Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Data Protection Engineer (Trellix), Zero Trust Program (TS/SCI) image - Rise Careers
Job details

Data Protection Engineer (Trellix), Zero Trust Program (TS/SCI)

Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.                                                

By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.

Kentro is hiring a specialized Data Protection Engineer (Trellix) to join the SIPR and Top-Secret Network Execution Teams for a major Zero Trust transformation at U.S. Special Operations Command (USSOCOM). While other roles focus on cloud-native security, this position is dedicated to securing the "tactical edge" and on-premises endpoints within the Command's classified environments.

As the Senior Trellix Engineer, you will be the technical authority for the design, deployment, and management of the Trellix (formerly McAfee) Data Loss Prevention (DLP) suite. You will be responsible for configuring and tuning the Trellix ePolicy Orchestrator (ePO) to enforce rigorous device control and data protection policies on workstations operating in disconnected and air-gapped environments. Your work will directly prevent the unauthorized exfiltration of classified intelligence via USB drives, printing, and clipboard transfer, ensuring that the Command’s most sensitive networks remain secure against insider threats and accidental data loss.

Responsibilities:

  • Trellix DLP Architecture: Lead the design and configuration of Trellix DLP Endpoint policies within the ePolicy Orchestrator (ePO) on SIPR and Top-Secret networks to monitor and block unauthorized data transfer vectors (USB, Web, Print, Clipboard).
  • Policy & Rule Tuning: Create and refine complex data classification rules and regex patterns to identify specific USSOCOM sensitive data types, actively tuning policies to reduce false positives and transition from "Audit" to "Block" mode.
  • Air-Gapped Operations: Manage the unique lifecycle of the ePO environment on the Top-Secret network, including the manual "sneaker-net" transfer of policy updates, agent patches, and threat intelligence definitions.
  • Integration: Configure ICAP integration between Trellix and other security components (such as Kiteworks or Web Proxies) to extend DLP inspection to network traffic and file transfers.
  • Incident Triage: Serve as the Tier 3 escalation point for DLP incidents, analyzing blocked actions and working with the SOC/SIEM team to ensure alerts are properly ingested into Splunk.

Location: Onsite in Tampa, FL

  • Senior Level: Master of Science (MS) degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • Senior Level: 10+ years of related technical experience.
  • Trellix/McAfee Expertise: Extensive (5+ years) hands-on experience architecting and administering Trellix (McAfee) ePolicy Orchestrator (ePO) and Data Loss Prevention (DLP) Endpoint products.
  • Device Control: Deep understanding of Device Control policies for managing removable storage, peripheral devices, and printing in a secure environment.
  • Regex & Classification: Proficiency in creating custom data identifiers using Regular Expressions (Regex) and dictionaries to detect sensitive information.
  • Troubleshooting: Proven ability to troubleshoot complex agent-based issues on Windows endpoints, including conflict resolution with other security software.

Preferred Experience & Skills ("Nice-to-Haves")

  • Experience working in Air-Gapped or isolated network environments (e.g., JWICS, SAPs).
  • Knowledge of Trellix Endpoint Security (ENS) and Threat Intelligence Exchange (TIE/DXL).
  • Familiarity with Kiteworks or Boldon James for data classification integration.
  • Experience with Splunk for log analysis and dashboarding.

Certifications:

  • Required: CompTIA Security+ CE (or higher) to meet DoD 8570 IAT Level II requirements.
  • Preferred: Trellix Certified Specialist - Data Loss Prevention (DLP) or equivalent McAfee certification.

Clearance:

  • Active Top-Secret clearance with SCI eligibility.

The Company

We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let’s solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence.

We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015) and two CMMI ML 3 ratings (DEV and SVC).

Industry Recognition

Growth | Inc 5000’s Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C.

Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner – Mid-Size Companies, Companies Owned by People of Color; Department of Labor’s HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award

Benefits

We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more.  We invest in our employees – Every employee is eligible for education reimbursement for certifications, degrees, or professional development.  Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.

We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities – virtual and in-person – e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy.

Commitment Equal Opportunity Employment & VEVRAA

Kentro is an equal opportunity employer.  All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state or local law.

Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.

As part of our VEVRAA compliance efforts, Kentro has established an equal opportunity plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.

We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.

Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.

How to Apply

To apply to Kentro Positions- Please click on the: “Apply for this Job” button at the bottom of this Job Description or the button at the top: “Application.”  Please upload your resume and complete all the application steps. You must submit the application for Kentro to consider you for a position.  If you need alternative application methods, please email [email protected] and request assistance.  

Accommodations

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email [email protected].  

Average salary estimate

$155000 / YEARLY (est.)
min
max
$140000K
$170000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Posted 12 hours ago

Kentro seeks an experienced ICAM Lead Identity Engineer to deliver hands-on deployment and management of Entra ID, Delinea PAM, and SailPoint IGA for a DOD TS/SCI onsite role in Tampa, FL.

Kentro seeks an experienced SIEM/Data Integration Engineer to architect and operate a Cribl Stream telemetry pipeline that optimizes security visibility and Splunk ingestion for a major Zero Trust initiative at USSOCOM in Tampa, FL.

Photo of the Rise User
Posted 17 hours ago

Public Storage is hiring a Lead PC Support Technician in Plano to lead desktop support operations, mentor technicians, and deliver advanced Windows and Office 365 end-user computing solutions.

Photo of the Rise User
Clark College Hybrid Hybrid in Clark College, Washington, United States
Posted 24 hours ago

Clark College is hiring an ITS Business Analyst to connect IT and campus partners, drive requirements gathering, ensure accessibility, and deliver data-informed solutions.

Kentro seeks an experienced SIEM/Data Integration Engineer to architect and operate a Cribl Stream telemetry pipeline that optimizes security visibility and Splunk ingestion for a major Zero Trust initiative at USSOCOM in Tampa, FL.

Photo of the Rise User
Posted 4 hours ago

Support AbbVie's global applications by designing and operating Cloudflare edge services, optimizing performance, and strengthening security across CDN, WAF, DNS and automation pipelines.

Lead the Engineering and Global Serialization IT strategy at Lilly MQ to deliver scalable, compliant digital and data solutions that improve manufacturing and serialization operations.

Photo of the Rise User

Lead and architect the enterprise IAM program at Model N, driving identity strategy, secure access design, and governance across cloud and on-prem environments.

Photo of the Rise User

Pomona College seeks a Director of Advancement Technology to lead strategy, administration, and adoption of fundraising systems (Salesforce, Marketing Cloud, integrations) to strengthen donor relations and operational effectiveness.

Kentro Hybrid No location specified
Posted 16 hours ago

Kentro is hiring a Senior IGA Engineer with active Top‑Secret/SCI to lead SailPoint deployments and ABAC trust-attribute management for USSOCOM's Zero Trust environment.

Photo of the Rise User
Posted 4 hours ago

Lead the architecture and implementation of Red Hat Satellite and Ansible-based automation as the Senior Linux Architect supporting NSWCDD's Comply to Connect initiative in Dahlgren, VA.

Posted 18 hours ago

GE Appliances seeks a Fall 2026 Digital Technology Intern in Louisville to contribute to application development, systems, infrastructure, and security projects while building technical and business skills.

Photo of the Rise User
GE HealthCare Hybrid IL03-01-Chicago-500 W Monroe St
Posted 17 hours ago

Experienced technology audit leader needed to lead IT audit engagements, strengthen controls, and develop audit talent within GE HealthCare's global Internal Audit function.

Posted 12 hours ago

Kentro seeks an experienced ICAM Lead Identity Engineer to deliver hands-on deployment and management of Entra ID, Delinea PAM, and SailPoint IGA for a DOD TS/SCI onsite role in Tampa, FL.

Photo of the Rise User
Posted 20 hours ago

Provide remote-first help desk support with periodic onsite visits for Tampa-area clients, troubleshooting Windows/macOS, Microsoft 365, Active Directory, and security incidents for a fast-growing MSP.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, onsite
DATE POSTED
December 23, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!