Job Title: Lead Data Security Architect
- Duration: 3 months
- Location: Remote
- Lead Data Security Architect to support a broader data security and remediation effort focused on reducing exposure across SharePoint, OneDrive, Microsoft Purview, and Cyera. This role provides technical leadership across the overall project, helping the client move from discovery and finding review into practical remediation, governance alignment, and sustainable operating processes.
Note: This is a W2 only role — C2C, C2H will not be considered
The Architect should be hands-on and remediation-oriented, able to work directly in Cyera and across Microsoft environments to investigate findings, validate root cause, recommend corrective actions, and help drive closure. The emphasis is on supporting the client through the work required to classify, tag, label, prioritize, and remediate data security findings in a structured way.
This role works alongside the client’s existing security, data governance, DLP, and operations teams, as well as delivery resources. The Architect is not intended to replace internal ownership or duplicate day-to-day operational roles. Instead, the role helps unblock remediation decisions, align technical actions to governance requirements, and provide hands-on support for complex findings that require architecture-level judgment.
Program Context: This work supports the client’s broader enterprise information management and data security objectives. Cyera and Microsoft Purview are expected to serve as key platforms for identifying sensitive data, assessing exposure, applying classification and labeling controls, and driving remediation. The Architect should align recommendations and execution of support to the client’s governance model, operational workflows, and longer-term roadmap for protecting and managing data across the enterprise.
Responsibilities
- Understand objectives, scope, current-state challenges, governance expectations, and desired outcomes for the broader data security and remediation effort.
- Review relevant SharePoint, OneDrive, Microsoft Purview, and Cyera context to identify where sensitive data exposure, oversharing, policy gaps, workflow constraints, or remediation backlog items are creating risk.
- Connect discovery, classification, tagging, labeling, remediation, and governance activities into one integrated project approach that supports practical execution and long-term operating maturity.
- Work with client teams to identify priority findings, ownership paths, decision points, remediation dependencies, and near-term actions requiring deeper technical validation.
- Assess how sensitive data is currently discovered, classified, tagged, labeled, monitored, and remediated across SharePoint, OneDrive, Cyera, and Microsoft Purview.
- Help define and refine classification, tagging, and labeling practices that support remediation, DLP policy alignment, access governance, and ongoing data protection objectives.
- Provide architecture-level guidance on labeling strategy, DLP policy impacts, access exposure, exception handling, and control behavior across the client’s Microsoft 365 and DSPM environment.
- Maintain and support client’s governance model, operational workflows, and risk reduction priorities.
- Work hands-on in Cyera and Microsoft Purview to improve findings, validate root cause, confirm control behavior, and support remediation actions.
- Support controlled validation activities in approved environments to confirm that remediation actions reduce exposure without creating unacceptable business disruption.
- Partner with security operations, DLP, governance, compliance, and business stakeholders to ensure findings are triaged, assigned, remediated, and tracked consistently.
- Define practical measures of remediation progress, including closure rate, exposure reduction, policy effectiveness, escalation clarity, and audit readiness.
- Take action to integrate DSPM, Microsoft Purview, classification, labeling, DLP, access governance, and incident response workflows.
- Document recommended ownership, cadence, escalation paths, and governance checkpoints so remediation can continue beyond the initial project window.
- Apply solutions to business-case terms, connecting technical remediation to risk reduction, operational maturity, and governance outcomes.
Qualifications
Required:
- 7+ years in security architecture, data security, or related cybersecurity consulting roles, with demonstrated ownership of client-facing engagements from scoping through delivery.
- Genuinely hands-on-keyboard — able to log into Cyera and Microsoft Purview directly, investigate a finding, and drive it to remediation personally, not only direct others to do so. This is a client-stated requirement, not a nice-to-have.
- Deep working knowledge of Microsoft 365 data-layer security: SharePoint Online, OneDrive for Business, Microsoft Purview (DLP, sensitivity labels, Insider Risk Management, Audit), and Entra ID access/consent fundamentals.
- Direct, practical expertise in Cyera specifically — Client ''s enterprise-standard DSPM platform — including how to investigate and remediate findings, not just interpret dashboards.
- Demonstrated ability to remediate findings surfaced by Cyera or any DLP tooling — revoking access, adjusting policy, closing out flagged exposure — since the client''s core concern is remediation capability, not just detection or reporting.
- Demonstrated ability to design and lead purple-team-style validation exercises (not full red-team penetration testing) — controlled, safety-guard railed simulations in test environments.
- Strong command of incident response fundamentals: MTTD/MTTC measurement, scope determination, evidence/audit readiness, and remediation tracking, including how DLP findings hand off to the SOC for incident response.
- Comfort working as a peer alongside a client''s existing in-house DLP engineer — augmenting and unblocking their work, not replacing or duplicating it.
- Working knowledge of relevant regulatory and contractual notification obligations (e.g., state breach notification laws, SEC cyber disclosure rules) sufficient to guide discovery questions — not intended to substitute for the client''s own legal/compliance counsel.
- Excellent stakeholder-facing communication skills; able to translate technical findings into a business case for both technical and executive audiences.
Preferred:
- Hands-on experience with both Cyera and Varonis is viewed favorably by the client, even though Cyera is the enterprise-standard platform — broader DSPM platform fluency is a plus.
- Relevant certifications such as CISSP, SANS/GIAC (e.g., GDSA, GCTI), or Microsoft security certifications (SC-100, SC-401).
- Experience assessing Copilot for M365 or other generative-AI access-exposure risk ahead of rollout.
- Prior experience in a public-company or regulated-industry environment (industrial, manufacturing, or similar).
- Comfort operating within a formal enterprise data governance structure spanning multiple business units — Data Governance Council, segment governance leads, RACI-based accountability model. We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication. Our goal is to cultivate a culture of belonging that encourages innovation, collaboration, and respect for all team members, ensuring that remains a great place to work for All!