EngineerJobs.io
← Back to all jobs

Job Description

Join the IT Security organization at Intuitive Surgical and help strengthen protection across endpoints, cloud applications, and network environments. In this onsite role in Peachtree Corners, GA, you’ll administer and tune DLP controls, manage EDR and incident response orchestration, and support zero trust enforcement. The work focuses on investigating DLP and endpoint security activity, correlating telemetry, and contributing to continuous improvements in the company’s security posture.

What you’ll do

  • Administer and tune DLP policies and rules within enterprise DLP and SASE/CASB platforms to help prevent unauthorized data exfiltration across endpoints, cloud applications, and network egress.
  • Deploy and support EDR agents on Windows, macOS, and Linux, maintaining sensor health, policy enforcement, and telemetry collection.
  • Build SOAR workflows for automated incident response and orchestration to accelerate alert triage, enrichment, containment, and escalation across the security tooling stack.
  • Support ZTNA enforcement in coordination with Network Security so least-privilege access aligns with zero trust architecture principles.
  • Investigate DLP alerts, including root cause analysis, data classification at risk, coordination on policy exceptions with business stakeholders, and documentation for compliance and audit purposes.
  • Triage and classify endpoint events by severity and business impact, correlating telemetry from EDR, SIEM, and DLP platforms to identify threats and data exposure risks.
  • Troubleshoot endpoints across Windows, macOS, and Linux, including agent deployment issues, policy conflicts, OS-specific anomalies, and sensor communication failures.
  • Use Elasticsearch to develop and refine operational metrics and dashboards covering DLP effectiveness, endpoint coverage gaps, automation ROI, and incident response performance.
  • Collaborate on SIEM detections with Detection Engineering by creating and tuning rules addressing DLP bypass techniques, EDR evasion, and insider threat indicators.
  • Partner during escalations with Incident Response and Investigations teams by providing endpoint forensic data, DLP event context, and automation support across the incident lifecycle.
  • Support internal investigations (including insider threat and policy violations) using DLP, EDR, and SIEM for evidence collection and forensic analysis.
  • Handle sensitive information with discretion while maintaining confidentiality throughout the investigative lifecycle, including privileged findings and personnel matters.

Qualifications

  • Minimum 2 years of experience.
  • Hands-on experience administering and tuning enterprise DLP and SASE/CASB solutions across endpoint, cloud, and network enforcement points.
  • Experience deploying, managing, and troubleshooting EDR platforms across Windows, macOS, and Linux.
  • Demonstrated ability to troubleshoot endpoints across Windows, macOS, and Linux, including agent lifecycle management, OS-level diagnostics, and policy conflict resolution.
  • Understanding of OS internals for Windows, macOS, and Linux, including file systems, process management, registry/plist configuration, logging subsystems, and kernel-level behaviors relevant to security tooling.
  • Working knowledge of ZTNA concepts and technologies, including identity-aware access controls, micro-segmentation, and least-privilege network policies.
  • Experience building SOAR automation and orchestration workflows for incident triage, enrichment, and response.
  • Familiarity with SIEM platforms and Elasticsearch for log analysis, alert correlation, and dashboard development.
  • Strong communication skills to convey technical findings to IT teams, engineering stakeholders, and business partners in a matrixed organization.
  • Demonstrated ability to handle sensitive and confidential information with discretion, including investigation findings, personnel data, and legal hold materials.
  • Investigative mindset: curiosity, attention to detail, methodical evidence handling, objectivity, and ability to build a factual narrative from disparate data sources.
  • Degree in a technical related field (or additional related experience).

Technologies

DLP, SASE/CASB, EDR, SOAR, ZTNA, Elasticsearch, SIEM, Windows, macOS, Linux

Compensation & workplace details

  • Salary: USD 124,200 - 210,300 per year (base range varies by region).
  • Shift: Day.
  • Workplace type: Set schedule. Onsite weekly, with the onsite percentage defined by the leader.

Additional information

  • Due to the nature of the business and the role, Intuitive and/or customer(s) may require proof of vaccination against certain diseases including COVID-19. Details can vary by role.
  • Equal Opportunity Employer.
  • U.S. Export Controls may apply for prospective employees who are nationals from countries on embargo or sanctions status.
  • Accommodation & Accessibility: Intuitive provides reasonable accommodations. Contact [email protected] for assistance during application or interview.

Preferred skills and experience

  • Experience in a SOC, incident response, or DLP operations function supporting enterprise-level environments.
  • SANS/GIAC certification(s) strongly preferred (e.g., GCFE, GCFA, GCED, GCIH, GCIA, GDSA, or GREM). CISSP or CompTIA Security+ are a plus.
  • Experience operating across a mature enterprise security stack spanning EDR, DLP, SASE/CASB, SOAR, SIEM, ZTNA, next-generation firewalls, identity providers, and email security gateways.
  • Experience developing automated playbooks for DLP incident handling, endpoint isolation, or threat enrichment workflows.
  • Understanding of insider threat detection methodologies, data classification frameworks, and regulatory requirements relevant to medical device or healthcare organizations (e.g., HIPAA, FDA).
  • Experience conducting or supporting workplace investigations, forensic examinations, or e-discovery processes in a corporate environment.
  • Familiarity with chain-of-custody procedures, legal hold requirements, and evidence preservation standards.
  • Prior systems administration experience across Windows, macOS, or Linux, including working understanding of Active Directory, group policy, endpoint management, and OS-level security hardening.

Similar Jobs