
5001 - 10000 employees
Founded 1951
⚖️ Legal
💼 Consulting
📋 Compliance
Legal • Consulting • Compliance
Fragomen is a global firm of immigration attorneys, solicitors, and consultants that provides immigration and mobility services to employers and individuals worldwide. The firm publishes research and insights (including worldwide immigration trends reports and regional overviews), issues immigration alerts, hosts events and webinars, and operates a Center for Strategy and Applied Insights to develop policy and compliance guidance. Fragomen also engages in technology and strategic partnerships (for example, a joint venture on digital identity solutions) to support immigration compliance, workforce mobility, and related advisory services.
🕒 August 5
Improve your chances of getting an interview by checking your resume score before you apply.

5001 - 10000 employees
Founded 1951
⚖️ Legal
💼 Consulting
📋 Compliance
Legal • Consulting • Compliance
Fragomen is a global firm of immigration attorneys, solicitors, and consultants that provides immigration and mobility services to employers and individuals worldwide. The firm publishes research and insights (including worldwide immigration trends reports and regional overviews), issues immigration alerts, hosts events and webinars, and operates a Center for Strategy and Applied Insights to develop policy and compliance guidance. Fragomen also engages in technology and strategic partnerships (for example, a joint venture on digital identity solutions) to support immigration compliance, workforce mobility, and related advisory services.
• Design, implement, and tune enterprise DLP policies across Microsoft 365, endpoint, email, SaaS, cloud, and collaboration platforms • Identify, classify, and protect sensitive information using data classification, sensitivity labels, policy conditions, and enforcement actions • Monitor and investigate DLP alerts involving potential data exposure, improper sharing, data exfiltration indicators, or policy violations • Partner with Legal, Compliance, Privacy, Risk, Records, and business stakeholders to align DLP controls with requirements • Develop and maintain DLP standards, operating procedures, runbooks, exception processes, and escalation workflows • Evaluate and improve controls for OneDrive, SharePoint, Box, Google Drive, Dropbox, ShareFile, NetDocuments, and similar services • Support CASB and SaaS governance efforts by identifying unsanctioned data movement, risky sharing, excessive permissions, and policy-enforcement opportunities • Conduct root-cause analysis on recurring alerts, control gaps, and data-handling issues • Collaborate with security operations, identity, messaging, endpoint, network, and application teams to integrate DLP telemetry into SIEM, SOAR, monitoring, and response processes • Prepare communications for end users, technical teams, stakeholders, and leadership regarding DLP findings, policy changes, and corrective actions • Provide technical guidance and mentorship to junior analysts and security team members • Help mature Fragomen’s enterprise data protection capabilities and strengthen its security posture
• 5+ years of experience in cybersecurity, data protection, security operations, governance, risk, compliance, or related technology roles, or equivalent combination of education and experience • Working knowledge of DLP concepts, sensitive data handling, information protection, data classification, and policy-based enforcement • Hands-on experience supporting or operating enterprise security controls, especially within Microsoft 365, email, endpoint, cloud, or SaaS platforms • Ability to analyze DLP alerts, user activity, sharing patterns, policy matches, and event logs • Working knowledge of identity and access concepts, authentication mechanisms, file permissions, collaboration tooling, and data-sharing workflows • Strong written and verbal communication skills • Ability to follow structured processes while continuously improving them • Knowledge of Microsoft Purview Information Protection and DLP • Knowledge of Microsoft Defender for Cloud Apps and CASB concepts • Knowledge of endpoint, email, and collaboration security controls across Windows, Microsoft 365, Exchange Online, Teams, SharePoint, and OneDrive • Experience with SIEM and security platforms such as Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar tools • Knowledge of sensitive data types and regulatory drivers, including PII, PCI, PHI, financial data, client confidential information, legal matter data, and regulated business records • Knowledge of TCP/IP, DNS, HTTP/S, VPNs, proxies, firewalls, APIs, and cloud storage patterns • Preferred: experience with Microsoft Purview DLP, Endpoint DLP, Information Protection, Insider Risk Management, eDiscovery, Audit, or Data Lifecycle Management • Preferred: experience with CASB, SaaS security, cloud access governance, or file-sharing risk management • Preferred: experience supporting investigations involving Legal, Compliance, Privacy, Risk, Records, HR, or regulatory stakeholders • Preferred: experience with SOAR, ticketing, workflow automation, and process documentation • Preferred relevant certifications such as Microsoft Security, Compliance, and Identity certifications; CISSP, SSCP, Security+, CISA, CISM; GIAC; or vendor certifications • Successful completion of the Firm’s pre-employment screening process • Legal authorization to work in the offered position’s location
• Hybrid & Remote work arrangements via the #FragomenWorks program • Three managerial check-ins per year to support career progression • Fragomen Academy • Leadership Academy • Practical Management Academy • Regional Development Conferences • Firmwide health and wellness initiatives • Programs supporting work-life balance • Benefits covering a wide range of well-being needs • Diversity, inclusion, and equal opportunity commitment • Community support and advice for immigrants • Sustainability and corporate social responsibility initiatives
Apply Now🕒 August 4
Security Engineer fixing code-level vulnerabilities across Kami’s digital classroom platform. Hardening cloud infrastructure, integrating secure SDLC guardrails, and automating incident response.
🇺🇸 United States – Remote
💰 $1M Seed Round on 2019-01
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🕒 August 4
1001 - 5000
Cybersecurity Advisor designing Identity and Access Management solutions for Optiv’s cyber-risk consulting clients. Driving security sales, advisory relationships, and scalable programs across client environments.
🇺🇸 United States – Remote
💵 $170k - $230k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🕒 August 4
1001 - 5000
Cybersecurity Advisor designing threat-management programs for Optiv, a cyber-risk consulting company. Partnering with sales and clients on scalable security solutions, roadmaps, proposals, and technology evaluations.
🕒 August 4
Allstate cybersecurity lead consultant automating adversarial testing and exposure validation. Building scalable penetration testing pipelines integrated with CI/CD and enterprise workflows.
🇺🇸 United States – Remote
💵 $100k - $170.5k / year
💰 Post-IPO Equity on 2014-01
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🕒 August 4
Cybersecurity advisory senior associate helping Riveron clients implement GRC and compliance programs. Leading IT risk assessments, audits, remediation, and client engagement delivery.
🇺🇸 United States – Remote
💵 $84k - $117k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer