Principal Security Engineer - AI Data Protection

United StatesFull-time$150k–$190kPosted Aug 7, 2026

Principal Engineer, Enterprise Browser Data Protection & Support

Principal Engineer

Enterprise Browser Data Protection & Support

Position Summary

Serve as the senior technical authority for the architecture, engineering, security, and operational support of enterprise browser and browser-based data protection capabilities. Lead platform strategy, complex troubleshooting, policy design, integrations, automation, and continuous improvement across a large, regulated enterprise environment.

Key Responsibilities

• Own the enterprise browser security architecture, roadmap, standards, and lifecycle.

• Design and implement browser-based data loss prevention controls, including download, upload, clipboard, print, screen capture, watermarking, and session restrictions.

• Integrate browser platforms with identity, endpoint management, DLP, SIEM/SOAR, secure web gateway, CASB, SASE, and zero trust technologies.

• Provide Tier 3/Tier 4 support, lead major incident response, perform root-cause analysis, and develop operational runbooks.

• Automate deployment, policy management, monitoring, reporting, and platform health checks.

• Partner with Cybersecurity, IAM, Endpoint, Network, Cloud, Risk, Compliance, and vendor teams; mentor engineers and influence enterprise design decisions.

Required Experience

• 12+ years in cybersecurity, infrastructure, endpoint, or platform engineering.

• 8+ years designing and supporting enterprise security technologies.

• 5+ years with enterprise browsers, browser isolation, secure web access, or browser-based DLP.

• Demonstrated experience leading architecture and engineering initiatives in large, complex environments; regulated-industry experience preferred.

Required Toolset

• Enterprise browsers/security: Island, Palo Alto Prisma Browser, Chrome Enterprise Premium, Microsoft Edge for Business, Menlo Security, or equivalent.

• Data protection: Microsoft Purview DLP, Netskope DLP, Symantec DLP, Forcepoint DLP, Digital Guardian, or equivalent.

• Endpoint/identity: Microsoft Intune, MECM/SCCM, Tanium, Jamf, Entra ID, Active Directory, Okta, CyberArk, or Ping Identity.

• Security/monitoring: Microsoft Defender XDR, CrowdStrike, Splunk, Microsoft Sentinel, Zscaler, Palo Alto, Netskope, or Cisco Secure Access.

• Automation/development: PowerShell, Python, REST APIs, Microsoft Graph, Git, Azure DevOps or GitHub; Terraform preferred.

• Strong knowledge of DNS, TLS/HTTPS, proxies, SWG, CASB, SASE, ZTNA, VPN, and cloud platforms.

Education & Certifications

• Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering; master's degree preferred.

• Required: CISSP, CCSP, CISM, or a comparable advanced security certification.

• Preferred: Microsoft SC-100, SC-300, or SC-400; GIAC GCED/GCIH; AWS Security - Specialty; Azure Solutions Architect; ITIL 4; or TOGAF.

Core Competencies

• Enterprise architecture, technical leadership, strategic planning, executive communication, vendor management, risk assessment, incident leadership, mentoring, and cross-functional collaboration.

Pay Transparency

• The salary range for this position is $150,000 to $190,000 per year, plus an opportunity to earn additional incentive earnings. Actual pay is based on various factors including, but not limited to, the budget, work location, and relevant skills and experience.

Benefits

Comprehensive benefits include medical, dental, and vision coverage, retirement plans, parental leave, flexible work arrangements, education reimbursement, wellness programs, and generous paid time off exceeding local requirements.

Citizens Benefits Overview

 For an overview of our benefits, visit our Careers site - https://jobs.citizensbank.com/benefits.

#LI-Citizens1

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free