Data Security Engineer

Fsp Retail Team
Glasgow, UK
4 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Artificial Intelligence Software System Penetration Testing Microsoft Azure Software as a Service Cloud Computing Cyber Security Data Governance Information Leak Prevention Data Security Information Lifecycle Management Microsoft Data Access Components
+4 more
Microsoft Security Essentials Software Security Microsoft Fabric CIS Benchmarks

Job description

Role Overview

We have an exciting opportunity for a Data Security Engineer to join our Cyber Engineering team, providing technical consultancy and service innovation across Microsoft-aligned cyber security offerings. The role focuses on data, identity and application security, with strong expertise in Microsoft Purview and supporting knowledge of Defender for Cloud Apps. Working with customers, teammates and service leads, you will assess security posture, identify risks and control gaps, and develop practical remediation plans aligned to business objectives.

Responsibilities:

  • Design and govern secure, practical controls that help organisations manage data risk, improve visibility and deliver measurable business value.

  • Provide expert guidance on Microsoft security capabilities, including Purview (information protection, data lifecycle, DLP, insider risk) and Defender for Cloud Apps, enabling effective data governance and SaaS visibility.

  • Deliver security gap analysis and maturity assessments across Microsoft 365, endpoint and SaaS environments, identifying risks and defining prioritised, actionable remediation plans.

  • Design and assure secure, scalable solutions aligned to customer needs, contributing to service innovation and engaging stakeholders to translate business objectives into practical, high-quality security outcomes.

  • Perform security assessments and maturity reviews across Microsoft 365, endpoint and SaaS environments, identifying risks and delivering prioritised remediation roadmaps.

  • Contribute to the growth and maturity of the Cyber Engineering service by producing high-quality customer deliverables and supporting pre-sales activity.

  • Maintain deep expertise in emerging threats, Microsoft security capabilities and industry frameworks to ensure customers benefit from current best practice.

  • Help evolve our services and drive consistency across customer environments, sharing knowledge across the team and helping shape repeatable Microsoft security offerings.

About you:

  • Experienced consultant with strong Microsoft data security expertise, particularly Microsoft Purview, information protection, data loss prevention and SaaS governance, with the ability to apply these capabilities in customer environments.

  • Comfortable assessing security posture, identifying control gaps and developing practical, prioritised remediation plans across Microsoft 365, endpoint and SaaS environments, aligned to customer risk and business priorities.

  • Clear communicator who can translate security risks, business requirements and implementation constraints into high-quality customer deliverables, actionable outcomes and clear recommendations for technical and non-technical stakeholders.

  • Commercially aware, with experience contributing to consultancy delivery, requirements gathering, pre-sales activity and Statements of Work, while supporting practical scope, effort and outcome definition.

Knowledge and experience in the following areas is highly advantageous:

  • Proven experience with Defender for Cloud Apps for SaaS discovery, governance and risk management.

  • Understanding and knowledge of security baselines and control frameworks used to support risk-based recommendations.

  • Experience of phased adoption approaches for data security and application governance controls.

  • Working knowledge of Azure DevOps or similar delivery tooling.

Desirable certifications:

  • SC-401 (Microsoft Information Security Administrator Associate)

  • SC-400 (Microsoft Information Protection and Compliance Administrator Associate)

  • MS-102 (Microsoft 365 Administrator Expert)

  • SC-200 (Microsoft Security Operations Analyst Associate)

What we look for in our people

  • Strong alignment with FSP values and ethos

  • Commitment to teamwork, quality and mutual success

  • Proactivity with an ability to operate with pace and energy

  • Strong communication and interpersonal skills

  • Dedication to excellence and quality

Who are FSP?

FSP is a leading consultancy specialising in Digital, Security and AI solutions. Our success is enabled by our unwavering commitment to excellence, our people centric culture alongside best-in-class operations, ensuring impactful and sustainable outcomes for our clients.

As a long standing and highly accredited Microsoft Partner, with extensive solution designations, we partner with clients across a range of commercial sectors, enabling digital transformation, innovation and robust cyber security.

We navigate the complexities of data sensitivity, confidentiality, governance and compliance. We blend strategic insight, depth of technical expertise, delivery and operational excellence to meet the specific requirements outlined.

We take a collaborative, one team approach with our clients to drive sustainable change, providing outstanding client experience and delivering exceptional results that are aligned with business priorities.

Our commitment to security and quality is reinforced by our ISO27001 and ISO9001 certifications (UKAS), as well as our CREST approved penetration testing and SOC capabilities. Additionally, we are an IASME Cyber Essentials Certification Body and Cyber Essentials Plus certified.

Find out more about our accolades here: about-fsp

Requirements

  • Experienced consultant with strong Microsoft data security expertise, particularly Microsoft Purview, information protection, data loss prevention and SaaS governance, with the ability to apply these capabilities in customer environments.

  • Comfortable assessing security posture, identifying control gaps and developing practical, prioritised remediation plans across Microsoft 365, endpoint and SaaS environments, aligned to customer risk and business priorities.

  • Clear communicator who can translate security risks, business requirements and implementation constraints into high-quality customer deliverables, actionable outcomes and clear recommendations for technical and non-technical stakeholders.

  • Commercially aware, with experience contributing to consultancy delivery, requirements gathering, pre-sales activity and Statements of Work, while supporting practical scope, effort and outcome definition.

Knowledge and experience in the following areas is highly advantageous:

  • Proven experience with Defender for Cloud Apps for SaaS discovery, governance and risk management.

  • Understanding and knowledge of security baselines and control frameworks used to support risk-based recommendations.

  • Experience of phased adoption approaches for data security and application governance controls.

  • Working knowledge of Azure DevOps or similar delivery tooling., * SC-401 (Microsoft Information Security Administrator Associate)

  • SC-400 (Microsoft Information Protection and Compliance Administrator Associate)

  • MS-102 (Microsoft 365 Administrator Expert), * Strong alignment with FSP values and ethos

  • Commitment to teamwork, quality and mutual success

  • Proactivity with an ability to operate with pace and energy

  • Strong communication and interpersonal skills

  • Dedication to excellence and quality

About the company

FSP is a leading consultancy specialising in Digital, Security and AI solutions. Our success is enabled by our unwavering commitment to excellence, our people centric culture alongside best-in-class operations, ensuring impactful and sustainable outcomes for our clients.

As a long standing and highly accredited Microsoft Partner, with extensive solution designations, we partner with clients across a range of commercial sectors, enabling digital transformation, innovation and robust cyber security.

We navigate the complexities of data sensitivity, confidentiality, governance and compliance. We blend strategic insight, depth of technical expertise, delivery and operational excellence to meet the specific requirements outlined.

We take a collaborative, one team approach with our clients to drive sustainable change, providing outstanding client experience and delivering exceptional results that are aligned with business priorities.

Our commitment to security and quality is reinforced by our ISO27001 and ISO9001 certifications (UKAS), as well as our CREST approved penetration testing and SOC capabilities. Additionally, we are an IASME Cyber Essentials Certification Body and Cyber Essentials Plus certified.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all