Skip to main content
Back to jobs

Senior Information Security Engineer- DLP/Insider Threat

External
athenahealth logoAthenahealth · Singapore, Singapore
$96K–$164K/yrFull-timeRemoteToday
Information Security EngineeringSenior Information Security Engineer
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all. Employer work visa sponsorship and support are not provided for this role. Applicants must be currently authorized to work in the United States at hire and must maintain authorization to work in the United States throughout their employment with our company. Senior Information Security Engineer- DLP/Insider Threat Position Summary The Senior Information Security Engineer- DLP/Insider Threat helps protect athenahealth 's sensitive company, customer, workforce, and healthcare data. This role supports the operation and improvement of data loss prevention and insider risk capabilities across endpoint, email, SaaS, cloud, collaboration, identity, and security platforms. This is a hands-on, engineering-focused role with an emphasis on tool configuration, alert tuning, technical troubleshooting, evidence quality, workflow improvement, and cross-functional response. About the Team This team supports data protection and insider risk capabilities that help safeguard PHI, PII, confidential business data, intellectual property, credentials, and other sensitive or regulated information. The work spans security tooling, alert triage, investigations, policy tuning, and operational support in partnership with multiple security and business teams. Essential Job Responsibilities DLP and insider risk platform operations Configure, monitor, and tune DLP, UEBA, DSPM/SSPM, and insider risk controls. Support tools such as Cyberhaven, Proofpoint, CrowdStrike, and Splunk. Maintain policies, classifiers, thresholds, exceptions, alert routing, and workflow logic. Support protection for PHI, PII, confidential business data, IP, credentials, and other sensitive data. Tooling, telemetry, and troubleshooting Troubleshoot tooling issues, endpoint policy behavior, telemetry gaps, alert quality, and coverage concerns. Validate data flows, integrations, event quality, and control effectiveness with platform owners and security partners. Identify improvements that reduce false positives, increase detection fidelity, and improve reliability. Alert triage and investigation Triage alerts involving sensitive data movement, endpoint activity, SaaS usage, email exfiltration, external sharing, removable media, personal cloud storage, unusual user behavior, and AI tool usage. Escalate cases to the Cybersecurity Operations Center as needed. Correlate findings across security tools when needed. Data exposure and control improvement Investigate data movement and user activity to identify policy tuning opportunities and potential incidents. Assess potential sensitive data exposure through AI workflows where telemetry is available. Recommend and help implement improvements that reduce data loss risk while preserving productivity and user experience. Process, reporting, and cross-functional support Maintain playbooks, SOPs, dashboards, metrics, reports, escalation paths, and evidence-handling practices. Partner with Incident Response, Cloud Security, Access Control, Endpoint Engineering, Privacy, Legal, Compliance, HR, and business stakeholders. Support alert routing, case workflows, integrations, and automation improvements. Support audits, control testing, and reporting related to HIPAA, data protection, and information security requirements. Team support and on-call coverage Cross-train team members in tool administration, workflows, and troubleshooting. Serve as backup support for team responsibilities and workflows. Participate in 24x7 on-call responsibilities. Expected Education & Experience Bachelor's degree or equivalent practical experience. Strong foundational skills in operating system, hardware, software, and network troubleshooting. Experience in information security, DLP, insider risk, UEBA, security operations, endpoint security, data/SaaS/AI security posture management, email security, or related technical security work. Hands-on experience administering, monitoring, or tuning enterprise security tools such as DLP, insider risk, UEBA, email security, endpoint security, cloud security posture, secrets detection, SIEM, or case management platforms. Experience supporting data protection controls across cloud, SaaS, endpoint, email, repository, data storage, or AI-enabled environments. Experience analyzing alerts, logs, user activity, endpoint activity, email events, cloud findings, repository findings, or data movement patterns. Experience administering end-user computers and troubleshooting issues as they arise. Helpful certifications or training may include Security+, GCIH, GCFE, CDPSE, CIPP/US, AIGP, CCSK, Microsoft SC-401, or insider risk training, but they are not required. Required Knowledge & Skills Knowledge of DLP, insider risk, UEBA, email security, cloud exposure, secrets detection, endpoint telemetry, and common exfiltration paths. Ability to configure, tune, and troubleshoot tools such as Cyberhaven


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at athenahealth? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect