Amazure Technologies Pvt Ltd
Website:
amazuretec.com
Job details:
L2 Forcepoint DLP Engineer
Location : Pune
Mode : On site
Experience: 3–6 years in DLP/Security Operations (1–3 years Forcepoint DLP)
Shift: Business hours with on-call support for critical incidents
Key Responsibilities
1. L2 Support & Advanced Troubleshooting
- Provide Level 2 support for Forcepoint DLP-related incidents escalated from L1.
- Perform root cause analysis (RCA) for complex incidents: agent failures, policy misconfigurations, false positives/negatives.
- Troubleshoot :-
-Endpoint agent communication failures, performance degradation.
-TLS/SSL inspection issues, reverse proxy conflicts.
-Email DLP (Exchange Online, SMTP gateway) issues.
-Web DLP (HTTP/HTTPS uploads, cloud storage) issues.
-DSPM connector failures, data discovery errors, classification mismatches.
- Resolve application compatibility conflicts across Windows/Mac endpoints.
- Coordinate with Forcepoint Support for bugs, patches, and hotfixes.
2. DLP Policy Management & Tuning
- Create, implement, and optimize Forcepoint DLP policies based on security requirements.
- Tune detection methods:
- Exact Data Matching (EDM) for structured data
- File Fingerprinting (structured & unstructured) up to 100M files
- OCR, Dictionaries, Natural Language Processing (NLP) scripts
- Content inspection rules, insider threat workflows
- Reduce false positives while maintaining high detection accuracy
- -Validate policy efficacy regularly and adjust rules based on business feedback
- Manage Endpoint Classification policies:
- MIP label import/application (Azure Information Protection).
- Custom labels, sensitivity tags, third-party classification integration.
3. Incident Response & Remediation
- Lead response to data leakage incidents and security breaches.
- Investigate detection, mitigation, and evidence generation for unauthorized access events.
- Perform single-click remediation: block, encrypt, quarantine, coach users.
- Document incident timelines, actions taken, and lessons learned.
- Prepare incident reports for management and compliance audits.
4. Platform Maintenance & Upgrades
- Perform routine system health checks, patch updates, and version upgrades.
- Execute maintenance windows with minimal service disruption.
- Restore DLP infrastructure from backups when required.
- Manage enforcer configurations, agent deployments, and policy synchronization.
- Monitor system performance (CPU, memory, disk) and optimize as needed.
5. DSPM Operations & Data Classification
- Administer Forcepoint DSPM for data discovery across:
-Cloud: AWS S3, Azure Blob, Google Cloud Storage, Microsoft 365 (OneDrive, SharePoint)
-On-prem: File servers, databases, network shares
- Configure DSPM connectors, API integrations, and authentication
- Review DSPM classification results and validate AI Mesh technology outputs
- Remediate risks to sensitive data: access governance, encryption, policy enforcement
- Integrate DSPM with DLP for unified data protection (classification tags used by both)
6. Integration & Automation
- Integrate Forcepoint DLP/DSPM with enterprise technologies:
-SIEM: Splunk, QRadar (log forwarding, correlation rules)
-ITSM: ServiceNow (incident, change, problem management)
-Active Directory/Azure AD (user sync, groups, RBAC)
-APIs for automation workflows and custom reporting
- Develop scripts (PowerShell/Python) for automation:
-Policy deployment validation
-Agent health checks
-Incident data extraction
-Report generation
7. Collaboration & Knowledge Sharing
- Work with Threat Intelligence, Network Security, Endpoint Security teams.
- Provide guidance and mentorship to L1 Engineer.
- Conduct knowledge sharing sessions on DLP/DSPM best practices.
- Maintain accurate documentation of configurations, policies, RCA, and incident responses.
8. Compliance & Audit Support
- Align DLP/DSPM policies with regulations: GDPR, CCPA, HIPAA, PCI-DSS, ISO 27001
- Support audit readiness: evidence generation, compliance validation, policy reviews
- Participate in security assessments, gap analysis, and remediation planning
Education
B.E./B.Tech in IT/Computer Science or MCA
- Experience with DSPM or cloud data security (AWS/Azure/GCP) preferred
Technical Skills
- Deep knowledge of Forcepoint DLP (Endpoint, Network, Email, Web, Cloud)
- Forcepoint DSPM (data discovery, AI classification, cloud connectors)
- Endpoint Classification: MIP/Azure Information Protection, custom labels
- DLP Detection Methods: EDM, Fingerprinting, OCR, NLP (300+ scripts), Regex, Dictionary
- Active Directory/Azure AD integration, RBAC, user context in incidents
- Troubleshooting: TLS/SSL, reverse proxies, SMTP, UDP/TCP, XML validation
- Scripting: PowerShell, Python, batch scripting for automation
Tools
- Forcepoint Security Manager (FSM) / ONE Data Security portal
- SIEM (Splunk/QRadar) for log analysis and correlation
- ServiceNow/Jira for ITSM workflows
- APIs for automation (REST API)
- VPN, remote access tools, packet capture (Wireshark)
Soft Skills
- Strong analytical and problem-solving skills
- Excellent communication (verbal & written) for client interaction
- SLA-driven, proactive, detail-oriented
- Mentoring ability (guide L1 Engineer)
Certifications (Preferred)
- Forcepoint DLP Certification (highly preferred)
- Security+ / CEH / CISSP / PCNSE
- AWS/Azure Security certifications (for DSPM)
Click on Apply to know more.