Overview
Skills
Job Details
Data Security Remediation Lead
Client: Federal Client
POP: 12+ months
Location: Remote
SCOPE
The Remediation Lead will drive the strategic and technical execution of the data security transformation, collaborating deeply with client stakeholders and data owners to define comprehensive remediation strategies and governance policies. In close partnership with the Project Architect, this role will identify solution requirements and direct the deployment, customization, and fine-tuning of BigID and Microsoft Purview to ensure the solution aligns with the specific nuances of the customer's environment. The Lead is responsible for developing project schedules, ensuring adherence to compliance standards, and managing the daily workload of a two-member engineering squad. Additionally, they will coordinate with vendor delivery support to facilitate knowledge transfer, ensuring the successful classification, labeling, and protection of Critical, Moderate, and Stale data assets across the M365 ecosystem.
REQUIRED SKILLS
- Bachelor s degree in computer science, Information Technology, or a relevant technical field + a minimum of 3 years of hands-on experience in network performance or security engineering, with 5 or more years of experience being highly desirable.
- Must have one of the following: Security + CE, CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, CND, CASP CE, CISSP, CSSLP, BigID Privacy, Security & Data Governance Professional, BigID Project Manager, Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Exceptional interpersonal skills with the ability to build trust with non-technical stakeholders and data owners. Must be capable of translating complex security risks into clear business language and managing client expectations regarding remediation scope, impact, and timelines.
- Superior verbal and written communication abilities are mandatory. The candidate must be able to author clear governance policies, produce professional status reports, and deliver convincing presentations to client leadership regarding data risk and project progress.
- Demonstrated experience leading technical teams (2+ engineers), including managing daily workflows, prioritizing tasks, and serving as the escalation point for technical blockers.
- Ability to coordinate effectively between the engineering squad, project architects, and vendor support.
- Deep, hands-on expertise in the Microsoft Purview compliance portal, specifically in defining and deploying Sensitivity Labels, Data Loss Prevention (DLP) policies, and Auto-labeling logic for SharePoint Online and OneDrive for Business.
- Proven experience with enterprise data discovery platforms (specifically BigID or similar tools), including scanner configuration, classification tuning, confidence scoring, and integrating findings with enforcement tools.
- Ability to translate regulatory requirements and business needs into actionable data governance policies, technical remediation strategies, and defensible deletion (ROT) workflows.
PREFERRED SKILLS
- 5+ years of experience
- Certifications:
- Active Microsoft Certified: Information Protection Administrator Associate (SC-400) is highly preferred. (Alternatively: Proven equivalent experience specifically with the SC-400 exam objectives)
- CISSP
- BigID Privacy, Security & Data Governance Professional
- BigID Project Manager
- Understanding and experience with NIST Special Publication [SP] 800-171
- Familiarity and understanding of United States Executive Order [EO] 14117 .
TASKS
- Interface with stakeholders and data owners to define remediation strategies, validate governance policies, and translate business needs into technical requirements. Manage client expectations regarding scope, risk, and timelines.
- Manage the daily workload of the engineering squad, develop and maintain project schedules, and coordinate activities between the client, engineering team, and vendor support.
- Collaborate with the Project Architect to ensure solution design meets compliance standards; review and approve technical configurations for BigID and Purview before deployment.
- Produce executive status reports, document remediation outcomes, and facilitate training and knowledge transfer from the vendor to the internal engineering staff.