Security Engineer — Data Protection & Compliance
Experience Required: Mid-Level (8–10 Years)
Job Summary
This profile defines the technical skills and experience required for a Security Engineer specializing in data protection, information governance, and compliance engineering. The role demands deep hands-on expertise across the Microsoft Purview suite — including Data Loss Prevention, Microsoft Information Protection, Compliance Manager, and Data Map — alongside identity and access management via Microsoft Entra ID P2, mobile device management via Intune, and cloud application governance via Microsoft Defender for Cloud Apps (MCAS). The candidate must be able to design, deploy, and operationalise controls that satisfy regulatory data protection obligations in enterprise-scale, PHI-handling environments.
Experience Requirements
- 8–10 years total experience in data security, information protection, or compliance engineering
- Minimum 3 years of hands-on Microsoft Purview experience in production enterprise environments
- Demonstrated experience across both design/deployment and steady-state operations of DLP and classification controls
- Experience in regulated industries where sensitive personal data (healthcare, financial, or equivalent) is in scope
- Experience working in environments with large BYOD device populations preferred
Microsoft Purview — Data Loss Prevention
- 3+ years designing and operating DLP policies across Exchange, SharePoint, Teams, and Endpoint channels
- Hands-on experience with Purview DLP AI Endpoint policies, including blocking sensitive data uploads to public AI tools
- Proficient in DLP policy modes: simulation, audit, and enforcement, with understanding of transition processes
- Experience managing DLP incident queues, reviewing exceptions, and tuning false-positive rates
- Understanding of DLP prerequisites: label taxonomy, classifier deployment, and Intune enrollment
Microsoft Purview — Sensitivity Labels & MIP
- Experience designing and implementing organisation-wide sensitivity label taxonomies
- Hands-on configuration of auto-labelling policies for Exchange, SharePoint, and Teams
- Deployment and tuning of built-in and custom sensitive information types (PHI pattern and regex-based classifiers)
- Experience managing label publishing, label analytics, and Activity Explorer monitoring
- Understanding of client-side versus service-side labelling and their respective limitations
Microsoft Purview — Compliance Manager
- Experience managing compliance assessments within Purview Compliance Manager
- Ability to configure and operate HIPAA assessment templates, including score tracking and evidence uploads
- Experience producing compliance reporting outputs for senior stakeholders (CISO, Legal)
- Familiarity with multi-regulation assessment management (SOC 2, HIPAA, HITRUST)
Microsoft Purview — Data Map & Data Catalogue
- Experience configuring Purview Data Map scanning across M365, Azure, and SQL data sources
- Ability to design and manage classification rules and scanning schedules for PHI discovery
- Familiarity with data flow documentation and lineage mapping within the Purview Data Catalogue
- Experience producing PHI system inventory outputs from Data Map scan results
Microsoft Purview — Insider Risk, eDiscovery & Communication Compliance
- Configuration of Insider Risk Management policies for data exfiltration, policy violations, and departing employee scenarios
- Familiarity with Purview eDiscovery Premium, including legal holds, content search, and review set management
- Experience configuring Communication Compliance policies for sensitive content monitoring
- Understanding of Purview AI Hub for AI model governance and bias assessment processes
Microsoft Defender for Cloud Apps (MCAS)
- Hands-on configuration of Cloud Discovery, log collectors, Shadow IT reporting, and risk scoring
- Experience configuring Session Policies and Access Policies for sanctioned applications
- Connector configuration for third-party applications such as Google Workspace, Salesforce, and custom apps
- Anomaly detection policy configuration and alert tuning within MCAS
Microsoft Entra ID P2
- Conditional Access policy design covering device compliance, location, risk-based access, and MFA
- Experience managing Entra Terms of Use policies and user acceptance tracking
- Configuration of Entra Access Reviews, including delegation and remediation tracking
- Entra B2B governance including external user lifecycle and access package management
- Familiarity with Entra ID Protection risk policies and reporting
Microsoft Intune — MAM & Endpoint DLP
- Mobile Application Management (MAM) configuration for BYOD device populations
- Deployment of Intune compliance policies, configuration profiles, and app protection policies
- Integration of Intune enrollment with Purview Endpoint DLP controls (USB, printing, cloud uploads)
- Familiarity with Intune reporting and compliance dashboards
Third-Party Risk & Vendor Governance
- Experience managing HIPAA Business Associate Agreement (BAA) processes: vendor identification, execution tracking, BAA register maintenance
- Familiarity with Third-Party Risk Management (TPRM) frameworks and vendor risk assessment methodologies
- Ability to connect MCAS connectors for third-party SaaS applications and enforce DLP policies across them
Compliance Framework Knowledge
- Working knowledge of SOC 2 Trust Services Criteria — C1.x (Confidentiality) and CC6.x (Logical Access Controls)
- Solid understanding of HIPAA Security Rule Technical Safeguards: §164.312(a)(2)(iv) encryption, §164.312(e) transmission security, §164.310(d) device controls
- Familiarity with HIPAA Administrative Safeguards: §164.308(a)(1) risk management, §164.308(b) BA agreements
- Awareness of HITRUST r2 framework and its mapping to HIPAA controls
Technical Skills Assessment:
Certifications :
HR screening reference: Use the criteria below to map candidate CV and interview responses against minimum proficiency thresholds.
Purview DLP (Exchange/SharePoint/Teams)
- Category: Data Protection
- Minimum Proficiency: Policy deployment & enforcement
- Minimum Years: 3+
- Requirement: Required
Purview DLP — Endpoint & AI
- Category: Data Protection
- Minimum Proficiency: Endpoint DLP + AI block policies
- Minimum Years: 2+
- Requirement: Required
Purview MIP / Sensitivity Labels
- Category: Classification
- Minimum Proficiency: Taxonomy design & auto‑labeling
- Minimum Years: 3+
- Requirement: Required
Purview Compliance Manager
- Category: Compliance
- Minimum Proficiency: Assessment mgmt + score tracking
- Minimum Years: 2+
- Requirement: Required
Purview Data Map / Catalogue
- Category: Data Governance
- Minimum Proficiency: Scan config + PHI discovery
- Minimum Years: 1+
- Requirement: Highly Preferred
MCAS / Defender for Cloud Apps
- Category: Cloud App Security
- Minimum Proficiency: Cloud Discovery + Session Policy
- Minimum Years: 2+
- Requirement: Required
Microsoft Entra ID P2
- Category: Identity
- Minimum Proficiency: CA policy design + Access Reviews
- Minimum Years: 2+
- Requirement: Required
Microsoft Intune (MAM/MOM)
- Category: Endpoint
- Minimum Proficiency: MAM + compliance policies
- Minimum Years: 2+
- Requirement: Required
Purview Insider Risk Management
- Category: Compliance
- Minimum Proficiency: Policy configuration
- Minimum Years: 1+
- Requirement: Highly Preferred
Purview eDiscovery Premium
- Category: Legal / eDisc
- Minimum Proficiency: Legal hold + content search
- Minimum Years: 1+
- Requirement: Preferred
Purview Communication Compliance
- Category: Compliance
- Minimum Proficiency: Policy configuration
- Requirement: Preferred
AI Governance
- Category: AI Governance
- Minimum Proficiency: AI model bias assessment
- Requirement: Nice to Have
BAA / TPRM Process Management
- Category: Vendor Risk
- Minimum Proficiency: BAA tracking & risk assessment
- Requirement: Highly Preferred
SOC 2 CC1.x / CC6.x Controls
- Category: Compliance
- Minimum Proficiency: Working knowledge
- Requirement: Highly Preferred
HIPAA §164.308 – §164.312
- Category: Compliance
- Minimum Proficiency: Solid understanding
- Requirement: Required
HITRUST r2 Framework
- Category: Compliance
- Minimum Proficiency: Awareness
- Requirement: Nice to Have
Certifications :
SC-400: Information Protection and Compliance Administrator
- Issuing Body: Microsoft
- Requirement: Required
SC-300: Identity and Access Administrator Associate
- Issuing Body: Microsoft
- Requirement: Highly Preferred
AZ-500: Azure Security Engineer Associate
- Issuing Body: Microsoft
- Requirement: Preferred
CIPP/US — Certified Information Privacy Professional (US)
- Issuing Body: IAPP
- Requirement: Preferred
CIPP/E — Certified Information Privacy Professional (Europe)
- Issuing Body: IAPP
- Requirement: Nice to Have
CHPS — Certified in Healthcare Privacy and Security
- Issuing Body: AHIMA
- Requirement: Nice to Have
CISSP — Certified Information Systems Security Professional
- Issuing Body: ISC²
- Requirement: Nice to Have
Note: SC-400 is a hard requirement. Candidates without it must demonstrate an active study commitment and a credible path to certification within 90 days of joining.
Non-Technical Requirements :
Regulatory & Legal Awareness
- Ability to read and interpret regulatory text (HIPAA CFR §164, SOC 2 TSC) and map controls to technical implementations.
- Comfortable engaging with legal and compliance stakeholders on BAA scope, TPRM findings, and data classification decisions.
- Understands the distinction between administrative, physical, and technical safeguards under HIPAA.
Evidence & Audit Discipline
- Systematic approach to evidence collection, including DLP policy exports, label analytics reports, access review outputs, and Compliance Manager improvement action screenshots.
- Experience producing control evidence packages that satisfy external auditor requirements.
- Maintains audit trail for policy changes, exceptions granted, and remediation actions.
Vendor & Stakeholder Management
- Ability to coordinate with SaaS vendors (Google Workspace admin, Tableau admin) to implement security controls and execute BAAs.
- Experience briefing compliance and legal teams on data protection posture and gap status.
Submit the application on:
Application Form
Interested to work with us? Send us your application and we will reach out to you, if you candidature fits any of our open positions.