Security Engineer
Senior Information Security Engineer focused on DLP and insider threat, protecting athenahealth’s sensitive data through advanced loss prevention strategies, risk assessment, and security operations to ensure compliance and safeguard customer and workforce information.
Join us as we work to create a thriving ecosystem that delivers accessible, high-quality, and sustainable healthcare for all.
Employer work visa sponsorship and support are not provided for this role. Applicants must be currently authorized to work in the United States at hire and must maintain authorization to work in the United States throughout their employment with our company.
Senior Information Security Engineer- DLP/Insider Threat
Position Summary
The Senior Information Security Engineer- DLP/Insider Threat helps protect athenahealth ’s sensitive company, customer, workforce, and healthcare data. This role supports the operation and improvement of data loss prevention and insider risk capabilities across endpoint, email, SaaS, cloud, collaboration, identity, and security platforms.
This is a hands-on, engineering-focused role with an emphasis on tool configuration, alert tuning, technical troubleshooting, evidence quality, workflow improvement, and cross-functional response.
About the Team This team supports data protection and insider risk capabilities that help safeguard PHI, PII, confidential business data, intellectual property, credentials, and other sensitive or regulated information. The work spans security tooling, alert triage, investigations, policy tuning, and operational support in partnership with multiple security and business teams.
Essential Job Responsibilities
DLP and insider risk platform operations
Configure, monitor, and tune DLP, UEBA, DSPM/SSPM, and insider risk controls.
Support tools such as Cyberhaven, Proofpoint, CrowdStrike, and Splunk.
Maintain policies, classifiers, thresholds, exceptions, alert routing, and workflow logic.
Support protection for PHI, PII, confidential business data, IP, credentials, and other sensitive data.
Tooling, telemetry, and troubleshooting
Troubleshoot tooling issues, endpoint policy behavior, telemetry gaps, alert quality, and coverage concerns.
Validate data flows, integrations, event quality, and control effectiveness with platform owners and security partners.
Identify improvements that reduce false positives, increase detection fidelity, and improve reliability.
Alert triage and investigation
Triage alerts involving sensitive data movement, endpoint activity, SaaS usage, email exfiltration, external sharing, removable media, personal cloud storage, unusual user behavior, and AI tool usage.
Escalate cases to the Cybersecurity Operations Center as needed.
Correlate findings across security tools when needed.
Data exposure and control improvement
Investigate data movement and user activity to identify policy tuning opportunities and potential incidents.
Assess potential sensitive data exposure through AI workflows where telemetry is available.<
Posted June 20, 2026