Lead Data Loss Prevention Engineer
Wells Fargo
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
About This Role
Wells Fargo is seeking a Lead Data Loss Prevention Engineer with deep expertise in Data Loss Prevention (DLP) policy authoring and content development. This role is responsible for designing, authoring, testing, and tuning DLP rules that protect sensitive data across email, endpoints, web, and SaaS/collaboration channels. The ideal candidate translates business and regulatory requirements into precise detection logic, continuously improves signal quality, and produces clear technical documentation and stakeholder communications.
This role sits at the intersection of engineering, risk, and operations, partnering closely with Information Protection, Incident Response, Legal, Risk, and platform teams to implement effective, scalable DLP controls.
In This Role, You Will
- Author, maintain, and optimize DLP rules and policies using techniques such as: Regular expressions, Keyword and dictionary-based detection, Exact Data Match (EDM) / Indexed Data Match (IDM), Document fingerprinting, Machine-learning classifiers, Classification labels and metadata.
- Translate business requirements, regulatory obligations, and risk scenarios into: Detection logic, Comprehensive test cases, Promotion criteria (monitor → prevent).
- Conduct technical investigations of security events and incidents, including post-incident analysis and digital forensics, to identify root causes and recommend long-term mitigation strategies.
- Continuously tune DLP policies to reduce false positives and negatives using telemetry, triage feedback, and controlled experimentation, measure and report precision, recall, and block efficacy.
- Manage DLP policy-as-code artifacts using version control, peer review, and change-management processes, maintaining traceability from requirement to implementation.
- Develop and maintain: Operational runbooks, Exception and release-code workflows, User-facing guidance and FAQs, Release notes for policy updates and changes.
- Partner with DLP operations and Incident Response teams to: Triage alerts and events, Analyze trends and root causes, Drive corrective actions with data owners and application teams.
- Define, track, and report key performance and risk indicators (KPIs/KRIs), including alert volumes, false-positive rates, channel coverage, and policy maturity.
- Support audits and regulatory exams by preparing evidence, maintaining documentation, and supporting quarterly and annual reviews.
- Align DLP rules and enforcement with Wells Fargo's information classification and labeling program, ensuring consistent use of tags and labels in policy conditions.
- Serve as a subject matter expert for: SaaS and application security reviews, AppMail and data-egress use cases, Secure data-sharing controls.
- Collaborate cross-functionally with Information Protection, Risk, Legal, Messaging & Collaboration, Endpoint, and Cloud teams to safely deploy and evolve controls.
- Mentor peers and contribute to standards, reusable patterns, and best practices for DLP engineering and security content development.
Required Qualifications
- 5+ years of Engineering experience, or equivalent demonstrated through work experience, training, military service, or education.
- 5+ years of experience in information protection, DLP engineering, or security content development.
- Hands-on experience authoring and managing policies on one or more enterprise DLP platforms, such as: Microsoft Purview, Broadcom (Symantec) DLP, Forcepoint, Proofpoint, Zscaler, or equivalent technologies.
- Strong expertise in regex and pattern-matching techniques, with working knowledge of: EDM/IDM, Sensitive data types (PII, PHI, PCI), Data classification and labeling.
- Familiarity with modern collaboration and productivity platforms, including: Microsoft 365 (Exchange, SharePoint, OneDrive, Teams) and/or Google Workspace.
- Scripting and query proficiency (PowerShell, SQL, and/or Python) and experience working in Git-based version control and CI/CD workflows.
- Excellent written communication and documentation skills, with the ability to communicate effectively to both technical and non-technical audiences.
Desired Qualifications
- Experience in financial services or other highly regulated industries, with familiarity with: NIST 800-53 / 800-171, ISO/IEC 27001, Data privacy and protection requirements.
- Knowledge of endpoint DLP, CASB/SSE, secure web gateways, email security, OCR, and document fingerprinting technologies.
- Background in exception governance and release-code processes, balancing risk exposure, business needs, and user experience.
- Relevant certifications such as: SC-400 or SC-100, CISSP, CCSP, GIAC.
Job Expectations
- Ability to travel up to 10% of the time.
- Ability to work in a fast-paced, high-demand environment while balancing multiple priorities.
- This position offers a hybrid work schedule.
- This position is not eligible for Visa sponsorship.
- Possible up to 10% travel.
Locations
1525 WT Harris Blvd, Charlotte, North Carolina; 300 South Brevard, Charlotte, NC; 2600 S Price Rd, Chandler, Arizona; 194 Wood Ave S, Iselin, NJ; 550 4th St, Minneapolis, MN; 333 Market St, San Francisco, CA; 1302 El Camino Menlo Park, CA
Pay Range
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
$119,000.00 - $224,000.00
Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
Key skills/competency
- DLP policy authoring
- Regular expressions (regex)
- Exact Data Match (EDM) / Indexed Data Match (IDM)
- Data classification and labeling
- Microsoft Purview / Broadcom (Symantec) DLP
- Incident response and analysis
- Security content development
- Risk management and compliance
- PowerShell / Python scripting
- Git-based version control
How to Get Hired at Wells Fargo
- Research Wells Fargo's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor. Focus on their strong risk-mitigating and compliance-driven environment.
- Tailor your resume: Customize your resume to highlight extensive experience in DLP engineering, information security, and financial services. Emphasize policy authoring, platform expertise (e.g., Microsoft Purview), and compliance frameworks (NIST, ISO).
- Showcase technical expertise: Prepare to demonstrate strong knowledge in regular expressions, EDM/IDM, data classification, and scripting (PowerShell/Python). Provide specific examples of optimizing DLP rules and managing policy-as-code.
- Prepare for behavioral questions: Practice responses that illustrate your ability to collaborate cross-functionally, manage competing priorities in a fast-paced environment, and balance risk exposure with business needs. Highlight problem-solving and incident analysis skills.
- Network strategically: Connect with current and former Wells Fargo employees, especially within information security or risk management, on LinkedIn to gain insights and potentially referrals.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background