R/GA

Staff Data Security Engineer

R/GA
Apply
11 days ago
Remote, United StatesStaff+

Base Salary

$127k - $189k/yr

Responsibilities

  • Design, deploy, tune, and manage DLP policies across Microsoft 365, Exchange Online, SharePoint, Teams, OneDrive, endpoints, cloud applications, SaaS platforms, on-premises systems, and network egress points.
  • Configure sensitivity labels, trainable classifiers, exact data match, adaptive protection, incident management, and Microsoft Defender integrations.
  • Manage Microsoft Defender for Endpoint, Endpoint DLP, Microsoft Defender for Cloud Apps, and related monitoring and control capabilities.
  • Configure Sentinel data connectors, KQL analytics rules, workbooks, and SOAR playbooks for DLP alerts and email-security events.
  • Monitor DLP incidents, perform root-cause analysis, reduce false positives, and continuously improve security controls and business processes.
  • Deploy and manage DSPM tooling, conduct data-risk assessments, identify overexposed sensitive data, and drive remediation with data owners.
  • Use Varonis for data-access governance, entitlement reviews, and abnormal-access detection across file shares, SharePoint, and cloud storage.
  • Develop data-handling standards, acceptable-use policies, enforcement models, automation, technical documentation, runbooks, SOPs, and leadership reporting.
  • Partner with IT, Legal, Compliance, business stakeholders, and data owners to classify and protect sensitive data assets.

Requirements

  • Bachelor’s degree in arts/sciences or equivalent experience.
  • At least 6 years of information-security experience, including at least 4 years focused on data security, DLP, or DSPM.
  • Hands-on expertise with Microsoft Purview DLP and strong proficiency with the Microsoft Defender XDR suite.
  • Demonstrated experience with Microsoft Sentinel, custom analytic rules, KQL query development, workbooks, and SOAR playbooks.
  • Experience with the Varonis Data Security Platform, DSPM concepts, data classification, and Microsoft Purview Information Protection.
  • Experience implementing DLP across email, endpoints, cloud applications, and network vectors.
  • Knowledge of ISO 27001/27701, SOC 2, and NIST-aligned compliance and security frameworks.
  • Experience implementing DMARC, SPF, and DKIM in Microsoft 365.
  • Preferred qualifications include Microsoft SC-400, SC-200, SC-100, or AZ-500 certifications; experience with Symantec DLP, Forcepoint, or Zscaler; and familiarity with CSPM in Azure, AWS, or GCP.

Benefits

  • Remote position, indicated by the #LI-Remote designation.
  • Annual bonus plan eligibility and possible participation in a long-term equity incentive plan.
  • Health, retirement, and other employee benefits.
  • Opportunities to work with diverse global colleagues in a respectful, collaborative environment.
R/GA

About R/GA

1,001-5,000 employees
Contact me