- Location
- Hyderabad, India
- Type
- Full-time
- Department
- Engineering
- Experience
- 3+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Working with Us
Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible.
Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us.
Position Summary
Bristol Myers Squibb is seeking an experienced DLP Engineer to join our data security and data protection efforts. The successful candidate will be responsible for implementing and managing enterprise data protection strategies to protect BMS sensitive and confidential data, while also ensuring compliance with industry regulations and standards.
The ideal candidate will bring 3-6 years of experience in data security and DLP, with a solid background in cybersecurity, risk management, and compliance. The candidate should bring strong hands-on proficiency in Microsoft Purview, alongside familiarity with other leading DLP tools and platforms, and a solid understanding of DLP rule and policy configuration, information protection frameworks, regulatory compliance, and foundational skills in scripting and regex-based content detection.
If you want an exciting and rewarding career that is meaningful, consider joining our diverse team!
Key Responsibilities
A. Functional and Technical
- Develop and implement data security and DLP policies and procedures across enterprise DLP platforms - leveraging tools such as Microsoft Purview, Symantec DLP, Forcepoint, Netskope, Zscaler, or equivalent - ensuring alignment with industry regulations and standards
- Configure and manage DLP rules and policies within the organization's chosen DLP platform(s), including scoped policy targeting, rule conditions, exceptions, and enforcement actions (audit, block, notify, restrict)
- Build and maintain Sensitive Information Types (SITs) or equivalent sensitive data classifiers - including custom regex-based patterns, keyword dictionaries, and document fingerprinting - to detect and protect sensitive data across cloud, email, endpoint, and collaboration environments
- Deploy and manage Information Protection controls including data classification, sensitivity labeling, auto-labeling policies, and encryption to protect data at rest, in transit, and in use across the enterprise
- Utilize Data Security Posture Management (DSPM) tools to identify data exposure risks, shadow data, overshared content, and excessive permissions; translate findings into actionable remediation plans and DLP policy enhancements
- Manage and monitor Network DLP solutions to inspect and control data in motion across web gateways, email, proxies, and CASB-integrated SaaS environments
- Evaluate and assess risks associated with data security and implement controls to mitigate those risks, leveraging DSPM posture insights and DLP telemetry across platforms
- Work with internal stakeholders to ensure that data security and DLP policies and procedures are being followed, and actively identify areas for improvement
- Conduct periodic assessments to identify risks to data security and develop action plans to mitigate those risks across cloud, network, and endpoint channels
- Maintain and update the response plan for investigating and escalating non-compliance events against BMS DLP policies
- Manage, delegate, and track incidents related to violations against BMS DLP policies
- Write and maintain scripts (PowerShell and/or Python) to automate DLP-related management tasks, alert triage, policy updates, and compliance reporting workflows
- Develop and apply Regular Expressions (Regex) for custom sensitive data pattern detection (e.g., PII, PHI, proprietary data, financial identifiers) within DLP platforms and content inspection engines
- Leverage foundational knowledge of Artificial Intelligence (AI) concepts to understand AI-powered detection mechanisms within DLP and data security tools - including trainable classifiers, AI-enhanced anomaly detection, and intelligent risk scoring for insider risk and data exfiltration scenarios
- Develop metrics related to the data protection program's status, performance, and maturity; and leverage those metrics to drive decisions around program enhancements and additions
- Stay current with industry trends and advancements in data security and DLP technologies - including developments in Microsoft Purview, DSPM, AI-driven data protection, and Network DLP - and make recommendations for improvements to existing systems and controls
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field
- 3-6 years of hands-on experience in data security and DLP, with a solid background in cybersecurity, risk management, and compliance
- Strong hands-on proficiency with Microsoft Purview - including DLP, Information Protection, Compliance portal, Sensitive Information Types (SITs), and DSPM; Purview expertise is a key differentiator for this role
- Experience with one or more enterprise DLP platforms such as Symantec DLP, Forcepoint, McAfee Total Protection for DLP, Netskope, Zscaler, or equivalent
- Working experience with Network DLP platforms for monitoring and controlling data in motion across web gateways, email relays, proxies, and cloud-connected environments
- Demonstrated experience creating and managing custom sensitive data classifiers or SITs - using regex patterns, keyword dictionaries, and supporting detection elements - within any enterprise DLP or data classification platform
- In-depth knowledge of industry regulations and standards such as GDPR, CCPA, and HIPAA and their implications for DLP policy design and enforcement
- Working knowledge of DSPM concepts and experience using DSPM tools (e.g., Microsoft Purview DSPM, Varonis, Cyera, BigID, Prisma Cloud, or similar) to assess and manage enterprise data risk posture
- Proficiency in writing Regular Expressions (Regex) for sensitive data pattern detection and content inspection rule development
- Basic scripting skills in PowerShell and/or Python for automation of DLP-related tasks, reporting, and policy management
- Foundational knowledge of Artificial Intelligence (AI) and Machine Learning (ML) concepts as applied to data protection - including understanding of AI-powered classifiers, anomaly detection, and intelligent risk-based alerting
- Strong analytical and problem-solving skills, with the ability to evaluate risks and develop controls to mitigate them
- Excellent communication and interpersonal skills, with the ability to work effectively with both technical and non-technical stakeholders
- Experience investigating and leading incident response efforts related to DLP policy violations and data security events
- Strong understanding of data security technologies including encryption, access controls, data classification, and information protection
- Experience with Security Incident and Event Management (SIEM) systems and principles (e.g., Microsoft Sentinel, Microsoft Defender, Splunk, or equivalent)
Position Summary
Bristol Myers Squibb is seeking an experienced DLP Engineer to join our data security and data protection efforts. The successful candidate will be responsible for implementing and managing enterprise data protection strategies to protect BMS sensitive and confidential data, while also ensuring compliance with industry regulations and standards.
The ideal candidate will bring 3-6 years of experience in data security and DLP, with a solid background in cybersecurity, risk management, and compliance. The candidate should bring strong hands-on proficiency in Microsoft Purview, alongside familiarity with other leading DLP tools and platforms, and a solid understanding of DLP rule and policy configuration, information protection frameworks, regulatory compliance, and foundational skills in scripting and regex-based content detection.
If you want an exciting and rewarding career that is meaningful, consider joining our diverse team!
Key Responsibilities
A. Functional and Technical
- Develop and implement data security and DLP policies and procedures across enterprise DLP platforms - leveraging tools such as Microsoft Purview, Symantec DLP, Forcepoint, Netskope, Zscaler, or equivalent - ensuring alignment with industry regulations and standards
- Configure and manage DLP rules and policies within the organization's chosen DLP platform(s), including scoped policy targeting, rule conditions, exceptions, and enforcement actions (audit, block, notify, restrict)
- Build and maintain Sensitive Information Types (SITs) or equivalent sensitive data classifiers - including custom regex-based patterns, keyword dictionaries, and document fingerprinting - to detect and protect sensitive data across cloud, email, endpoint, and collaboration environments
- Deploy and manage Information Protection controls including data classification, sensitivity labeling, auto-labeling policies, and encryption to protect data at rest, in transit, and in use across the enterprise
- Utilize Data Security Posture Management (DSPM) tools to identify data exposure risks, shadow data, overshared content, and excessive permissions; translate findings into actionable remediation plans and DLP policy enhancements
- Manage and monitor Network DLP solutions to inspect and control data in motion across web gateways, email, proxies, and CASB-integrated SaaS environments
- Evaluate and assess risks associated with data security and implement controls to mitigate those risks, leveraging DSPM posture insights and DLP telemetry across platforms
- Work with internal stakeholders to ensure that data security and DLP policies and procedures are being followed, and actively identify areas for improvement
- Conduct periodic assessments to identify risks to data security and develop action plans to mitigate those risks across cloud, network, and endpoint channels
- Maintain and update the response plan for investigating and escalating non-compliance events against BMS DLP policies
- Manage, delegate, and track incidents related to violations against BMS DLP policies
- Write and maintain scripts (PowerShell and/or Python) to automate DLP-related management tasks, alert triage, policy updates, and compliance reporting workflows
- Develop and apply Regular Expressions (Regex) for custom sensitive data pattern detection (e.g., PII, PHI, proprietary data, financial identifiers) within DLP platforms and content inspection engines
- Leverage foundational knowledge of Artificial Intelligence (AI) concepts to understand AI-powered detection mechanisms within DLP and data security tools - including trainable classifiers, AI-enhanced anomaly detection, and intelligent risk scoring for insider risk and data exfiltration scenarios
- Develop metrics related to the data protection program's status, performance, and maturity; and leverage those metrics to drive decisions around program enhancements and additions
- Stay current with industry trends and advancements in data security and DLP technologies - including developments in Microsoft Purview, DSPM, AI-driven data protection, and Network DLP - and make recommendations for improvements to existing systems and controls
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field
- 3-6 years of hands-on experience in data security and DLP, with a solid background in cybersecurity, risk management, and compliance
- Strong hands-on proficiency with Microsoft Purview - including DLP, Information Protection, Compliance portal, Sensitive Information Types (SITs), and DSPM; Purview expertise is a key differentiator for this role
- Experience with one or more enterprise DLP platforms such as Symantec DLP, Forcepoint, McAfee Total Protection for DLP, Netskope, Zscaler, or equivalent
- Working experience with Network DLP platforms for monitoring and controlling data in motion across web gateways, email relays, proxies, and cloud-connected environments
- Demonstrated experience creating and managing custom sensitive data classifiers or SITs - using regex patterns, keyword dictionaries, and supporting detection elements - within any enterprise DLP or data classification platform
- In-depth knowledge of industry regulations and standards such as GDPR, CCPA, and HIPAA and their implications for DLP policy design and enforcement
- Working knowledge of DSPM concepts and experience using DSPM tools (e.g., Microsoft Purview DSPM, Varonis, Cyera, BigID, Prisma Cloud, or similar) to assess and manage enterprise data risk posture
- Proficiency in writing Regular Expressions (Regex) for sensitive data pattern detection and content inspection rule development
- Basic scripting skills in PowerShell and/or Python for automation of DLP-related tasks, reporting, and policy management
- Foundational knowledge of Artificial Intelligence (AI) and Machine Learning (ML) concepts as applied to data protection - including understanding of AI-powered classifiers, anomaly detection, and intelligent risk-based alerting
- Strong analytical and problem-solving skills, with the ability to evaluate risks and develop controls to mitigate them
- Excellent communication and interpersonal skills, with the ability to work effectively with both technical and non-technical stakeholders
- Experience investigating and leading incident response efforts related to DLP policy violations and data security events
- Strong understanding of data security technologies including encryption, access controls, data classification, and information protection
- Experience with Security Incident and Event Management (SIEM) systems and principles (e.g., Microsoft Sentinel, Microsoft Defender, Splunk, or equivalent)
If you come across a role that intrigues you but doesn’t perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career.
Uniquely Interesting Work, Life-changing Careers
With a single vision as inspiring as “Transforming patients’ lives through science™ ”, every BMS employee plays an integral role in work that goes far beyond ordinary. Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting global participation in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues.
On-site Protocol
BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs. The occupancy type that you are assigned is determined by the nature and responsibilities of your role:
Site-essential roles require 100% of shifts onsite at your assigned facility. Site-by-design roles may be eligible for a hybrid work model with at least 50% onsite at your assigned facility. For these roles, onsite presence is considered an essential job function and is critical to collaboration, innovation, productivity, and a positive Company culture. For field-based and remote-by-design roles the ability to physically travel to visit customers, patients or business partners and to attend meetings on behalf of BMS as directed is an essential job function.
Supporting People with Disabilities
BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to [email protected]. Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement.
Candidate Rights
BMS will consider for employment qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.
If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california-residents/
Data Protection
We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection.
Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.
If you believe that the job posting is missing information required by local law or incorrect in any way, please contact BMS at [email protected]. Please provide the Job Title and Requisition number so we can review. Communications related to your application should not be sent to this email and you will not receive a response. Inquiries related to the status of your application should be directed to Chat with Ripley.
R1605268 : DLP Engineer