Data Security Specialist

Milbank LLP

New York (NY)

On-site

USD 140,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Milbank LLP is seeking a Data Security Specialist to protect the confidentiality of the firm’s data assets across cloud and on-premises environments. The role involves designing and implementing data protection measures, responding to incidents, and ensuring compliance with regulations like GDPR and CCPA.

The ideal candidate will have extensive experience in information security, particularly in data protection and DLP, alongside strong analytical and communication skills. We're offering a competitive salary range of $140,000 to $160,000.

Qualifications

  • 4+ years in information security with at least 2 years focused on data protection.
  • Hands-on experience with enterprise DLP and rights management platforms.
  • Experience in protecting sensitive data from generative AI exposure.

Responsibilities

  • Design data loss prevention policies across services and endpoints.
  • Investigate data security incidents and perform root-cause analysis.
  • Support compliance with GDPR, CCPA, and other regulations.

Skills

Data Loss Prevention (DLP)
Data Protection
Information Security
Microsoft M365
Generative AI Controls
Scripting/Automation

Education

Bachelor’s degree in computer science or Information Security

Tools

PowerShell
Python
KQL
Microsoft Purview
Azure Rights Management Services

Job description

The Data Security Specialist is responsible for protecting the confidentiality, integrity, and availability of the firm’s data assets across cloud and on-premises environments. This role designs, implements, and maintains controls that safeguard sensitive client, legal, and corporate information against unauthorized access, loss, and exfiltration — including emerging risks from generative AI and large language model (LLM) usage.

Responsibilities
Data Protection & Governance
  • Design and operate data loss prevention (DLP) policies across email, endpoints, and cloud services (Microsoft Purview, M365, Azure).
  • Implement and tune data classification, labeling, and encryption frameworks aligned with firm policy and regulatory requirements.
  • Manage rights management (IRM/MIP), tokenization, and key management solutions.
  • Design and enforce AI data leakage prevention controls — governing how sensitive data is used with Microsoft 365 Copilot, ChatGPT Enterprise, and other GenAI/LLM tools — including prompt and response monitoring, sensitivity-label enforcement, and blocking unsanctioned AI services.
Monitoring & Incident Response
  • Investigate data security incidents, perform root-cause analysis, lead containment and remediation.
  • Monitor SIEM, CASB, and DLP alerts; triage events and escalate per the incident response plan.
  • Partner with the SOC and forensics teams on insider threat and exfiltration investigations.
  • Detect and respond to AI-related data exposure events, including sensitive data submitted to public LLMs, prompt injection, and shadow AI usage.
Risk & Compliance
  • Support compliance with GDPR, CCPA, NYDFS Part 500, SOC 2, and client security obligations.
  • Conduct data risk assessments for new applications, vendors, and AI/LLM use cases.
  • Maintain evidence and artifacts for internal and external audits.
  • Contribute to the firm’s AI governance program, aligning controls with frameworks such as NIST AI RMF and ISO/IEC 42001.
Engineering & Automation
  • Develop scripts and automations (PowerShell, Python, KQL) to scale data security operations.
  • Integrate data security controls into CI/CD, SaaS onboarding, and identity workflows.
  • Maintain documentation, runbooks, and control mappings.
Compensation

The anticipated base salary range offered for this role will be between $140,000 to 160,000 and represents the firm’s good faith and reasonable estimate of the range of possible base compensation. Actual base compensation will be dependent upon several factors, including but not limited to the candidate’s relevant experience, performance, qualifications, degrees, and location, well as the needs of the firm.

Qualifications
  • Bachelor’s degree in computer science, Information Security, or related field (equivalent experience accepted).
  • 4+ years in information security with at least 2 years focused on data protection, DLP, or data governance.
  • In-depth, hands-on experience with a range of enterprise DLP and rights management platforms, with deep expertise in the Microsoft M365 stack — including Microsoft Purview DLP (Exchange Online, SharePoint, OneDrive, Teams, and Endpoint DLP), Microsoft Purview Information Protection (MIP) sensitivity labels, Azure Information Protection (AIP), Azure Rights Management Services (Azure RMS), Double Key Encryption (DKE), and Customer Key. Experience tuning policies, authoring custom sensitive information types (SITs), trainable classifiers, and integrating Purview with Defender for Cloud Apps (MCAS) is required.
  • Experience with Microsoft Purview Insider Risk Management, Communication Compliance, eDiscovery (Premium), and Data Lifecycle Management.
  • Demonstrated experience with AI data leakage prevention — protecting sensitive data from exposure to generative AI and LLM services. This includes hands-on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub, Copilot interaction auditing, sensitivity-label enforcement on Copilot responses), CASB/SSE-based GenAI app discovery and blocking (Defender for Cloud Apps, Netskope, Zscaler), prompt and response inspection, and policies preventing the upload or pasting of sensitive content into public AI tools (ChatGPT, Gemini, Claude, etc.).
  • Working knowledge of third-party DLP/IRM tools (e.g., Symantec/Broadcom DLP, Forcepoint, Netskope, Zscaler, Digital Guardian) and how they complement or integrate with M365 controls.
  • Hands-on experience with at least one major cloud (Azure, AWS, or GCP).
  • Working knowledge of encryption standards, PKI, IAM, and Zero Trust principles.
  • Familiarity with regulatory frameworks: GDPR, CCPA, HIPAA, NYDFS, SOC 2, ISO 27001.
  • Strong analytical, written, and verbal communication skills.
Preferred Qualifications
  • Industry certifications: SC-400 (Microsoft Information Protection Administrator), CISSP, CIPP, CCSP, AZ-500, or GIAC equivalents.
  • Experience in a law firm, financial services, or other highly regulated environment.
  • Scripting/automation proficiency (PowerShell — including Exchange Online, Compliance Center, and Graph PowerShell modules — Python, KQL).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Principal Architect
Data Security Principal Architect

Compunnel, Inc. • Cumberland (RI)

On-site
USD 120,000 - 160,000
Senior Information Security Engineer - Data Protection & Insider Risk
Senior Information Security Engineer - Data Protection & Insider Risk

Cravath, Swaine & Moore LLP • New York (NY)

Hybrid
USD 160,000 - 200,000
Medical, dental, vision insurance
401(k) plan with company match
Paid time off and health club benefits
+1
Lead AI and Data Security Engineer
Lead AI and Data Security Engineer

East West Bank • San Marino (CA)

On-site
USD 160,000 - 220,000
AI Security Specialist
AI Security Specialist

MAP SSG • New York (NY)

On-site
USD 140,000 - 180,000
AI Security Specialist
AI Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 180,000
Data Protection Consultant – Purview, DLP & AI Security
Data Protection Consultant – Purview, DLP & AI Security

Jobtailor • United States

On-site
USD 150,000 - 190,000
Data Security Administrator
Data Security Administrator

Jobtailor • City of Syracuse (NY)

Hybrid
USD 90,000 - 120,000
Sr Data Protection & Governance Analyst
Sr Data Protection & Governance Analyst

Starkey Laboratories • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Medical Insurance
Dental & Vision Insurance
401(k) Matching
+4
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement benefits
Paid time off
Data Security Analyst
Data Security Analyst

Clarivate • Philadelphia

Hybrid
USD 90,000 - 120,000