2 open positions available
Lead design and implementation of enterprise data protection and DLP capabilities across Microsoft 365, endpoints, and cloud platforms. | 7+ years in information security with 4+ years focused on data security, DLP, DSPM, and proficiency with Microsoft Purview DLP, Defender suite, Sentinel, and related tools. | Job Title: Lead Information Security Engineer We are seeking a Lead Information Security Engineer to drive the design and implementation of enterprise data protection capabilities across Microsoft 365, endpoints, and cloud platforms. You will play a key role in protecting sensitive data across its full lifecycle, discovering, classifying, and securing data while reducing enterprise risk. You will work across multiple technologies and teams to ensure data security controls are scalable, actionable, and aligned to business and regulatory requirements. You will work cross-functionally with IT, Legal, Compliance, and business stakeholders to ensure sensitive data is identified, classified, and protected across all endpoints, cloud workloads, and collaboration platforms. Key Responsibilities • Design, deploy, and tune DLP policies across Microsoft Purview DLP, covering Exchange Online, SharePoint, Teams, OneDrive, and endpoint devices? • Configure and manage labeling policies, trainable classifiers, and exact data match (EDM) for sensitive data types? • Integrate DLP capabilities with the Defender suite. Configure and manage Microsoft Defender for Endpoint and its Endpoint DLP component to monitor and control data on client devices. Leverage Microsoft Defender for Cloud Apps (MDCAS) for cloud-based DLP and real-time monitoring of SaaS applications. • Configure data connectors and analytic rules in Sentinel for DLP alerts and email security events. • Proactively monitor and analyze DLP-related false positives and negatives, working with business owners to refine policies and minimize disruption to business operations. • Develop robust testing and validation procedures for new and updated DLP policies. • Extend DLP coverage beyond Microsoft 365 to third-party SaaS platforms, on-premises systems, and network egress points to reduce unauthorized data access and exfiltration • Collaborate with stakeholders to develop data handling standards and acceptable use policies and establish consistent policy frameworks, enforcement models, and automation for data protection • Create and maintain technical documentation, runbooks, and Standard Operating Procedures (SOPs) for the Data Security program. • Build automation and scalable processes to reduce manual effort Data Security Posture Management (DSPM)? • Deploy and manage DSPM tooling to provide continuous visibility into sensitive data discovery, risk exposure, and access patterns? • Leverage Varonis for data access governance, entitlement reviews, and detection of abnormal data access behaviors across file shares, SharePoint, and cloud storage? • Conduct regular data risk assessments, identify overexposed sensitive data, and drive remediation with data owners? • Integrate DSPM findings into broader risk reporting and security metrics dashboards? • Produce regular reporting on policy effectiveness, data risk posture, and key security metrics for leadership? • Partner with data owners across business units to ensure proper classification of structured and unstructured data assets? AI Data Security • Support AI data security initiatives by helping govern and protect sensitive data used by generative AI, Copilot experiences, and AI agents. Partner to identify AI-related data exposure risks, improve visibility into prompt and response activity, apply data protection and governance controls, and align monitoring and remediation workflows with DSPM, Data Security, and Insider Risk Management objectives. Microsoft Intune • Engineer and maintain Intune solutions for endpoint management, including device enrollment, policy configuration, MDM/MAM to enforce data protection and compliance on managed devices. Ensure seamless integration between Intune's endpoint management capabilities and Defender/Purview DLP policies to support Windows, Mac, iOS and Android devices. • Implement end-to-end Microsoft 365 security and compliance solutions, including baseline security hardening, and integration with enterprise identity and access management. Microsoft Sentinel & SIEM Integration: • Configure data connectors and analytic rules in Sentinel for DLP alerts and email security events. Implement secure pipelines to forward logs and telemetry from Microsoft 365 and Sentinel to Splunk using Azure Event Hub, • Monitor and analyze Microsoft Sentinel cost drivers, including data ingestion, retention, and analytics rule execution. Implement cost optimization strategies such as data filtering, log sampling, and retention policy tuning. Work Experience • 7+ years of experience in information security, with at least?4?years focused on data security, DLP or DSPM.? • Hands-on expertise with Microsoft Purview DLP, including policy creation, scoped deployments, adaptive protection, and incident management? • Strong proficiency with Microsoft Defender XDR suite: Defender for Endpoint, Defender for Cloud Apps, Defender for Identity, and Defender for Office 365? • Demonstrated experience with Microsoft Sentinel, including custom analytic rules, KQL query development, workbooks, and SOAR playbooks? • Proven experience with Varonis Data Security Platform for data access governance, risk prioritization, and threat detection? • Experience with DSPM concepts and tooling, including sensitive data discovery and cloud data risk management? • Solid understanding of data classification frameworks and Microsoft Purview Information Protection (sensitivity labels, auto-labeling, trainable classifiers)? • Experience implementing DLP across multiple vectors: email, endpoint, cloud applications, and network • Demonstrated capability to analyze, operationalize, and continuously improve security controls and business processes • Knowledge of relevant compliance frameworks and regulations: ISO?27001/27701,?SOC?2?and?NIST?aligned?compliance and security frameworks, particularly as they relate to data protection and DLP • Proven experience with email authentication standards (DMARC, SPF, DKIM) and their implementation in Microsoft 365. • Excellent analytical and problem-solving skills with a security-first mindset? Preferred Qualifications: • Microsoft certifications: SC-400 (Information Protection Administrator), SC-200 (Security Operations Analyst), SC-100 (Cybersecurity Architect), or AZ-500? • Experience with additional DLP or CASB platforms (e.g., Symantec DLP, Forcepoint, Zscaler) • Familiarity with cloud security posture management (CSPM) in Azure, AWS, or GCP environments? Education? • Bachelor’s degree in arts/sciences (BA/BS) or equivalent experience
Lead technical strategy and architectural decisions for scalable customer service and internal business platforms. | 11+ years software and infrastructure engineering experience with leadership, expertise in Azure cloud, security, and scalable distributed systems. | Concero is looking for Principal Azure Engineer for an enterprise level client. In this important role you will have shared responsibility for our various engineering delivery pipelines. The solutions in these areas are critical for the success and daily operations of our organization and our 90,000+ employees. Knowledge, Skills, and Abilities: • Be able to communicate complex solutions at all levels up to and including C suite • Significant Experience of the Microsoft product set across platform, endpoint and security • Significant experience of security technologies across the MS stack including MFA, SSO, MIM, OTP as well a strong general security background • Lead technical strategy and architectural decisions for our core customer service and internal business platforms • Design and implement scalable solutions spanning frontend and backend services • Create reusable technical designs that can be leveraged across multiple teams • Drive adoption of emerging technologies that enhance our customer experience • Work closely with product and engineering teams to deliver technical excellence • Mentor and grow senior technical talent across the organization • Proven ability to influence and build consensus across teams • Excellence in mentoring senior engineers and building strong teams • Track record of driving technical decisions at organizational scale • Strong communication skills and stakeholder management Required: • Must be presently authorized to work in the U.S. without a requirement for work authorization sponsorship by our company for this position now or in the future • Must be committed to incorporating security into all decisions and daily job responsibilities • 11 + years of software & infrastructure engineering experience with proven technical leadership • Experience designing distributed systems and scalable architectures • Expertise in cloud platforms (AZURE) and modern web technologies • Experience building high throughput booking and end point systems and real-time services • Strong ability to bridge frontend and backend technical domains • Experience leading technical strategy and engineering decisions for our core customer service and internal business platforms • Experience implementing comprehensive monitoring and security practices Preferred: • Bachelor's degree in Computer Science, Computer Information Systems, Management Information Systems, or related field preferred
Create tailored applications specifically for Concero with our AI-powered resume builder
Get Started for Free