Overview
Skills
Job Details
Title : Senior Data Security Engineer
Location : Washington DC (Onsite Work)
Duration Contract
Job Description:
Job Summary:
We are seeking a highly experienced Senior Data Security Engineer with deep expertise in Sensitivity Classification Frameworks and implementing Data Loss Prevention (DLP) solutions using Microsoft Purview. The ideal candidate will lead data protection initiatives, design and implement classification policies, and manage DLP solutions to safeguard sensitive enterprise data across cloud and on-prem environments.
Key Responsibilities:
Lead the design, deployment, and management of Sensitivity Classification frameworks aligned with organizational compliance and security policies.
Architect and implement Data Loss Prevention (DLP) solutions leveraging Microsoft Purview across Microsoft 365 and other enterprise data repositories.
Develop and enforce data classification policies, labeling strategies, and protection mechanisms to mitigate data leakage risks.
Collaborate with security, compliance, and business teams to identify sensitive data and tailor DLP controls accordingly.
Conduct risk assessments and provide recommendations to enhance data governance and data security posture.
Monitor DLP alerts, investigate incidents, and coordinate remediation activities.
Provide senior-level guidance and mentoring to junior security engineers and stakeholders.
Stay updated with the latest trends and best practices in data security, DLP technologies, and compliance regulations.
Must-Have Skills & Qualifications:
Minimum 7 years of experience in data security, information protection, or related roles with a focus on data classification and DLP.
Hands-on experience with Microsoft Purview Data Loss Prevention (DLP) solutions and sensitivity labeling across Microsoft 365 and Azure environments.
Strong understanding of Sensitivity Classification Frameworks, including designing and implementing classification labels, policies, and rules.
Expertise in configuring, tuning, and managing DLP policies to detect and prevent sensitive data exposure.
Familiarity with compliance standards such as GDPR, HIPAA, PCI-DSS, and how they relate to data classification and protection.
Experience with Microsoft Information Protection (MIP) suite, including Azure Information Protection (AIP).
Ability to analyze data flow and classify sensitive data across multiple sources (SharePoint, Exchange, OneDrive, Teams, endpoints).
Solid scripting skills (PowerShell preferred) to automate classification and DLP tasks.
Excellent communication skills with the ability to translate technical concepts to business stakeholders.
Proven leadership experience in guiding teams and managing data security projects end-to-end.
Preferred:
Certifications such as Microsoft Certified: Security, Compliance, and Identity Fundamentals or Microsoft 365 Certified: Security Administrator Associate.
Experience with other DLP technologies or CASB tools.
Knowledge of cloud security best practices across AWS, Azure, or Google Cloud Platform.