Data Security Specialist w/ DLP, M365 and Azure

Intersources Inc.
Washington, DC, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cyber Security Continuous Integration Data Governance Information Leak Prevention Data Security Identity and Access Management Information Lifecycle Management
+21 more
Python (Programming Language) Key Management Massachusetts Comprehensive Assessment Systems Open Web Application Security Public Key Infrastructure Windows PowerShell Broadcom Cloud Services Kusto Query Language Zero Trust Network Access Runbook Microsoft SharePoint Security Information and Event Management Symantec Scripting Data Classification Office365 Large Language Models AI Platforms Information Technology GPT

Job description

The Data Security Specialist is responsible for protecting the confidentiality, integrity, and availability of the firm’s data assets across cloud and on-premises environments. This role designs, implements, and maintains controls that safeguard sensitive client, legal, and corporate information against unauthorized access, loss, and exfiltration - including emerging risks from generative AI and large language model (LLM) usage., Data Protection & Governance

  • Design and operate data loss prevention (DLP) policies across email, endpoints, and cloud services (Microsoft Purview, M365, Azure).
  • Implement and tune data classification, labeling, and encryption frameworks aligned with firm policy and regulatory requirements.
  • Manage rights management (IRM/MIP), tokenization, and key management solutions.
  • Design and enforce AI data leakage prevention controls - governing how sensitive data is used with Microsoft 365 Copilot, ChatGPT Enterprise, and other GenAI/LLM tools - including prompt and response monitoring, sensitivity-label enforcement, and blocking unsanctioned AI services.

Monitoring & Incident Response

  • Investigate data security incidents, perform root-cause analysis, lead containment and remediation.
  • Monitor SIEM, CASB, and DLP alerts; triage events and escalate per the incident response plan.
  • Partner with the SOC and forensics teams on insider threat and exfiltration investigations.
  • Detect and respond to AI-related data exposure events, including sensitive data submitted to public LLMs, prompt injection, and shadow AI usage.

Risk & Compliance

  • Support compliance with GDPR, CCPA, NYDFS Part 500, SOC 2, and client security obligations.
  • Conduct data risk assessments for new applications, vendors, and AI/LLM use cases.
  • Maintain evidence and artifacts for internal and external audits.
  • Contribute to the firm’s AI governance program, aligning controls with frameworks such as NIST AI RMF and ISO/IEC 42001.

Engineering & Automation

  • Develop scripts and automations (PowerShell, Python, KQL) to scale data security operations.
  • Integrate data security controls into CI/CD, SaaS onboarding, and identity workflows.
  • Maintain documentation, runbooks, and control mappings.

Collaboration

  • Advise business units, and IT teams on secure data handling practices.
  • Deliver targeted training and awareness on data protection topics.

Requirements

Candidate Job description below) : Candidates must have hands-on expertise with the Microsoft M365/Purview stack (DLP, sensitivity labels, AIP, Insider Risk Management), AI data leakage prevention using tools like Defender for Cloud Apps or Netskope, scripting in PowerShell/Python/KQL, and familiarity with compliance frameworks like GDPR, CCPA, and SOC 2. The Data Security Specialist is responsible for protecting the confidentiality, integrity, and availability of the firm’s data assets across cloud and on-premises environments. This role designs, implements, and maintains controls that safeguard sensitive client, legal, and corporate information against unauthorized access, loss, and exfiltration - including emerging risks from generative AI and large language model (LLM) usage.

They would prefer candidates with work experience in financial institutions, government, or any highly regulated industry. Roles are remote but would like people in the NYC or DC area to be in office for interviews. Attached are job descriptions and below are some highlights of what they’re looking for., * Bachelor’s degree in computer science, Information Security, or related field (equivalent experience accepted).

  • 4+ years in information security with at least 2 years focused on data protection, DLP, or data governance.
  • In-depth, hands-on experience with a range of enterprise DLP and rights management platforms, with deep expertise in the Microsoft M365 stack - including Microsoft Purview DLP (Exchange Online, SharePoint, OneDrive, Teams, and Endpoint DLP), Microsoft Purview Information Protection (MIP) sensitivity labels, Azure Information Protection (AIP), Azure Rights Management Services (Azure RMS), Double Key Encryption (DKE), and Customer Key. Experience tuning policies, authoring custom sensitive information types (SITs), trainable classifiers, and integrating Purview with Defender for Cloud Apps (MCAS) is required.
  • Experience with Microsoft Purview Insider Risk Management, Communication Compliance, eDiscovery (Premium), and Data Lifecycle Management.
  • Demonstrated experience with AI data leakage prevention - protecting sensitive data from exposure to generative AI and LLM services. This includes hands-on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub, Copilot interaction auditing, sensitivity-label enforcement on Copilot responses), CASB/SSE-based GenAI app discovery and blocking (Defender for Cloud Apps, Netskope, Zscaler), prompt and response inspection, and policies preventing the upload or pasting of sensitive content into public AI tools (ChatGPT, Gemini, Claude, etc.).
  • Working knowledge of third-party DLP/IRM tools (e.g., Symantec/Broadcom DLP, Forcepoint, Netskope, Zscaler, Digital Guardian) and how they complement or integrate with M365 controls.
  • Hands-on experience with at least one major cloud (Azure, AWS, or GCP).
  • Working knowledge of encryption standards, PKI, IAM, and Zero Trust principles.
  • Familiarity with regulatory frameworks: GDPR, CCPA, HIPAA, NYDFS, SOC 2, ISO 27001.
  • Strong analytical, written, and verbal communication skills., * Industry certifications: SC-400 (Microsoft Information Protection Administrator), CISSP, CIPP, CCSP, AZ-500, or GIAC equivalents.
  • Experience in a law firm, financial services, or other highly regulated environment.
  • Scripting/automation proficiency (PowerShell - including Exchange Online, Compliance Center, and Graph PowerShell modules - Python, KQL).
  • Familiarity with AI security frameworks (NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLM Applications) and emerging AI threat patterns such as prompt injection and model data exfiltration., * Risk-based decision making
  • Attention to detail and confidentiality
  • Cross-functional collaboration
  • Continuous learning in a rapidly evolving threat landscape

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on intersourcesinc.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:42 min

Balancing security compliance regulations with rapid AI experimentation

Damandeep Kochhar Damandeep Kochhar +4 · WWC Europe 2026

54 sec

Overview of enterprise Java and generative AI

Timo Salm Timo Salm · WWC 2025

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

1:05 min

Session overview and setup for building AI applications

Sandra Ahlgrimm Sandra Ahlgrimm +1 · WWC 2024

Videos

See all

Related articles

See all