We are seeking an experienced **Data Loss Prevention (DLP) Policy & Controls Specialist** to support the design, implementation, tuning, and ongoing management of enterprise DLP policies and controls.The role will focus on translating security, regulatory, and control requirements into practical and deployable DLP policies across email, endpoint, web, cloud/SaaS, and GenAI environments.
Location: Montreal (Day 1 onboarding onsite/in office presence 3x/week)
Key Responsibilities
- Design, develop, and maintain DLP policies across email, endpoint, web, cloud/SaaS, and GenAI environments.
- Manage the DLP policy lifecycle, including policy creation, testing, tuning, implementation support, documentation, and optimization.
- Translate security, risk, regulatory, and control requirements into deployable DLP policies and controls.
- Tune DLP policies to improve detection accuracy and reduce false positives and false negatives.
- Apply sensitive data classification and detection methods to strengthen DLP control effectiveness.
- Incorporate jurisdiction-specific requirements, including data residency and regulatory constraints such as China Onshore requirements.
- Partner with engineering and operations teams to ensure DLP controls are technically feasible and operationally supportable.
- Assess and document DLP control coverage, gaps, limitations, exceptions, and compensating controls.
- Support risk, compliance, and audit inquiries related to DLP control design and effectiveness.
- Analyze technical, operational, and regulatory information and communicate findings clearly to technology and business stakeholders.
- Support DLP metrics, reporting, and control-effectiveness monitoring.
Required Skills & Experience
- Minimum 5+ years of relevant experience in DLP, cybersecurity, data protection, information security, or technology risk.
- Strong hands-on experience with DLP policy creation and lifecycle management.
- Strong understanding of DLP detection and enforcement controls.
- Experience with DLP policy tuning, including reducing false positives and false negatives.
- Experience translating security and control requirements into deployable DLP policies.
- Strong understanding of sensitive data classification and detection methods.
- Experience supporting risk and audit inquiries, including control coverage, gaps, limitations, and compensating controls.
- Experience addressing jurisdiction-specific regulatory and data residency requirements.
- Strong documentation, analytical, and stakeholder communication skills.
- Ability to collaborate effectively with engineering and operations teams to develop practical and supportable controls.
Good-to-Have Skills
- Experience with GenAI DLP / AI data protection
- Knowledge of DSPM, data classification, and sensitivity labeling
- Familiarity with GDPR, CCPA/CPRA, PCI DSS, and financial-services regulatory requirements
- Experience with DLP incident and alert analysis
- Experience developing DLP metrics, reporting, and control-effectiveness dashboards
- General understanding of cloud security, SaaS security, and cloud data protection