Purview Incident Response Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
The Purview Incident Response Analyst specializes in responding to data security, insider risk, and information protection incidents within Microsoft environments. The analyst uses Microsoft Purview, Microsoft Azure, CrowdStrike, Sumo Logic, and related security monitoring platforms to investigate suspicious activity, assess data exposure risks, and support remediation. This six month contract role partners with compliance, legal, cybersecurity, business, and application teams to protect sensitive data and support organizational security requirements. The role may include participation in a 24 hour on call support rotation. Responsibilities: Lead complex reviews, investigations, response, recovery, and remediation activities for data security, insider risk, and information protection incidents. Use Microsoft Purview and related monitoring platforms to identify suspicious activity, analyze potential data exposure, preserve relevant evidence, and document investigation findings. Architect, design, implement, and improve security technologies and processes in collaboration with security leadership, departmental colleagues, and business and application owners. Manage, administer, monitor, and support two to three security applications, resolve operational issues, automate repeatable processes, and cross train team members. Measure and report enterprise security capabilities using automated and manual tools. Develop and maintain security policies, standards, standard operating procedures, security strategies, capability plans, and business case documents. Perform security, risk, and impact reviews for new and existing systems before and after implementation. Develop, maintain, audit, and enhance enterprise security controls across cloud, data protection, endpoint, identity, network, application, database, and server environments. Respond to audits, assessments, and compliance requests, including work related to HIPAA, Payment Card Industry standards, National Institute of Standards and Technology guidance, and other applicable requirements. Contribute to security awareness training and communications, mentor junior staff, and participate in an on call rotation as assigned. Perform other duties as assigned.
Requirements
Minimum five years of cybersecurity experience and minimum eight years of information technology experience. Bachelor’s degree or equivalent in a technical discipline, or a corresponding educational background supported by professional security certifications relevant to the role. Demonstrated experience leading complex security incident investigations and response activities involving data security, insider risk, information protection, or data loss prevention. Experience leading, supporting, managing, and administering at least one security application, with the ability to work independently across broad security initiatives. In depth knowledge of information security principles, threats, risks, controls, and network, application, systems, cloud, and data security architecture. Experience documenting, designing, and implementing security controls across desktop, server, network, database, cloud, and application environments. Experience with security posture and exposure management, threat detection, vulnerability identification and remediation, identity protection, security operations, and security orchestration, automation, and response capabilities. Experience leading security projects and initiatives, with strong leadership, project management, communication, customer service, and organizational skills. Experience supporting HIPAA, Payment Card Industry, National Institute of Standards and Technology, and related audit or compliance requirements. One advanced, professional, or expert level security certification is preferred. Tools and Technologies: Microsoft Purview, including data loss prevention, insider risk, information protection, and incident investigation capabilities Microsoft Azure and cloud security capabilities
About the company
MatchPoint Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US. We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India. Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise. We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Understanding and Mitigating Common Web Vulnerabilities
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again