Назад
Company hidden
1 день назад

IR Engineer II - DLP Response Engineer (Purview)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IR Engineer II - DLP Response Engineer (Purview) (Microsoft Purview/DLP): Administering and improving Insider Risk Management and Data Loss Prevention capabilities across Microsoft 365, endpoints, email, collaboration, and cloud workloads with an accent on alert triage, policy engineering, and sensitive data protection. Focus on investigating insider risk and AI-related data security alerts, tuning detection logic, validating evidence, and coordinating risk-based escalations.

Location: Phoenix, Arizona, United States; full-time onsite role

Company

hirify.global is a financial institution serving clients nationwide through multiple bank brands and mortgage services.

What you will do

  • Administer, configure, test, and continuously improve Microsoft Purview Data Loss Prevention and Insider Risk Management policies, detection logic, thresholds, exceptions, exclusions, and workflows.
  • Manage sensitivity labels, Sensitive Information Types, trainable classifiers, policy tips, user notifications, endpoint DLP controls, and related information protection capabilities.
  • Monitor, validate, and triage DLP, insider risk, and AI-related alerts involving sensitive data, generative AI interactions, data movement, anomalous behavior, and potential policy violations.
  • Support investigations through evidence collection, case documentation, alert dispositioning, escalation routing, and correlation with identity, endpoint, user activity, and data security telemetry.
  • Improve detection accuracy and operational efficiency by analyzing false positives, tuning policies, refining use cases, and maintaining SOPs, runbooks, test plans, and case-handling guidance.
  • Coordinate with Security Operations, Data Governance, Privacy, Legal, HR, IT, and business stakeholders, while supporting audits, regulatory examinations, control testing, and reporting.

Requirements

  • 5+ years of experience in cybersecurity, information security, data protection, insider risk, security operations, compliance engineering, or a related technology function.
  • Intermediate to advanced experience administering or supporting Microsoft Purview or Microsoft 365 security, compliance, or information protection capabilities.
  • Intermediate to advanced experience reviewing, validating, or triaging security, compliance, DLP, insider risk, or user activity alerts.
  • Working knowledge of sensitive data handling, data loss prevention, information protection, data classification, risk-based monitoring, and telemetry correlation.
  • Strong analytical, documentation, troubleshooting, and communication skills, including the ability to translate technical findings into business risk.
  • High school diploma required; a related bachelor's degree is preferred. Advanced speaking and writing skills are required.

Nice to have

  • Experience with Purview Endpoint DLP and DLP for Exchange, Teams, SharePoint, and OneDrive, including custom rules, alert queues, policy tips, exceptions, and false-positive tuning.
  • Experience with Purview Insider Risk Management policies, indicators, user activity review, case workflows, and risk-based escalation.
  • Experience with sensitivity labels, encryption, auto-labeling, Sensitive Information Types, Exact Data Match, trainable classifiers, or data classification.
  • Microsoft SC-401, SC-200, SC-900, or SC-300 certification, or CISSP, CISM, Security+, or GSEC certification.

Culture & Benefits

  • Medical and dental insurance.
  • Paid time off and a 401(k) matching program.
  • Tuition assistance and a wellness program.
  • Employee volunteer program and an ownership stake in the company.
  • Opportunities to build business and financial knowledge through practical experience.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →