We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Staff Engineer II, Cyber - DLP Solution Engineer

Western Alliance Bancorporation
dental insurance, tuition assistance, 401(k)
United States, Arizona, Phoenix
Aug 28, 2026

Job Title:

Staff Engineer II, Cyber - DLP Solution Engineer

Location:

Block 23

What you'll do:

As a Staff Engineer II - Cyber (DLP Solution Engineer), you'll work both independently and as part of a cohesive team to design, implement, and guide enterprise data protection and data loss prevention (DLP) capabilities. This principal-level individual contributor role is responsible for assisting with the setting of technical direction for DLP tooling, detection strategy, control validation, and long-term operational resilience across endpoints, network, cloud, collaboration, and SaaS environments.

You'll take ownership to communicate, collaborate, and justify cybersecurity recommendations to a broad base of stakeholders across IT, Cyber, Risk, Audit, Privacy, Legal, Compliance, HR, and business functions. This role operates with broad autonomy and is expected to think systemically, not tactically, while remaining technically credible and hands-on for critical initiatives involving data loss prevention controls, policy implementation, and risk reduction options.

Western Alliance Bank's Insider Risk and Data Loss Prevention program is a strategic capability within the Information Security function, supporting the bank's continued growth as a Large Financial Institution. It focuses on identifying, preventing, and managing risks related to the unauthorized access, movement, or exposure of sensitive data. In this role, you will act as a technical subject matter expert and control owner responsible for defining DLP strategy, policies, detection logic, control frameworks, and implementation guidance.

This role requires deep working knowledge of DLP technologies and configurations to effectively design controls, guide implementation performed by engineering and operations teams, validate control effectiveness, and ensure technical outcomes remain aligned with business risk tolerance and regulatory expectations. You'll partner closely with Data Security, Insider Risk, Security Monitoring, Privacy, Legal, HR, Infrastructure, and vendor teams to mature the bank's data protection capabilities and maintain scalable, resilient solutions.
  • Define and evolve enterprise Data Loss Prevention (DLP) and data protection strategies across endpoint, network, email, cloud, collaboration, and SaaS environments.
  • Assist in the setting of technical direction for DLP tooling, detection philosophy, control coverage, and implementation standards.
  • Design and document DLP policies, detection logic, control frameworks, escalation criteria, and technical requirements aligned with business risk tolerance and regulatory expectations.
  • Serve as a technical authority on DLP tools, including Broadcom/Symantec DLP, Microsoft Purview DLP, Varonis, data discovery/classification platforms, and related technologies.
  • Assist in guiding engineering and operations teams responsible for hands-on platform administration to ensure DLP controls are implemented accurately, consistently, and in accordance with approved design intent.
  • Lead engineering design for enterprise-scale DLP detections, policy implementation patterns, data protection workflows, testing approaches, and control validation activities.
  • Assist in guiding DLP tooling strategy, including vendor capability assessment, configuration standards, integration opportunities, cost efficiency, lifecycle planning, and scalability considerations.
  • Drive detection quality, coverage mapping, false-positive reduction, policy tuning, and control effectiveness validation across DLP and data protection capabilities.
  • Partner to enhance data classification, labeling, protection, and policy enforcement capabilities across structured and unstructured data sources.
  • Collaborate with Insider Risk, Security Monitoring, Data Security, and Information Technology teams to align DLP signals with broader risk-based monitoring, behavioral analytics, and response processes.
  • Support advanced investigations or data loss events of interest, including technical analysis, root cause evaluation, risk context, and control improvement recommendations.
  • Partner with Privacy, Legal, Compliance, Audit, HR, and business stakeholders to ensure data protection controls are well-governed, documented, defensible, and aligned to regulatory frameworks.
  • Serve as a technical advisor to leadership on data protection risks, control gaps, tool limitations, maturity opportunities, and practical risk reduction options.
  • Respond to audit inquiries and contribute to regulatory exams, internal audits, control testing, and cyber resilience initiatives.
  • Partner to establish engineering standards, implementation guidance, operating models, runbooks, and technical documentation to support consistent execution by engineering and operations teams.
  • Continuously evaluate tooling capabilities, data integrations, alert workflows, reporting, and operational processes to improve coverage, scalability, resilience, and cost efficiency.
  • Evaluate and prototype emerging technologies that may enhance data-centric security, DLP, data protection, insider risk integration, or automated response capabilities.
  • Serve as a subject matter expert and mentor, where appropriate to engineers, analysts, and operational partners across data protection, DLP, and related security domains.

What you'll need:

  • 6+ years of advanced cybersecurity, security engineering, data protection, DLP, security operations, or related technology experience.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related field required.
  • Demonstrated leadership in DLP solution design, detection engineering, security engineering, or enterprise control implementation.
  • Strong experience with enterprise DLP platforms such as Broadcom/Symantec DLP, Microsoft Purview DLP, or equivalent technologies.
  • Demonstrated ability to translate business, regulatory, audit, and risk requirements into technical controls, implementation guidance, detection logic, and measurable outcomes.
  • Deep understanding of data protection principles, including data classification, labeling, encryption, tokenization, data lifecycle management, data movement controls, and sensitive data handling.
  • Advanced knowledge of enterprise telemetry and security tooling, including logging platforms, SIEM, EDR/XDR, IAM telemetry, CASB/SSE, proxies, secure email gateways, and cloud security monitoring.
  • Experience working with or alongside teams responsible for security engineering, platform administration, security operations, infrastructure, or application support.
  • Hands-on experience or strong working knowledge of scripting, automation, APIs, or data extraction using tools such as Python, PowerShell, KQL, SQL, or similar technologies.
  • Advanced experience of logging, data parsing, enrichment, and integration concepts such as JSON, syslog, APIs, key-value formats, and structured event data.
  • Advanced experience aligning controls to frameworks and expectations such as NIST, ISO, FFIEC, audit requirements, regulatory exams, or internal control testing.
  • Proven ability to translate technical findings into executive-level risk context and communicate clearly with both technical and non-technical stakeholders.
  • Strong analytical, problem-solving, documentation, and stakeholder management skills.
  • Ability to handle sensitive data protection and investigation-related matters with discretion, professionalism, and appropriate need-to-know handling.
  • Advanced speaking and writing skills.
Certifications Preferred
  • CISSP, CISM, GIAC expert-level certifications, or equivalent advanced security certification.
  • Microsoft Certified: Information Security Administrator Associate (SC-401) or equivalent Purview / information protection credential.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200), Microsoft Sentinel, Microsoft Defender, or related security operations certification.
  • Security+, GSEC, GCIH, GCIA, GCFA, or other relevant security, detection, incident response, data protection, or governance certifications.

Benefits you'll love:
We offer all the important things you'd want - like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you'll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow your career!

About the company:

Western Alliance Bank, Member FDIC, is a wholly owned subsidiary of Western Alliance Bancorporation. Serving clients nationwide, Western Alliance Bank includes six legacy bank brands - Alliance Association Bank, Alliance Bank of Arizona, Bank of Nevada, Bridge Bank, First Independent Bank and Torrey Pines Bank - that remain part of the company's heritage, as well as AmeriHome Mortgage, a Western Alliance Bank Company.

Western Alliance Bancorporation is committed to equal employment and will consider all qualified applicants without regard to race, sex, color, religion, age, nation origin, marital status, disability, protected veteran status, sexual orientation, gender identity or genetic information. Western Alliance Bancorporation is committed to working with and providing reasonable accommodations for individuals with disabilities. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process and/or need an alternative method of applying, please email HR@westernalliancebank.com or call 602-386-2488. When contacting us, please provide your contact information and state the nature of your accessibility issue. We will only respond to inquiries concerning requests that involve a reasonable accommodation in the application process.

Western Alliance Bancorporation

Applied = 0

(web-665cd84569-66c2c)