Security Operations Data Loss Prevention Engineer
Everpure · Lehi, Utah; Santa Clara, California · United States · On-site
Pay: USD 205,000 – 308,000 a year
Posted Sep 28, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem.
This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.
THE ROLE
As our Security Operations Data Loss Prevention (DLP) Engineer, you will own and elevate Everpure’s enterprise data protection strategy across every digital and physical vector.
In this high-impact individual contributor role, you will establish data governance standards and architect practical controls that safeguard customer information, source code, intellectual property, and other sensitive assets without hindering business velocity. You will partner with Engineering, Legal, Privacy, DevSecOps, and GISO leadership to define how sensitive data is discovered, classified, monitored, and protected across the enterprise.
WHAT YOU'LL DO
Architect Enterprise DLP Strategy: Own and mature the multi-channel DLP program end to end across endpoint, network, SaaS, application, cloud, and generative AI environments. Define program metrics, track outcomes, evaluate build-versus-buy decisions, and report data-protection posture to GISO leadership.
Establish Data Standards & Governance: Author data-classification frameworks, handling requirements, and exception processes. Maintain a sensitive-data map with data owners so the organization understands where regulated and proprietary data lives, how it is classified, and who is accountable for it.
Protect Endpoints & Physical Channels: Design and operate controls across macOS, Windows, and Linux, including removable media, printing, clipboard, screen capture, and local cloud-sync channels. Define requirements for hard-copy handling, device disposal, and media sanitization, including the specific needs of manufacturing and lab environments.
Protect Network, Application & Cloud Data: Define egress inspection strategies across email, web, and general network traffic, including practical SSL/TLS inspection boundaries and encrypted-flow visibility. Detect and prevent sensitive-data movement through applications, APIs, databases, file shares, CI/CD systems, and unstructured repositories while partnering with Cloud and DevSecOps teams across AWS, Azure, and GCP.
Protect AI Workflows & Sensitive Assets: Establish practical guardrails for sensitive data flowing into and out of public AI assistants, embedded copilots, internal models, and agentic tools. Address prompt content, file uploads, context windows, tool integrations, source code, and build-system secrets while enabling safe AI adoption.
Build Detections & Automate Response: Design,…