About this role
At Bristol Myers Squibb, our employees often ask, “Who are you working for?”—a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.
Position Summary
Bristol Myers Squibb is seeking an experienced DLP Engineer to join our data security and data protection efforts. The successful candidate will be responsible for implementing and managing enterprise data protection strategies to protect BMS sensitive and confidential data, while also ensuring compliance with industry regulations and standards.
This position will be part of the Data Protection team in the Hyderabad office . The position will be expected to coordinate with stakeholders in the US and globally.
The ideal candidate will bring 3–5 years of experience in information security and DLP engineering, with strong hands-on proficiency across enterprise DLP platforms and the Microsoft Purview ecosystem — including sensitivity labels and auto-labeling , DLP rule and policy configuration, and regex-based content detection. The candidate should also bring practical experience with Power Automate and Azure Logic Apps workflow automation, KQL-based investigation and reporting , and securing and integrating GenAI tools such as Microsoft 365 Copilot and Claude with DLP and data protection controls.
If you want an exciting and rewarding career that is meaningful, consider joining our diverse team!
Key Responsibilities
A. Functional and Technical
- Design, implement, configure, and administer enterprise DLP solutions (e.g., Microsoft Purview DLP, Symantec/Broadcom, Forcepoint, Trellix, Netskope, Zscaler) across endpoint, network, email, web, and cloud channels, ensuring alignment with industry regulations and standards
- Build, test, and deploy DLP policies and detection logic — custom classifiers, regular expressions (Regex), keyword dictionaries, Sensitive Information Types (SITs), Exact Data Matching (EDM), Indexed Document Matching (IDM), and document fingerprinting — including scoped policy targeting, rule conditions, exceptions, and enforcement actions (audit, block, notify, restrict)
- Design, publish, and manage sensitivity labels (Microsoft Purview Information Protection / MIP): label taxonomy design, label policies and scoping, encryption and content-marking settings, container labels for Teams/SharePoint/Microsoft 365 Groups, and label-based DLP policy conditions
- Configure and operate auto-labeling at scale — client-side and service-side auto-labeling policies for Exchange, SharePoint, and OneDrive; simulation mode testing, tuning label-match accuracy with SITs and trainable classifiers, and monitoring label adoption, label analytics, and mislabeling trends
- Enforce downstream protection based on labels — label-driven DLP rules, conditional access to labeled content, and label inheritance/handling in AI tools (e.g., ensuring Copilot and other GenAI assistants honor sensitivity labels and encryption on protected content)
- Perform continuous rule tuning and policy optimization : analyze DLP events, validate true vs. false positives, document findings, and iteratively refine detection to improve accuracy and reduce alert noise
- Manage the DLP platform end to end — agent deployment, upgrades, health monitoring, coverage gap analysis, and maintenance of management/detection server infrastructure
- Design and build automated workflows using Microsoft Power Automate and Azure Logic Apps for DLP alert routing, enrichment, user notifications, approval workflows, incident ticket creation (ServiceNow/Jira), automated remediation actions, and compliance reporting processes
- Extend DLP coverage and governance to AI and GenAI channels — monitor and control sensitive data flowing into AI tools and assistants such as Microsoft 365 Copilot, Copilot Studio agents, Claude, ChatGPT, and other LLM/GenAI applications , using Purview DLP for AI apps, browser/endpoint controls, and CASB policies to prevent data leakage through prompts, uploads, and AI-generated outputs
- Integrate DLP tooling with the broader security and productivity ecosystem — SIEM/SOAR (Splunk, Microsoft Sentinel), email gateways, proxies, CASB, Active Directory / Entra ID, CMDB, Insider Risk Management, and AI platforms via APIs and connectors (including Copilot and Claude enterprise integrations) for alert triage assistance, event summarization, and reporting automation
- Write and maintain scripts and automation (PowerShell, Python, REST APIs, Graph API) for policy deployment, dictionary and user-ID updates, health checks, and scheduled compliance reporting
- Support data discovery and classification at rest — scanning file shares, databases, SharePoint, OneDrive, Teams, and cloud repositories to locate, classify, and protect sensitive data
- Act as Tier 2/3 escalation for DLP incidents : investigate potential data exfiltration, coordinate containment and remediation with SOC/IR teams, and contribute DLP telemetry to insider threat monitoring
- Write and optimize KQL queries across Microsoft Sentinel, Defender XDR Advanced Hunting, and Purview audit logs to investigate DLP incidents, hunt for exfiltration behavior, correlate DLP/label/user activity, and build custom analytics rules, dashboards, and workbooks
- Develop metrics and dashboards related to the data protection program's status, performance, and maturity (policy coverage, alert volumes, false-positive rates, violation trends) for leadership, audit, and compliance stakeholders; maintain runbooks, SOPs, and architecture documentation
- Partner with legal, privacy, compliance, and business data owners to translate regulatory requirements ( GDPR, HIPAA, PCI-DSS, SOX ) into enforceable technical controls, including AI acceptable-use enforcement
- Stay current with industry trends and advancements in data security and DLP technologies — including developments in Microsoft Purview, AI-driven data protection, and GenAI data governance — and make recommendations for improvements to existing systems and controls
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology , or a related field — or equivalent practical experience
- 3–5 years of experience in information security / security engineering, including 2+ years of hands-on DLP administration and engineering in an enterprise environment
- Proven hands-on expertise with at least one major enterprise DLP platform : Microsoft Purview DLP, Symantec/Broadcom DLP, Forcepoint DLP, Trellix DLP, Netskope, or Zscaler
- Hands-on experience with Microsoft Purview Information Protection — sensitivity labels and auto-labeling : label taxonomy and policy design, service-side and client-side auto-labeling, simulation/tuning, trainable classifiers, encryption and content-marking configuration, and integrating labels with DLP policy enforcement
- Working experience building automation with Power Automate and/or Azure Logic Apps (flows, connectors, approvals, HTTP/API actions) in a security or IT operations context
- Hands-on configuration and integration experience — setting up and managing connectors between DLP platforms and adjacent systems: SIEM connectors (Microsoft Sentinel data connectors, Splunk add-ons/HEC, syslog/CEF forwarding), SOAR and ticketing connectors (ServiceNow, Jira), AI agent and LLM connectors (Copilot / Copilot Studio plugins, Claude and Azure OpenAI API integrations, custom Power Platform connectors), CASB integrations, and Graph API/webhook-based event feeds — including authentication setup (OAuth, service principals, API keys), permission scoping, and connector health monitoring
- Exposure to securing and integrating AI/GenAI tools — Microsoft 365 Copilot readiness and data governance, DLP for AI applications, and API-based integrations with LLM platforms such as Copilot, Claude (Anthropic), or Azure OpenAI ; understanding of prompt-level data leakage risks
- Working knowledge of KQL (Kusto Query Language) — writing and optimizing queries in Microsoft Sentinel, Defender Advanced Hunting, and Purview Audit/Activity Explorer to investigate DLP alerts, hunt for data exfiltration patterns, correlate label/DLP events, and build custom detections, workbooks, and reports
- Proficiency in writing Regular Expressions (Regex) for sensitive data pattern detection and content inspection rule development
- Scripting skills in PowerShell and/or Python ; comfort with REST and Microsoft Graph APIs
- Strong grasp of data protection concepts: classification, data-at-rest/in-motion/in-use controls, encryption, access controls, content inspection, EDM/IDM/fingerprinting
- Solid networking fundamentals (TCP/IP, HTTP/S, SMTP, TLS, DNS, proxies) and understanding of how data moves across email, web, endpoint, and cloud channels
- Proficiency with the Microsoft 365 ecosystem (Exchange Online, SharePoint, OneDrive, Teams), Entra ID / Active Directory, and Windows/Linux administration
- Experience in DLP alert triage, incident investigation, and collaboration with SOC/IR teams
- Knowledge of industry regulations and standards such as GDPR, CCPA, HIPAA, PCI-DSS, SOX, ISO 27001, and NIST CSF and their implications for DLP policy design and enforcement
- Strong analytical and problem-solving skills, with the ability to evaluate risks and develop controls to mitigate them
- Excellent communication and interpersonal skills, with the ability to work effectively with both technical and non-technical stakeholders
- Preferred: SC-401 / SC-200, Security+, vendor DLP certifications; experience with Insider Risk Management (Purview IRM, DTEX, Proofpoint ITM), CASB, Splunk SPL, or Copilot Studio / AI agent governance
We hire for skills and capabilities, not just credentials – if this role excites you, but doesn’t perfectly match your resume, we encourage you to apply anyway.
How We Work
Where you work matters – because collaboration, innovation and patient impact happen in many settings. Our roles are structured across four work models: site-essential, site-by-design, field-based and remote-by-design. The model assigned to this role is based on its core responsibilities. Learn more at https://careers.bms.com/ways-of-working.
Supporting People with Disabilities
BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to [email protected] . Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement.
Candidate Rights
BMS will consider qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.
For roles based in Los Angeles County only: If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california-residents/
Data Protection
We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection .
Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.
If this posting is missing required information required by local law or incorrect, contact BMS at [email protected] with the Job Title and Requisition number. Do not send application-related inquiries to this email. To check your application status, please login to your Candidate Home Account.
R1605268 : DLP Engineer