What are the responsibilities and job description for the Red Team Threat Hunter Specialist (DLP) -Hybrid in Charlotte, NC position at RSC Solutions?
TITLE: Red Team Threat Hunter Specialist (DLP)
LOCATION: Charlotte, NC
2 DAYS ONSITE IN THE OFFICE
ONLY LOCAL CANDIDATES IN CHARLOTTE!! NO RELOCATION!!!
NO C2C 3RD PARTY VENDORS!!!
JOB DESCRIPTION:
The Red Team Analyst - Data Loss Prevention will serve as an offensive security specialist within the Enterprise Information Protection (EIP) program, responsible for testing, validating, and stress‐testing DLP controls against real‐world insider threat and data exfiltration scenarios.
This role focuses on thinking like a malicious insider—employee, contractor, or compromised identity—to simulate and execute data loss techniques across endpoints, email, cloud collaboration platforms, and unstructured data repositories. Findings will directly inform control improvements, detection tuning, policy enforcement, and insider risk modeling across EIP and Insider Risk programs.
Responsibilities:
1) Design and execute red team-style data exfiltration scenarios aligned to insider threat, negligent user, and compromised account risk.
2) Simulate data loss techniques across endpoint, email, cloud storage, collaboration tools, web upload, printing, and removable media.
3) Test DLP controls for bypass techniques, misconfigurations, policy gaps, and detection blind spots.
4) Emulate high‐risk behaviors tied to role‐based access, privileged users, leavers, and third‐party identities.
5) Validate effectiveness of DLP policies, sensitivity labels, endpoint controls, and alerting logic.
6) Partner with EIP engineering teams to tune detection rules, thresholds, and policy guardrails.
7) Execute testing tied to new DLP capabilities, roadmap initiatives, and tool deployments (e.g., endpoint DLP, unstructured data controls).
8) Produce clear, defensible reports outlining attack paths, control weaknesses, risk severity, and remediation guidance.
9) Present findings to EIP leadership, Insider Risk governance forums, and control owners.
10) Track remediation activities and validate improvements through re‐testing.
Required Skills:
1) 5 years of experience in red team, offensive security, purple team, or adversary simulation roles.
2) Proven experience testing or bypassing Data Loss Prevention (DLP) or data protection controls.
3) Strong understanding of insider threat behaviors, data exfiltration techniques, and endpoint attack vectors.
4) Hands‐on experience with endpoint, email, cloud, and collaboration security controls.
5) Ability to translate technical findings into business and risk‐relevant insights.
6) Direct experience working with Varonis, Microsoft Purview (DLP, Information Protection, Insider Risk), and Proofpoint environments (TRAP, TAP, CASB).
7) Experience testing unstructured data environments and user‐driven data movement.
8) Knowledge of threat modeling frameworks applied to human‐centric and insider risk.
9) Background in regulated industries (financial services, healthcare, or technology).