Sr Security DAP

  • Full-time
  • Location: India - Hyderabad
  • Company: Mattel Global Business Services

Job Description

The Senior Security Engineer – Insider Threat & Data Protection (DLP) is responsible for designing, deploying, and managing data protection and insider threat detection technologies to safeguard Mattel’s global enterprise. This senior-level role focuses on preventing data loss, detecting insider-driven risks, and ensuring compliance with privacy and data protection standards. The position combines strong technical expertise with investigative and analytical skills to identify, respond to, and mitigate potential insider threats while fostering a culture of security and trust across the organization.

Roles and Responsibilities

  • Engineer, implement, and manage enterprise Data Loss Prevention (DLP) and insider threat monitoring solutions across Mattel’s global environments.
  • Develop, configure, and tune DLP and insider threat detection policies to accurately detect and prevent data misuse or unauthorized data movement.
  • Integrate DLP and insider threat technologies with identity, cloud, and endpoint platforms to improve visibility, correlation, and automated response.
  • Collaborate with Legal, HR, and Compliance teams to ensure insider threat monitoring aligns with ethical, privacy, and global data protection standards.
  • Investigate alerts and incidents involving data exfiltration, insider misuse, or suspicious behavior, providing clear documentation and escalation as needed.
  • Perform root cause analysis of insider threat events and recommend technical and procedural improvements to reduce risk exposure.
  • Create and maintain dashboards and metrics that measure DLP effectiveness, insider threat trends, and overall program performance.
  • Collaborate with IT, Infrastructure, and Security Engineering teams to enable secure collaboration and ensure compliance with data handling policies.
  • Develop and maintain documentation, operational standards, and playbooks for data loss prevention, insider threat response, and investigation workflows.
  • Evaluate and recommend emerging DLP and behavioral analytics tools to enhance detection, monitoring, and response capabilities.
  • Support audits and compliance assessments related to data protection and insider threat management frameworks.
  • Contribute to continuous improvement initiatives by automating repetitive analysis and monitoring tasks where possible.
  • Stay up to date on evolving data protection regulations (e.g., GDPR, CCPA) and ensure that security controls align with compliance requirements.
  • 5–7+ years of experience in security engineering, data protection, or insider threat operations within enterprise environments. 

  • Hands-on experience implementing and managing DLP and insider threat monitoring platforms (endpoint, email, network, and cloud-based). 

  • Deep understanding of data classification, handling, and access control models across enterprise ecosystems. 

  • Experience analyzing user activity and data movement to detect anomalous or risky behavior. 

  • Proficiency in integrating DLP and insider threat technologies with SIEM, SOAR, and cloud platforms for enhanced visibility and automation. 

  • Strong knowledge of endpoint, network, and cloud DLP technologies and best practices for data security enforcement. 

  • Experience in policy tuning, rule creation, and reducing false positives within DLP and insider threat systems. 

  • Familiarity with scripting and automation (Python, PowerShell, or equivalent) for policy management and workflow optimization. 

  • Working knowledge of privacy and regulatory frameworks including GDPR, CCPA, and ISO 27001. 

  • Excellent analytical, investigative, and communication skills, with the ability to collaborate across global, cross-functional teams. 

Preferred: 

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or a related field (or equivalent practical experience). 

  • Certifications such as GCITP, CCITP, CDPSE, or equivalent credentials in data protection or insider threat management. 

  • Experience with insider threat frameworks and behavioral analytics tools supporting large enterprise environments. 

  • Familiarity with CASB, DLP-as-a-Service, and cloud security solutions (Microsoft 365, Google Workspace, or equivalent). 

  • Knowledge of the MITRE ATT&CK framework for insider threat and data exfiltration scenarios. 

  • Experience conducting forensic investigations related to insider threats, data leakage, or intellectual property protection.  

Shift Timing:  

10:00 – 18:00 PST (22:30 – 06:30 IST), Monday through Friday, with emergency on-call responsibilities as required. 

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice