> Markdown version of [/jobs/ext/1133793-senior-data-security-engineer-ussocom-zero-trust-azure-securit](https://www.wearedevelopers.com/jobs/ext/1133793-senior-data-security-engineer-ussocom-zero-trust-azure-securit). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Data Security Engineer (USSOCOM-Zero Trust, Azure Securit - **Company:** Kentro LLC - **Location:** Tampa, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Amazon S3, Microsoft Azure, Server Message Block, Cloud Computing, Cyber Security, Information Leak Prevention, Data Security, Database Storage Structures, Identity and Access Management, Massachusetts Comprehensive Assessment Systems, Metadata, Microsoft Security Essentials, Network File Systems, NoSQL, Performance Tuning, Azure Active Directory, Kusto Query Language, Zero Trust Network Access, SQL Databases, Systems Integration, HybridCloud, Storage Technologies, Information Technology, Microsoft Sentinel, Splunk, Vulnerability Analysis - **Published:** July 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9009415/senior-data-security-engineer-ussocom-zero-trust-azure-securit ## About the Role * Education: Master's degree (MA/MS) in Computer Science, Cybersecurity, Information Technology, or a related technical discipline. * Experience: 10+ years of relevant experience in enterprise systems engineering, data security, or cybersecurity operations. * Technical Skills: + Azure Security Expert: Expert-level proficiency in Microsoft Azure security architecture, with a dedicated focus on implementing and managing Microsoft Purview and Microsoft Defender XDR. + Microsoft Security Stack: Deep, hands-on expertise in the broader Microsoft Defender suite, specifically: o Microsoft Purview (Sensitivity Labeling, DLP, Information Barrier policies). o Microsoft Defender for Cloud Apps (Cloud Access Security Broker - CASB policies). o Microsoft Entra ID (Identity and Access Management). o Microsoft Conditional Access (Context-aware, zero-trust security policies). + Trellix & Palantir DLP Expertise: Proven experience designing, tuning, and enforcing Trellix Full Data Loss Prevention (DLP) policies at an enterprise scale. Must have specific expertise in the integration of Palantir catalog solutions with Data Loss Prevention tools. + Data Rights Management: Strong experience implementing and administering AD-RMS and Azure RMS in complex, multi-domain, or hybrid cloud environments. + Data Catalog Integration: Proven experience integrating and managing metadata across enterprise catalogs such as Palantir, Microsoft Unified Catalog, and utilizing Purview Audit and Activity Explorer. + Storage & Database Knowledge: Strong understanding of storage protocols (NFS, SMB/CIFS, S3) and database structures (SQL, NoSQL) to troubleshoot security scanning access. * Required Certifications: * Must possess one of the following DoD 8570/8140 IAT Level III certifications: + CISSP + CASP+ + CCSP + CISM Preferred Technical Skills (A-Plus): * Advanced knowledge of Kusto Query Language (KQL) for writing sophisticated detection rules, hunting queries, and diagnostic analysis within Microsoft Sentinel/Defender XDR. * Strong proficiency in Splunk Processing Language (SPL) for building advanced dashboards, alerts, and performing forensic analysis. Clearance Requirement: * TS/SCI * Must be a US Citizen ## Description As a Senior Data Security Engineer, you will architect, deploy, and manage advanced data rights management, DLP policies, and security monitoring solutions. You will serve as the premier subject matter expert for Microsoft Azure security, with a heavy focus on Microsoft Purview and Microsoft Defender XDR. Furthermore, you will lead the implementation of Trellix Full Data Loss Prevention (DLP) and the Microsoft Defender suite to enforce continuous compliance, prevent unauthorized data exfiltration, and establish secure access boundaries for USSOCOM's critical intelligence, * Azure Security & XDR: Architect and manage comprehensive Azure security solutions, serving as the primary lead for deploying and tuning Microsoft Purview and Microsoft Defender XDR across hybrid and classified environments. * Defender & Access Policy: Design and configure precise security policies within the Microsoft Defender suite, specifically leveraging Microsoft Purview, Microsoft Defender for Cloud Apps (MCAS), Entra ID, and Microsoft Conditional Access to control resource access based on identity, device compliance, and risk. * Trellix DLP Enforcement: Design, deploy, and enforce Trellix Full Data Loss Prevention (DLP) policies across endpoints and networks to stop unauthorized exfiltration of CUI and classified data without impacting mission performance. * Data Rights Management: Manage Active Directory Rights Management (AD-RMS) and Azure RMS as the primary DRM engines to enforce persistent, encryption-based protection of files and emails across USSOCOM networks. * Catalog & DLP Integration: Drive data catalog integration and metadata synchronization with enterprise platforms including Palantir, Microsoft Unified Catalog, Purview Audit, and Activity Explorer. Specifically, lead the integration of Palantir catalog solutions with Data Loss Prevention (DLP) tools to ensure seamless, end-to-end data security and monitoring. * Classification Tuning: Collaborate with mission owners to train classifiers and DLP rules to recognize unique USSOCOM data types (e.g., mission names, operational codes) and drastically reduce false positive rates in security alerts. ## Related Videos - [A Data Mesh needs Open Metadata](https://www.wearedevelopers.com/videos/505-a-data-mesh-needs-open-metadata) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Leveraging Real time data in FSIs](https://www.wearedevelopers.com/videos/806-leveraging-real-time-data-in-fsis) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crafting Custom Frameworks with Rust: A Deep Dive into Procedural Macros](https://www.wearedevelopers.com/videos/849-crafting-custom-frameworks-with-rust-a-deep-dive-into-procedural-macros) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)