> Markdown version of [/jobs/ext/2255936-data-security-engineer](https://www.wearedevelopers.com/jobs/ext/2255936-data-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Data Security Engineer - **Company:** Fsp Retail Team - **Location:** Glasgow, UK - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Data Governance, Information Leak Prevention, Data Security, Information Lifecycle Management, Microsoft Data Access Components, Microsoft Security Essentials, Software Security, Microsoft Fabric, CIS Benchmarks - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815094924-data-security-engineer ## About the Role * Experienced consultant with strong Microsoft data security expertise, particularly Microsoft Purview, information protection, data loss prevention and SaaS governance, with the ability to apply these capabilities in customer environments. * Comfortable assessing security posture, identifying control gaps and developing practical, prioritised remediation plans across Microsoft 365, endpoint and SaaS environments, aligned to customer risk and business priorities. * Clear communicator who can translate security risks, business requirements and implementation constraints into high-quality customer deliverables, actionable outcomes and clear recommendations for technical and non-technical stakeholders. * Commercially aware, with experience contributing to consultancy delivery, requirements gathering, pre-sales activity and Statements of Work, while supporting practical scope, effort and outcome definition. Knowledge and experience in the following areas is highly advantageous: * Proven experience with Defender for Cloud Apps for SaaS discovery, governance and risk management. * Understanding and knowledge of security baselines and control frameworks used to support risk-based recommendations. * Experience of phased adoption approaches for data security and application governance controls. * Working knowledge of Azure DevOps or similar delivery tooling., * SC-401 (Microsoft Information Security Administrator Associate) * SC-400 (Microsoft Information Protection and Compliance Administrator Associate) * MS-102 (Microsoft 365 Administrator Expert), * Strong alignment with FSP values and ethos * Commitment to teamwork, quality and mutual success * Proactivity with an ability to operate with pace and energy * Strong communication and interpersonal skills * Dedication to excellence and quality ## Description Role Overview We have an exciting opportunity for a Data Security Engineer to join our Cyber Engineering team, providing technical consultancy and service innovation across Microsoft-aligned cyber security offerings. The role focuses on data, identity and application security, with strong expertise in Microsoft Purview and supporting knowledge of Defender for Cloud Apps. Working with customers, teammates and service leads, you will assess security posture, identify risks and control gaps, and develop practical remediation plans aligned to business objectives. Responsibilities: * Design and govern secure, practical controls that help organisations manage data risk, improve visibility and deliver measurable business value. * Provide expert guidance on Microsoft security capabilities, including Purview (information protection, data lifecycle, DLP, insider risk) and Defender for Cloud Apps, enabling effective data governance and SaaS visibility. * Deliver security gap analysis and maturity assessments across Microsoft 365, endpoint and SaaS environments, identifying risks and defining prioritised, actionable remediation plans. * Design and assure secure, scalable solutions aligned to customer needs, contributing to service innovation and engaging stakeholders to translate business objectives into practical, high-quality security outcomes. * Perform security assessments and maturity reviews across Microsoft 365, endpoint and SaaS environments, identifying risks and delivering prioritised remediation roadmaps. * Contribute to the growth and maturity of the Cyber Engineering service by producing high-quality customer deliverables and supporting pre-sales activity. * Maintain deep expertise in emerging threats, Microsoft security capabilities and industry frameworks to ensure customers benefit from current best practice. * Help evolve our services and drive consistency across customer environments, sharing knowledge across the team and helping shape repeatable Microsoft security offerings. About you: * Experienced consultant with strong Microsoft data security expertise, particularly Microsoft Purview, information protection, data loss prevention and SaaS governance, with the ability to apply these capabilities in customer environments. * Comfortable assessing security posture, identifying control gaps and developing practical, prioritised remediation plans across Microsoft 365, endpoint and SaaS environments, aligned to customer risk and business priorities. * Clear communicator who can translate security risks, business requirements and implementation constraints into high-quality customer deliverables, actionable outcomes and clear recommendations for technical and non-technical stakeholders. * Commercially aware, with experience contributing to consultancy delivery, requirements gathering, pre-sales activity and Statements of Work, while supporting practical scope, effort and outcome definition. Knowledge and experience in the following areas is highly advantageous: * Proven experience with Defender for Cloud Apps for SaaS discovery, governance and risk management. * Understanding and knowledge of security baselines and control frameworks used to support risk-based recommendations. * Experience of phased adoption approaches for data security and application governance controls. * Working knowledge of Azure DevOps or similar delivery tooling. Desirable certifications: * SC-401 (Microsoft Information Security Administrator Associate) * SC-400 (Microsoft Information Protection and Compliance Administrator Associate) * MS-102 (Microsoft 365 Administrator Expert) * SC-200 (Microsoft Security Operations Analyst Associate) What we look for in our people * Strong alignment with FSP values and ethos * Commitment to teamwork, quality and mutual success * Proactivity with an ability to operate with pace and energy * Strong communication and interpersonal skills * Dedication to excellence and quality Who are FSP? FSP is a leading consultancy specialising in Digital, Security and AI solutions. Our success is enabled by our unwavering commitment to excellence, our people centric culture alongside best-in-class operations, ensuring impactful and sustainable outcomes for our clients. As a long standing and highly accredited Microsoft Partner, with extensive solution designations, we partner with clients across a range of commercial sectors, enabling digital transformation, innovation and robust cyber security. We navigate the complexities of data sensitivity, confidentiality, governance and compliance. We blend strategic insight, depth of technical expertise, delivery and operational excellence to meet the specific requirements outlined. We take a collaborative, one team approach with our clients to drive sustainable change, providing outstanding client experience and delivering exceptional results that are aligned with business priorities. Our commitment to security and quality is reinforced by our ISO27001 and ISO9001 certifications (UKAS), as well as our CREST approved penetration testing and SOC capabilities. Additionally, we are an IASME Cyber Essentials Certification Body and Cyber Essentials Plus certified. Find out more about our accolades here: about-fsp ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)