> Markdown version of [/jobs/ext/1846470-data-protection-engineer-journeyman-ussocom-zero-trust](https://www.wearedevelopers.com/jobs/ext/1846470-data-protection-engineer-journeyman-ussocom-zero-trust). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Data Protection Engineer - Journeyman (USSOCOM/Zero Trust) - **Company:** Kentro LLC - **Location:** Tampa, FL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Data Centers, Information Leak Prevention, Data Security, Identity and Access Management, Network Security, Network Monitoring, Windows PowerShell, Azure Active Directory, Kusto Query Language, Zero Trust Network Access, Software Vulnerability Management, Enterprise Data Management, Data Processing, Scripting, Cloud Platform System, Data Classification, HybridCloud, Information Technology, Cloud Migration, Splunk, Devsecops - **Published:** July 2, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9009416/data-protection-engineer-journeyman-ussocomzero-trust ## About the Role * Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related field. Additional years of relevant experience may substitute for education in accordance with contract requirements. * Experience: 3-7 years of experience in cybersecurity, information assurance, cloud security, or data protection engineering. Experience supporting DoD or Federal Government environments is preferred. * Technical Skills: Microsoft Purview, Microsoft Defender XDR, Microsoft Defender for Cloud Apps, Microsoft Entra ID, Trellix Data Loss Prevention (DLP), data classification, encryption technologies, cloud security fundamentals, PowerShell or Python scripting, and security monitoring. * Working knowledge of DoD Zero Trust Architecture, NIST SP 800-207, NIST Risk Management Framework (RMF), NIST SP 800-53, and DoD Controlled Unclassified Information (CUI) requirements. * Required Certifications: Active DoD 8570/8140 IAT Level II certification (e.g., Security+ CE, CySA+, CCNA Security, or equivalent)., * Experience administering Microsoft Purview and Microsoft Defender security products. * Familiarity with Trellix DLP administration and data protection technologies. * Experience supporting USSOCOM, SOF, or other DoD organizations. * Exposure to DevSecOps, Platform One, and Continuous ATO (cATO) concepts. * Experience supporting cloud migration or hybrid cloud environments. * Knowledge of Zero Trust principles and identity-based security models. * Familiarity with Cross Domain Solutions (CDS) and classified data handling. * Basic experience with Kusto Query Language (KQL) or Splunk Processing Language (SPL). * Strong analytical, troubleshooting, and communication skills with the ability to work effectively within cross-functional engineering teams. Clearance Requirement: * Minimum Clearance - TS/SCI * Must be a US Citizen ## Description Kentro is hiring for a Journeyman Data Protection Engineer to support USSOCOM/EDAT - Zero Trust Data. The Journeyman Data Protection Engineer supports the implementation, administration, and optimization of enterprise data protection capabilities across Microsoft and Trellix security platforms. Working under the guidance of senior engineers and architects, this role assists in securing sensitive government data, implementing Data Loss Prevention (DLP) controls, supporting Zero Trust initiatives, and maintaining compliance with DoD cybersecurity requirements., * Azure Security & XDR: Support the deployment, configuration, and maintenance of Microsoft Purview and Microsoft Defender XDR solutions across cloud and hybrid enterprise environments. Assist with monitoring security alerts, investigating incidents, and implementing recommended security improvements. * Defender Suite & Access Management: Assist in administering Microsoft Defender security services, Microsoft Purview, Defender for Cloud Apps, Microsoft Entra ID, and Conditional Access policies to protect enterprise resources and enforce identity-based security controls. * Trellix DLP Administration:Configure, maintain, and troubleshoot Trellix Data Loss Prevention (DLP) policies to protect Controlled Unclassified Information (CUI) and other sensitive government data. Support policy tuning and incident response activities. * Network Data Security: Support the operation and maintenance of Trellix Network Prevent and Monitor services. Assist with monitoring network traffic, investigating potential data exfiltration events, and implementing data protection controls. * Datacenter & Hybrid Security: Assist in implementing and maintaining security controls protecting data moving between on-premises datacenters and cloud environments. Support encryption, secure communications, and network security initiatives. * Zero Trust Implementation: Support the implementation of Zero Trust data protection capabilities aligned with DoD Zero Trust Architecture and NIST SP 800-207 guidance. * Identity & Access Integration: Collaborate with Identity and ICAM teams to integrate data protection controls with identity services, including Attribute-Based Access Control (ABAC) and policy-based access management. * Compliance & Continuous Monitoring: Assist with Continuous Authorization to Operate (cATO) activities by supporting security assessments, compliance validation, vulnerability remediation, and continuous monitoring of enterprise data security controls. * Documentation & Operations: Develop technical documentation, standard operating procedures, security implementation guides, and engineering documentation. Participate in troubleshooting, change management, and operational support activities ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)