
Senior Microsoft Purview Security Engineer
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
• Oversee Microsoft Purview and data-protection initiatives from the stages of requirements collection and solution design to implementation, testing, documentation, and final production rollout.
• Install, configure, manage, and enhance Microsoft Purview along with its integration into Microsoft 365, Microsoft Entra ID, Azure, endpoints, and enterprise systems.
• Create and apply data classification, sensitivity labeling, encryption, and data loss prevention policies.
• Design automated and trainable classifiers for sensitive information, including taxpayer details, financial data, personally identifiable information, credentials, intellectual property, and regulated content.
• Set up and uphold DLP controls across Exchange Online, SharePoint, OneDrive, Teams, endpoints, and compatible cloud applications.
• Manage Purview roles, permissions, administrative boundaries, and ensure least-privilege access.
• Configure and sustain Information Protection, Data Loss Prevention, Data Lifecycle Management, Records Management, Audit, and Communication Compliance functionalities.
• Assist with eDiscovery processes like preservation, legal holds, collections, searches, review sets, exports, and collaboration with Legal and Privacy teams.
• Develop retention labels, retention policies, disposition criteria, and records-management frameworks.
• Enforce technical controls to comply with IRS §7216 restrictions and safeguard taxpayer information against unauthorized access or disclosure.
• Maintain verifiable documentation of policy configurations, administrative actions, access, sharing, labeling, retention, and exceptions.
• Evaluate Purview settings, data governance practices, permissions, policy effectiveness, exceptions, and control efficiency.
• Conduct tests and make adjustments to policies prior to production deployment.
• Resolve issues related to Purview services, policies, integrations, permissions, and classifications.
• Monitor platform performance, policy implementation, scanner coverage, connector statuses, and integration efficiency.
• Develop automation scripts using PowerShell and Python for administration, reporting, access reviews, validation, and evidence collection.
• Generate dashboards and reports detailing sensitive data locations, policy adherence, labeling uptake, DLP trends, access risks, retention statuses, and compliance deficiencies.
• Integrate Purview with Microsoft Defender XDR, Microsoft Entra ID, Azure, AWS, and additional platforms.
• Collaborate with architecture, application, development, IT, cloud, Security, Legal, Privacy, and Governance, Risk, and Compliance (GRC) teams.
• Assess applications, cloud services, integrations, and AI applications for handling sensitive data.
• Produce technical designs, configuration standards, procedures, data-flow documentation, control mappings, and guidance for administrators.
• Offer training and technical assistance to administrators, data owners, business users, and stakeholders in Legal, Privacy, and Compliance.
• Investigate innovative AI solutions within the Microsoft ecosystem.
• A minimum of five years of experience in security engineering, data security, data governance, Microsoft 365 administration, compliance engineering, or a related field.
• Practical experience in deploying and managing Microsoft Purview within an enterprise Microsoft 365 setting.
• Familiarity with Purview Information Protection, sensitivity labeling, Data Loss Prevention, Data Lifecycle Management, Records Management, Audit, and eDiscovery.
• In-depth understanding of data classification, data governance, privacy, retention, encryption, least privilege, and compliance-control design.
• Proven experience managing Microsoft 365 and Microsoft Entra ID roles, permissions, groups, identities, and access controls.
• Capable of designing, testing, implementing, documenting, and maintaining security and compliance policies.
• Experience in assessing business and regulatory demands and converting them into technical controls.
• Background in implementing controls for sensitive financial, tax, customer, or personally identifiable information.
• Knowledge of implementing or integrating security and data-protection features in Microsoft Azure and/or AWS.
• Strong skills in troubleshooting, analysis, project management, and technical documentation.
• Excellent written and verbal communication skills, including the ability to articulate technical controls to Legal, Privacy, Compliance, and business stakeholders.
• Highly self-motivated, capable of managing competing priorities, and comfortable working independently in a fast-paced environment.
• A Bachelor’s degree in cybersecurity, information technology, computer science, information systems, or a related field, or equivalent professional experience is preferred.
• Preferred: experience in highly regulated organizations, IRS taxpayer-data safeguarding guidance, FTC Safeguards Rule, Microsoft Defender XDR, Defender for Cloud Apps, Microsoft Sentinel, CrowdStrike Falcon, SaaS/cloud integrations, APIs, Microsoft Graph, infrastructure-as-code, configuration management, or Microsoft certifications.
• Equal opportunity employment
• Supportive, open, and inclusive atmosphere
• Small, collaborative, hands-on environment
• Occasional planned work outside normal business hours for major deployments, migrations, or maintenance activities
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.