> Markdown version of [/jobs/ext/1144100-senior-data-protection-engineer-ussocom-zero-trust-azure-secur](https://www.wearedevelopers.com/jobs/ext/1144100-senior-data-protection-engineer-ussocom-zero-trust-azure-secur). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Data Protection Engineer (USSOCOM-Zero Trust, Azure Secur - **Company:** Kentro LLC - **Location:** Tampa, FL, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Artificial Intelligence, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Data Centers, Data Discovery, Information Leak Prevention, Data Transformation, Data Security, Query Languages, Cryptographic Protocols, Identity and Access Management, Python (Programming Language), Key Management, Network Security, Performance Tuning, Windows PowerShell, Kusto Query Language, Zero Trust Network Access, Data Streaming, Data Processing, HybridCloud, Information Technology, Cybercrime, Splunk, Devsecops, Security Orchestration, Automation & Response - **Published:** July 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9009414/senior-data-protection-engineer-ussocom-zero-trust-azure-secur ## About the Role * Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field. (Additional years of relevant experience may be substituted for formal education requirements when permitted by contract guidelines). * Experience: 10+ years of experience in cybersecurity, information assurance, or data security engineering. 5+ years supporting DoD, Intelligence Community, or Federal Government cybersecurity initiatives. * Technical Skills: + Data Loss Prevention (DLP) + Data Discovery and Classification + Encryption and Key Management + Cloud Security Architecture + Security Automation and Orchestration + Scripting and automation using PowerShell, Python, or similar technologies Security Framework Knowledge: * DoD Zero Trust Reference Architecture * NIST SP 800-207 Zero Trust Architecture * NIST Risk Management Framework (RMF) * NIST 800-53 Security Controls * DoD Cybersecurity Policies and Directives * Controlled Unclassified Information (CUI) Requirements Required Certifications: Must possess one of the following DoD 8570/8140 IAT Level III certifications: * CISSP * CASP+ * CCSP * CISM Preferred Qualifications: * Advanced Query Languages: Advanced knowledge and proficiency in Kusto Query Language (KQL) and Splunk Processing Language (SPL) for sophisticated threat hunting, alerting, and dashboard creation. * Experience supporting USSOCOM, SOF, or Joint Service environments. * Experience with Cross Domain Solutions (CDS) and classified data handling requirements. * Familiarity with DevSecOps, Platform One, and cATO methodologies. * Experience supporting enterprise cloud migrations and data modernization initiatives. * Knowledge of AI/ML governance and the protection of sensitive training datasets. Clearance Requirement: * TS/SCI * Must be a US Citizen ## Description Kentro is hiring a Senior Data Protection Engineer to support the USSOCOM EDAT Zero Trust initiative. The Senior Data Protection Engineer serves as a key member of the USSOCOM Enterprise Zero Trust Data Team, responsible for designing, implementing, and maintaining data-centric security capabilities across classified and unclassified environments., * As a Senior Data Protection Engineer, you will act as a premier subject matter expert in Microsoft Azure Security, Network Data Security, and Trellix DLP enforcement. * Azure Security & XDR: Serve as a Microsoft Azure security expert, spearheading the design, deployment, and tuning of Microsoft Purview and Microsoft Defender XDR across hybrid enterprise environments. * Defender Suite & Access: Architect and enforce continuous compliance using the Microsoft Defender suite. Leverage deep expertise in Microsoft Purview, Defender for Cloud Apps, Entra ID, and Microsoft Conditional Access to control resource access based on identity and risk. * Trellix DLP Enforcement: Design, engineer, and rigorously enforce Trellix Full Data Loss Prevention (DLP) policies across the enterprise to prevent the unauthorized disclosure of controlled and classified information. * Network Data Security: Act as a specialized Network Data Security Engineer. Deploy and manage Trellix Network Prevent and Monitor services to oversee data flows, inspect traffic, and actively block unauthorized exfiltration attempts in real-time. * Datacenter Security: Engineer, implement, and monitor robust network security controls and encryption protocols governing all data traffic moving to and from on-premises datacenters and hybrid cloud environments. * Zero Trust Architecture: Design and implement data-centric security architectures aligned with DoD and USSOCOM Zero Trust initiatives (NIST SP 800-207). * Identity & ABAC Integration: Integrate data security controls with Identity, Credential, and Access Management (ICAM) systems and support the implementation of Attribute-Based Access Control (ABAC) and policy-driven access models. * Compliance & cATO: Support Continuous Authorization to Operate (cATO) initiatives through automated security validation, compliance monitoring, and risk assessments of enterprise data repositories. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)