Bristol Myers Squibb
DLP Engineer
Hyderabad - TS - IN
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- IN
- Work mode
- On-site / unstated
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
At Bristol Myers Squibb, our employees often ask, “Who are you working for?”—a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.
Position Summary
Bristol Myers Squibb is seeking an experienced DLP Engineer to join our data security and data protection efforts. The successful candidate will be responsible for implementing and managing enterprise data protection strategies to protect BMS sensitive and confidential data, while also ensuring compliance with industry regulations and standards.
This position will be part of the Data Protection team in the Hyderabad office . The position will be expected to coordinate with stakeholders in the US and globally.
The ideal candidate will bring 3–5 years of experience in information security and DLP engineering, with strong hands-on proficiency across enterprise DLP platforms and the Microsoft Purview ecosystem — including sensitivity labels and auto-labeling , DLP rule and policy configuration, and regex-based content detection. The candidate should also bring practical experience with Power Automate and Azure Logic Apps workflow automation, KQL-based investigation and reporting , and securing and integrating GenAI tools such as Microsoft 365 Copilot and Claude with DLP and data protection controls.
If you want an exciting and rewarding career that is meaningful, consider joining our diverse team!
Key Responsibilities
A. Functional and Technical
- Design, implement, configure, and administer enterprise DLP solutions (e.g., Microsoft Purview DLP, Symantec/Broadcom, Forcepoint, Trellix, Netskope, Zscaler) across endpoint, network, email, web, and cloud channels, ensuring alignment with industry regulations and standards
- Build, test, and deploy DLP policies and detection logic — custom classifiers, regular expressions (Regex), keyword dictionaries, Sensitive Information Types (SITs), Exact Data Matching (EDM), Indexed Document Matching (IDM), and document fingerprinting — including scoped policy targeting, rule conditions, exceptions, and enforcement actions (audit, block, notify, restrict)
- Design, publish, and manage sensitivity labels (Microsoft Purview Information Protection / MIP): label taxonomy design, label policies and scoping, encryption and content-marking settings, container labels for Teams/SharePoint/Microsoft 365 Groups, and label-based DLP policy conditions
- Configure and operate auto-labeling at scale — client-side and service-side auto-labeling policies for Exchange, SharePoint, and OneDrive; simulation mode testing, tuning label-match accuracy with SITs and trainable classifiers, and monitoring label adoption, label analytics, and mislabeling trends
- Enforce downstream protection based on labels — label-driven DLP rules, conditional access to labeled content, and label inheritance/handling in AI tools (e.g., ensuring Copilot and other GenAI assistants honor sensitivity labels and encryption on protected content)
- Perform continuous rule tuning and policy optimization : analyze DLP events, validate true vs. false positives, document findings, and iteratively refine detection to improve accuracy and reduce alert noise
- Manage the DLP platform end to end — agent deployment, upgrades, health monitoring, coverage gap analysis, and maintenance of management/detection server infrastructure
- Design and build automated workflows using Microsoft Power Automate and Azure Logic Apps for DLP alert routing, enrichment, user notifications, approval workflows, incident ticket creation (ServiceNow/Jira), automated remediation actions, and compliance reporting processes
- Extend DLP coverage and governance to AI and GenAI channels — monitor and control sensitive data flowing into AI tools and assistants such as Microsoft 365 Copilot, Copilot Studio agents, Claude, ChatGPT, and other LLM/GenAI applications , using Purview DLP for AI apps, browser/endpoint controls, and CASB policies to prevent data leakage through prompts, uploads, and AI-generated outputs
- Integrate DLP tooling with the broader security and productivity ecosystem — SIEM/SOAR (Splunk, Microsoft Sentinel), email gateways, proxies, CASB, Active Directory / Entra ID, CMDB, Insider Risk Management, and AI platforms via APIs and connectors (including Copilot and Claude enterprise integrations) for alert triage assistance, event summarization, and reporting automation
- Write and maintain scripts and automation (PowerShell, Python, REST APIs, Graph API) for policy deployment, dictionary and user-ID updates, health checks, and scheduled compliance reporting
- Support data discovery and classification at rest — scanning file shares, databases, SharePoint, OneDrive, Teams, and cloud repositories to locate, classify, and protect sensitive data
- Act as Tier 2/3 escalation for DLP incidents : investigate potential data exfiltration, coordinate containment and remediation with SOC/IR teams, and contribute DLP telemetry to insider threat monitoring
- Write and optimize KQL queries across Microsoft Sentinel, Defender XDR Advanced Hunting, and Purview audit logs to investigate DLP incidents, hunt for exfiltration behavior, correlate DLP/label/user activity, and build custom analytics rules, dashboards, and workbooks
- Develop metrics and dashboards related to the data protection program's status, performance, and maturity (policy coverage, alert volumes, false-positive rates, violation trends) for leadership, audit, and compliance stakeholders; maintain runbooks, SOPs, and architecture documentation
- Partner with legal, privacy, compliance, and business data owners to translate regulatory requirements ( GDPR, HIPAA, PCI-DSS, SOX ) into enforceable technical controls, including AI acceptable-use enforcement
- Stay current with industry trends and advancements in data security and DLP technologies — including developments in Microsoft Purview, AI-driven data protection, and GenAI data governance — and make recommendations for improvements to existing systems and controls
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology , or a related field — or equivalent practical experience
- 3–5 years of experience in information security / security engineering, including 2+ years of hands-on DLP administration and engineering in an enterprise environment
- Proven hands-on expertise with at least one major enterprise DLP platform : Microsoft Purview DLP, Symantec/Broadcom DLP, Forcepoint DLP, Trellix DLP, Netskope, or Zscaler
- Hands-on experience with Microsoft Purview Information Protection — sensitivity labels and auto-labeling : label taxonomy and policy design, service-side and client-side auto-labeling, simulation/tuning, trainable classifiers, encryption and content-marking configuration, and integrating labels with DLP policy enforcement
- Working experience building automation with Power Automate and/or Azure Logic Apps (flows, connectors, approvals, HTTP/API actions) in a security or IT operations context
- Hands-on configuration and integration experience — setting up and managing connectors between DLP platforms and adjacent systems: SIEM connectors (Microsoft Sentinel data connectors, Splunk add-ons/HEC, syslog/CEF forwarding), SOAR and ticketing connectors (ServiceNow, Jira), AI agent and LLM connectors (Copilot / Copilot Studio plugins, Claude and Azure OpenAI API integrations, custom Power Platform connectors), CASB integrations, and Graph API/webhook-based event feeds — including authentication setup (OAuth, service principals, API keys), permission scoping, and connector heal
Similar jobs
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job