Senior Data Security Engineer (DLP & AI Security) - Microsoft Purview , Concentric AI & Varonis
Role details
Job location
Tech stack
Job description
Microsoft Purview Data Protection & Governance
-
Configure and manage Microsoft Purview Information Protection components:
-
Sensitivity labels
-
Data classification
-
Auto labeling policies
-
Implement and manage DLP policies across:
-
Exchange Online
-
SharePoint Online
-
OneDrive
-
Microsoft Teams
-
Endpoint DLP
-
Tune DLP rules to reduce false positives while ensuring regulatory compliance.
-
Monitor alerts, incidents, and policy violations; perform root cause analysis.
-
Support data discovery and classification scans across M365 workloads.
Concentric AI Sensitive Data Discovery & Risk Prioritization
-
Deploy and manage Concentric AI for:
-
Sensitive data discovery
-
Context aware risk scoring
-
Data access analytics
-
Identify overexposed, stale, or risky data across repositories.
-
Correlate user behavior, data sensitivity, and access patterns.
-
Use Concentric insights to fine tune Purview DLP and labeling strategies.
-
Generate risk based remediation recommendations.
Varonis Data Security Analytics & Access Governance
-
Deploy, configure, and manage Varonis modules for:
-
Sensitive data discovery and classification
-
Data access analytics and permissions analysis
-
Threat detection and data exposure reduction
-
Identify excessive permissions, inactive users, and anomalous data access.
-
Investigate insider threats, abnormal behavior, and data exfiltration attempts.
-
Drive remediation by tightening access controls and reducing data exposure.
-
Integrate Varonis insights with Purview and Concentric findings for unified risk management.
Incident Handling & Incident Response Support
-
Investigate data exposure and DLP incidents using Purview, Concentric, and Varonis dashboards.
-
Perform incident triage, analysis, and coordination with SOC, IR, and IT teams.
-
Support incident containment actions:
-
Policy blocks
-
User access restrictions
-
Label enforcement
-
Maintain incident documentation and post incident analysis reports.
Reporting, Governance & Compliance
-
Prepare monthly and quarterly reports covering:
-
Data risk posture
-
DLP trends
-
Sensitive data exposure metrics
-
Track KPIs such as:
-
Reduction in data exposure risk
-
DLP incident trends
-
Label adoption and coverage
-
Support audit and compliance initiatives aligned to:
-
ISO 27001
-
GDPR
-
SOC 2
-
HIPAA (where applicable)
-
Maintain SOPs, playbooks, and governance documentation.
Integration & Continuous Improvement
-
Integrate Purview and Concentric with:
-
Microsoft Entra ID
-
SIEM platforms (Splunk / Sentinel where applicable)
-
Recommend improvements for data security posture based on analytics.
-
Stay updated with evolving data security threats, Purview features, Concentric AI and Varonis capabilities.
Requirements
Primary Skill - Data Security, DLP Experience in - Data Classification, DLP solution. Role Owner of Data Security Program Resource needs to manage the tool as Admin / define new policies Mandatory Tools - Microsoft Purview & Concentric AI and/or Varnish Data Security Tools Good to have - DSPM. AI experience is required. (Mainly Security for AI)., We are looking for a skilled Data Security Engineer with strong hands on experience in Microsoft Purview Information Protection , Concentric AI and Varonis to support enterprise data discovery, classification, risk prioritization, and data loss prevention (DLP) initiatives. The role focuses on protecting sensitive and business critical data across cloud, endpoint, and collaboration platforms through automation, policy enforcement, analytics, and continuous risk reduction., * Strong hands on experience with Microsoft Purview Information Protection & DLP.
- Experience implementing Endpoint, M365, and Cloud DLP policies.
- Hands on exposure to Concentric AI for sensitive data discovery and risk analysis.
- Hands on experience with Varonis for data security analytics and access governance.
- Good understanding of data security, privacy, and information protection principles.
- Experience supporting enterprise scale M365 environments.
Good to Have
- Experience with Insider Risk Management.
- Familiarity with SIEM tools (Splunk, Sentinel).
- Understanding of data privacy regulations (GDPR, PCI DSS).
- Exposure to CASB / Defender for Cloud Apps.
Soft Skills
- Strong analytical and investigative mindset.
- Ability to convert technical findings into executive friendly insights.
- Excellent communication and documentation skills.
- Collaborative, process driven approach to security delivery.