> Markdown version of [/jobs/ext/2636654-information-security-engineer-data-protection-insider-risk-hybrid](https://www.wearedevelopers.com/jobs/ext/2636654-information-security-engineer-data-protection-insider-risk-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - Data Protection & Insider Risk - Hybrid - **Company:** Genesis10 - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $160,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Leak Prevention, Data Loss, Data Security, Identity and Access Management, Python (Programming Language), Microsoft Security Essentials, Windows PowerShell, Role-Based Access Control, Azure Active Directory, Cloud Services, Kusto Query Language, Runbook, Unstructured Data, Enterprise Data Management, Privacy Controls, EndPointSecurity, Symantec, Data Logging, Data Processing, Scripting, Data Classification, Okta, Microsoft Power Automate, Large Language Models, Information Technology, SailPoint - **Published:** August 8, 2026 - **Apply:** https://www.dice.com/job-detail/5bc6ecc4-7ce7-4c47-a3e6-df777c83004f ## About the Role * At least 7 years of experience in information security, with direct focus on data protection, insider risk, or identity governance * Hands-on experience with one or more DLP and data classification platforms (e.g., Microsoft Purview, Symantec, Forcepoint, Netskope, etc.) * Experience managing identity and access governance solutions (e.g., Microsoft Entra ID Governance, SailPoint, Saviynt, Okta IGA) * Working knowledge of Microsoft security ecosystem (Purview, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Sentinel) * Strong understanding of data classification schemes, sensitive data types, and data handling controls * Experience investigating security alerts and incidents involving user behavior and data misuse * Familiarity with endpoint, cloud, and SaaS security architectures * Strong documentation, communication, and cross-functional collaboration skills * Ability to work additional hours as needed Desired skills: * Experience with User and Entity Behavior Analytics (UEBA) or insider risk platforms * Knowledge of privacy-by-design principles and employee monitoring considerations * Scripting or automation experience (PowerShell, Python, KQL, etc.) * Security certifications such as CISSP, CISM, CCSP, GIAC, or vendor-specific certifications * Bachelor's degree in Information Security, Computer Science, Information Technology, or a related technical field ## Description We are seeking an experienced, dynamic Senior Information Security Engineer with expertise in data leakage prevention (DLP), insider risk management, and identity and access governance (IAG). This role is responsible for protecting sensitive data across endpoints, cloud services, and SaaS platforms by designing, implementing, and operating security controls that identify, classify, monitor, and govern access to enterprise data. This position also plays a hands-on role in securing Microsoft Copilot for M365 and other emerging AI-enabled tools, focusing on technical controls, data protection enforcement, and security logging. The ideal candidate has experience managing data classification and labeling programs, insider risk detection, identity governance platforms, and modern security tooling, and is comfortable working across IT, security, and compliance functions to enable the business securely., * Designs, implements, and operates Data Loss/Leakage Prevention (DLP) controls across endpoints, email, cloud services, and SaaS platforms * Leads and maintains data identification, classification, and labeling strategies for structured and unstructured data * Monitors, investigates, and responds to data exfiltration and misuse events, including both accidental and malicious activity * Tunes detection policies to reduce false positives while maintaining effective risk coverage * Operates and enhances insider risk detection and response programs, including behavioral analytics and user activity monitoring * Partners with IT/IS management on insider risk investigations, ensuring appropriate governance and privacy controls * Develops workflows for escalation, evidence handling, and remediation of insider risk incidents * Manages and optimizes identity and access governance (IAG) platforms, including access reviews, entitlement management, and lifecycle automation * Supports least-privilege access models, role-based access control (RBAC), and segregation of duties (SoD) initiatives * Integrates identity signals with data protection and insider risk tooling to enable contextual, risk-based controls * Serves as a subject matter expert for security platforms related to DLP, insider risk, data classification, and identity governance * Evaluates, onboards, and operationalizes new security tools and features * Creates and maintains runbooks, procedures, dashboards, and metrics to demonstrate program effectiveness * Supports regulatory and compliance requirements related to data protection and access control (e.g., SOX, HIPAA, GDPR, CCPA, etc., as applicable) * Provides guidance to IT and business teams on secure data handling and access practices * Contributes to security awareness efforts related to data handling, insider risk, and acceptable use * Implements and operates security controls for Microsoft Copilot for M365 using Purview, Defender, and Entra ID to enforce access boundaries and reduce data exposure * Configures DLP, sensitivity labels, permissions, logging, and alerting to ensure AI-assisted access aligns with data classification and authorization models * Investigates and responds to data exposure or misuse involving Copilot or other AI-enabled workflows, and support secure onboarding of additional AI/LLM tools * Performs additional duties as assigned ## Related Videos - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [3 Key Steps for Optimizing DevOps Workflows](https://www.wearedevelopers.com/videos/962-3-key-steps-for-optimizing-devops-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)