Summary
What you’ll impact
The Senior Data Security Engineer will architect, deploy, and manage advanced data protection solutions for the organization, focusing on cloud security and data protection technologies. This role serves as the primary subject matter expert for security technologies and leads integration of data catalog and rights management across classified environments.
Responsibilities
What you'll do
- Azure Security & XDR: Architect and manage comprehensive Azure security solutions, serving as the primary lead for deploying and tuning Microsoft Purview and Microsoft Defender XDR across hybrid and classified environments.
- Defender & Access Policy: Design and configure precise security policies within the Microsoft Defender suite, specifically leveraging Microsoft Purview, Microsoft Defender for Cloud Apps (MCAS), Entra ID, and Microsoft Conditional Access to control resource access based on identity, device compliance, and risk.
- Trellix DLP Enforcement: Design, deploy, and enforce Trellix Full Data Loss Prevention (DLP) policies across endpoints and networks to stop unauthorized exfiltration of CUI and classified data without impacting mission performance.
- Data Rights Management: Manage Active Directory Rights Management (AD-RMS) and Azure RMS as the primary DRM engines to enforce persistent, encryption-based protection of files and emails across USSOCOM networks.
- Catalog & DLP Integration: Drive data catalog integration and metadata synchronization with enterprise platforms including Palantir, Microsoft Unified Catalog, Purview Audit, and Activity Explorer. Specifically, lead the integration of Palantir catalog solutions with Data Loss Prevention (DLP) tools to ensure seamless, end-to-end data security and monitoring.
- Classification Tuning: Collaborate with mission owners to train classifiers and DLP rules to recognize unique USSOCOM data types (e.g., mission names, operational codes) and drastically reduce false positive rates in security alerts.
Requirements
What you’ll bring
- Education: Bachelor's degree (BA/BS) in Computer Science, Cybersecurity, Information Technology, or a related technical discipline. Bachelor's Degree can be substituted for the following certifications:
- SecurityX / CASP+
- CCSP
- Cloud+
- CSC
- GCLD
- GCSA
- GSEC
- Experience: 10+ years of relevant experience in enterprise systems engineering, data security, or cybersecurity operations.
- Azure Security Expert: Expert-level proficiency in Microsoft Azure security architecture, with a dedicated focus on implementing and managing Microsoft Purview and Microsoft Defender XDR.
- Microsoft Purview (Sensitivity Labeling, DLP, Information Barrier policies).
- Microsoft Defender for Cloud Apps (Cloud Access Security Broker - CASB policies).
- Microsoft Entra ID (Identity and Access Management).
- Microsoft Conditional Access (Context-aware, zero-trust security policies).
- Trellix & Palantir DLP Expertise: Proven experience designing, tuning, and enforcing Trellix Full Data Loss Prevention (DLP) policies at an enterprise scale. Must have specific expertise in the integration of Palantir catalog solutions with Data Loss Prevention tools.
- Data Rights Management: Strong experience implementing and administering AD-RMS and Azure RMS in complex, multi-domain, or hybrid cloud environments.
- Data Catalog Integration: Proven experience integrating and managing metadata across enterprise catalogs such as Palantir, Microsoft Unified Catalog, and utilizing Purview Audit and Activity Explorer.
- Storage & Database Knowledge: Strong understanding of storage protocols (NFS, SMB/CIFS, S3) and database structures (SQL, NoSQL) to troubleshoot security scanning access.
- Must possess one of the following DoD 8570/8140 IAT Level III certifications:
- CISSP
- CASP+
- CCSP
- CISM
- TS/SCI
- Must be a US Citizen