partner with employees to align interests, unlock development opportunities, and support long‑term success. Flexible Workplace: We embrace a remote-first culture through our Flexible Workplace. Most employees hold Home-Flex roles, working primarily from home, often with the flexibility to work from various locations including CSAA offices. Our flexible workplace empowers you to balance remote work with intentional in‑person moments that deepen connection and collaboration. Inclusion and Belonging: An inclusive and welcoming workplace is the cornerstone of our success. By fostering an environment where people feel valued and heard, we deepen our ability to understand and meet the unique needs of our members. This strengthens innovation and enhances our products and services, giving us a competitive edge in the market. Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don’t miss important updates from us. CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations. If you would like to request an accommodation to participate in the job application or interview process, please contact TalentAcquistion@csaa.com If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education. CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.). CSAA Insurance Group is an equal opportunity employer. . The national average salary range for this position is $122,850.00-$136,500.00. However, we have a location-based compensation structure. Our salary ranges vary and are calculated based on work location. The starting pay range for this position across all the states we hire in is $122,850.00-$164,000.00. This role also includes an opportunity for a company-wide annual discretionary bonus, through our Annual Incentive Plan (AIP), of up to 10% of eligible pay. This job posting will be unposted on Fri, 27 Mar 2026.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Support with security analyses and the structuring of requirements • Contribute to documentation and concepts (e.g., policies, processes, guidelines, security concepts) • Support risk assessments (e.g., prepare risk workshops, maintain risk registers) • Expand and develop our internal lab infrastructure • Contribute to our digital products
• Monitor and analyze security events using SIEM tools to detect and respond to threats in real-time • Investigate security incidents, perform root cause analysis, and document findings for remediation and reporting • Manages the full vulnerability lifecycle across enterprise systems, including identifying security weaknesses, assessing and prioritizing risk, coordinating remediation efforts, and validating that issues are resolved • Works closely with IT and business teams to ensure vulnerabilities are addressed in a timely manner based on risk, impact, and relevant threat intelligence • Analyze logs from endpoints, servers, network devices, and cloud platforms to identify suspicious activity • Support incident response activities including containment, eradication, and recovery • Manage vendor security assessment reviews to enable informed decision-making related to third party engagements • Participate in threat hunting activities to proactively identify hidden threats in the environment
IT Specialist - Cybersecurity Governance
EatonEaton, founded in 1911, is a global power management company with annual sales over $20 billion. Headquartered in Dublin, Leinster, Ireland, Eaton operates over
Lead the development and management of IT security policies while collaborating with stakeholders to ensure compliance with regulatory frameworks. Drive continuous improvement and champion best practices in Governance, Risk, and Compliance.
Cyber Advisors (CA) is a rapidly growing Cybersecurity Consulting firm and MSP. We are seeking a Red Team Lead for our Security team to support our accelerating company growth and the equally important growth of one’s own career. CA believes in inclusion and is dedicated to continued employee development. We offer a competitive salary and benefits, and are seeking candidates who focus on innovation and results. Successful CA employees are detail-oriented and have excellent communication skills. The successful candidate will be a creative problem-solver who can structure and organize assignments efficiently. Candidates should apply to join a forward-thinking team that values contributions and well-being. SUMMARY The Red Team Lead is responsible for developing, executing, and continuously improving the organization’s red team operations. This role requires a balance of strategic planning and hands-on technical execution through customer-facing work. The individual in this role will lead adversary simulation exercises, develop attack methodologies, and collaborate with internal and external stakeholders to enhance security resilience. KEY RESPONSIBILITIES Strategic Oversight & Program Leadership: - Develop and implement a comprehensive red team strategy aligned with industry best practices and evolving threat landscapes. - Define and maintain tactics, techniques, and procedures (TTPs) for adversary emulation. - Design and oversee red teaming methodologies, operational workflows, and toolsets to enhance effectiveness. - Conduct threat modeling and scenario planning to simulate real-world attack scenarios tailored to client environments. - Ensure integration of red team activities with defensive security functions to enhance security posture improvements. - Provide strategic guidance on emerging attack vectors, evasion techniques, and countermeasures. Mentorship & Team Development: - Mentor, coach, and support the red team in client delivery, professional development, and knowledge-sharing. - Establish and refine delivery methodologies, playbooks, and documentation standards. - Serve as an escalation point and subject matter expert for complex client challenges. - Drive innovation by developing custom tooling, automation, and attack simulation frameworks. - Maintain expertise in attack simulation technologies, C2 frameworks, and exploit development. - Conduct research on new and emerging threats, vulnerabilities, and attack methodologies. - Represent the company in industry forums, conferences, and public speaking engagements as needed. Client Engagement & Billable Work: - Lead and execute red team engagements, including assumed breach, adversary simulation, and objective-based attack scenarios. - Perform network, cloud, and application-layer penetration testing to identify security vulnerabilities. - Conduct covert operations, social engineering, and physical security assessments as part of engagements. - Develop and present technical reports, executive summaries, and strategic recommendations to clients. - Support purple team engagements by collaborating with blue teams to fine-tune detection and response mechanisms. - Ensure all engagements adhere to industry standards, ethical guidelines, and legal compliance requirements. KEY SKILLS & QUALIFICATIONS Experience: - Bachelor’s degree in computer science, Cybersecurity, or a related field (or equivalent experience). - 5+ years of experience in red teaming, offensive security, or adversary emulation. - Strong understanding of MITRE ATT&CK framework, threat actor methodologies, and evasion techniques. - Proficiency with red teaming toolsets, including C2 frameworks (Cobalt Strike, Mythic, Brute Ratel, Sliver) and exploit development. - Extensive knowledge of Windows and Linux exploitation, Active Directory attacks, and lateral movement techniques. - Experience conducting cloud security assessments in AWS, Azure, and GCP. - Excellent technical writing, reporting, and presentation skills for both technical and executive audiences. - Ability to manage multiple projects and provide client-focused security solutions. Preferred Qualifications and Expertise: - Experience leading purple team engagements and collaborating with defensive security teams. - Familiarity with Zero Trust security models, EDR/XDR bypass techniques, and offensive security research. - Development experience with Python, PowerShell, C, or other scripting languages for tool creation. - Relevant certifications such as OSCP, OSEP, CRTO, OSCE3, GXPN, CISSP, or AWS Security. WHAT WE OFFER - Competitive compensation and performance-based incentives. - Vacation and PTO. - Employer-paid Health and Dental Insurance for CA employees. - 401(k) with employer matching. - Opportunities for professional development, including certifications and ongoing training. - Engaging, dynamic work on a wide range of client security challenges.



