About this role
Job title: Lead, Infrastructure Security Engineer - CASB and DSPM
About the Role Lead Infrastructure Security Engineer with CASB, DSPM, and Microsoft 365 data security technologies. Responsible for designing, implementing, and maintaining data protection strategies across cloud and SaaS environments leveraging Z Scaler, with a focus on safeguarding sensitive data, regulatory compliance, and mitigating insider and external threats.
What You'll Do
- Design and implement enterprise-wide data security solutions leveraging CASB, DSPM, and Microsoft 365 security capabilities, preferably with Z Scaler.
- Develop secure architectures for SaaS, IaaS, and PaaS environments with a focus on data visibility and protection.
- Deploy, configure, and optimize CASB solutions to enforce security policies across cloud applications (introspection, shadow IT discovery); monitor user activity, detect anomalies, and prevent data exfiltration; integrate CASB with identity providers and SIEM/SOAR.
- Lead the implementation and operationalization of DSPM tools to discover, classify, and monitor sensitive data across environments; establish data classification frameworks and automate data risk assessments; provide continuous visibility into data exposure, access risks, and compliance gaps; integrate Microsoft CoPilot and Z Scaler or similar CASB / DSPM products.
- Administer and enhance Microsoft 365 security controls, including: sensitivity labels and information protection; Insider Risk Management; Microsoft Defender for Cloud Apps; secure Exchange Online, SharePoint Online, OneDrive, and Teams environments.
- Investigate security alerts related to data access, sharing, and exfiltration; collaborate with SOC and Incident Response teams to remediate threats; develop detection rules and automated response workflows.
- Ensure alignment with regulatory frameworks; support audits and compliance reporting; define and enforce data governance policies and standards.
What We're Looking For
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 7+ years of cybersecurity experience with a strong focus on data security.
- Hands-on experience with CASB solutions.
- Proven experience implementing and managing DSPM tools and frameworks.
- Deep expertise in Microsoft 365 security and compliance features.
- Strong understanding of cloud platforms.
- Experience with DLP, data classification, encryption, and access controls.
- Familiarity with SIEM/SOAR tools.
- Knowledge of IAM, including Zero Trust principles.
Nice to Have
- Experience with Z Scaler for CASB, DSPM, and DLP functions.
- Experience with Azure / AWS to design security controls.
- Experience with Splunk and Entra ID.
- Relevant certifications.
- Experience with automation and scripting.
- Knowledge of API integrations and security orchestration.
- Experience in highly regulated industries.
Compensation & Benefits
- Salary range: USD 133,600.00 to 220,400.00 per year.
- Market-competitive base salaries, with yearly bonus potential.
- Medical, dental, vision, life insurance, disability insurance, PTO, and leave options including parental and military leave.
- 401(k) plan with company match.
- Company-funded pension plan.
- Wellness programs including up to $1,600 a year for personal wellbeing needs.
- Education benefits to help finance traditional college enrollment toward an approved degree and accredited certificate programs.
- Employee Stock Purchase Plan: shares can be purchased at 85% of the lower of two prices after one year of service.
- Eligibility to participate in a discretionary bonus plan.