Sr. Security Engineer

Remote • Posted 3 hours ago • Updated 3 hours ago
Contract W2
Contract Independent
3 Months
No Travel Required
Remote
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🎯 Assessing qualifications...

Job Details

Skills

  • DLP
  • Data Security
  • GCIH
  • GCIA
  • Microsoft
  • Security Engineering
  • SIEM
  • Cyera

Summary

Job Title: Senior Security Engineer – Remediation & Incident Response
Duration: 3 months
Location: Remote
  •  Senior Security Engineer to support a broader enterprise data security program focused on identifying, classifying, labeling, and remediating sensitive data exposure across Microsoft 365 environments.
This role is not intended to participate directly in a proof-of-value or vendor evaluation effort. Instead, the resource will become part of the remediation workstream that follows discovery and classification, helping the client turn security findings into closed, documented outcomes.
The role will work alongside the client''''s internal security, DLP, and operations teams to triage findings, validate root cause, coordinate corrective action, and support closure of remediation items. The emphasis is on practical execution: understanding what data is exposed, how it should be classified or labeled, what risk it creates, and what action is needed to reduce that risk.
This is a core delivery resource for the overall project, with involvement beginning during data discovery, classification, tagging, labeling, and remediation planning, then increasing during remediation execution and post-deployment stabilization.
Program Context: This engagement supports the client''''s broader Enterprise Information Management and Data Security objectives. The work should be positioned as a reusable operating model for discovery, classification, labeling, policy alignment, remediation, and ongoing incident response across current and future data security channels.
Responsibilities
  • Support activities including data discovery, classification, tagging, labeling, risk prioritization, and remediation planning.
  • Partner with client security, DLP, SOC, and data governance teams to understand current workflows, ownership models, ticket volume, and remediation hand-offs.
  • Triage findings surfaced through data security tooling, monitoring, or validation activities and help determine the appropriate remediation path.
  • Drive remediation actions to closure, including access changes, policy adjustments, data handling updates, quarantine or containment steps, and coordination with the appropriate operational owners.
  • Coordinate with the SOC and response teams when findings indicate incident response, containment, or escalation requirements.
  • Document remediation decisions, closure evidence, recurring patterns, and operational lessons learned to support audit readiness and future-state process improvement.
  • Provide technical input into the remediation roadmap and target-state data security operating model based on findings encountered during the engagement. Ongoing / Post-Deployment
  • Continue as the primary hands-on remediation and incident-response resource — investigating false positives/negatives, adjusting behavioral baselines, and driving real findings to closure as the environment sees production traffic.
  • Remain the day-to-day working partner to Client''''s in-house DLP engineer for as long as the engagement continues, rather than handing remediation entirely back to the client after go-live.
Qualifications
Required:
  • 5+ years in security engineering, with direct hands-on experience configuring Microsoft 365 security tooling (Purview DLP, sensitivity labels, Insider Risk Management, Audit) and Entra ID.
  • Direct, hands-on remediation experience — not just detection or reporting. Able to take a Cyera or DLP finding and personally drive it to resolution: revoke access, adjust a policy, quarantine data, or take the equivalent corrective action. This is the client''''s top priority for this role.
  • Practical expertise in Cyera specifically (Client''''s enterprise-standard DSPM platform) and deep expertise in Microsoft Purview and the broader Microsoft 365 security stack.
  • Working knowledge of SIEM/SOC alerting pipelines and incident response processes — this role is a key hand-off point between DLP/DSPM detection and SOC-driven containment, so understanding both sides matters.
  • Comfort working as a peer alongside a client''''s existing in-house DLP engineer on shared remediation work, communicating clearly about who is handling what.
  • Demonstrated experience designing or executing controlled, purple-team-style validation exercises in an isolated test environment — not full red-team penetration testing.
  • Practical understanding of common SharePoint/OneDrive incident patterns: compromised-account exfiltration, oversharing/public-link exposure, insider data theft, ransomware via sync clients, malicious OAuth consent grants, and lateral movement via overprivileged access.
  • Ability to translate technical remediation work into clear documentation suitable for both technical and client-facing review.
Preferred:
  • Hands-on experience with both Cyera and Varonis — the client has indicated familiarity with both platforms is a plus, even though Cyera is the enterprise standard for this engagement.
  • Experience with UEBA/behavioral-baseline tooling specifically for insider-risk or departing-employee scenarios.
  • Familiarity with OneDrive sync-client behavior and endpoint EDR correlation for ransomware-pattern detection.
  • Relevant certifications such as GIAC/SANS (e.g., GCIA, GCIH), Microsoft SC-200, or vendor-specific DSPM certifications.
  • Prior experience embedded alongside a client''''s in-house security/DLP team on an ongoing remediation or hyper care basis, rather than a discrete assessment of engagement.
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91097117
  • Position Id: 9037207
  • Posted 3 hours ago

Company Info

About Cloud Destinations LLC

One of the leading US-based staffing and IT consulting partner. Experience exceptional service and top-tier talent across industries. Count on us for staffing solutions that cater to the unique demands of the American market.

Our experienced recruiters ensure a seamless fit within your team, accelerating success. But we go beyond staffing and empower employees with fully sponsored certification programs, keeping them ahead. Experience comprehensive benefits including health, wellness coverage, dental insurance, vision insurance, as well as flexible hours, remote work options, and a robust 401K plan to ensure a secure future at the companies we represent.

At Cloud Destinations, we bring industry expertise and a passion for excellence. From Enterprise Cloud Strategy to Managed Infrastructure Services, Digital Transformation, BI & Data Analytics, Security, Data Engineering, and more, we navigate the IT landscape with finesse. Choose us as your trusted partner, witness transformative talent and exceptional service. Let's unlock new possibilities and drive your success in the dynamic world of IT together.

About_Company_One
Contact the job poster
Kevin Kumar

Kevin Kumar

Sr Recruiter @ Cloud Destinations LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Full-time

$90+

Remote

Today

Easy Apply

Contract

100 - 105

Remote

Today

Easy Apply

Contract

$90 - $100

Search all similar jobs